★ Audit scope mismatch
deBridge's assessment for RD-F-001 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Most recent EVM audit: Halborn "DLN EVM Upgrades" dated 2024-12-30 (PDF: `DLN-EVM_Upgrades_SSC.pdf` in debridge-security repo). DlnSource proxy at `0xeF4fB24...` was upgraded to impl `0x322B481...` (solc 0.8.28) on 2025-12-08 (tx `0x25b203...`). DlnDestination proxy at `0xe7351fd...` was upgraded to impl `0xE540eb6...` (solc 0.8.28) on 2026-02-13 (tx `0xf18791...`). These deployed implementations post-date the last confirmed EVM audit by 5–14 months. No subsequent audit PDF found in debridge-...
Sources #
- GitHubhttps://github.com/debridge-finance/debridge-securityretrieved 2026-04-28
- https://etherscan.io/address/0xeF4fB24aD0916217251F553c0596F8Edc630EB66retrieved 2026-04-28
- https://etherscan.io/address/0xe7351fd770a37282b91d153ee690b63579d6dd7fretrieved 2026-04-28
Methodology #
Check whether the commit SHA cited in the audit report matches the bytecode deployed at the production proxy/implementation address.
See the full factor methodology and distribution across all protocols →