Reach out for an audit or to learn more about Macro
or Message on Telegram

The 0xMacro Library

Here you will find Macro's growing
collection of public resources.

Check them out below.

Public Audits

A curated list of audits we have worked with in the past, available to the community.

SevenSeas-25

A collective of seasoned professionals in blockchain, data science, and finance committed to making crypto markets more efficient and transparent.

Audit Report Release Date
December 16, 2024
About

Audited a small code change to boring solvers allowing solvers to cover a deficit if they so choose.

Summary of Findings
Report Link
Full Report
References

Repository

Citrus Finance-1

Multi-chain All-in-One DeFi Platform.

Audit Report Release Date
December 9, 2024
About

We reviewed Citrus's custom Safe Module that allows them to execute a configuration task across multiple chains using only a single signature.

Summary of Findings
2
Medium
1
Code Quality
Report Link
Full Report
References

Website

Repository

Kodiak-3

Berachain’s Native Liquidity Hub.

Audit Report Release Date
December 6, 2024
Summary of Findings
1
Medium
1
Low
8
Code Quality
3
Informational
Report Link
Full Report
References

Github Organization | Private Repo

Website

Infinex-14

A user-friendly, secure cross-chain wallet currently supporting six EVM and non-EVM blockchains, including Ethereum and Solana.

Audit Report Release Date
December 5, 2024
About

We reviewed several Account updates, including refactors and a new feature that allows users to transfer their tokens (native, ERC20, ERC721, and ERC1155) from their Infinex account to any specified destination address.

Summary of Findings
1
Medium
3
Low
6
Code Quality
1
Informational
Report Link
Full Report
References

Website

GitHub Organization - Repo private as of December 16, 2024

Derive-1

A decentralized protocol that creates unique and programmable onchain options, perpetuals, and structured products.

Audit Report Release Date
November 27, 2024
Summary of Findings
1
Low
4
Code Quality
1
Informational
Report Link
Full Report
References

Website

Github Organization | Private Repo

SevenSeas-23

A collective of seasoned professionals in blockchain, data science, and finance committed to making crypto markets more efficient and transparent.

Audit Report Release Date
November 27, 2024
About

Audited the AaveV3 and LombardBtc decoders, allowing boring vaults to claim rewards with AaveV3, as well as mint LBTC and swap CBBTC for LBTC.

Summary of Findings
1
Medium
Report Link
Full Report
References

Repository

Superstate-4

Investment products that benefit from the speed, programmability, and compliance advantages of blockchain tokenization.

Audit Report Release Date
November 18, 2024
About

Focus of the audit was on reviewing redemption fee logic for Superstate tokens, as well as verifying logic for obtaining Superstate tokens onchain. In addition, during audit we reviewed several smaller incremental changes across Superstate system components

Summary of Findings
2
High
1
Medium
2
Low
5
Code Quality
2
Informational
Report Link
Full Report

SevenSeas-20

A collective of seasoned professionals in blockchain, data science, and finance committed to making crypto markets more efficient and transparent.

Audit Report Release Date
November 13, 2024
About

We reviewed SevenSeas's Solana program – running on Eclipse.xyz – that holds deposited tokens to bridge to Ethereum mainnet via Hyperlane.xyz.

Summary of Findings
1
Low
4
Code Quality
Report Link
Full Report
References

Repository

Rekt-2

A multi-industry company that offers drinks and beverages as well as NFT and radio services.

Audit Report Release Date
November 6, 2024
About

We audited the token distribution contract that uses a merkle tree to validate claims for users to claim owed Rekt tokens.

Summary of Findings
1
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Private Repo and Organization

Website

Superstate-3

Investment products that benefit from the speed, programmability, and compliance advantages of blockchain tokenization.

Audit Report Release Date
November 4, 2024
About

Audit scope included review of the custom real time price oracle for Superstate's tokens associated with different funds. Also we reviewed transition to upgradeable system contracts together with liquidation logic integration for Morpho project.

Summary of Findings
3
Medium
2
Low
5
Code Quality
Report Link
Full Report

Kwenta-19

A synthetic perpetuals trading platform

Audit Report Release Date
October 28, 2024
About

We audited functionality that added interacting with the new Zap contract allowing users to deposit, withdraw, unwind, and modify collateral utilizing Zap.

Summary of Findings
2
Critical
1
Medium
Report Link
Full Report
References

Repository

Website

Infinex-12

A user-friendly, secure cross-chain wallet currently supporting six EVM and non-EVM blockchains, including Ethereum and Solana.

Audit Report Release Date
October 17, 2024
About

We reviewed the initial version of PatronVesting, which allows the owner to manage different tiers that define the conditions for users claiming their Patron NFTs.

Summary of Findings
4
Low
2
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Website

GitHub Organization - Repo private as of December 16, 2024

Infinex-11

A user-friendly, secure cross-chain wallet currently supporting six EVM and non-EVM blockchains, including Ethereum and Solana.

Audit Report Release Date
October 17, 2024
About

We reviewed RewardCampaign, which allows the owner to create campaigns where users can claim rewards based on pre-defined vesting entries.

Summary of Findings
2
Medium
5
Low
9
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Website

GitHub Organization - Repo private as of December 16, 2024

SevenSeas-18

A collective of seasoned professionals in blockchain, data science, and finance committed to making crypto markets more efficient and transparent.

Audit Report Release Date
October 16, 2024
About

We reviewed various protocols and their associated decoders allowing boringVaults to integrate them, including Bitcorn, Usual Money, Satlayer, Frax staking, and Lido bridging. Additionally a new withdrawal queue and solver was audited, allowing for anyone to solve requests and trading shares from one boring vault for another.

Summary of Findings
1
High
Report Link
Full Report
References

Repository

thirdWeb-21

Web3 developer tooling

Audit Report Release Date
October 7, 2024
About

We reviewed several changes to thirdweb's modular contracts, including support for signature-based minting and maxMintPerWallet limits for claimable modules. We also reviewed the Paymaster contract, which now accommodates payment tokens with non-standard decimal places.

Summary of Findings
3
High
2
Medium
1
Low
2
Code Quality
Report Link
Full Report
References

Repository

Website

Infinex-9

A user-friendly, secure cross-chain wallet currently supporting six EVM and non-EVM blockchains, including Ethereum and Solana.

Audit Report Release Date
September 24, 2024
About

PatronNFT, a ERC721A NFT contract that utilizes new batch transfer functionality to allow for cheaper transfers of consecutive token ids, allowing for distribution of multiple tokens to cost less gas.

Summary of Findings
1
Critical
1
Medium
Report Link
Full Report
References

Website

GitHub Organization - Repo private as of November 8th, 2024

thirdWeb-20

Web3 developer tooling

Audit Report Release Date
September 24, 2024
About

We reviewed the PayGateway contract that is now supporting thirdweb’s modular architecture. Additionally, we have reviewed changes on the Royalty modules, which have been changed to support the “creator token standard."

