CASE-09 · 18 min

Audit present, question open

Type of case study: Constructed scenario with invented figures. No real incident, no real protocol.

Scenario

A protocol points to two audit reports and an ongoing bounty for reported vulnerabilities. The contracts are upgradeable. The task is not to assess the reports — it is to determine what they refer to and what the code running today has to do with them.

Data

Audit report 1
commit a1b2c3, published 19 months ago
Audit report 2
commit d4e5f6, published 7 months ago, scope: the interest module only
Currently active implementation contract
live for 5 weeks, no published report covering it
Upgrade authority
3-of-7 multisig
Delay before an upgrade takes effect
none
Bounty program
active, cap USD 250,000
Value held in the contract
USD 310m

Questions

What do the two audit reports evidence about the code running today?

Which of the listed points weighs more for the risk assessment than the missing current report?

Analysis dimensions exercised

Sources

Institutional perspectives

Bank · Insurance · Asset management

← Case studies