Velocity ProtocolDevelopers

Audits

What the two published reports actually cover, and the status of the review of Velocity's own code.

The two audit reports published below were performed on the pre-fork Drift Protocol v2 codebase, at fork point 0ae3e3b1d. They do not cover Velocity's own deployment, and they do not cover anything added or changed since the fork. OtterSec has separately reviewed Velocity's own program. That review is complete and its findings are fixed in the deployed code; the final report is pending publication and will be linked here as soon as it is. So the accurate reading of this page is neither "audited" nor "unaudited": the inherited base has two published reports, and the post-fork work has been reviewed by a firm whose report is not out yet.

Until that report lands, the migration guide is the public record of what changed after the fork, and its change log lists the audit-fix work alongside the rest. Risks covers what that gap means for an open position, and Bug bounty is the disclosure route for a finding.

Pre-fork: Drift Protocol v2

Trail of Bits

Drift Protocol engaged Trail of Bits to audit its decentralized exchange and its onchain program. The team conducted the security review from November 7 to December 2, 2022, with full knowledge of the target system, including source access and documentation, and using a mix of automated and manual static and dynamic testing. The focus was flaws that could compromise the confidentiality, integrity or availability of the exchange.

The audit uncovered no high-severity flaws in any of those three categories. Trail of Bits then reviewed Drift's fixes and mitigations between January 23 and January 25, 2023. A summary of the outstanding findings after that review is below.

Audit Result

The full list of unresolved and partially resolved findings is on page 73 of the report. The one finding marked undetermined concerns testing code used in production and is described on page 77. View the full report here.

Neodyme

Neodyme's review covers the same pre-fork protocol-v2 codebase. It was authored on May 10th 2024 and last updated on June 27th 2024. View the full report here.

Post-fork: Velocity

OtterSec

The scope was the Velocity program and the vaults program as they stood after the fork. This is the only review that covers Velocity's own changes, which is to say the AMM, the fee redesign, the tiered admin key model, isolated pools, builder codes, and the signed-message order path. None of that surface appears in either report above.

The review delivered a set of numbered High and Medium findings across the two programs, and every one of them is fixed. The final report is pending publication rather than pending completion, so what is outstanding is the document, not the work. This page will carry the link the moment it is final.