Summary of Findings
2
Medium
4
Low
6
Code Quality
Report Link
Full Report
References

Repository

Website

Heroglyphs-1

Keeping Ethereum decentralized and cypherpunk.

Audit Report Release Date
September 19, 2024
About

We audited GuessOurBlock contracts, a betting game that allows users to place bets on blocks that will be validated by a Heroglyphs validator, and include this ticker in their graffiti.

Summary of Findings
2
High
2
Medium
2
Low
5
Code Quality
Report Link
Full Report

Zora-1

An decentralized creator-focused NFT marketplace.

Audit Report Release Date
September 6, 2024
About

We audited the Zora mints functionality, allowing for purchasing mints tokens which can be used to mint NFTs in the Zora protocol at a standard rate.

Summary of Findings
2
Medium
1
Low
1
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Repository

Website

Infinex-10

A user-friendly, secure cross-chain wallet currently supporting six EVM and non-EVM blockchains, including Ethereum and Solana.

Audit Report Release Date
September 6, 2024
About

We reviewed the Governance Points (GP) distributor contract, a trusted and straightforward contract for sending tokens to users, and some minimal changes to the GP token contract. Additionally, we audited some feature abstractions to base contracts to avoid duplicated code and included further view helper functions in contracts.

Summary of Findings
Report Link
Full Report
References

Website

GitHub Organization - Repo private as of October 7, 2024

Kwenta-18

A synthetic perpetuals trading platform

Audit Report Release Date
September 2, 2024
About

We audited Kwenta's reimbursement contracts, which are used to reimburse users with high trade volume over the past 30 days. The audit also involved reviewing ZK-circuits written in Go using the Brevis service.

Summary of Findings
1
Critical
2
High
2
Medium
2
Low
6
Code Quality
Report Link
Full Report
References

Repository

Website

Infinex-8

A user-friendly, secure cross-chain wallet currently supporting six EVM and non-EVM blockchains, including Ethereum and Solana.

Audit Report Release Date
August 28, 2024
About

We audited the Infinex Cardrun game, a card pack opening game using Pyth Entropy randomness requests to decide the card's content.

Summary of Findings
1
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Website

GitHub Organization - Repo private as of September 16, 2024

Infinex-6

A user-friendly, secure cross-chain wallet currently supporting six EVM and non-EVM blockchains, including Ethereum and Solana.

Audit Report Release Date
August 28, 2024
About

We audited Infinex Patron point of purchase, App, Beacon and Vaults contracts. Allowing users to use authorized signatures to access a Patron token purchase, register the proper on-chain receipt, and manage payments.

Summary of Findings
2
Low
6
Code Quality
Report Link
Full Report
References

Website

GitHub Organization - Repo private as of September 2, 2024

Orange-2

A protocol for building trustless, decentralized, and portable reputation for Web3.

Audit Report Release Date
August 23, 2024
About

Reviewed Orange migration contract, a pre-audited and deployed contract previously used as a bridge repurposed for their token migration. Allows users to burn old tokens by providing a valid authorized signature and claiming their new tokens.

Summary of Findings
2
Low
7
Code Quality
Report Link
Full Report
References

Repository

Website

SevenSeas-16

A collective of seasoned professionals in blockchain, data science, and finance committed to making crypto markets more efficient and transparent.

Audit Report Release Date
August 15, 2024
About

Audited new bridging integrations and a "Drone" contract controlled by the boring vault to allow interacting with protocols with multiple addresses when necessary.

Summary of Findings
1
High
3
Informational
Report Link
Full Report
References

Repository

Maple Finance-2

An institutional capital network that provides the infrastructure for credit experts to run on-chain lending businesses and connects institutional lenders and borrowers.

Audit Report Release Date
August 14, 2024
About

We audited the protocol token migration from the MPL token to the new Syrup token as part of Maple's upgrade. This includes the Syrup Merkle tree distribution, the MPLUserActions contract that facilitates user migration to Syrup and xSyrup, and the SyrupUserActions contract that allows syrupUSDC swaps into DAI or USDC. Additionally, minor changes to the fixed and open loan terms were added.

Summary of Findings
1
Low
2
Code Quality
Report Link
Full Report
References

Github Organization - Private Repo

Website

Infinex-5

A user-friendly, secure cross-chain wallet currently supporting six EVM and non-EVM blockchains, including Ethereum and Solana.

Audit Report Release Date
August 14, 2024
About

We reviewed Infinex account changes with some refactors and two feature additions: Enabling users to sync their fund's recovery address using CCQ integration and direct CCTP bridging and recovery.

Summary of Findings
3
Medium
4
Low
3
Code Quality
Report Link
Full Report
References

Website

GitHub Organization - Repo private as of September 2, 2024

Kwenta-16

A synthetic perpetuals trading platform

Audit Report Release Date
August 12, 2024
About

We audited Kwenta's MarginPaymaster contract, an ERC-4337-compliant custom Paymaster contract that optimistically sponsors transactions signed by a privileged actor, attempting to recoup gas costs in USDC or SNX-V3 margin.

Summary of Findings
2
Medium
1
Low
6
Code Quality
1
Informational
Report Link
Full Report
References

Repository

Website

Kwenta-17

A synthetic perpetuals trading platform

Audit Report Release Date
July 26, 2024
About

Audited the update that added the ability to reward USDC along with KWENTA tokens in their staking contract.

Summary of Findings
2
Medium
Report Link
Full Report
References

Repository

Website

Polynomial-3

A decentralised derivative trading exchange powered by the Synthetix protocol on Optimism that allows leverage trading up to 50x.

Audit Report Release Date
July 26, 2024
About

Reviewed the integration of bridging functionality with SocketDotTech's bridge, allowing USDC to be bridged to the polynomial network and simultaneously allow for the creation of polynomial accounts and staking of the bridged assets.

Summary of Findings
1
Medium
Report Link
Full Report
References

GitHub Organization (private repo)

Website

Inverter-1

A modular protocol for Primary Issuance Markets, enabling maximal value capture from token economies.

Audit Report Release Date
July 19, 2024
About

Inverter is a protocol and a modular framework for no-code solutions on Ethereum enabling customizable and dynamic token issuance and asset flow management. We have reviewed contracts related to core modules such as orchestrator and many use case specific modules handling staking, payments, authorization and many others.

Summary of Findings
8
High
10
Medium
11
Low
12
Code Quality
2
Gas Optimizations
4
Informational
Report Link
Full Report
References

Repository

Website

TreasureDAO-6

Gateway to the cross-game economy. Built for the Treasure ecosystem.

Audit Report Release Date
July 15, 2024
About

Review of improvements for MagicSwap V2 (custom UniswapV2 DEX) and of Staking Rewards implementation contract.

