Kaskad

Audits & Security

Audit Program

Kaskad's smart contracts have been independently audited prior to mainnet launch.

Sherlock

Kaskad partnered with Sherlock for its primary security audit. Sherlock's model provides:

  • Contest-based audits — multiple independent security researchers review the codebase simultaneously
  • Audit coverage — financial backing for any missed vulnerabilities found post-audit
  • Continuous review — ongoing security monitoring as the protocol evolves

Sherlock Audit — Completed

Auditors: hildingr, TessKimy
Audit period: February 16 – March 9, 2026
Final report date: April 30, 2026
Repository: Kaskad-Lending/kaskad-squashed
Final commit: 28307ddb107874a1309d50897b975cde2c3ee41c

📄 View Full Report

Findings Summary

SeverityFoundUnresolved
High90
Medium80
Low / Informational40

All High and Medium issues were resolved or acknowledged before the final commit. Zero issues remain unaddressed.

Audit Scope

The following contracts were audited:

ContractDescription
KaskadRewardsController.solReward distribution and index management
KaskadActivityTracker.solEpoch-based supply/borrow uptime tracking
EmissionManager.solEpoch emission scheduling and distribution
KaskadGovernor.solBounded governance and voting logic
KaskadStrategy.solVoting weight calculation
KSKDEmissionVault.solEmission vault and pull mechanics
KSKD.solProtocol token
StKSKDVault.solStaking vault and entry time logic
GrowthPool.solGrowth pool mechanics
BasketRevenueSplitter.solRevenue distribution
DaoRevenueSplitter.solDAO revenue routing
Basket4626.solERC-4626 basket utility
DecisionParams.solGovernance parameter bounds
SupplyAdjustment.solSupply adjustment logic
CommunityRoundVesting.solCommunity vesting contracts
TeamVesting.solTeam vesting contracts
EpochConfig.solEpoch configuration
+ 3 interfacesIEmissionManager, IKaskadActivityTracker, IKaskadStrategy

Bug Bounty Program

A formal bug bounty program will be launched alongside mainnet deployment, covering:

  • Smart contract vulnerabilities (critical, high, medium, low)
  • Oracle manipulation vectors
  • Cross-chain message integrity issues
  • Governance attack surfaces

Details and reward tiers will be published before mainnet launch.

Security Practices

  • Multi-sig governance — all protocol upgrades require multi-signature approval
  • Timelock delays — parameter changes are subject to time delays for community review
  • Circuit breakers — automated halting mechanisms for anomalous market conditions
  • Formal verification — planned for critical contract paths (liquidation, oracle)