Security

Last updated 9 October 2026

Audit complete Zenith · Oct 2026

Smart contracts audited by Zenith.

All findings resolved and fixes verified.

Veridise

A second audit, with Veridise, is planned.

Contract design

The contract stack is organised into a small set of modules: lending, leverage, liquidation, risk and access control, and a thin periphery. These notes summarise the security-relevant choices. The full design is in Introducing Lattica, section 3 .

One entry point

Pool is the universal entry point for supply, withdraw, borrow, repay, roll and leverage. Outside a borrower reclaiming their own collateral on repayment, no caller can move collateral out of Pool. Its one privileged collateral-movement function is gated to the registered Liquidator.

Leverage stays off-chain by design

Leverage positions open through entry points gated to a permissioned execution role. The leverage multiple never reaches the contracts: Pool and Ledger see only a principal amount and a term, tracked against the same utilisation and portfolio accounting as a direct loan. Closes are never pause-gated, so principal can always return to the pool.

Signed, expiring quotes

Premium quotes are generated off-chain and verified on-chain as EIP-712 signatures. Quotes that have expired, replay a used nonce or carry an invalid signature revert at origination. Pool, PremiumOracle and Liquidator each use a distinct signing domain, so a signature made for one cannot be replayed against another.

Permissionless liquidation, fixed destination

Anyone can trigger a liquidation, but seized collateral always flows to a fixed liquidation wallet set at deploy time and rotatable only by the protocol admin. There is no seizure bonus to race for and no caller who can redirect collateral.

Vault accounting

latUSDC derives share price from tracked accounting rather than the raw token balance, with a virtual-share offset against the first-depositor inflation attack. It is deliberately not ERC-4626, so there is no second entry point for deposits and withdrawals.

No standing operator key

LatticaFactory deploys the full stack in one transaction, then renounces its admin role on every contract, leaving a timelock as the only admin authority.

Circuit breaker

The Configurator tracks realised losses against what the risk engine predicted. An operational role can trip the breaker instantly to block new originations, but only the timelocked admin can clear it.

Bug bounty

[Placeholder] Bug bounty programme (William is setting up a placeholder on Immunefi, 2026-10-10). Scope, rewards and how to report go here once it's live.

Contract addresses

Contract addresses will be published here after the second audit.

Report a vulnerability

[Placeholder] Security contact email for responsible disclosure (William is setting it up, 2026-10-10).