Summary of Findings
1
Low
3
Code Quality
2
Gas Optimizations
1
Informational
Report Link
Full Report

SevenSeas-10

A collective of seasoned professionals in blockchain, data science, and finance committed to making crypto markets more efficient and transparent.

Audit Report Release Date
July 10, 2024
About

Added decoders allowing bridging assets from boring vaults to and from Arbritrum and Optimism chains. Additionally added ability for vaults to interact with pancake swap v3.

Summary of Findings
2
Low
Report Link
Full Report
References

Repository

SevenSeas-9

A collective of seasoned professionals in blockchain, data science, and finance committed to making crypto markets more efficient and transparent.

Audit Report Release Date
July 10, 2024
About

Added decoders to interact with the Reserve protocol through Into the Block's specialized position manager.

Summary of Findings
2
Medium
1
Low
Report Link
Full Report
References

Repository

Superstate-2

Investment products that benefit from the speed, programmability, and compliance advantages of blockchain tokenization.

Audit Report Release Date
July 10, 2024
About

We performed a security review on the Superstate USTB repo, which mainly focused on USCC and SuperstateToken contracts, an allowlisted ERC20 token implementation with Permit and ERC-7246 encumbered balances extension.

Summary of Findings
1
Medium
8
Code Quality
Report Link
Full Report
References

Repository

Website

Polynomial-2

A decentralised derivative trading exchange powered by the Synthetix protocol on Optimism that allows leverage trading up to 50x.

Audit Report Release Date
July 8, 2024
Summary of Findings
1
Medium
3
Low
1
Code Quality
Report Link
Full Report
References

Repository

Website

Connext-7

A modular interoperability protocol

Audit Report Release Date
July 3, 2024
About

System of contracts for providing multiple mechanisms for bridging XERC20 compatible tokens using the Arbitrum canonical bridge.

Summary of Findings
1
Critical
2
Medium
1
Low
3
Code Quality
2
Informational
Report Link
Full Report
References

Repository

Website

Superstate-1

Investment products that benefit from the speed, programmability, and compliance advantages of blockchain tokenization.

Audit Report Release Date
July 1, 2024
About

We reviewed onchain redemption system relying on Chainlink price feed for exchanging USTB (Superstate token) for USDC. System features also several admin controlled configuration features.

Summary of Findings
2
Medium
4
Code Quality
2
Informational
Report Link
Full Report
References

Repository

Website

Mintra-2

On-chain, fee-sharing, Pulsechain NFT app

Audit Report Release Date
June 27, 2024
About

We reviewed Mintra's ERC721 and ERC1155 collection contracts that support customization on maximum supply, time-boxed minting, fee logic, token gating, etc.

Summary of Findings
1
High
3
Medium
7
Low
8
Code Quality
1
Informational
Report Link
Full Report
References

Repository

Website

thirdWeb-19

Web3 developer tooling

Audit Report Release Date
June 27, 2024
About

We reviewed Thirdweb's Modular Contracts framework, a set of core and extension contracts to support customization of minting, burning, token metadata, etc.

Summary of Findings
7
Medium
10
Low
6
Code Quality
Report Link
Full Report
References

Repository

Website

Infinex-4

A user-friendly, secure cross-chain wallet currently supporting six EVM and non-EVM blockchains, including Ethereum and Solana.

Audit Report Release Date
June 19, 2024
About

We conducted an audit of the Curve App, focusing on the implementation of the app and its proper integration with Curve NG pools. We also reviewed changes in the management App Module in the core Infinex Account system.

Summary of Findings
2
High
3
Medium
2
Low
8
Code Quality
Report Link
Full Report
References

Website

GitHub Organization - Repo private as of June 24, 2024

Polynomial-1

A decentralised derivative trading exchange powered by the Synthetix protocol on Optimism that allows leverage trading up to 50x.

Audit Report Release Date
June 17, 2024
About

Reviewed this fork of Synthetix V3 with minor changes, and their cannon deployment scripts.

Summary of Findings
2
Medium
2
Low
1
Code Quality
Report Link
Full Report
References

GitHub Organization (private repo)

Website

Cannon-1

A DevOps tool for building on Ethereum that manages protocol deployments on blockchains.

Audit Report Release Date
June 17, 2024
About

On-chain registry for software packages, similar to node. Users can register a package name, and give permissions to users to update packages. Usable on mainnet ethereum and optimism.

Summary of Findings
1
Low
Report Link
Full Report
References

Repo

Website

Shroom-1

Community currency token to reward user engagement in the r/MushroomPlanet subreddit

Audit Report Release Date
June 10, 2024
About

We audited the Shroom community currency token implementation, adding custom fee logic to the standard ERC-20 implementation using Thirdweb's audited contracts.

Summary of Findings
1
High
2
Code Quality
1
Informational
Report Link
Full Report

SevenSeas-8

A collective of seasoned professionals in blockchain, data science, and finance committed to making crypto markets more efficient and transparent.

Audit Report Release Date
June 4, 2024
Summary of Findings
1
Low
4
Code Quality
1
Informational
Report Link
Full Report
References

Repository

Infinex-3

A user-friendly, secure cross-chain wallet currently supporting six EVM and non-EVM blockchains, including Ethereum and Solana.

Audit Report Release Date
May 24, 2024
About

We reviewed Infinex's governance system, which is composed of a set of contracts used to elect council members and assign them to designated GnosisSafe wallets. Cross-chain communication is utilized to determine the voting power and propagate the elected members to different chains.

Summary of Findings
4
High
5
Medium
2
Code Quality
3
Informational
Report Link
Full Report
References

Website

GitHub Organization - Repo private as of June 24, 2024

Orange-1

A protocol for building trustless, decentralized, and portable reputation for Web3.

Audit Report Release Date
May 23, 2024
Summary of Findings
1
Medium
1
Low
5
Code Quality
2
Informational
Report Link
Full Report
References

Repository

Website

Compound-2

Building infrastructure for the future of finance.

Audit Report Release Date
May 20, 2024
About

We audited Quark Wallets' new additions and modifications, which now support multi-Quark operations. Users can now sign multiple Quark operations or a single operation to be executed cross-chain. The new Paycall and Quotecall scripts were also audited in this round.

Summary of Findings
1
Low
6
Code Quality
Report Link
Full Report
References

Repository

Website

SevenSeas-6

A collective of seasoned professionals in blockchain, data science, and finance committed to making crypto markets more efficient and transparent.

Audit Report Release Date
May 14, 2024
Summary of Findings
1
Medium
Report Link
Full Report
References

Repository

Titan Node-1

Livepeer Video Mining Pool providing Transcoding and Staking services.

Audit Report Release Date
May 13, 2024
About

We reviewed the Titan Node PaymentStream contract, a streamlined payment management system that enables payees to claim ERC20 tokens released linearly over time. The contract also includes safeguard mechanisms allowing for the finalization of payments if necessary.

