DiscordNFT Collection
LYNX

Security

Audits & Security

Lynxify smart contracts were independently audited by yAudit in July 2026. The full report is live on yAudit.

Audit partner

yAudit

LYNX Token Contracts — audited by fedebianu and devtooligan

Auditor
yAudit
Status
Complete
In scope
17 contracts

yAudit reviewed the Hedera vault, HTS bridge, strategies, keeper workflows, governance, and migration paths. The main risks were migration sequencing, permissionless keeper DEX paths, asset valuation and loss recognition, and HTS share accounting. Every reported issue was remediated; developer responses in the report mark all findings Fixed.

View report on yAudit

Audit coverage

  • Reentrancy
  • Access Control
  • NAV Accounting
  • HTS Token Logic
  • Keeper Automation
  • Migration Safety
  • Governance
  • Slippage / MEV

Audit scope

17 production contracts (~3,049 lines) reviewed over 4 days. Libraries and interfaces in the same tree were included where they affect accounting, HTS, or keeper flows.

ScopeContractsAuditorTypeStatusDateReport
LYNX Vault & HTS BridgeLynxVault, LynxHTSBridgeyAuditSmart Contract AuditCompleteJuly 2026yAudit
Strategy ManagerStrategyManageryAuditSmart Contract AuditCompleteJuly 2026yAudit
Liquidity Pool & RouterSaucerSwapLiquidityStrategy, LynxLpAllocator, LynxKeeperRouteryAuditSmart Contract AuditCompleteJuly 2026yAudit
Staking StrategiesHederaStakingStrategy, LynxCompositeStakingStrategy, LynxStakingAllocatoryAuditSmart Contract AuditCompleteJuly 2026yAudit
Governance (DAO)LynxGovernor, LynxTimelock, LynxVotesyAuditSmart Contract AuditCompleteJuly 2026yAudit
Vault MigrationVaultMigrationStrategyyAuditSmart Contract AuditCompleteJuly 2026yAudit

Mainnet contracts

Current Hedera mainnet deployment after the 26 Aug 2026 cutover. Each ID opens the contract or token on HashScan.

ContractGroupHedera IDEVM
LynxVault
Vault & HTS Bridge0.0.108248790x0000…a52caf
LynxHTSBridge
Vault & HTS Bridge0.0.108249030x0000…a52cc7
LYNX (HTS)
Vault & HTS Bridge0.0.96336010x0000…92ff41
StrategyManager
Strategy Manager0.0.108248970x0000…a52cc1
SaucerSwapLiquidityStrategy
Liquidity0.0.108249090x0000…a52ccd
LynxLpAllocator
Liquidity0.0.108265370x0000…a53329
LynxCompositeStakingStrategy
Staking0.0.108249550x0000…a52cfb
LynxStakingAllocator
Staking0.0.108249570x0000…a52cfd
LynxKeeperRouter
Keeper0.0.108265350x0000…a53327
LynxGovernor
Governance0.0.108249790x0000…a52d13
LynxTimelock
Governance0.0.108249770x0000…a52d11
LynxVotes
Governance0.0.108249740x0000…a52d0e
VaultMigrationStrategy

Cutover relay on the retired June 2026 source manager

Vault Migration0.0.108249870x0000…a52d1b

yAudit findings

35 findings. Developer responses in the report mark every item Fixed. The yAudit write-up has technical detail, impact, and the remediating commits.

Critical
0
None found
High
3
Fixed
Medium
11
Fixed
Low
11
Fixed
Informational
10
Fixed
H-1
highFixed

Migration seed ordering can brick cutover or let migrated NAV be captured

Seeding after drain made cutover impossible; seeding an empty live vault let a dust deposit capture migrated NAV. Fixed by minting bridge backing while the successor stays paused, then moving funds.

H-2
highFixed

Public keeper paths can execute DEX operations with weak slippage bounds

Permissionless router calls could swap and mint LP with min-out of 0 or 1. Fixed by restricting those routes to the keeper and adding amount-scaled slippage.

H-3
highFixed

Composite staking withdrawals can turn remaining HBAR principal into fake harvest profit

Withdrawals reduced the wrong cost basis after selling hold legs, so the next harvest streamed non-existent yield into NAV. Fixed by tracking basis through liquidation.

