Proof of Audits
Deployed reviews

Independent public evidence record

Aave V4 at one exact block.

Inspect real contract addresses, runtime bytecode hashes, implementation slots, official audit sources, and every relationship this record has not proven.

Independent analysis from public sources. This is not an official Aave review, customer relationship, partnership, endorsement, score, or safety conclusion.

Observed on-chain

A fixed snapshot, not a blanket claim.

8Material contracts with runtime bytecode observed
8Runtime hashes recorded at the same block
2EIP-1967 implementation slots confirmed
0Score points claimed without complete mapping

This independent snapshot uses a partial material scope. It is publicly derived, incomplete, not owner verified, not publicly scored, and not a safety conclusion. It records what Proof of Audits observed at one block and keeps every missing audit, authority, function, and exit relationship open.

Implemented review system

Platform capabilities stay separate from record evidence.

These capabilities come from implemented deployed-protocol tables, services, workflow gates, and public consumers. A capability can exist while this Aave record still lacks the evidence needed to use it.

48 implemented capabilities · Aave evidence may remain open
01 / 48
0101 · 1/6Drag or swipe

Case and evidence control

Separate record for every version

Evidence from one release cannot silently carry over to a later release.
Why it matters

Keep one review tied to one protocol version, with sources that can be checked later.

Implemented platform capabilityIncluded when the accepted scope requires it

Capability 1 of 48: Separate record for every version. Group: Case and evidence control.

Swipe the card or use arrow keys

Audit-to-live code diff

Reports are discovered. Exact coverage still has to be proven.

Discovered review sources10
Open selected primary source
Coverage decision workspaceCandidate evidence is not a match
Published auditOfficial reports found
Reviewed artifactCommit/tag not mapped
Live implementation0xfe89…f704 confirmed

Exact coverage requires the reviewed commit, compiler configuration, scope exclusions, reproducible build, and live runtime match.

Evidence gap register

Every missing proof becomes owned work.

G-01Critical

Map every audit report to exact repository commit, files, and exclusions

Audit liaisonOPEN
G-02Critical

Reproduce Core Hub and Main Spoke builds and compare runtime hashes

Build verifierOPEN
G-03Critical

Resolve proxy administrators and governance execution authority

Authority reviewerOPEN
G-04High

Resolve Access Manager, configurator, oracle, position-manager, and gateway implementations

Deployment reviewerOPEN
G-05High

Map Chainlink feeds, oracle controls, heartbeat, deviation, and fallback behavior

Oracle reviewerOPEN
G-06High

Bind supply, withdraw, borrow, and repay selectors to reviewed functions

Function reviewerOPEN
G-07High

Run normal, constrained-liquidity, paused, and emergency exit simulations

Exit reviewerOPEN
G-08High

Collect operator interviews, incident evidence, monitoring receipts, and recovery proof

Evidence leadWAITING ON PROTOCOL

Interview status

No interview claimed until the accountable person answers.

01
NOT COLLECTED

Governance / execution owner

Questions

Who can queue and execute upgrades? What delay and veto paths apply?

Required proof

Executor addresses, timelock config, recent AIP trace

02
NOT COLLECTED

Protocol Security Council

Questions

Which emergency powers exist today, and when do they step down?

Required proof

Signer policy, pause/freeze matrix, incident drill

03
NOT COLLECTED

Core engineering owner

Questions

Which commits produced the live Hub and Spoke implementations?

Required proof

Release tag, compiler settings, build artifacts

04
NOT COLLECTED

Oracle / risk owner

Questions

Who changes feeds, caps, premiums, and fallback behavior?

Required proof

Feed registry, role grants, monitoring and escalation

05
NOT COLLECTED

Incident-response owner

Questions

How are users notified, exits protected, and recovery decisions recorded?

Required proof

Runbook, response SLA, drill or observed incident evidence

External ITS v2 decision

Nine buckets visible. Score withheld.