Summary of Findings
1
Low
6
Code Quality
Report Link
Full Report
References

Website

Repo

Infinex-2

A user-friendly, secure cross-chain wallet currently supporting six EVM and non-EVM blockchains, including Ethereum and Solana.

Audit Report Release Date
May 10, 2024
About

We conducted an audit of Infinex's Governance Points contract and its staking mechanism to reward users of Infinex accounts across the many chains they are deployed on.

Summary of Findings
1
High
1
Low
1
Code Quality
Report Link
Full Report
References

Website

Cannon Package

GitHub Organization - Repo private as of May 13, 2024

Infinex-1

A user-friendly, secure cross-chain wallet currently supporting six EVM and non-EVM blockchains, including Ethereum and Solana.

Audit Report Release Date
May 10, 2024
About

We conducted an audit of Infinex Accounts, focusing on its innovative use of a proxy beacon, upgradable architecture with multiple modules, and customizable key management system. This design empowers users to manage their accounts independently without relying on external parties. Additionally, the upgradable structure allows for seamless implementation of new features and updating configuration parameters, provided users opt in.

Summary of Findings
1
Critical
3
High
2
Medium
3
Low
8
Code Quality
3
Informational
Report Link
Full Report
References

Website

Cannon Package

GitHub Organization - Repo private as of May 13, 2024

Illuvium-2

A decentralised studio building an Interoperable Blockchain game universe on Ethereum.

Audit Report Release Date
April 24, 2024
About

We reviewed a vesting contract that rewards users with ERC20 tokens based on a defined vesting tier.

Summary of Findings
4
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Website

thirdWeb-17

Web3 developer tooling

Audit Report Release Date
April 23, 2024
About

We reviewed an update on Thirdweb's smart wallet contract to support Seaport bulk orders for EIP-1271.

Summary of Findings
5
Code Quality
Report Link
Full Report
References

Repository

Website

SevenSeas-5

A collective of seasoned professionals in blockchain, data science, and finance committed to making crypto markets more efficient and transparent.

Audit Report Release Date
April 22, 2024
Summary of Findings
1
Informational
Report Link
Full Report
References

Repository

thirdWeb-18

Web3 developer tooling

Audit Report Release Date
April 5, 2024
About

Review of thirdweb's Airdrop contract, which encompasses push, claimable, and signature-based airdrops in a single contract. We also audited the PaymentsGateway contract, a component of thirdweb Pay. It serves as the entry point for pay transactions and handles fee management, logging, and routing the transaction to the swap provider.

Summary of Findings
1
Medium
3
Low
7
Code Quality
1
Gas Optimization
Report Link
Full Report

Illuvium-1

A decentralised studio building an Interoperable Blockchain game universe on Ethereum.

Audit Report Release Date
March 28, 2024
About

We reviewed an UUPS upgradable ERC-20 implementation with role-based access control and pausing capability.

Summary of Findings
2
Medium
3
Code Quality
Report Link
Full Report
References

Website

SevenSeas-4

A collective of seasoned professionals in blockchain, data science, and finance committed to making crypto markets more efficient and transparent.

Audit Report Release Date
March 20, 2024
About

Audited a new vault protocol, the Boring Vault, which is a simplistic contract itself, but is managed by a contract that requires calls to be pre-approved via a merkle tree, and the vaults share exchange rate and withdrawals are managed and handled by the protocol.

Summary of Findings
4
Medium
4
Low
4
Code Quality
2
Informational
Report Link
Full Report
References

Repository

SevenSeas-2

A collective of seasoned professionals in blockchain, data science, and finance committed to making crypto markets more efficient and transparent.

Audit Report Release Date
March 15, 2024
About

Audited a Pendle adaptor and its corresponding Pendle pricing extension, to allow cellars to interact the Pendle protocol and hold various Pendle tokens as positions, including LP, YT, PT, and SY tokens.

Summary of Findings
2
High
1
Low
1
Informational
Report Link
Full Report
References

Repository

Mento-3

A decentralized and transparent stable value asset protocol (including stablecoins) on the Celo blockchain

Audit Report Release Date
March 11, 2024
About

Audited an adjustment to the vote escrow curve function and adjustments to the governance contracts setup.

Summary of Findings
1
High
1
Medium
6
Low
2
Code Quality
2
Informational
Report Link
Full Report
References

Repository

Website

IDEX-B-1

DEX with leverage and gas-free trading

Audit Report Release Date
February 24, 2024
About

Audit of changes made to the core protocol including margin requirement changes, support for pending deposit, a new EscrowContract has been added, support for quote token migration, and other minor refactors.

Summary of Findings
1
Medium
3
Low
2
Code Quality
Report Link
Full Report

Connext-5

A modular interoperability protocol

Audit Report Release Date
February 22, 2024
About

We reviewed the new Connext's connector for Scroll L2. Scope included both ScrollHubConnector and ScrollSpokeConnector contracts.

Summary of Findings
1
Low
2
Code Quality
Report Link
Full Report
References

Repository

Website

Covenant-1

Borrow and lend against any tokenized asset through liquid, tradeable debt markets.

Audit Report Release Date
February 21, 2024
About

Covenant is a decentralized, non-custodial debt market, built on perpetual debt. It is a lending protocol based on Aave architecture with interest rate calculation externalized to AMM markets for particular debt asset. Macro audited their core protocol implementation prior to their beta release.

Summary of Findings
1
Critical
9
Medium
10
Low
5
Code Quality
2
Informational
Report Link
Full Report

Sommelier-16b

Automated DeFi yield optimization strategies

Audit Report Release Date
February 12, 2024
About

Audited Sommelier's multichain contracts that allow assets to be shared between different chains using Chainlink's CCIP protocol. Additionally, we audited the Compound v3 adapter as well as the support for various staking adapters including EtherFi, KelpDAO, Lido, Renzo, Stader, Swell.

Summary of Findings
4
High
2
Medium
2
Low
8
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Repository

Website

Patchwork-2

Supercharge tokens, contracts, and addresses by layering rich blocks of interoperable, interconnected, interactive data on top of any onchain entity.

Audit Report Release Date
February 1, 2024
About

Patchwork protocol was refactored and new functionality was added to the core system contract for managing and charging various fees related to different system operations. We have reviewed these changes and additional updates that were introduced to extract assignment functionality into a specific contract

Summary of Findings
2
High
3
Medium
4
Low
7
Code Quality
Report Link
Full Report
References

Repository

Twitter

Sommelier-16a

Automated DeFi yield optimization strategies

Audit Report Release Date
January 22, 2024
About

Audited the new addition to cellars to support multi-asset deposits as well as the support for MorphoBlue adapters.

