Concrete — Complete GuideIndependent guide, unofficial

05

Security model and audit history

Level: Intermediate · An audit reduces risk; it never eliminates it.

Three security layers (from the Risks & Safety docs)

1. Vault infrastructure

  • Audited before launch by Halborn, Cantina, Code4rena or Zellic; ongoing bug bounty with Cantina.
  • Separated roles - no single key controls everything.
  • On-chain accounting limits - change threshold, cooldown and validity window bound how off-chain values move the vault; the vault pauses on unusual changes.
  • Controlled upgrades - UUPS proxies; pull-based upgrades (vault owners pull from the factory; Concrete cannot push code into deployed vaults).
  • Multisig / MPC custody - Gnosis Safe or Fordefi MPC; signing authority split across independent groups.
  • Queued withdrawals create a monitoring window before funds leave.

2. Strategy layer

  • Every strategy passes risk, accounting and compliance review before receiving funds.
  • Whitelisted interactions only.
  • Transaction validation - automated transactions pass multiple independent checks incl. simulation.
  • Granular controls - each strategy pausable independently; a policy engine governs actions with multi-party approval.

3. Oversight & verification

  • Hypernative: 24/7 monitoring of vault addresses.
  • ZeroShadow: pre-delegated authority to pause vaults per mandate.
  • Independent valuation cross-checks at regular intervals.

Audit timeline (as listed in the official docs, newest first)

DateScopeAuditor
25 Aug 2026AssetCX OFT & OFT AdapterHalborn
13 Jul 2026Earn v2 1.5 & AssetCx 1.3Halborn
19 May 2026Earn v2 1.4 & AssetCx 1.2Halborn
22 Apr 2026Earn v2 - Hurdle RateHalborn
17 Apr 2026Earn V2 - Position Management HelperHalborn
2 Mar 2026Earn v2 - Improvements & priority withdrawal mechanismHalborn
20 Feb 2026Earn V2 CoreCantina
13 Feb 2026Looping Strategy Swapper ContractHalborn
9 Jan 2026AssetCXHalborn
18 Dec 2025Earn V2 - Whitelisting HookHalborn
23 Oct 2025Earn V2 - Predeposit VaultHalborn
10 Oct 2025Earn V2 Core - Async & Standard implementationsHalborn
29 Sep 2025Upgradable Multisig and Queue changesHalborn
19 Jul 2025Earn V1Halborn
6 Jun 2025Earn V1Zellic
16 May 2025Withdrawal Queue ToggleHalborn
10 Feb 2025Earn V1 competition (Parts 1 & 2)Code4rena
2024 – Mar 2025Strategies, Spokes/HUB v1, Morpho vault & lender integrations, Curve/Pendle strategy, rewards distribution, vault manager, upgradeability, harvest rewards, withdrawal pause…Halborn

Full PDFs: docs.concrete.xyz/Audits. Each audit covers a specific code version - check that the report matches the deployed version of the vault you use.

Reading an audit report (mini-guide)

  1. Confirm scope + commit hash vs the deployed contract.
  2. Look at critical/high findings: were they fixed or acknowledged?
  3. Note centralization/trust assumptions (admin, operator, pausers).
  4. Ask what is out of scope (off-chain accounting, custodians, integrations).

Trust assumptions you still accept

  • Operators pushing correct valuations for custodied strategies.
  • Custody providers (Fireblocks/Fordefi/Safe signers).
  • Partner protocols the strategies touch.
  • Governance roles (Vault Admin etc.) acting properly - roles are separated, not eliminated.
  • Off-chain services (allocator, withdrawal manager) staying live.

Reporting a vulnerability

Concrete runs a bug bounty with Cantina - see the Cantina/Concrete listing and docs support. Do not test on mainnet funds you do not own.