Audits & Risk
Risk disclosures for the Upshift protocol and the full list of third-party smart contract audits.
Risks
Smart Contract Risks
The protocol will be interacting with a number of smart contracts, all of which impose risks. This can be both known and unknown risks that could result in the failure or vulnerability of the smart contracts which could result in assets being locked or lost forever.
Oracle Risks
Liquidations depend on a live, accurate price feed from oracles. Oracle downtime, incorrect prices, or manipulation can cause wrongful liquidations. Fallback systems, safety switches, and emergency notification systems are in place to mitigate this risk.
Bridge Risks
The protocol interacts with various bridges to move assets from blockchain to blockchain. While all bridges have been carefully reviewed for their risks and liquidity constraints, risks of bridge hacks and loss of funds cannot be alleviated.
Who bears the risk in case the risk engine fails?
There are three layers to risk mitigation:
- The protocol's insurance pool takes the first loss.
- The protocol's treasury as a second loss.
- Should (1) and (2) be depleted, the losses will have to be socialized amongst users.
Note: risk parameters significantly penalize supported protocols that do not have insurance pools or coverage themselves. This implies a de-facto first risk mitigation layer before the Upshift protocol gets affected.
Audits
Security audits don't eliminate risks fully. Please do not deposit more assets than you can afford to lose.
| Auditor | Date | Scope | Report |
|---|---|---|---|
| Halborn | April 2026 | Stellar Vault | Report |
| Hacken | April 2026 | Atomic Vault | Report |
| Hacken | March 2026 | Instant Redemption Subaccount | Report |
| Hacken | January 2026 | AllocationWhitelist | Report |
| Hacken | December 2025 | — | Report |
| OtterSec | September 2025 | Solana Vault | Report |
| Hacken | September 2025 | — | Report |
| ChainSecurity | January 2025 | — | Report |
| Sigma Prime | August 2024 | — | Report |
| Zellic | April 2023 | Fractal Protocol | Report |
| Zellic | March 2022 | Fractal Protocol (final report) | Report |