#Audits
Exolane's smart contracts have undergone multiple security audits by leading blockchain security firms.
#Audit Summary
Codebase Lineage: Exolane's smart contracts are based on Perennial V2, protocol. The audits listed below were conducted on the V2 codebase, which Exolane deploys with its own configuration and market parameters.
| Audit | Auditor | Date | Focus | Status |
|---|---|---|---|---|
| V2 | Sherlock | August 2023 | Core Protocol | ✅ Complete |
| V2 | Zellic | August 2023 | Core Protocol | ✅ Complete |
| V2 Fix Review | Sherlock | September 2023 | Issue Remediation | ✅ Complete |
| V2.1 | Sherlock | October 2023 | Protocol Updates | ✅ Complete |
| V2.2 | Sherlock | March 2024 | Protocol Updates | ✅ Complete |
| V2.3 | Sherlock | August 2024 | Protocol Updates | ✅ Complete |
| V2.4 | Sherlock | February 2025 | Protocol Updates | ✅ Complete |
#About Auditors
#Sherlock
Sherlock is a leading smart contract security firm that combines traditional audits with a decentralized security network.
- Methodology: Expert-led audits + competitive audit contests
- Track Record: Hundreds of DeFi protocols secured
- Coverage: Full protocol security coverage
#Zellic
Zellic is a blockchain security firm specializing in complex DeFi protocols.
- Methodology: Deep manual review + automated analysis
- Specialization: Complex financial protocols
- Approach: Adversarial security research
#Audit Scope
Our audits cover:
| Component | Audited |
|---|---|
| Market contracts | ✅ |
| Oracle integration | ✅ |
| Collateral system | ✅ |
| Liquidation logic | ✅ |
| Funding rate math | ✅ |
| Position management | ✅ |
| Access controls | ✅ |
| Vault contracts | ✅ |
#Audit Findings
#Severity Classification
| Severity | Description |
|---|---|
| Critical | Direct loss of funds possible |
| High | Significant impact to protocol |
| Medium | Moderate impact or complex exploit |
| Low | Minor issues or improvements |
| Informational | Best practices, gas optimizations |
#Finding Resolution
All Critical and High severity findings have been:
- ✅ Acknowledged
- ✅ Fixed or mitigated
- ✅ Verified by auditors
#Continuous Security
Security is ongoing, not one-time:
| Activity | Frequency |
|---|---|
| Code reviews | Every change |
| Automated testing | Continuous |
| Fuzz testing | Continuous |
| Invariant testing | Continuous |
| New audits | Major versions |
#Accessing Audit Reports
Full audit reports are available:
- On-chain: Referenced in contract metadata
- GitHub: In the audits folder
- Request: Contact team for specific reports
#Limitations of Audits
Important: Audits do not guarantee security.
Audits reduce risk but cannot eliminate it entirely. Smart contract exploits can occur in audited code. Please review our Risk Disclosure for a complete understanding of risks.