defirisk.co
rubric v1.7.0

Contract unverified on Etherscan/Sourcify

Sanctum's assessment for RD-F-046 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

On-chain programs are open source on GitHub (igneous-labs org) and support solana-verify reproducible builds. Original Infinity V1 (S program) was open-source at audit time. However: (a) Controller Program V2 (inf-1.5, March 2026) is the live Infinity V2 codebase — no audit PDF for this version found in sanctum-static/audits/ (contains only V1 PDFs); (b) Router program audit coverage unconfirmed; (c) on-chain verified state for V2 bytecode not confirmed via solana-verify output in public sources.

Sources #

  • GitHub
    GitHub: sanctum-static/audits directoryigneous-labs/sanctum-static/audits/ contains only V1 PDFs (Ottersec, Neodyme-INV-24-01, Sec3-Sanctum_S)retrieved 2026-05-04
  • GitHub
    GitHub: igneous-labs/inf-1.5igneous-labs/inf-1.5: Controller Program V2 tagged March 12 2026 — no corresponding audit in sanctum-static/audits/retrieved 2026-05-04

Methodology #

Determine whether the protocol's deployed contracts have source code verified on Etherscan or Sourcify (public ABI available).

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol sanctum factor RD-F-046 score yellow collected_at 2026-05-04 18:49:23