We audited the core token layer of the Apyx stablecoin system. At a protocol level, the scoped contracts serve three distinct but tightly connected roles: * `src/ApxUSD.sol` is the hub-side stablecoin. It is the main ERC-20 asset of the system, carries the protocol's compliance and supply-control hooks, and is the asset that ultimately backs user balances and bridge liquidity. * `src/ApyUSD.sol` is the yield-bearing ERC-4626 vault over `ApxUSD`. It packages yield accrual, vesting-aware accounting, fee handling, and the protocol's cooldown-based exit flow rather than offering immediate free-form redemptions. * `src/bridge/BridgedApyxToken.sol` is the destination-chain bridged representation controlled by Chainlink CCIP pool infrastructure. It is the cross-chain token surface through which bridged supply is minted, burned, and capped on non-hub chains. Overall, no high- or medium-severity vulnerabilities were found. However, a number of lower-severity issues were noted, namely: * `ApyUSD` accepts deposits before `unlockToken` is configured, which can leave withdrawals and redeems blocked until post-deployment setup is completed. * `ApyUSD.setUnlockToken()` accepts incompatible replacements, so a bad admin rotation can brick the vault exit path. * `ApyUSD.setVesting()` can strand unvested yield and create an immediate share-price discontinuity when vesting contracts are rotated. * `BridgedApyxToken` supply-cap changes and cross-chain cap divergence can create a CCIP lane-block condition requiring manual intervention. We recommend all issues be addressed.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | 2 | - | - | - | 2 |
Acknowledged | 2 | - | - | - | 2 |
Fixed | - | - | - | - | 0 |
| Total | 4 | 0 | 0 | 0 | 4 |
| # | File Name |
|---|---|
| 1 | src/ApyUSD.sol |
| 2 | src/bridge/IBridgedToken.sol |
| 3 | src/ApxUSD.sol |
| 4 | src/bridge/BridgedApyxToken.sol |
| 5 | src/bridge/BridgeRoles.sol |