The Taler protocol implements an upgradable vault system modeled after ERC-4626, though it does not fully conform to the specification. At its core, the `Vault` contract manages deposits, share minting, and strategy execution. Redemptions in the `AsyncRedemptionModule` are asynchronous and occur in epochs that are settled by an executor. The net asset value (NAV) of each vault is computed within the `Accounting` contract, which aggregates data from underlying adapters integrating with protocols such as Morpho, Aave, as well as generic share-based vaults. Strategy execution is routed through the `ExecutionGateway`, which implements the `IAvatar` interface from Gnosis Zodiac. This design enforces that all strategy interactions are executed through a Zodiac Roles Modifier (ZRM) integration, providing an additional layer of permissioning and control. The audit identified 2 Medium, 7 Low, and 7 Informational findings. Both medium severity issues are located in the `FeeModule`. TAL-1 describes a rounding desync between the global `totalPendingFeeShares` tracker and per entry settlement math that can cause an underflow revert, blocking all fee claims and entry removals. TAL-2 shows that removing the last performance fee entry resets the high water mark to zero, allowing a fee manager to re-add an entry at a lower baseline and collect performance fees on NAV recovery that was already compensated. The test suite broadly covers unit and integration behavior with 29 Solidity test files, including integration and fork based end to end coverage across Aave, Morpho, and execution policy flows.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | - | - | - | - | 0 |
Acknowledged | 3 | - | - | - | 3 |
Fixed | 11 | 2 | - | - | 13 |
| Total | 14 | 2 | 0 | 0 | 16 |
| # | File Name |
|---|---|
| 1 | Scope not recorded here: see the report |