Ethereum mainnetTransactions use real assets. Access is KYC-gated; review the legal and risk disclosures before transacting.

Corrovera review of the Solana curator vault

External review. This review was conducted by a party other than Forest Road. What the engagement did and did not cover is set out under Method and in the report itself, the limits of a review bear on what its findings are worth, and should be read alongside them. It does not by itself authorize a production launch. It reviews the source at the baseline below, which is not necessarily identical to the code deployed on any network. Forest Road Vault is live on Ethereum mainnet; its Solana curator vault remains on devnet and BSC has its own deployment status. An open finding applies only to the product, version and deployment state named by this review. Each review's scope bounds what its clean result is worth. Nothing here is a securities-law representation; token characterization is a matter for counsel.

Scope
The Solana curator-vault program, its tests and release tooling, the curator website paths, the canonical artifact and devnet evidence. It is not a review of the Ethereum V2 credit protocol, and no Solana mainnet deployment was in scope.
Method
Independent Corrovera review followed by two remediation verifications, execution probes, event and error census, stateful campaigns, committed mutation controls, reproducible-build checks and byte-for-byte comparison with the devnet ProgramData account.
Reviewed baseline
Initial closeout 99b0371; final remediated source b7164af; canonical devnet program 3ZPRvNDUDRZuZ8Hug873JtSDJueA8D7PEVE21uLLAvwh
Internal report
audit-reports/curator-vault-audit-2026-09-20/

Findings and remediation history

Result

The review and its two remediation verifications closed the four confirmed Medium source and test-assurance findings. The final package also corrected the notice/draw regression introduced by the first remediation. No High or Medium program-source or test-assurance finding remains in the current devnet release.

This result applies to the Solana curator vault and its website paths. It does not review the Ethereum V2 credit contracts, and it does not authorize Solana mainnet deployment.

Evidence that changed the verdict

The final package added field-level decoding for every event, a complete instruction/error/event surface census, a stateful campaign that records every result and reaches real withdrawals, and compiled mutation controls that also make the campaign fail. The release build pins its container, Solana version, SBF architecture and platform tools.

The canonical 475,824-byte ELF has SHA-256 c3f365f888cda2daf06bbf8339c7e8ea89cd090b2dac030367f346e78f3b450e. It is active on devnet at program 3ZPRvNDUDRZuZ8Hug873JtSDJueA8D7PEVE21uLLAvwh, and the verifier matched the deployed ProgramData bytes and published IDL exactly. State accounts remained byte-identical across the artifact activation.

Remaining boundary

The production Vercel release must expose and verify its exact commit on every promotion. Solana mainnet still requires counsel approval, a reviewed 2-of-4 Squads, a separately chosen emergency signer, specialist Solana review and a human deployment ceremony.

Earlier roundReview of the exact deployed Ethereum V2 contracts