Audit Reports
This page covers the audits that apply to Tydro: the audits of the Aave V3 base codebase, and any audits of other dependencies.
Two layers of review
Tydro's security review has two parts. The lending base is the Aave V3 codebase, which has been independently audited across multiple rounds by six firms and formally verified by Certora. Tydro then adds its own contracts and configuration on top, and those are reviewed separately. A deployment's own code and modifications are not covered by audits of the base.
Tydro v2 audits
Multiply Review
Payload/Economic Review
Aave V3 base codebase audits
These audits cover the core lending logic Tydro is built on. They do not cover Tydro's own contracts, configuration, or integrations.
V3 Round 1, October 2021
V3 Round 2, December 2021
V3.0.1, December 2022
Formal verification, November 2021 to January 2022
Note: how to read an audit report
An audit is one input to security. A report reflects a defined scope and a point in time. It does not cover code changed after the review, and a clean report does not prove the absence of bugs. Read these reports and evaluate the level of the diligence applied, alongside the controls described in Smart contract security architecture.
Bug bounties
Tydro has a bug bounty for verified issues. Reach out via official channels to contact our engineers.
Last updated
