{"workflow":null,"planning":null,"id":"45bf3777-cc84-44eb-a7ad-bbb2c0833d07","state":"completed","template":"audit","objective":"Audit the vault: src/CDPVault.sol, src/ParameterizedVault.sol and src/ImdUSD.sol, at the pinned commit, for a mainnet launch. Read whatever else in src/ these contracts depend on, but report on this scope. Seven audit rounds and their fixes are already in (docs/AUDIT-*.md; the newest is docs/AUDIT-RETRY2-PANEL-VAULT-2026-10-08.md, whose Resolution section says how each finding was answered). Two commits no panel has read: 58f73de (a repayment that leaves its backing behind stays in the supply backing is measured against) and d7fceab (the fee base, the banks, bite). They are what to break first. A finding of an earlier round counts only if its fix regressed or left a gap; the two accepted items (retry2 #6: a price fall re-prices a debt-bound term as cold; retry2 #3's trade-off: while most supply is new the fee base is small and redemptions pay more) are findings only if their stated reason is wrong.\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. THE FEE BASE (CDPVault._feeBase, Position.feeExcess, _feeExcess, _moveExcess with fee = true, _reduceDebt's repayment flag, the credit release in _lag, WORK_MINTED_THIS_TX_SLOT). The base is the live supply, less principal still cold and work minted in the transaction, plus warm principal repaid by wipe, bite or cover in the last hours, kept per position and released only as that position borrows back from its bank. Prove or break: no sequence, by one position or several, in one transaction or across many, moves the base below the honest warm supply (pinning the fee at the cap cheaply) or above it (diluting it, resetting the base rate) without seasoned capital held for hours; a redemption against a position adds nothing; the release cannot be triggered by capital that was never repaid; the cost of the accepted trade-off (a small base while most supply is new) in fee and in peg floor at launch.\n2. THE SUPPLY KEPT FOR BACKING (58f73de: Position.excess, _excess, _excessNow, _moveExcess with fee = false, in wipe, free and draw; _backingPerUnit's supply = live + excess). Prove or break: a repayment that leaves its backing behind can no longer raise what a redemption is paid, in one transaction or across several; an honest repay-and-withdraw is not underpaid; the excess cannot be released by another position, inflated, or left stranded (bite, cash and cover add nothing to it; free releases it by the term's fall at a price that may be unreadable).\n3. BANKS THAT COOL (_lag: a bank cools at BACKING_HALF_LIFE while it waits and is gone after a quiet BACKING_WARMUP; credit only to the position that lost the warmth; the bank re-dated at every touch of its side). Prove or break: no visit pattern keeps warmth alive past what honest cooling gives; credit cannot exceed what left warm; the secured and debt sides cannot feed each other.\n4. COLD CAPITAL PER POSITION after d7fceab (the quiet-day cutoff now applies to the vault totals and banks only; a position's own figures cool without it; _cool, _pow, _coldNow, laggedNow; the 128-bit saturation). Confirm the previous panel's answers still hold and that the totals, now at least the sum of the positions only up to rounding and except after a quiet day, never let laggedNow exceed honest warm-up.\n5. LIQUIDATION AND COVER ON DRAINED POSITIONS (bite always requires a mark, grace and an open window; cover takes a re-lock worth less than the recorded bad debt at its value, CoverBelowCollateralValue; _coverDust). Can a drained borrower now hold cover off, can a rebuilding borrower be harmed, can cover or bite be griefed, and do the bad-debt record and totalBadDebt stay consistent?\n6. Contract size (ParameterizedVault initcode 46,993 of 49,152, runtime 22,780 of 24,576), the fresh-debt record, earn's wage gate, positions, redemption, the stability fee, price gating and arithmetic: for regressions.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","blockedReason":null,"createdAt":"2026-10-08T07:37:28.509Z","updatedAt":"2026-10-08T08:28:59.916Z","paidBy":"0x5167d014a056e43883e1bbea5530c3c0dc993281","parentJobId":null,"project":{"id":"45bf3777-cc84-44eb-a7ad-bbb2c0833d07","head":"45bf3777-cc84-44eb-a7ad-bbb2c0833d07","running":null,"versions":[{"jobId":"45bf3777-cc84-44eb-a7ad-bbb2c0833d07","workflowId":null,"objective":"Audit the vault: src/CDPVault.sol, src/ParameterizedVault.sol and src/ImdUSD.sol, at the pinned commit, for a mainnet launch. Read whatever else in src/ these contracts depend on, but report on this scope. Seven audit rounds and their fixes are already in (docs/AUDIT-*.md; the newest is docs/AUDIT-RETRY2-PANEL-VAULT-2026-10-08.md, whose Resolution section says how each finding was answered). Two commits no panel has read: 58f73de (a repayment that leaves its backing behind stays in the supply backing is measured against) and d7fceab (the fee base, the banks, bite). They are what to break first. A finding of an earlier round counts only if its fix regressed or left a gap; the two accepted items (retry2 #6: a price fall re-prices a debt-bound term as cold; retry2 #3's trade-off: while most supply is new the fee base is small and redemptions pay more) are findings only if their stated reason is wrong.