Security
Last updated 9 October 2026
Smart contracts audited by Zenith.
All findings resolved and fixes verified.
A second audit, with Veridise, is planned.
Contract design
The contract stack is organised into a small set of modules: lending, leverage, liquidation, risk and access control, and a thin periphery. These notes summarise the security-relevant choices. The full design is in Introducing Lattica, section 3 .
One entry point
Pool is the universal entry point for supply, withdraw, borrow, repay, roll and leverage. Outside a borrower reclaiming their own collateral on repayment, no caller can move collateral out of Pool. Its one privileged collateral-movement function is gated to the registered Liquidator.
Leverage stays off-chain by design
Leverage positions open through entry points gated to a permissioned execution role. The leverage multiple never reaches the contracts: Pool and Ledger see only a principal amount and a term, tracked against the same utilisation and portfolio accounting as a direct loan. Closes are never pause-gated, so principal can always return to the pool.
Signed, expiring quotes
Premium quotes are generated off-chain and verified on-chain as EIP-712 signatures. Quotes that have expired, replay a used nonce or carry an invalid signature revert at origination. Pool, PremiumOracle and Liquidator each use a distinct signing domain, so a signature made for one cannot be replayed against another.
Permissionless liquidation, fixed destination
Anyone can trigger a liquidation, but seized collateral always flows to a fixed liquidation wallet set at deploy time and rotatable only by the protocol admin. There is no seizure bonus to race for and no caller who can redirect collateral.
Vault accounting
latUSDC derives share price from tracked accounting rather than the raw token balance, with a virtual-share offset against the first-depositor inflation attack. It is deliberately not ERC-4626, so there is no second entry point for deposits and withdrawals.
No standing operator key
LatticaFactory deploys the full stack in one transaction, then renounces its admin role on every contract, leaving a timelock as the only admin authority.
Circuit breaker
The Configurator tracks realised losses against what the risk engine predicted. An operational role can trip the breaker instantly to block new originations, but only the timelocked admin can clear it.
Bug bounty
[Placeholder] Bug bounty programme (William is setting up a placeholder on Immunefi, 2026-10-10). Scope, rewards and how to report go here once it's live.Contract addresses
Contract addresses will be published here after the second audit.