Audits
AggreLend treats audits as an ongoing process. We keep the program small, lend-only, and reviewable, and we schedule new reviews whenever meaningful changes ship.
AggreLend Core
-
Primary auditor: HawkProof (Rust/Solana focus).
Report: (coming soon) — https://www.hawkproof.com (opens in a new tab) -
Planned re-audit (Q4 2025): Scope: integration of Jupiter Lending venue family and related program upgrades; results and overview will be posted here after completion.
Audits are point-in-time assessments. We pair them with defensive program design and runtime guards. When material changes land between reports, we call them out in release notes and changelogs.
Underlying Venue Audit References
AggreLend routes deposits only to the deposit/lend legs of well-known protocols that publish security materials. Review their hubs here:
-
Kamino Finance — Security Audits:
https://docs.kamino.finance/automated-liquidity/security-and-risks/security-audits (opens in a new tab) -
Drift — Audits (Trail of Bits and more):
https://www.drift.trade/audit (opens in a new tab)
https://docs.drift.trade/security/audits (opens in a new tab) -
Save (formerly Solend) — Audit (Kudelski):
https://docs.save.finance/protocol/audit (opens in a new tab) -
MarginFi — Audits (OtterSec / Sec3 in repo, docs overview):
https://github.com/mrgnlabs/marginfi-v2/tree/main/audits (opens in a new tab)
https://docs.marginfi.com/mfi-v2 (opens in a new tab) -
DefiTuna — Audits (Torii / Sec3):
https://docs.defituna.com/security-and-risks/audits (opens in a new tab)