Liquity V2 is currently live on ETH Sepolia Testnet. Mainnet Launch is coming soon
Auditing Liquity V2
Liquity V1
Liquity V2
Max Fiege
·
December 20, 2024
Auditing Liquity V2

The deployment of Liquity V2 on Ethereum mainnet is imminent. This deployment will be immutable, meaning that upgrading the smart contracts thereafter will not be an option. Accordingly, their security is paramount. 

The Liquity V2 codebase has undergone extensive rounds of audits as well as formal verification to ensure as robust of a foundation for the BOLD stablecoin as possible. Note that the codebase is comprised of two independent sections:

  1. The Core Protocol: Responsible for minting BOLD against collateral
  2. The Voting Module: Responsible for directing protocol liquidity incentives

Liquity AG has worked with the following firms over the past four months to enforce the mission critical standard Liquity is known for:

In addition to these audits, Liquity AG will continue to underwrite a bug bounty program hosted on Hats Finance. As the V2 codebase draws heavily from the battle tested foundation of V1, this bounty will continue to accept submissions for both. You can learn more about the different features added in V2  by viewing the technical readme

All licensed forks of Liquity V2 have been requested to audit any modifications they make. Users of Liquity V2 forks, or those providing liquidity to their issued stablecoins, should always conduct due diligence to understand the delta between codebases and to be aware of any additional risks that may be present.

About Certora

Certora is a leading blockchain security firm specializing in formal verification of smart contracts. Their flagship tool, the Certora Prover, uses mathematical logic to analyze bytecode, identifying vulnerabilities across all potential contract states. Trusted by major protocols like Aave and Compound, Certora enhances blockchain reliability through rigorous verification, audits, and community collaboration. This commitment has positioned them as a trusted partner in securing decentralized applications.

Certora’s formal verification work on the Liquity V2 codebase focused specifically on the logic underpinning batch delegation for interest rate management. 

About ChainSecurity

ChainSecurity is a leading blockchain security firm specializing in smart contract audits and formal verification. Founded by experts from ETH Zurich, the company has collaborated with over 75 blockchain projects, including major DeFi protocols like MakerDAO and Compound. Their expertise and client-focused approach have established ChainSecurity as a top choice for ensuring the integrity of smart contracts. 

About Coinspect

Coinspect, founded in 2014, is a boutique blockchain security consulting firm specializing in smart contract audits, source code reviews, and penetration testing. With over 25 years of combined cybersecurity expertise, the firm has worked with major projects such as Ethereum Foundation, Bitcoin Core, Monero, and Zcash to enhance the security of decentralized applications.

  • Coinspect Core Protocol Audit Report  (To be published soon)
  • Coinspect Voting Module Audit Report (To be published January 2025)

About Dedaub

Dedaub is a leading blockchain security firm specializing in smart contract auditing and analysis. Founded in 2021 by Neville Grech and Yannis Smaragdakis, the company combines academic rigor with practical hacking expertise to provide comprehensive security solutions for decentralized applications. Dedaub's services include smart contract audits, decompilation, vulnerability detection, and real-time blockchain monitoring, with a client roster featuring prominent organizations such as the Ethereum Foundation, Chainlink, and Coinbase.

Dedaub conducted two core protocol audits, with the second coming after initial findings from both their and ChainSecurity’s work were addressed. Dedaub further conducted a review of the voting module as well.

About Recon

Recon is a blockchain security firm specializing in invariant testing and smart contract auditing. Their platform, Recon Pro, integrates tools like Echidna, Medusa, and Foundry to provide comprehensive invariant testing in the cloud, enabling developers to identify and address vulnerabilities before deployment. Their services include cloud-based fuzzing, live monitoring, and governance fuzzing, aiming to enhance the robustness of smart contracts in the blockchain ecosystem.

  • Recon Core Protocol Audit Report (To be published January 2025)