Summary of Findings
1
High
1
Medium
2
Low
4
Code Quality
2
Gas Optimizations
2
Informational
Report Link
Full Report
References

Repository

Website

Sommelier-15

Automated DeFi yield optimization strategies

Audit Report Release Date
January 22, 2024
About

The ability to have a sequencer check was added to the price router to be used for cellars on layer 2 chains, preventing pricing when the sequencer is down.

Summary of Findings
1
Medium
Report Link
Full Report
References

Repository

Website

Kwenta-12

A synthetic perpetuals trading platform

Audit Report Release Date
January 17, 2024
About

Audit of Zap, a contract that allows the feeless exchange of USDC to sUSD and vice versa via SynthetixV3 spot markets.

Summary of Findings
1
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Repository

Website

Kwenta-11

A synthetic perpetuals trading platform

Audit Report Release Date
January 17, 2024
About

Kwenta V3 smart margin contract was made upgradeable and implemented Zap functionality to exchange USDC to uUSD and back. The ability for USDC to be converted to sUSD and used as collateral, or have collateral be withdrawn and converted to USDC was added.

Summary of Findings
1
Code Quality
Report Link
Full Report
References

Repository

Website

Mintra-1

On-chain, fee-sharing, Pulsechain NFT app

Audit Report Release Date
January 15, 2024
About

Audit of Mintra’s marketplace contract, a fork of Thirdweb's direct listing marketplace, with changes being made to permissions, royalty logic, and support for bulk buy.

Summary of Findings
10
Code Quality
2
Gas Optimizations
Report Link
Full Report
References

Repository

Website

Mento-2

A decentralized and transparent stable value asset protocol (including stablecoins) on the Celo blockchain

Audit Report Release Date
January 9, 2024
About

Audited Mento's new governance contracts using vote escrowed mento tokens to vote, as well as a immutable factory to deploy and setup relevant contracts.

Summary of Findings
3
Low
7
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Repository

Website

Compound-1

Building infrastructure for the future of finance.

Audit Report Release Date
January 1, 2024
About

We audited Compound Quark Wallet, a flexible, trustless, custom smart contract account that allows entitled users to execute Quark Operations through direct execution or signatures. The system design allows for any arbitrary code execution, deploying new scripts atomically during a Quark Operation execution or re-using deployed scripts. Additionally, we audited specific scripts, such as Ethcall, Multicall, UniswapFlashLoan, and UniswapFlashSwapExactOut.

Summary of Findings
1
High
3
Medium
2
Low
9
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Repository

Website

Sommelier-14

Automated DeFi yield optimization strategies

Audit Report Release Date
December 15, 2023
About

Audit of the following additions by Sommelier: A Curve adaptor and Convex curve adaptor allowing cellars to have a curve pool and Convex Curve positions. A pricing extension to price curve 2 pools. A slippage router to allow for deposits and withdrawals with specified slippage. A withdrawal queue, allowing users to specify withdrawal conditions and for a solver to bundle and execute withdrawal orders on their behalf.

Summary of Findings
3
High
2
Medium
2
Low
6
Code Quality
1
Gas Optimization
2
Informational
Report Link
Full Report
References

Repository

Website

Maple Finance-1

An institutional capital network that provides the infrastructure for credit experts to run on-chain lending businesses and connects institutional lenders and borrowers.

Audit Report Release Date
December 15, 2023
About

An audit of incremental updates to Maple V2 contracts packaged into the Q4 release. These included a new FIFO queue-based withdrawal manager submodule, a new pool permission manager submodule, and additional smaller changes and improvements for the rest of the system.

Summary of Findings
2
Medium
1
Low
12
Code Quality
3
Informational
Report Link
Full Report
References

Github Organization - Private Repo

Website

Kwenta-10

A synthetic perpetuals trading platform

Audit Report Release Date
December 6, 2023
About

Kwenta made conditional orders payable with ETH, allowing deposits and withdraws of ETH used for payment. Integration with EIP7412 was also added to allow price oracles to be updated when needed via off-chain verification.

Summary of Findings
1
Medium
1
Low
1
Code Quality
1
Informational
Report Link
Full Report
References

Repository

Website

Farcaster-3

A protocol for decentralized social apps

Audit Report Release Date
November 2, 2023
About

Audit of Farcaster v3.1 contracts. Updates implement new manager pattern to simplify future migrations, and adding additional mitigations to event spamming vectors

Summary of Findings
3
Low
7
Code Quality
2
Gas Optimizations
Report Link
Full Report
References

Repository

Website

Sommelier-12

Automated DeFi yield optimization strategies

Audit Report Release Date
October 27, 2023
About

Audited the new Aura position adaptor, Curve and Redstone pricing extensions, and small updates to the Frax adaptors.

Summary of Findings
2
Medium
2
Low
Report Link
Full Report
References

Repository

Website

Connext-4

A modular interoperability protocol

Audit Report Release Date
October 18, 2023
About

Audited upgrades to support an optimistic system on Spoke Connectors.

Summary of Findings
1
Low
4
Code Quality
1
Informational
Report Link
Full Report
References

Repository

Website

thirdWeb-15

Web3 developer tooling

Audit Report Release Date
October 6, 2023
About

Audited BurnToClaimERC721 as well as changes made to MarketplaceV3 since the previous audit.

Summary of Findings
1
Medium
3
Low
12
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Repository

Website

Nori-4

Carbon removal marketplace

Audit Report Release Date
October 2, 2023
About

Finished the second part of auditing core Nori contracts such as Market, Certificate, Removal, RestrictedNORI, and library helpers

Summary of Findings
1
Medium
4
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Repository

Website

Kwenta-9

A synthetic perpetuals trading platform

Audit Report Release Date
September 29, 2023
About

Small audit to review addition of a command that allows callers to update Synthetix keeper fee.

Summary of Findings
1
Code Quality
2
Gas Optimizations
Report Link
Full Report

Patchwork-1

Supercharge tokens, contracts, and addresses by layering rich blocks of interoperable, interconnected, interactive data on top of any onchain entity.

Audit Report Release Date
September 27, 2023
About

Patchwork protocol enables new onchain use cases by defining and utilising new composition capabilities for ERC721 and ERC1155 tokens. We have reviewed a contract which enforces compliance and manages token transfers with these extra capabilities, including additional access controlled functionality for enabling cross token associations. In addition we have performed review of a set of abstract contracts that are meant to be inherited and reused for implementing specific token composition behaviors in a Patchwork compliant way.

Summary of Findings
2
High
3
Medium
3
Low
11
Code Quality
Report Link
Full Report
References

Repository

Twitter

Endaoment-2

A grantmaking foundation supporting every kind of giving, built entirely onchain.

Audit Report Release Date
September 22, 2023
About

Audited an update to the Aave, Yearn, and Compound portfolios to inherit from the updated Portfolio contract.

