Security

Audit reports

The full PDFs as the firms delivered them — no summaries standing in for the document, no gate. Each entry states the codebase that was reviewed, because that is the part a summary usually loses.

Upstream dependencies

Reviews of the on-chain components our contracts inherit from. They are published here because a dependency's audit is part of our surface too — but they are audits of that dependency, not of BlackQuant's own contracts.

Kiln Lagoon Vault Diff Review — Security Assessment

Reviewed
Lagoon v0 vault protocol (ERC-7540), version 0.6.0
Window
20–24 April 2026 · one engineer-week

A diff review of the v0.5.1-to-v0.6.0 upgrade: entry and exit fee arithmetic across the settlement, asynchronous claim and synchronous paths, the haircut mechanism for synchronous redemptions, the external sanctions-list oracle, whitelist and blacklist access modes, and the VaultInit delegatecall and storage layout. Deployment scripts and off-chain infrastructure were out of scope.

  • 1Medium
  • 1Low

Both findings resolved at fix review, 29 April 2026.

PDF969 KB

OpenZeppelin Contracts v5.6 Audit

Reviewed
OpenZeppelin Contracts library, v5.4.0 → v5.6.0-rc.1
Window
26 January – 5 February 2026

A diff audit of the Solidity library our contracts inherit from — access control and AccessManager, ERC-4337 and ERC-7579 account abstraction, the crosschain and bridge contracts, Governor, the proxy and upgradeability primitives, and the ERC-20/721/1155 token extensions.

  • 0Critical
  • 0High
  • 2Medium
  • 10Low
  • 5Notes

18 findings in total — 14 resolved, 2 partially resolved.

PDF369 KB

How to read these

An audit is a snapshot of specific commits over a fixed window, by people who had a fixed number of days. It is evidence that the code was looked at carefully, not a proof that it is safe — and a report covering a dependency says nothing about the code we wrote on top of it. Read the scope section of each PDF before drawing a conclusion from it; that is why the whole document is here rather than a score.

Found something?

Report a vulnerability directly to the security inbox. We acknowledge within one working day and will not take legal action against good-faith research.