★ Audit scope mismatch
Orca's assessment for RD-F-001 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Six audit engagements documented in .audits/ directory. OtterSec verifiable build (verify.osec.io) confirms on-chain program whirLbMiicVdio4qvUfM5KAg6Ct8VwpYzGff3uctyCc matches commit e5f089bc5c49b01f5c8abb43c78457ab6c440568, verified 2026-02-04. Most recent Sec3 audit dated 2025-08-22 is the latest coverage point. Solana verifiable builds substitute for the Etherscan bytecode-match methodology on non-EVM substrates; hash match confirmed by OtterSec's independent verification service. No material mismatch between audited and deployed code identified.
Sources #
- URLOtterSec Verifiable Build Status — Whirlpools Programhttps://verify.osec.io/status/whirLbMiicVdio4qvUfM5KAg6Ct8VwpYzGff3uctyCcretrieved 2026-05-16
- Sec3 Audit Report 2025-08-22 (most recent)https://github.com/orca-so/whirlpools/blob/main/.audits/2025-08-22.pdfretrieved 2026-05-16
- Orca Whirlpools .audits directory (6 audit PDFs)https://github.com/orca-so/whirlpools/tree/main/.auditsretrieved 2026-05-16
Methodology #
Check whether the commit SHA cited in the audit report matches the bytecode deployed at the production proxy/implementation address.
See the full factor methodology and distribution across all protocols →