ApxUSD Stablecoin

Arbitrum
Audited on 2026/02/13
No open critical findings

Summary

The Apyx protocol is a stablecoin ecosystem where `ApxUSD` is backed by off-chain preferred shares from crypto treasury companies. Dividend yields from these shares are minted as `ApxUSD`, vested linearly, and distributed to holders who deposit into the yield-bearing `ApyUSD` vault. OpenZeppelin's `AccessManager` serves as the centralized permission layer across all contracts. The system implements six primary flows: 1. **Minting**: EIP-712 signed orders with enforced delays mint new `ApxUSD`. 2. **Locking**: `ApxUSD` is deposited into the ERC-4626 vault for yield-bearing `ApyUSD` shares. 3. **Unlocking**: `ApyUSD` is burned and an async redeem request is created on `UnlockToken` with a cooldown before the user can claim `ApxUSD`. 4. **Vesting**: Yield is minted to `YieldDistributor`, deposited into `LinearVestV0`, and vested linearly into `ApyUSD`'s `totalAssets`. 5. **Commit**: ERC-20 tokens can be deposited into `CommitToken` for points, redeemable after a cooldown. 6. **Redemption**: `ApxUSD` can be burned via `RedemptionPoolV0` for a reserve asset at an admin-controlled exchange rate. <br></br> During the audit, one high-severity and two medium-severity findings were identified. **APX-1**: Stale `vestingAmount` can block user withdrawals—`pullVestedYield()` does not update `vestingAmount`; after an extended vesting period, the contract can attempt to transfer more than it holds and revert. **APX-2**: Nested `initializer` in `ERC20DenyListUpgradable` extension breaks proxy deployment. **APX-3**: `RedemptionPoolV0` incorrectly assumes `reserveAsset` has 18 decimals. Seven low-severity and four informational findings were also identified. Overall, during the audit many low and informational issues were found, still the codebase is in good shape and most findings are minor. The test suite comprises 419 tests across 41 suites. It includes fuzz tests as well as integration tests. No invariant tests are present. Coverage for the scoped contracts is approximately 91% lines and 91% statements, with 68% branch coverage. `UnlockToken` and `AddressList` have the weakest coverage. Adding invariant tests and improving branch coverage would strengthen the suite. **Fix-Review Update:** The Apyx team has successfully addressed all reported vulnerabilities (**APX-1** to **APX-12**, and **APX-14**) with changes that enhance the security and functionality of the code. These fixes include updating critical functions, adding validation and more tests, improving monitoring, and correcting documentation to better reflect the contracts' behavior. Moreover, **APX-13** was acknowledged, but may be fixed in the future.


Issues (14)

Low
Medium
High
Critical
Total
Not fixed
2---2
Acknowledged
----0
Fixed
921-12
Total1121014


Contract (1)