Context
A DeFi lending protocol approaching mainnet launch asked for a full audit covering collateral management, liquidation logic, oracle integration, and cross-chain message handling. The team had internal tests but no prior external security review.
The liquidate() function issued an external callback to the liquidator's contract before updating the borrower's collateral balance. A malicious liquidator could recurse into liquidate() and drain the collateral pool in a single transaction.
The Chainlink oracle integration fetched latestAnswer() without checking the updatedAt timestamp. If a feed goes stale during a network congestion event, the protocol continues operating on an outdated price — enabling under-collateralised borrows.
updatedAt > block.timestamp - MAX_STALENESS; revert on stale dataHow We Worked
Manual review covered the business logic. Automated static analysis (Slither + custom rules) ran concurrently. We then forked Ethereum mainnet and replicated the reentrancy attack in a local environment — the PoC drained 100% of simulated collateral in one transaction. The team patched all criticals and highs within four days; we re-tested and issued a signed completion letter before launch.