Fork retains upstream audit coverage
Ondo Finance's assessment for RD-F-131 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Compound v2 upstream: Trail of Bits + OpenZeppelin audits + Certora FV (inherited). Flux Finance delta-audit: Code4rena January 2023. C4 Jan 2023 M-02 (donation vulnerability) resolution status unconfirmed. Delta-audit is 39 months old.
Sources #
- Audithttps://code4rena.com/reports/2023-01-ondo/retrieved 2026-04-28
- https://docs.fluxfinance.com/trust-and-securityretrieved 2026-04-28
Methodology #
Determine whether the fork's deployed code is covered by either: (a) the upstream audit plus a delta-audit for fork-specific changes, or (b) a fresh independent audit of the fork.
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol ondo-finance factor RD-F-131 score yellow collected_at 2026-05-14 12:01:55