This was a re-audit of the `ZerolendPoolProxy` contract, which serves as a cross-chain proxy enabling TON Wallet users to interact with the ZeroLend lending protocol on TAC/EVM chains via messages sent through the cross-chain layer. The contract inherits from TacProxyV1Upgradeable, UUPSUpgradeable, and Ownable2StepUpgradeable, implementing a smart account abstraction layer that creates individual smart accounts per TON user (`header.tvmCaller`) to execute all ZeroLend interactions. The provided proxy interface gives users the ability to: - Supply collateral to the ZeroLend protocol - Withdraw previously deposited collateral from the ZeroLend protocol - Borrow assets from the ZeroLend protocol - Repay borrowed assets to the ZeroLend protocol - Bridge any tokens present in their smart account wallet back to TON chain via the `claimSA()` function The audit revealed that while the overall implementation is sound and provides users with a proxy interface to use the key features of the ZeroLend protocol, there are some areas for improvement related to token handling and operational transparency. This audit identified 1 Medium severity (`TAC-1`) finding and 3 other smaller auditor suggestions to improve the code overall safety. **Fixes Review**: The recent updates indicate that all identified issues have been effectively addressed with the exception of vulnerability TAC-1, which will be fixed in a future update; the three suggestions—S1, S2, and S3 are being resolved. This suggests a positive progression in improving the overall security posture of the code.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | - | - | - | - | 0 |
Acknowledged | - | 1 | - | - | 1 |
Fixed | - | - | - | - | 0 |
| Total | 0 | 1 | 0 | 0 | 1 |