Authority, upgrade and team history

UNKNOWN_INSUFFICIENT_EVIDENCE
Pending / 190

User funds and exit rights

UNKNOWN_INSUFFICIENT_EVIDENCE
Pending / 120

Protection, monitoring and backstops

UNKNOWN_INSUFFICIENT_EVIDENCE
Pending / 110

Audit reality and current-code proof

UNKNOWN_INSUFFICIENT_EVIDENCE
Pending / 100

Care and accountability

UNKNOWN_INSUFFICIENT_EVIDENCE
Pending / 100

Live change and upgrade discipline

UNKNOWN_INSUFFICIENT_EVIDENCE
Pending / 80

Incident response and user recovery

UNKNOWN_INSUFFICIENT_EVIDENCE
Pending / 80

Our team user-care review

UNKNOWN_INSUFFICIENT_EVIDENCE
Pending / 70

Verified investor and user signal

UNKNOWN_INSUFFICIENT_EVIDENCE
Pending / 50

Complete feature output

Every evidence track shows proof, limitation, and next decision.

01
OBSERVED

Current-code proof

Runtime bytecode was read for eight material contracts at one exact Ethereum block. The Core Hub and Main Spoke EIP-1967 implementation slots matched the scoped implementations.

Evidence state recorded
02
PUBLIC SOURCES

Audit coverage

Ten reports are present in the official Aave V4 audit directory. Exact report-to-commit, file, and deployed-contract coverage still requires a formal mapping.

Evidence state recorded
03
OPEN

Authority graph

The Access Manager root is in scope. Role holders, proxy administration, and the governance execution path remain unresolved in this independent record.

Requires independent resolution
04
NOT PROVEN

User exits

Supply, withdraw, borrow, and repay are declared actions. Function selectors, liquidity constraints, emergency behavior, and simulations are not yet approved evidence.

Requires independent resolution
05
NOT COLLECTED

Operator interviews

No Aave operator interview is claimed. A formal review would request accountable owners for governance, emergency, oracle, upgrade, and incident-response decisions.

Requires independent resolution
06
OPEN

Change discipline

This record fixes one reference block. Later upgrades, new Spokes, cap changes, and authority changes require a new scope version and freshness decision.

Requires independent resolution
07
OPEN

Incident and recovery

Preparedness, observed response, user recovery, and drill evidence must be assessed separately. Public statements are not treated as approved criterion evidence.

Requires independent resolution
08
BLOCKED

Publication

Partial material scope cannot produce a public score badge. Unknown critical deployment effects block publication until independently resolved.

Requires independent resolution

Deployment graph

Material contracts stay inspectable.

ComponentContractRuntime hashObserved state
Core Hubcritical · 1,419 runtime bytesimplementation 0xfe89fd96f270ac3c0f11921af0390dbb1340f7040xcca852bc8ce826c90x6fe3bd0c49cd595d1d63Implementation slot confirmed
Main Spokecritical · 1,419 runtime bytesimplementation 0xabd0e26fe17bde4f1f1187ed8aa80c274e03d8b50x94e7a5dc2f56c4850xd5a0f33aee3ad117b542Implementation slot confirmed
Access Managercritical · 21,008 runtime bytes0x08ae3be3a87fdf010x34f8bd1e192a538f92e8Runtime observed; authority graph open
Hub Configuratorhigh · 13,833 runtime bytes0x1f075348e0525c3d0x12b260d3b0c50c76ecbfRuntime observed; audit mapping open
Spoke Configuratorhigh · 11,825 runtime bytes0x9bfff48befa5389a0xb0e1af0d5b0d6f80c8a5Runtime observed; audit mapping open
Main Spoke Oraclehigh · 2,396 runtime bytes0x99b2b6ce212a61270x9f0daa8269756020c009Runtime observed; dependencies open
Config Position Managerhigh · 13,330 runtime bytes0x51305839052d575c0x8449f037d3a3325bcb57Runtime observed; function mapping open
Native Token Gatewayhigh · 8,787 runtime bytes0xe68ab4f9bbbe42be0x9d4b0f40977543e6453fRuntime observed; function mapping open

Provenance

Claims link back to primary evidence.

Want this evidence record for your live protocol?

Apply for one of 10 sponsored founding baselines. Your team reviews the completed record and decides whether to authorize publication; findings remain independent.

Apply for sponsored baseline