Summary of Findings
1
Low
4
Code Quality
3
Gas Optimizations
Report Link
Full Report

PoolTogether-1

A decentralized prize savings protocol

Audit Report Release Date
September 19, 2023
About

Audited V5 Prize Pool and V5 TWAB Controller contracts.

Summary of Findings
2
Critical
4
High
4
Medium
7
Low
16
Code Quality
4
Gas Optimizations
Report Link
Full Report

Kwenta-8

A synthetic perpetuals trading platform

Audit Report Release Date
September 19, 2023
About

Audit of Kwenta's Smart Margin v3 contract, which leverages Synthetix v3's account-based architecture and offers improved tools for trading Synthetix derivatives.

Summary of Findings
2
High
3
Medium
2
Low
2
Code Quality
1
Gas Optimization
1
Informational
Report Link
Full Report
References

Repository

Website

Kwenta-7

A synthetic perpetuals trading platform

Audit Report Release Date
September 19, 2023
About

Audit of the V2 version of Kwenta's staking rewards and rewards escrow contracts, as well as V1 -> V2 escrow migrator contract.

Summary of Findings
1
Medium
3
Low
6
Code Quality
1
Gas Optimization
Report Link
Full Report

Sommelier-11

Automated DeFi yield optimization strategies

Audit Report Release Date
August 30, 2023
About

Audited the addition of Frax collateral and debt adaptors, and changes to the AxelarProxy contract.

Summary of Findings
2
Medium
2
Low
3
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Repository

Website

Farcaster-2

A protocol for decentralized social apps

Audit Report Release Date
August 29, 2023
About

Audit of two new features in the KeyRegistry and IdRegistry contracts.

Summary of Findings
1
Code Quality
Report Link
Full Report
References

Repository

Website

thirdWeb-14

Web3 developer tooling

Audit Report Release Date
August 21, 2023
About

Audited the EvolvingNFT and LoyaltyPoints contracts, as well as changes to the smart contract wallet account contracts and their factories.

Summary of Findings
1
Critical
1
High
4
Medium
5
Low
10
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Repository

Website

Farcaster-1

A protocol for decentralized social apps

Audit Report Release Date
August 18, 2023
About

Audit of Farcaster's core L1 and L2 contracts.

Summary of Findings
2
Medium
5
Low
10
Code Quality
Report Link
Full Report
References

Repository

Website

Mento-1

A decentralized and transparent stable value asset protocol (including stablecoins) on the Celo blockchain

Audit Report Release Date
August 17, 2023
About

Audited multiple contracts for the v2.2 Mento protocol release. Adding Oracle circuit breakers and updating the constant sum pricing module, pool manager, and a new and simpler ERC20 token implementation for stable tokens.

Summary of Findings
1
High
3
Medium
3
Low
7
Code Quality
Report Link
Full Report
References

Repository

Website

Sommelier-10

Automated DeFi yield optimization strategies

Audit Report Release Date
August 12, 2023
About

The CellarAdaptor was audited again with the added scope of using SavingsDai ERC4626 vault as a position, and no issues were found.

Summary of Findings
Report Link
Full Report
References

Repository

Website

Sommelier-9

Automated DeFi yield optimization strategies

Audit Report Release Date
August 4, 2023
About

Audited the addition of the SharePriceOracle contract that uses Chainlink automation to update the share price of a cellar in order to reduce gas costs and lower share price volatility, as well as cellars that integrate this oracle.

Summary of Findings
3
High
1
Medium
2
Low
4
Code Quality
1
Informational
Report Link
Full Report
References

Repository

Website

Kwenta-6

A synthetic perpetuals trading platform

Audit Report Release Date
July 21, 2023
About

Audit of smart-margin V2.10 on the code changes from the prior audit of smart-margin V2.02, including a command that allows whitelisted token swaps to and from sUSD.

Summary of Findings
2
Code Quality
2
Gas Optimizations
1
Informational
Report Link
Full Report

IDEX-1

DEX with leverage and gas-free trading

Audit Report Release Date
July 21, 2023
About

We audited the core smart contracts, including their exchange and governance protocols.

Summary of Findings
8
Medium
4
Low
5
Code Quality
2
Informational
Report Link
Full Report

Connext-2

A modular interoperability protocol

Audit Report Release Date
July 12, 2023
About

Audit scope included, among other things, new connectors to support additional chains, templatized IXReceiver contracts, updates to the Optimism connector to support Bedrock, and adding initial implementation of Optimistic roots to avoid the direct use of AMBs to propagate messages to the RootManage.

Summary of Findings
7
High
8
Medium
6
Low
15
Code Quality
1
Informational
Report Link
Full Report
References

Repository

Website

Connext-3

A modular interoperability protocol

Audit Report Release Date
July 6, 2023
About

Audit of Wormhole hub and spoke connectors.

Summary of Findings
4
Code Quality
Report Link
Full Report
References

Repository

Website

Bitcone-1

ERC20 token for the Coneheads community

Audit Report Release Date
July 6, 2023
About

We audited Bitcone's ERC20 token contract deployed on the Polygon blockchain.

Summary of Findings
3
Informational
Report Link
Full Report
References

Deployed Contract

thirdWeb-13

Web3 developer tooling

Audit Report Release Date
June 30, 2023
About

We audited two new contracts being deployed by thirdWeb: Dynamic Drops and Loyalty Cards.

Summary of Findings
1
High
1
Medium
4
Code Quality
2
Informational
Report Link
Full Report
References

Repository

Website

Sommelier-8

Automated DeFi yield optimization strategies

Audit Report Release Date
June 28, 2023
About

Audited the updated PriceRouter to include pricing extensions as well as the corresponding price extensions for balancer pools and lido wsETH. Added Frax and Morpho position adapters, as well as using Axelar to bridge transaction from the sommelier chain.

Summary of Findings
4
Medium
1
Low
6
Code Quality
3
Gas Optimizations
3
Informational
Report Link
Full Report
References

Repository

Website

Citadel-3

A fully on-chain game

Audit Report Release Date
June 26, 2023
About

We audited minor refactors, a new auth strategy for delegatecash, and improved events among other things

Summary of Findings
2
Low
5
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Citadel Game Docs

GitHub Organization - Private Repo

Kwenta-5

A synthetic perpetuals trading platform

Audit Report Release Date
June 22, 2023
About

Re-audited Kwenta's accounts and events functionality.

Summary of Findings
1
Code Quality
3
Informational
Report Link
Full Report

Fuji-1

A cross-chain money market aggregator optimizing lending and borrowing positions

Audit Report Release Date
June 21, 2023
About

We reviewed Fuji's full platform, including their lending, cross-chain, and permits functionality.

Summary of Findings
5
Critical
7
High
8
Medium
9
Low
10
Code Quality
4
Gas Optimizations
Report Link
Full Report
References

Repository

Tales-Of-Elleria-1

3D role-playing GameFi project

Audit Report Release Date
June 19, 2023
About

We audited their staking and bridge contracts that are used to manage staking and rewards logic.

