立刻保护您的项目
借助最大的web3安全提供商来增强您的项目。
CertiK 安全专家将审核您的请求,并尽快与您联系。

CertiK and Lien Finance’s Second Audit Engagement and Pen Test

技术博客 ·教育 ·
CertiK and Lien Finance’s Second Audit Engagement and Pen Test

Early last month, CertiK proudly announced a successful audit for Lien Finance’s iDOL, Fairswap, Oracle, and Token smart contracts. Details from the engagement can be found here. Recently, the CertiK team and Lien Finance team closed another audit engagement on the iDOL, Lien Token, and Oracle modules, and a penetration test on the wallet.

“Lien is a simple and elegant protocol that allows anyone to create a unique derivative contract. Depending on your prediction of the ETH price in the future, the protocol provides users with the opportunity to take advantage of its price development more effectively than just hodling ETH itself.”

Scope of Work

Audit Code Review

A second round of auditing was carried out in the following commit hashes that includes remediations as well as minor changes based on feedback from their mainnet launch. These commit hashes are as follows:

  1. iDOL
  2. Lien Token
  3. Oracle

During this second round of the two week audit, the CertiK team analyzed the code of the core protocol within iDOL and delved into greater depth on the Fairswap repository to identify any potential vulnerabilities, misalignments with the specification and unaccounted for functionalities / behaviors.

Penetration Test

At the start of the engagement, CertiK worked with Lien Finance to identify the target and set the limits on the scope of the test. A White Box type of testing approach was done where CertiK performed the test with the source code available from the shared GitHub repository.

The main objective of the engagement is to test the overall resiliency of the application to various real-world attacks against the application’s controls and functions, and thereby be able to identify its weaknesses and provide recommendations to fix and improve its overall security posture.

CertiK performed a full penetration test on the web application and tested it against different web vulnerabilities including the OWASP Top Ten.

Summary and Overview

During both tests, the CertiK team took an iterative approach with the Lien team to remediate most of the optimization findings pointed out, as well as all the vulnerabilities and mathematical discrepancies the engineers were able to identify within their codebase.

“Overall, the Lien team demonstrated an in-depth understanding of the mathematical formulas involved in the solution they aspire to launch, and showcased healthy code ethics within each project’s codebase,” said by the CertiK team.

We look forward to working with the Lien team and securing the DeFi ecosystem together.

About CertiK

CertiK is a technology-led blockchain security company founded by Computer Science professors from Yale University and Columbia University built to prove the security and correctness of smart contracts and blockchain protocols.

CertiK’s mission of every audit is to apply different approaches and detection methods, ranging from manual, static, and dynamic analysis to ensure that the project is checked against known attacks and potential vulnerabilities. CertiK leverages a team of seasoned engineers and security auditors to apply testing methodologies and verifications on the project, in turn creating a more secure and robust software system.

CertiK has serviced more than 100 clients with high quality auditing and consulting services, ranging from stablecoins such as Binance’s BGBP and Paxos Gold to decentralized oracles such as Band Protocol and Tellor.

Consult with one of our experts at [email protected]

Stay connected!

Website|Twitter|Linkedin|GitHub

相关博客

CertiK’s Path Forward: Advancing Trust, Transparency, and Web3 Infrastructure

CertiK’s Path Forward: Advancing Trust, Transparency, and Web3 Infrastructure

As conversations at the 2026 World Economic Forum at Davos-Klosters, Switzerland continue to influence how global leaders engage with emerging technologies, one message is becoming increasingly clear: Web3 is entering a new phase defined by institutional participation, regulatory engagement, and long-term infrastructure.

React/Next.js CVE-2025-55182 Vulnerability Analysis

React/Next.js CVE-2025-55182 Vulnerability Analysis

A critical vulnerability, CVE-2025-55182, was recently disclosed and carries a CVSS 10.0 (the most critical) severity rating. The issue affects React/Next.js environments. Our security research team has analyzed the vulnerability and detected many applications in the Web3 ecosystem running the affected versions, including several that are actively exploitable.

Highlights from CertiK’s Road to Mainnet Event in Buenos Aires

Highlights from CertiK’s Road to Mainnet Event in Buenos Aires

On November 20, 2025, CertiK brought together Web3 builders, founders, and investors in Buenos Aires for our Road to Mainnet and Beyond event, a VIP mixer held at a private estate in Palermo Chico. This event, presented with MomentumX Global and Headline Entertainment, provided an opportunity for meaningful conversations about Web3 security, decentralized finance (DeFi), artificial intelligence (AI), venture capital, and other emerging technologies.