UpshiftDocs

Audits & Risk

Risk disclosures for the Upshift protocol and the full list of third-party smart contract audits.

Risks

Smart Contract Risks

The protocol will be interacting with a number of smart contracts, all of which impose risks. This can be both known and unknown risks that could result in the failure or vulnerability of the smart contracts which could result in assets being locked or lost forever.

Oracle Risks

Liquidations depend on a live, accurate price feed from oracles. Oracle downtime, incorrect prices, or manipulation can cause wrongful liquidations. Fallback systems, safety switches, and emergency notification systems are in place to mitigate this risk.

Bridge Risks

The protocol interacts with various bridges to move assets from blockchain to blockchain. While all bridges have been carefully reviewed for their risks and liquidity constraints, risks of bridge hacks and loss of funds cannot be alleviated.

Who bears the risk in case the risk engine fails?

There are three layers to risk mitigation:

  1. The protocol's insurance pool takes the first loss.
  2. The protocol's treasury as a second loss.
  3. Should (1) and (2) be depleted, the losses will have to be socialized amongst users.

Note: risk parameters significantly penalize supported protocols that do not have insurance pools or coverage themselves. This implies a de-facto first risk mitigation layer before the Upshift protocol gets affected.

Audits

Security audits don't eliminate risks fully. Please do not deposit more assets than you can afford to lose.

AuditorDateScopeReport
HalbornApril 2026Stellar VaultReport
HackenApril 2026Atomic VaultReport
HackenMarch 2026Instant Redemption SubaccountReport
HackenJanuary 2026AllocationWhitelistReport
HackenDecember 2025Report
OtterSecSeptember 2025Solana VaultReport
HackenSeptember 2025Report
ChainSecurityJanuary 2025Report
Sigma PrimeAugust 2024Report
ZellicApril 2023Fractal ProtocolReport
ZellicMarch 2022Fractal Protocol (final report)Report