Summary of Findings
1
High
3
Medium
7
Low
5
Code Quality
2
Gas Optimizations
Report Link
Full Report
References

Repository

Website

thirdWeb-12

Web3 developer tooling

Audit Report Release Date
June 15, 2023
About

Audit of two separate features, the Smart Accounts and Open Edition ERC-721 Accounts.

Summary of Findings
1
High
5
Medium
2
Low
6
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Repository

Website

Glo-1

A stablecoin supported by the Glo Foundation.

Audit Report Release Date
May 25, 2023
About

We reviewed the token contract, including access controls and core ERC-20 functionality.

Summary of Findings
1
Low
2
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Repository

Website

Kwenta-4

A synthetic perpetuals trading platform

Audit Report Release Date
May 4, 2023
About

We audited the Kwenta smart margin accounts functionality and related contracts.

Summary of Findings
3
Medium
3
Low
8
Code Quality
3
Gas Optimizations
Report Link
Full Report

thirdWeb-11

Web3 developer tooling

Audit Report Release Date
April 24, 2023
About

We audited two separate features for thirdWeb, including PackVFR and the Extension Registry contracts.

Summary of Findings
2
Medium
5
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Repository

Website

Sommelier-7

Automated DeFi yield optimization strategies

Audit Report Release Date
April 4, 2023
About

The Cellar, Registry, CellarFactory, PriceRouter, and SwapRouter contracts were audited, as well as position adaptors integrating Aave, compound, uniswapV3, one inch and 0x.

Summary of Findings
2
Critical
2
High
1
Medium
1
Code Quality
1
Informational
Report Link
Full Report
References

Repository

Website

Bueno.art-2

No-code NFT generation and deployment

Audit Report Release Date
March 31, 2023
About

Audit of Bueno.art's deployed 1155Drop contract deployed on Ethereum, as well as the clone factory contract used to deploy the 1155Drop contract.

Summary of Findings
1
Critical
2
High
2
Medium
4
Low
3
Code Quality
3
Gas Optimizations
Report Link
Full Report

Bueno.art-3

No-code NFT generation and deployment

Audit Report Release Date
March 31, 2023
About

We audited Bueno.art's deployed 1155Drop contract, specifically looking at the differences between solidity contracts and the deployed version on Ethereum mainnet referenced in the previous Bueno.art audit.

Summary of Findings
2
Low
3
Code Quality
Report Link
Full Report

TreasureDAO-3

Gateway to the cross-game economy. Built for the Treasure ecosystem.

Audit Report Release Date
March 27, 2023
About

System for fractionalizing NFTs using custom Nft Vaults and providing liquidity by relying on customized UniswapV2 DEX.

Summary of Findings
3
High
7
Medium
9
Low
13
Code Quality
Report Link
Full Report

thirdWeb-9

Web3 developer tooling

Audit Report Release Date
March 13, 2023
About

Audit of thirdWeb's Airdrop and Multichain Registry functionality.

Summary of Findings
1
High
5
Medium
1
Low
2
Code Quality
4
Gas Optimizations
Report Link
Full Report
References

Repository

Website

Synthetix-1

DeFi liquidity layer

Audit Report Release Date
March 2, 2023
About

Macro audited three separate parts of the Synthetix V3 infrastructure: ERC standard tokens (20 and 721), Hardhat Router and Hardhat Storage

Summary of Findings
5
High
4
Medium
3
Code Quality
1
Gas Optimization
Report Link
Full Report
References

Repository

Website

Synthetix-2

DeFi liquidity layer

Audit Report Release Date
March 2, 2023
About

We audited the Synthetix V3 contracts, specifically focusing on the core functionaltiy of the Synthetix V3 protocol.

Summary of Findings
3
High
2
Code Quality
Report Link
Full Report
References

Repository

Website

Synthetix-3

DeFi liquidity layer

Audit Report Release Date
March 2, 2023
About

Re-audit of the Synthetix V3 contracts, specifically focusing on the core functionaltiy of the Synthetix V3 protocol. This was a second audit of similar functionality that was reviewed in the Synthetix-2 audit.

Summary of Findings
2
High
3
Medium
3
Low
4
Code Quality
1
Informational
Report Link
Full Report
References

Repository

Website

thirdWeb-10

Web3 developer tooling

Audit Report Release Date
March 1, 2023
About

We audited a collection of token extensions related to ERC721 tokens. This included functionality for ownership, permissions, sales, royalties, and more. We also reviewed the routing functionality for the contract.

Summary of Findings
2
High
2
Medium
1
Low
2
Code Quality
1
Gas Optimization
1
Informational
Report Link
Full Report
References

Repository

Website

The-Graph-1

Blockchain indexing and query protocol.

Audit Report Release Date
February 24, 2023
About

Audit of The Graph's subscription contract, which allows users to pay for their service with ETH for their services

Summary of Findings
3
High
1
Medium
3
Low
4
Code Quality
4
Gas Optimizations
1
Informational
Report Link
Full Report
References

Repository

Website

Sommelier-5

Automated DeFi yield optimization strategies

Audit Report Release Date
February 20, 2023
About

Audited their Euler Debt and E token adapters.

Summary of Findings
2
High
2
Code Quality
Report Link
Full Report
References

Repository

Website

Nori-2

Carbon removal marketplace

Audit Report Release Date
February 14, 2023
About

We re-audited Nori's core contracts, which are used to manage their carbon offsetting platform.

Summary of Findings
1
Medium
2
Low
4
Code Quality
1
Informational
Report Link
Full Report
References

Repository

Website

xDonations-1

A Connext project allowing NGOs to fundraise via on-chain cryptocurrency donations

Audit Report Release Date
February 10, 2023
About

Audit of the xDonations donation contract.

Summary of Findings
2
High
1
Low
1
Code Quality
1
Gas Optimization
1
Informational
Report Link
Full Report

Arcade-2

P2P Loan Protocol for NFTs

Audit Report Release Date
February 6, 2023
About

Our review included their core protocol and market contracts.

Summary of Findings
2
Critical
3
High
5
Medium
1
Low
9
Code Quality
4
Gas Optimizations
Report Link
Full Report
References

Repository

Website

Connext-1

A modular interoperability protocol

Audit Report Release Date
January 31, 2023
About

We audited Connext's messaging layer contracts, responsible for coordinating state updates between various Connext modules.

Summary of Findings
1
Critical
4
High
4
Medium
5
Low
9
Code Quality
5
Gas Optimizations
Report Link
Full Report
References

Repository

Website

thirdWeb-8

Web3 developer tooling

Audit Report Release Date
January 30, 2023
About

Audit of their wallet accounts and signature drop 1155 contracts.

