> For the complete documentation index, see [llms.txt](https://docs.tydro.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.tydro.com/vi.-security/audit-reports.md).

# Audit Reports

This page covers the audits that apply to Tydro: the audits of the Aave V3 base codebase, and any audits of other dependencies.

### Two layers of review

Tydro's security review has two parts. The lending base is the Aave V3 codebase, which has been independently audited across multiple rounds by six firms and formally verified by Certora. Tydro then adds its own contracts and configuration on top, and those are reviewed separately. A deployment's own code and modifications are not covered by audits of the base.

### **Tydro v2 audits**

**Multiply Review**

<table><thead><tr><th width="235.12109375">Auditor</th><th>Date</th><th>Report</th></tr></thead><tbody><tr><td>Zellic</td><td>August 2026</td><td><div data-gb-custom-block data-tag="file" data-src="https://710064532-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBm7pNGfoWEDcBs1hL6I%2Fuploads%2F5Aa2BOUuz6tx3jZxVXVB%2FMultiply%20-%20Zellic%20Audit%20Report%20(2).pdf?alt=media&amp;token=ed492e4d-146b-4fa3-8c0c-820212f3d8d4"></div><p></p></td></tr></tbody></table>

**Payload/Economic Review**

<table><thead><tr><th width="235.12109375">Auditor</th><th>Date</th><th>Report</th></tr></thead><tbody><tr><td>Zellic</td><td>August 2026</td><td><div data-gb-custom-block data-tag="file" data-src="https://710064532-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBm7pNGfoWEDcBs1hL6I%2Fuploads%2FDiXIQQHeLLfM0ztydxda%2FTydro%20-%20PayloadEconomic%20Review%20-%20Zellic%20Audit%20Report%20(1).pdf?alt=media&amp;token=5be4242c-1477-4c02-9afb-f49b59bbacc6"></div><p></p></td></tr></tbody></table>

### Aave V3 base codebase audits

These audits cover the core lending logic Tydro is built on. They do not cover Tydro's own contracts, configuration, or integrations.

**V3 Round 1, October 2021**

| Auditor       | Date          | Report                                                                                                    |
| ------------- | ------------- | --------------------------------------------------------------------------------------------------------- |
| ABDK          | January 2022  | [View report](https://github.com/aave/aave-v3-core/blob/master/audits/27-01-2022_ABDK_AaveV3.pdf)         |
| OpenZeppelin  | November 2021 | [View report](https://github.com/aave/aave-v3-core/blob/master/audits/01-11-2021_OpenZeppelin_AaveV3.pdf) |
| Trail of Bits | January 2022  | [View report](https://github.com/aave/aave-v3-core/blob/master/audits/07-01-2022_TrailOfBits_AaveV3.pdf)  |
| PeckShield    | January 2022  | [View report](https://github.com/aave/aave-v3-core/blob/master/audits/14-01-2022_PeckShield_AaveV3.pdf)   |

**V3 Round 2, December 2021**

| Auditor    | Date         | Report                                                                                                  |
| ---------- | ------------ | ------------------------------------------------------------------------------------------------------- |
| SigmaPrime | January 2022 | [View report](https://github.com/aave/aave-v3-core/blob/master/audits/27-01-2022_SigmaPrime_AaveV3.pdf) |

**V3.0.1, December 2022**

| Auditor    | Date          | Report                                                                                                      |
| ---------- | ------------- | ----------------------------------------------------------------------------------------------------------- |
| PeckShield | December 2022 | [View report](https://github.com/aave/aave-v3-core/blob/master/audits/09-12-2022_PeckShield_AaveV3-0-1.pdf) |
| SigmaPrime | December 2022 | [View report](https://github.com/aave/aave-v3-core/blob/master/audits/23-12-2022_SigmaPrime_AaveV3-0-1.pdf) |

**Formal verification, November 2021 to January 2022**

| Auditor | Date         | Report                                                                                                                 |
| ------- | ------------ | ---------------------------------------------------------------------------------------------------------------------- |
| Certora | January 2022 | [View report](https://github.com/aave/aave-v3-core/blob/master/certora/Aave_V3_Formal_Verification_Report_Jan2022.pdf) |

<table><thead><tr><th width="235.12109375">Auditor</th><th>Date</th><th>Report</th></tr></thead><tbody><tr><td>Zellic</td><td>August 2026</td><td><p><a href="https://files.gitbook.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBm7pNGfoWEDcBs1hL6I%2Fuploads%2Fakc507jHCVuMyDTeQgCx%2FMultiply%20-%20Zellic%20Audit%20Report%20(1).pdf?alt=media&#x26;token=c977ba6a-b21b-4c17-8d74-d4b973183f72">View report</a></p><p></p></td></tr><tr><td>LlamaRisk</td><td>August 2026</td><td><a href="https://files.gitbook.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUBm7pNGfoWEDcBs1hL6I%2Fuploads%2FmQNBksTR9jAV0e5inBGS%2FTydro_%20kBTC%20Parameter%20Review%20-%20LlamaRisk%20v2.pdf?alt=media&#x26;token=0e2c6cb8-2658-4b36-ba22-db33c401ea72">View report</a></td></tr></tbody></table>

### Note: how to read an audit report

An audit is one input to security. A report reflects a defined scope and a point in time. It does not cover code changed after the review, and a clean report does not prove the absence of bugs. Read these reports and evaluate the level of the diligence applied, alongside the controls described in Smart contract security architecture.

### Bug bounties

Tydro has a bug bounty for verified issues. Reach out via official channels to contact our engineers.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.tydro.com/vi.-security/audit-reports.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
