Back to work
Public report

Soroswap Aggregator

Stellar's Swap Aggregator

design reviewcode review
August 31, 2024StellarCode Review Audit

Critical / High

1Highest severity

Medium

1Moderate risk

Low / Informative

6Lower severity

Report files

1Downloadable assets

Audit lifecycle

This engagement is in progress.

In Progress

Completed

Scheduled

Scope, timeline, and review plan were agreed.

2

Current stage

In Progress

Manual review and verification work were carried out.

3

Upcoming

Completed

The engagement wrapped with a published final report.

Executive Summary

High-level assessment and conclusions

A concise overview of the audit scope, core findings, and the key outcomes from the engagement.

PaltaLabs engaged Runtime Verification Inc. to conduct a security audit of the Soroswap Aggregator and Adapters contracts' code. The objective was to review the platform’s business logic and implementation in Rust (Soroban) and identify any issues that could cause the system to malfunction or be exploited.
The audit was conducted over the course of 3 calendar weeks (July 15, 2024, through August 5, 2024) and focused on analyzing the security of the source code of Soroswap's Aggregator as well as the Adapters used to communicate with swap routing contracts from different protocols (Soroswap and Phoenix), which enables users to atomically perform optimal swaps using different protocols simultaneously. The swaps are split between multiple routers according to a custom pathing provided with the transaction, allowing the user to optimize the amounts returned by each protocol and enhancing the returns from that swap

Reports

Download the audit artifacts

Access the published PDF deliverables associated with this engagement.

1 file

PDF report 1

Soroswap_Aggregator.pdf

Download the published report for this engagement.

Download PDF