Quantstamp has completed an audit of the `BTCPlusRedeem` contract. This contract is responsible for allowing users to redeem `btcPlus` into `solvBTC` based on a NAV-based conversion model. It integrates a global rate-limiting mechanism to control withdrawal frequency and max amount, and routes redemptions through a designated `redemptionVault` which must hold and approve sufficient `solvBTC` liquidity. Overall, the code is clean, minimal, and well-structured. We did not identify any major vulnerabilities or critical security issues in this contract. The findings identified are primarily low-severity or design-level considerations, such as the lack of user slippage protection (SOLV-1, SOLV-2), global withdrawal limit griefing potential (SOLV-3), and strong dependency on correct admin configuration. These are expected trade-offs given the contract’s role and trust assumptions and do not represent immediate correctness or safety flaws. The test coverage should be further expanded to improve confidence in edge-case behavior. **Fix-Review:** Following the fix review, two issues have been fixed (SOLV-4, and SOLV-5) and the remaining issues have been acknowledged.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | 3 | - | - | - | 3 |
Acknowledged | - | - | - | - | 0 |
Fixed | 2 | - | - | - | 2 |
| Total | 5 | 0 | 0 | 0 | 5 |
| # | File Name |
|---|---|
| 1 | Scope not recorded here: see the report |