URMCDP Audit Report
The URMCDP report examines collateralized borrowing, interest accrual, liquidation, oracle behavior, and configuration changes. Its final table records three high-severity findings (one acknowledged and two resolved) and five medium-severity findings marked resolved.
Report Summary
The URMCDP report examines collateralized borrowing, interest accrual, liquidation, oracle behavior, and configuration changes. Its final table records three high-severity findings (one acknowledged and two resolved) and five medium-severity findings marked resolved.
Scope and remediation reference
The coverage section identifies a contracts.zip source archive and a separate fix commit. The findings address the CDP and its collateral adapters. The remediation commit below is the report's fix reference, not a claim that the entire current deployment was reviewed. Source: PDF page 4.
Borrowing and liquidation findings
The high-severity findings cover adapter addresses, inconsistent debt valuation, and interest compounding triggered by repeated minimum borrows. The valuation finding is described as solved by design, with an external-liquidity assumption that the report recommends verifying. The adapter-address issue remains acknowledged in the final record. Source: PDF page 7.
Fixes and remaining assumptions
Medium-severity findings address liquidation buffers, interest-rate checkpoints, oracle-dependent repayment, TWAP consistency, and configuration changes affecting existing positions. The report documents fixes while retaining operational caveats, including oracle availability for forced liquidation and mutable TWAP settings. These qualifications matter when evaluating the final result. Source: PDF page 9.
Reading the final PASS result
The final summary considers the reviewed result satisfactory after remediation review. Its table still distinguishes an acknowledged high-severity finding from resolved findings. PASS is the conclusion for the documented review and assumptions, not a statement that no findings existed or that later changes are covered. Source: PDF page 24.
How to Evaluate This Report
Check the original PDF for the code version, reviewed components, exclusions, and remediation status. An audit applies to its documented scope; it does not automatically cover later upgrades or changes to external dependencies.
Planning a similar review? Compare our audit methodology and scope checklist, then discuss your project with CTDSEC.
| Project | URMCDP |
|---|---|
| Review type | Solidity CDP contract review |
| Scope | URM CDP contracts supplied as contracts.zip; collateral, borrowing, interest accrual and liquidation logic discussed in the findings |
| Report source | Featured public PDF |
| Source file | Cybersecurity_Audit_CTDSEC_URMCDP_PASS.pdf |
| Remediation commit | 7d216b1682f7f7a51ee67bdd0c1fc5eec739e74e |
Severity Summary
Counts and statuses reflect the public PDF's findings and final summary, not a new assessment of the current deployment.
Check the original final summary on PDF page 24. Acknowledged findings are not verified fixes.
Open the Public Report
Use the original PDF for complete context, exact wording, and detailed remediation notes.
Planning a similar review?
Request a smart contract audit for your protocol
Send the repository, target network, language, and launch timeline so CTDSEC can scope your audit accurately.