Skip to main content

Security

Core Protocol Audits​

Full security reviews of the Mellow MetaVaults core architecture, including Vault, Subvault, queues, Oracle, Verifier, ShareManager, FeeManager, and RiskManager.

ReportAuditorDateScopeCommit
Mellow Core VaultsSherlock2025-07-28Modular vault infrastructure for institutional-grade asset management on EVM chainsc2d66f3
Mellow Core VaultsNethermind2025-09-03Core protocol contracts: Vault, Subvault, queues, Oracle, Verifier, and managers69413d5

Module and Incremental Audits​

Focused reviews of individual modules and contract updates.

ReportAuditorDateScopeCommit
NM-0682 MigratorNethermind2025-10-15Migrator contract for migrating MultiVault instances into new core vaultsa04e285
NM-0703 Oracle SubmitterNethermind2025-11-17OracleSubmitter — Chainlink-compatible price feed adapter for oracle price reportsd3bf393
NM-0735 Swap ModuleNethermind2025-11-19SwapModule for permissioned token swaps via DEX aggregators and CoW Protocol688382e
NM-0758 SyncDepositQueueNethermind2025-12-09SyncDepositQueue for instant synchronous deposits with oracle-price-based adjustmentf4c311b
NM-0798 BurnableTokenizedShareManagerNethermind2026-01-07BurnableTokenizedShareManager enabling public ERC20 burn/burnFrom for vault shares09d8155
NM-0812 Redeem Queue Fee FixNethermind2026-01-21Fee transfer fix from ShareManager to feeRecipient via burn and mint685be83
NM-0758 SyncDepositQueueNethermind2026-03-02Updated review of SyncDepositQueue reflecting a fix identified on Feb 27, 2026c9c7181

Bug Bounty​

Mellow Core Vaults Bug Bounty is a live bug bounty on the Sherlock platform, inviting security researchers to find and report vulnerabilities in the Mellow Core Vaults system. The program offers up to 100,000 USDC in rewards for valid findings and is part of Sherlock's ongoing post-deployment security incentives.