01
Manual Security Audit
sha256 03678e5aea79dae4d3c993c0b40a92c234da7d8df6d41a4f9a741873f1ebcdcf
The final assessment reconciled 65 canonical findings across core markets, arithmetic, rewards, adapters, registry, lifecycle, and deployment posture. Thirty-eight findings were resolved or removed, 25 remain acknowledged or conditional, two experimental surfaces are excluded from deployment, and none remains open.
01
sha256 03678e5aea79dae4d3c993c0b40a92c234da7d8df6d41a4f9a741873f1ebcdcf
02
sha256 00ae8f553a8dc93dff65174bd52f10f83d9cd5b9ea930c125ac65eef4ac75297
Jitter Protocol combines principal and yield token issuance, an AMM, positions, liquidity, rewards, oracle aggregation, third-party adapters, registry discovery, lifecycle controls, and an experimental orderbook. The review followed value and authority through that entire graph, then separated production guarantees from deployment exclusions and operating assumptions.
The final manual assessment records 65 canonical findings: 38 resolved or architecture- eliminated, 25 acknowledged or conditional, two deployment-excluded, and zero open. No confirmed Critical or High attack chain was identified that lets an unprivileged user steal Jitter V1 core principal. The High experimental-orderbook finding is excluded from the V1 deployment graph.
The reviewed tree becomes a release artifact only after a clean commit and dependency graph are frozen, acknowledged arithmetic and reward boundaries are recorded in the runbook, production adapters are signed off, excluded packages are removed, and the Move, formal, mutation, deployment, and operational suites pass from a clean checkout.
The demo package is excluded from production deployment and remains testnet-only.
Requests, vaults, markets, SY registrations, and underlying types are now bound at both layers.
Registered source witnesses and exact aggregator-rule binding now authenticate the source.
Execution now validates exact aggregator, market, freshness, and single-use price information.
Source count, freshness, required-source, deviation monitoring, and emergency pause remain the controls.
Ember is not deployed. Activation requires authoritative upstream timestamps and production-ABI tests.
Upstream versions remain an operational dependency with monitoring and recovery runbooks.
Owner cancellation, administrative resolution, linked storage, and queued-reserve accounting mitigate the risk.
Both adapters are excluded until actual payout equality is proven or settlement uses actual output with a user minimum.
Current is not deployed; production activation requires domain and overflow validation.
The accepted keeper model requires an immediate refresh after vault creation and baseline monitoring.
Accrual and upstream version availability remain monitored integration dependencies.
NAVI remains undeployed until capability, recovery, and migration semantics are complete.
Persistent oracle paths now enforce package registration, version, and pause checks.
Suilend remains undeployed until production compound and refresh semantics are validated.
Deployment is restricted to the tested domain with monitoring and an upgrade path until safe guard values are calibrated.
The architecture now binds one canonical distributor and validates market scope atomically.
Keeper service levels, alerting, and settlement drills remain explicit operational requirements.
Campaign close is separate from emergency pause, preserving liability-reducing exits.
Execution uses the quoted candidate state and rejects zero-output removals.
Market creation now requires zero PT and YT TreasuryCap supply.
Deregistration is rejected while a live market or liability references the SY registration.
Exact underlying type binding now spans requests, vaults, and market state.
One on-chain treasury source now controls recipient and accounting state.
Bounded operational use and explicit unpause cleanup are accepted for the small configured set.
The bridge was removed; YT exposure changes stay on canonical gated position routes.
Destruction now requires PT, YT, LP, and accrued interest to be zero.
Zero remains an explicit integration choice; user-facing SDK routes must enforce nonzero deadlines.
Events now emit values captured from the executed candidate state.
The unused event and its dead construction path were removed.
The revised lifecycle lets circulating LP reach zero and reserves drain safely.
Point configuration and reward topology now attach to the canonical market and distributor gate.
Market-scoped rewarder selection replaced the mutable global union.
Registration generation and start-time baselines prevent historical backpay.
Referral state now binds policy, project, position, owner, and registration generation.
Canonical permissionless checkpoint and claim routes preserve detached pending rewards.
The accepted architecture documents scope topology and pairs LP and pool checkpoint capabilities.
Withdrawal remains an auditable ACL or multisig governance operation.
Claimant-less sub-raw dust is accepted because principal is unaffected; closed-lot residuals are monitored.
Canonical integrations use Project and Stamp witnesses and isolate manual issuance.
Permissionless bounded checkpoints mitigate the accepted catch-up requirement.
Effective-time versioning settles old intervals under their prior configuration.
Normal campaign close is separate from emergency pause and preserves canonical exits.
The package is excluded from V1 deployment and retains bounded keeper cleanup requirements.
Orderbook exposure was removed from canonical rewards until a stable topology exists.
Cumulative fee accounting resolves the issue before any future deployment.
Execution now consumes the exact candidate state returned by the solver.
The solver recovers the last valid bracket and resumes maximality search.
The bounded implementation is optimized, with gas and dense-vector behavior retained as monitored limits.
An explicit validity representation replaced the overlapping sentinel.
The extreme index frontier remains accepted until the guard is calibrated or the proof domain expands.
Unused public helpers were removed from the production surface.
The signed Q64 negative domain remains a documented boundary that must fail closed outside its range.
Canonical discovery, exact IDs, and explicit multi-instance administration mitigate the accepted design.
Nonzero result validation is now independent from the configured basis-point value.
AdminCap is an explicit multisig trust boundary; scoped ACL operations are preferred.
Lifecycle events and generation controls harden the accepted governance boundary.
SDK and indexer revalidation plus lifecycle runbooks control the discovery-layer risk.
Governance and downstream checks now assert the root marker and allowed version.
Deployment manifests now use recursive discovery with regression coverage.
Persistent position mutation now requires GlobalConfig and core package version checks.
Creation requires strict-active status; version-only paths are limited to liability reduction.
Same-version registration is idempotent and version changes require explicit approval.
The helper is private and only the gated ticket route remains public.
Recovery may disable a campaign, but enabling now requires strict package-active status.
The formal program passed 191 of 191 shared-suite proofs, mapped all 65 Jitter findings, and detected all 14 deliberate mutations. Direct proofs and models cover solver boundaries, market-ledger conservation, calendar reward-lot conservation, registry behavior, adapter conversion direction, reserve-fee remainders, and final user-fund preservation.
Ten symbolic obligations remain at the proof frontier: indexed-quote zero-edge bodies,
production logarithms, power-of-two log specifications, production natural logarithm behavior,
and full-domain sqrt_u256 convergence. These are coverage gaps rather than confirmed
vulnerabilities; they become release blockers if production parameters can reach those domains.
Formal verification does not prove third-party adapter semantics, oracle economic truth, honest administration or keeper operation, arbitrary transaction gas feasibility, RPC availability, frontend correctness, wallet behavior, key custody, or specification completeness.
The original deliverables and publication history are available in the public report repository.