Summary of Findings
1
Critical
2
High
3
Medium
1
Low
1
Code Quality
Report Link
Full Report
References

Repository

Website

Double-1

A DeFi primitive for AMM liquidity providing

Audit Report Release Date
January 20, 2023
About

Audited Double core vaults, reward distribution, and UniswapV2 liquidity provider and migratory contracts

Summary of Findings
2
High
1
Medium
1
Low
3
Code Quality
1
Gas Optimization
4
Informational
Report Link
Full Report
References

Website

GitHub Organization - Private Repo

mStable-1

Stablecoin yield aggregator

Audit Report Release Date
January 11, 2023
About

Audit of mStable's MetaVaults, which are based on EIP-4626 vaults. We reviewed the underlying logic that allows users to deposit and withdraw assets from these vaults.

Summary of Findings
2
High
4
Medium
2
Low
3
Code Quality
3
Gas Optimizations
3
Informational
Report Link
Full Report
References

Repository

Website

Sommelier-4

Automated DeFi yield optimization strategies

Audit Report Release Date
January 11, 2023
About

Audited the core Sommelier contracts, including the contract factory, router, staking, and 3rd party integrations.

Summary of Findings
5
High
8
Medium
2
Low
7
Code Quality
Report Link
Full Report
References

Repository

Website

Maker-1

Decentralized stablecoin and lending protocol

Audit Report Release Date
December 22, 2022
About

Audit of MakerDAO's dss-kiln module, which is used to manage liquidations. We reviewed its core functionality, including the mathematical logic underlying the liquidations functions.

Summary of Findings
1
Medium
2
Low
7
Code Quality
5
Informational
Report Link
Full Report
References

Repository

Website

Nori-1

Carbon removal marketplace

Audit Report Release Date
December 13, 2022
About

We audited Nori's core contracts, which are used to manage their carbon offsetting platform. This included access controls, bridging functionality and certificate minting functions.

Summary of Findings
4
High
6
Medium
4
Low
9
Code Quality
4
Gas Optimizations
Report Link
Full Report
References

Repository

Website

Bueno.art-1

No-code NFT generation and deployment

Audit Report Release Date
December 8, 2022
About

Audit of Bueno.art's deployed 721Drop contract on Polygon, including their contract proxy and administrative functions.

Summary of Findings
2
High
3
Medium
6
Low
5
Code Quality
1
Gas Optimization
Report Link
Full Report

thirdWeb-7

Web3 developer tooling

Audit Report Release Date
December 7, 2022
About

We audited three new staking contracts for thirdweb: TokenStake, a contract for staking ERC20 tokens; NFTStake, a contract for staking ERC721 NFTs; and EditionStake, a contract for staking ERC1155 tokens. Each contract supports configurable staking rewards.

Summary of Findings
1
Critical
2
High
3
Medium
1
Low
8
Code Quality
3
Gas Optimizations
Report Link
Full Report
References

Repository

Website

Citadel-1

A fully on-chain game

Audit Report Release Date
December 2, 2022
About

We audited their main contracts, ZK ConstructionBay contract and Deployment scripts.

Summary of Findings
1
Critical
9
High
17
Medium
18
Low
21
Code Quality
6
Gas Optimizations
Report Link
Full Report
References

Citadel Game Docs

GitHub Organization - Private Repo

thirdWeb-6

Web3 developer tooling

Audit Report Release Date
November 17, 2022
About

Audit of Marketplace and TieredDrop contracts.

Summary of Findings
4
Critical
1
High
1
Medium
4
Low
3
Code Quality
2
Gas Optimizations
Report Link
Full Report
References

Repository

Website

thirdWeb-5

Web3 developer tooling

Audit Report Release Date
November 11, 2022
About

Audit of their ERC20, ERC721 and ERC1155 drop contracts.

Summary of Findings
1
Medium
2
Code Quality
Report Link
Full Report
References

Repository

Website

PartyDAO-1

Multiplayer crypto software

Audit Report Release Date
October 31, 2022
About

Audit of PartDAO's core contracts, which are used to manage their governance and treasury.

Summary of Findings
1
High
2
Medium
1
Low
9
Code Quality
2
Gas Optimizations
1
Informational
Report Link
Full Report
References

Repository

Website

Kwenta-3

A synthetic perpetuals trading platform

Audit Report Release Date
October 19, 2022
About

Audit of the smart margin contracts, including the future's market and interfaces.

Summary of Findings
1
High
1
Medium
3
Low
2
Code Quality
1
Gas Optimization
Report Link
Full Report

Sommelier-3

Automated DeFi yield optimization strategies

Audit Report Release Date
October 7, 2022
About

Macro is excited to continue its ongoing engagement with Sommelier Finance as they realize their vision of algorithmic, automated DeFi yield optimization strategies. Cellars support dynamic management and balancing across multiple asset types: ERC20s, other ERC4626s, and other Cellars – which are themselves ERC4626 vaults. They utilize governance and control mechanisms for management; Uniswap V2/V3 for asset rebalancing; and Chainlink price oracles for asset valuation.

Summary of Findings
3
High
9
Medium
4
Low
11
Code Quality
10
Informational
Report Link
Full Report
References

Repository

Website

thirdWeb-4

Web3 developer tooling

Audit Report Release Date
September 29, 2022
About

Audit of their ERC20, ERC721 and ERC1155 token contracts.

Summary of Findings
1
Critical
3
Medium
2
Low
4
Code Quality
1
Gas Optimization
1
Informational
Report Link
Full Report
References

Repository

Website

thirdWeb-3

Web3 developer tooling

Audit Report Release Date
August 19, 2022
About

We audited thirdWeb's Pack functionality and subsequent extensions and interfaces for the contract.

Summary of Findings
1
High
3
Medium
7
Low
5
Code Quality
1
Informational
Report Link
Full Report
References

Repository

Website

Kwenta-2 Mini

A synthetic perpetuals trading platform

Audit Report Release Date
July 22, 2022
About

We reviewed upcoming Kwenta feature designs to give their team confidence in the direction they were going.

Report Link
Full Report
References

SEE REPORT HERE: Due to the nature of this audit, a formal report was not created so the link above does not work.

Repository

Website

KIP-18: Cross Margin

KIP-19: Advanced Orders

thirdWeb-2

Web3 developer tooling

Audit Report Release Date
June 17, 2022
About

We audited three new exciting features for thirdweb: Multiwrap, a contract that allows transferring and trading of multiple assets as a single unit; DropERC1155, a contract that allows users to easily mint multiple sets of NFTs with no redeployment; and SignatureDrop, a contract that allows facilitating both drops and mints via signatures.

Summary of Findings
2
High
7
Low
5
Code Quality
5
Gas Optimizations
Report Link
Full Report

Cool Stuff

Useful resources for developing on Solidity, Ethereum, and the EVM.