Medium, low, and informational

IDFindingSeverityStatus
M-1Spot deviation can veto impairment synchronizationmediumFixed
M-2Failed pull valuation can leave impairment above principalmediumFixed
M-3Composite deployments lack amount-scaled slippage protectionmediumFixed
M-4Cached impairment misprices vault entry and exitmediumFixed
M-5Migration drain can report success while LP positions and tokens remain behindmediumFixed
M-6Migration omits source shares held outside bridge escrowmediumFixed
M-7Loss booking is unreachable because the keeper is the routermediumFixed
M-8Incorrect HTS approveNFT() selector prevents LP position closuremediumFixed
M-9Unvalued pair-token balances enable false loss booking and share dilutionmediumFixed
M-10Raw 1:1 share wrapping can exhaust HTS LYNX supply at ~92,233 WHBARmediumFixed
M-11Permissionless spot-price harvest can persistently understate LP NAVmediumFixed
L-1Extreme composite pool prices can halt the keeper looplowFixed
L-2Mainnet migration scripts use an incompatible manager ABIlowFixed
L-3Replacing a funded hold leg hides the previous tokenlowFixed
L-4Quorum tracks optional LynxVotes deposits instead of total share ownershiplowFixed
L-5Migration drain cap checks fail after capital is consolidatedlowFixed
L-6External fee recipient can block redemptionslowFixed
L-7Unrestricted proposals can weaken allocation-governance safeguardslowFixed
L-8Duplicate position serials in the LP allocator alias enabled statelowFixed
L-9Pausing the vault does not stop permissionless deployment of idle assetslowFixed
L-10Undeployed staking split slices unlock as false vault yieldlowFixed
L-11Native HBAR sent to the vault is stranded and cannot be recoveredlowFixed
I-1Core contracts lack renewal funding and expire at a fixed dateinfoFixed
I-2Redeem rounding underpays an external fee recipientinfoFixed
I-3Paused vault reports unlimited deposit and mint capacityinfoFixed
I-4Default mainnet staking manifest contains testnet hold-token IDsinfoFixed
I-5Duplicate composite hold tokens are double-counted in exposureinfoFixed
I-6Public deploy calls spend the router’s HBAR reserve on LP mint feesinfoFixed
I-7Strategy-reported gains are booked without verifying deliveryinfoFixed
I-8The timelock delay cannot be updated after deploymentinfoFixed
I-9LP drain implicitly sweeps the strategy’s entire pair-token balanceinfoFixed
I-10HSS failures can leave an enabled loop without a pending scheduleinfoFixed

Source: yAudit “LYNX Token Contracts” report, completed 2026-07-23. Reviewed commits 116b6c5 and b27206b. Fixes landed in follow-up commits listed in the yAudit report.

Internal CI review

In addition to yAudit, Lynx runs static analysis, fuzzing, and formal checks in CI. These are engineering gates — not a substitute for the independent report above.

Unit tests
157 / 157
Property fuzz
6,000 ops
Echidna
2 / 2
Halmos
7 / 7
Slither
141 triaged
Aderyn
5H + 16L

What CI covers

  • Direct-deploy ERC-4626 vault (no proxy) with cost-basis NAV and offset-6 inflation defense.
  • Bridge invariant: LYNX.totalSupply() equals vault shares escrowed in the HTS bridge.
  • HBAR deposit slippage via minSharesOut; harvest gains stream over 7 days.
  • Keeper / LP guards: amount-scaled min-out, fail-fast LP deploy, exposure-cap loss booking.

High-severity static analysis (triaged)

Slither / Aderyn alerts — not yAudit findings. No open exploit path after review.

  • H-01high

    SaucerSwap LP admin reentrancy ordering

    createLPPosition / increaseLPPosition update storage after external SaucerSwap calls. Slither reentrancy-eth; Aderyn H-2.

    Accepted
  • H-02high

    Payable contracts lock native HBAR

    LynxVault, LynxHTSBridge, and SaucerSwapLiquidityStrategy accept native value without a generic withdraw() sweep. Aderyn H-1.

    Accepted
  • H-03high

    Arbitrary-send-eth on staking wrap

    Slither arbitrary-send-eth: LynxKeeperRouter sends native HBAR to configured WHBAR helper during staking harvest wrap.

    Accepted
  • H-04high

    FullMath caret operator (Aderyn H-2)

    Aderyn flags Uniswap V3 FullMath.sol for incorrect use of the caret operator.

    False positive
  • H-05high

    Weak randomness on schedule probing

    Aderyn H-5 flags prevrandao / pseudo-random slot probing in LynxKeeperRouter schedule discovery.

    Accepted

Full CI logs and artifacts: GitHub Actions. Remaining tool noise (medium/low style flags) is tracked in repo triage, not duplicated here.