Public audit report

URMCDP Audit Report

The URMCDP report examines collateralized borrowing, interest accrual, liquidation, oracle behavior, and configuration changes. Its final table records three high-severity findings (one acknowledged and two resolved) and five medium-severity findings marked resolved.

Report Summary

The URMCDP report examines collateralized borrowing, interest accrual, liquidation, oracle behavior, and configuration changes. Its final table records three high-severity findings (one acknowledged and two resolved) and five medium-severity findings marked resolved.

Scope and remediation reference

The coverage section identifies a contracts.zip source archive and a separate fix commit. The findings address the CDP and its collateral adapters. The remediation commit below is the report's fix reference, not a claim that the entire current deployment was reviewed. Source: PDF page 4.

Borrowing and liquidation findings

The high-severity findings cover adapter addresses, inconsistent debt valuation, and interest compounding triggered by repeated minimum borrows. The valuation finding is described as solved by design, with an external-liquidity assumption that the report recommends verifying. The adapter-address issue remains acknowledged in the final record. Source: PDF page 7.

Fixes and remaining assumptions

Medium-severity findings address liquidation buffers, interest-rate checkpoints, oracle-dependent repayment, TWAP consistency, and configuration changes affecting existing positions. The report documents fixes while retaining operational caveats, including oracle availability for forced liquidation and mutable TWAP settings. These qualifications matter when evaluating the final result. Source: PDF page 9.

Reading the final PASS result

The final summary considers the reviewed result satisfactory after remediation review. Its table still distinguishes an acknowledged high-severity finding from resolved findings. PASS is the conclusion for the documented review and assumptions, not a statement that no findings existed or that later changes are covered. Source: PDF page 24.

How to Evaluate This Report

Check the original PDF for the code version, reviewed components, exclusions, and remediation status. An audit applies to its documented scope; it does not automatically cover later upgrades or changes to external dependencies.

Planning a similar review? Compare our audit methodology and scope checklist, then discuss your project with CTDSEC.

ProjectURMCDP
Review typeSolidity CDP contract review
ScopeURM CDP contracts supplied as contracts.zip; collateral, borrowing, interest accrual and liquidation logic discussed in the findings
Report sourceFeatured public PDF
Source fileCybersecurity_Audit_CTDSEC_URMCDP_PASS.pdf
Remediation commit7d216b1682f7f7a51ee67bdd0c1fc5eec739e74e

Severity Summary

Counts and statuses reflect the public PDF's findings and final summary, not a new assessment of the current deployment.

Check the original final summary on PDF page 24. Acknowledged findings are not verified fixes.

3 High - 1 acknowledged; 2 resolved
5 Medium - 5 resolved
0 Low - None listed in the findings section
0 Informational - None listed in the findings section

Open the Public Report

Use the original PDF for complete context, exact wording, and detailed remediation notes.

Planning a similar review?

Request a smart contract audit for your protocol

Send the repository, target network, language, and launch timeline so CTDSEC can scope your audit accurately.

Get an Audit Quote