Audit reports
The full PDFs as the firms delivered them — no summaries standing in for the document, no gate. Each entry states the codebase that was reviewed, because that is the part a summary usually loses.
Upstream dependencies
Reviews of the on-chain components our contracts inherit from. They are published here because a dependency's audit is part of our surface too — but they are audits of that dependency, not of BlackQuant's own contracts.
Kiln Lagoon Vault Diff Review — Security Assessment
- Reviewed
- Lagoon v0 vault protocol (ERC-7540), version 0.6.0
- Window
- 20–24 April 2026 · one engineer-week
- Target
- hopperlabsxyz/lagoon-v0
A diff review of the v0.5.1-to-v0.6.0 upgrade: entry and exit fee arithmetic across the settlement, asynchronous claim and synchronous paths, the haircut mechanism for synchronous redemptions, the external sanctions-list oracle, whitelist and blacklist access modes, and the VaultInit delegatecall and storage layout. Deployment scripts and off-chain infrastructure were out of scope.
- 1Medium
Both findings resolved at fix review, 29 April 2026.
OpenZeppelin Contracts v5.6 Audit
- Reviewed
- OpenZeppelin Contracts library, v5.4.0 → v5.6.0-rc.1
- Window
- 26 January – 5 February 2026
A diff audit of the Solidity library our contracts inherit from — access control and AccessManager, ERC-4337 and ERC-7579 account abstraction, the crosschain and bridge contracts, Governor, the proxy and upgradeability primitives, and the ERC-20/721/1155 token extensions.
- 2Medium
18 findings in total — 14 resolved, 2 partially resolved.
Found something?
Report a vulnerability directly to the security inbox. We acknowledge within one working day and will not take legal action against good-faith research.