TAC- Zerolend Proxy Re-Audit

Ethereum
Audited on 2025/09/09
No open critical findings

Summary

This was a re-audit of the `ZerolendPoolProxy` contract, which serves as a cross-chain proxy enabling TON Wallet users to interact with the ZeroLend lending protocol on TAC/EVM chains via messages sent through the cross-chain layer. The contract inherits from TacProxyV1Upgradeable, UUPSUpgradeable, and Ownable2StepUpgradeable, implementing a smart account abstraction layer that creates individual smart accounts per TON user (`header.tvmCaller`) to execute all ZeroLend interactions. The provided proxy interface gives users the ability to: - Supply collateral to the ZeroLend protocol - Withdraw previously deposited collateral from the ZeroLend protocol - Borrow assets from the ZeroLend protocol - Repay borrowed assets to the ZeroLend protocol - Bridge any tokens present in their smart account wallet back to TON chain via the `claimSA()` function The audit revealed that while the overall implementation is sound and provides users with a proxy interface to use the key features of the ZeroLend protocol, there are some areas for improvement related to token handling and operational transparency. This audit identified 1 Medium severity (`TAC-1`) finding and 3 other smaller auditor suggestions to improve the code overall safety. **Fixes Review**: The recent updates indicate that all identified issues have been effectively addressed with the exception of vulnerability TAC-1, which will be fixed in a future update; the three suggestions—S1, S2, and S3 are being resolved. This suggests a positive progression in improving the overall security posture of the code.


Issue (1)

Low
Medium
High
Critical
Total
Not fixed
----0
Acknowledged
-1--1
Fixed
----0
Total01001


Contracts (73)