Core Protocol Audit
The following summarizes Cyfrin's comprehensive audit of Lotus Protocol. Read the full report for methodology, findings, and remediations.
Summary
Cyfrin is conducting a comprehensive smart contract audit of Lotus Protocol over a five-week engagement that began mid-July 2026. The audit covers the full protocol surface: the core lending contract, all risk engines and liquidation modules, governance (LotusGovernor and OperatorTimelock), vault integrations including the real-world-asset adapters (Coinbase Prime, WisdomTree WTGXX), the bundler, market hooks, the lens, the module and vault factories, pre-liquidation, and oracle staleness bounds.
The engagement also includes formal verification: machine-checked proofs of core accounting invariants using the Certora prover, developed by Cyfrin as part of the audit.
This audit is the final tier of a layered review process, following pre-audit reviews by 0x52 and Enigma Dark across multiple cycles and AI-assisted vulnerability scans, all complete with confirmed findings remediated. The full review history is documented in Security at Lotus.