The **Onre** protocol is a Solana program built with the Anchor framework that facilitates the sale of real world reinsurance assets through an offers-based system, enabling depositors to earn institutional-grade yield backed by real world reinsurance. The component here constitutes an isolated marketmaker trading wrapper, which allows the `boss` to set an `executor` able to trade tokens on either Orca or Raydium markets. While anyone can deposit tokens, only the `boss` can withdraw from the vault. The protocol contains a kill-switch operated by the global OnRe admins in line with other protocol components. We have not identified any major issues. However, the intended limitation of the `executor` role to trades only may still be abused by a missing token whitelist, which would allow a compromised `executor` to extract value through malicious trades (OMB-1). Overall, the protocol is well written, and the code quality reflects a strong commitment to security and safety. The codebase is generally well structured and clearly documented.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | - | - | - | - | 0 |
Acknowledged | 1 | - | - | - | 1 |
Fixed | 2 | - | - | - | 2 |
| Total | 3 | 0 | 0 | 0 | 3 |
| # | File Name |
|---|---|
| 1 | Scope not recorded here: see the report |