The engagement
Two passes, and the second one had to prove itself.
The first pass was a deployment audit: independent reproduction of the deployed bytecode against the frozen source, an exhaustive role census reconstructed from the chain's own event log, parameter conformance against the pinned config, and a hard read of what the public record does and does not disclose. It closed with a plain statement of two gaps — no fork reproduction, and no independent adversarial cross-examination — because a report that hides its limits is not evidence.
The second pass closed both gaps. A harness bound to the live mainnet addresses and drove the deployed contracts from genesis through mint, deposit, origination, funding, default and settlement. Four independent reviewers read all twenty-three contracts under distinct adversarial lenses. Every surviving candidate was then handed to a skeptic instructed to refute it — and the results were reported honestly: one candidate was refuted outright, one finding was de-escalated from Medium to Low when the refutation held, and one of the protocol's own prior risk acceptances was corrected after its stated exploit path failed to reproduce.
What the second pass found
Every finding below is a passing test against production bytecode unless marked source. The deployed code proved unusually hardened — sixteen prior review rounds and the protocol's own maximum-assurance-grade campaign (a 1,085/1,085-mutation sweep across five axes plus 126 fork-based exploitation tests, completed 2026-08-13, with SEVERE 0 · MODERATE 0 · exploitable 0) sit behind it — so the exposure this engagement found sits in operator-reachable state machines, launch sequencing, and what has been disclosed, not in anyone-drains-the-vault bugs.
| # | Severity | Summary |
|---|---|---|
| DV-01 | Medium | A fixed-gas "is the source broken?" recovery probe misreads a healthy-but-heavy impairment source as broken; a good-faith governance call then drops the senior mark to par with an irreversible high-water-mark ratchet. |
| DV-02 | Medium | A never-cleared shared incident-id namespace lets one privileged action permanently strand the reserve-loss machine — blocking the protocol's only on-chain custody-loss absorption path. |
| DV-03 | Medium | Origination and funding require no junior capital; a facility funds with both cascade layers empty, and a default drives the full loss straight onto senior holders. |
| DV-04 – DV-08 | Low | Five hardening findings: an inconsistently-applied hook gas floor, a global-solvency cancel gate, a provably vacuous cascade guard, a launch-inert yield-sizing bug, and a false anti-latch invariant comment. |
| Config | Medium | Four signing Safes sharing one owner set; queued governance that cannot be vetoed and is undisclosed on the public surface — reproduced live, and reported against the protocol's own register. |
The full report carries each finding with its reproduction, the adversarial verdict, and a recommendation. The deployment audit carries the verification appendices — bytecode, roles, parameters and storage — in full.
Stated plainly. These are AI-assisted audits — deterministic analysis, independent multi-model review, adversarial refutation of every candidate, and reproduction of every finding against live bytecode — carrying the methodology maximum assurance requires, layered on Forest Road Vault's own maximum-assurance-grade campaign (the 1,085-mutation sweep and 126 fork-exploitation tests above). Forest Road Vault is an early, aligned design partner rather than an arm's-length commercial client; Corrovera is not yet selling audits and makes no claim of superiority to professional teams. The findings are real, reproduced on live bytecode, and published in full alongside their limits.