\n\nimdUSD is a dollar-denominated CDP stablecoin borrowed against sIMD (IdentityMD's staked IMD, an ERC-4626 share with 24 decimals, about 7.95 IMD each). Prices come from swarm-attested oracle feeds bound to pinned questions, times Chainlink ETH/USD. Everything about the deployment is in src/DeploymentConfig.sol and docs/MAINNET-RUNBOOK.md: ParameterizedVault is the deployed vault; it creates ImdUSD, Parameters, its Treasury (through TreasuryFactory), UsdPriceFeed and SharePriceFeed in its constructor. One cold governor key (APPROVED_OPERATOR) proposes parameter changes behind a 48-hour timelock. Collateral pricing is per 1e18 raw units throughout. IMD's only market is a full-range Uniswap v4 pool, about $2.3M a side with a 1% fee; docs/PARAMETERS-2026-10-05.md has the numbers every economic parameter was chosen from.\n\nAnswer each numbered question, including the ones where nothing is wrong:\n1. THE FEE BASE (CDPVault._feeBase, Position.feeExcess, _feeExcess, _moveExcess with fee = true, _reduceDebt's repayment flag, the credit release in _lag, WORK_MINTED_THIS_TX_SLOT). The base is the live supply, less principal still cold and work minted in the transaction, plus warm principal repaid by wipe, bite or cover in the last hours, kept per position and released only as that position borrows back from its bank. Prove or break: no sequence, by one position or several, in one transaction or across many, moves the base below the honest warm supply (pinning the fee at the cap cheaply) or above it (diluting it, resetting the base rate) without seasoned capital held for hours; a redemption against a position adds nothing; the release cannot be triggered by capital that was never repaid; the cost of the accepted trade-off (a small base while most supply is new) in fee and in peg floor at launch.\n2. THE SUPPLY KEPT FOR BACKING (58f73de: Position.excess, _excess, _excessNow, _moveExcess with fee = false, in wipe, free and draw; _backingPerUnit's supply = live + excess). Prove or break: a repayment that leaves its backing behind can no longer raise what a redemption is paid, in one transaction or across several; an honest repay-and-withdraw is not underpaid; the excess cannot be released by another position, inflated, or left stranded (bite, cash and cover add nothing to it; free releases it by the term's fall at a price that may be unreadable).\n3. BANKS THAT COOL (_lag: a bank cools at BACKING_HALF_LIFE while it waits and is gone after a quiet BACKING_WARMUP; credit only to the position that lost the warmth; the bank re-dated at every touch of its side). Prove or break: no visit pattern keeps warmth alive past what honest cooling gives; credit cannot exceed what left warm; the secured and debt sides cannot feed each other.\n4. COLD CAPITAL PER POSITION after d7fceab (the quiet-day cutoff now applies to the vault totals and banks only; a position's own figures cool without it; _cool, _pow, _coldNow, laggedNow; the 128-bit saturation). Confirm the previous panel's answers still hold and that the totals, now at least the sum of the positions only up to rounding and except after a quiet day, never let laggedNow exceed honest warm-up.\n5. LIQUIDATION AND COVER ON DRAINED POSITIONS (bite always requires a mark, grace and an open window; cover takes a re-lock worth less than the recorded bad debt at its value, CoverBelowCollateralValue; _coverDust). Can a drained borrower now hold cover off, can a rebuilding borrower be harmed, can cover or bite be griefed, and do the bad-debt record and totalBadDebt stay consistent?\n6. Contract size (ParameterizedVault initcode 46,993 of 49,152, runtime 22,780 of 24,576), the fresh-debt record, earn's wage gate, positions, redemption, the stability fee, price gating and arithmetic: for regressions.\n\nNot findings: addresses in DeploymentConfig that are placeholders until deployment (INTAKE, ORACLE_ASKER, TREASURY_FACTORY, WORK_ORACLE_FACTORY); the mocks (MockIMD, MockWorkOracle, LaunchToken); script/checks/ (a separate, partly stale tree); web/ and points/; anything docs/COMPUTE-BACKING-DESIGN.md describes as future work; and findings of the earlier audits in docs/AUDIT-*.md and docs/INTERNAL-AUDIT-2026-10-04.md, unless the fix regressed. A constant set to a deliberate economic value is not a finding; an arithmetic or ordering error in how it is used is.\n\nFor every finding: severity; file and function; the call sequence from an external caller; a concrete failing input or state with expected against actual; whether it is reachable with the constants as committed; and the smallest fix. Also report every place a comment or NatSpec claims a property the code does not have, and say which contracts you read in full and which you could not reach.","baseCommit":"d7fceab63a0310979dd911929f00e9469aa68258","state":"completed","createdAt":"2026-10-08T07:37:28.509Z"}]},"deliver":false,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":null,"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T08:07:38.984Z","verdict":null,"seat":{"tokenId":"1016","agentId":"52230"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T08:02:58.600Z","verdict":null,"seat":{"tokenId":"1061","agentId":"52151"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T08:28:59.916Z","verdict":null,"seat":{"tokenId":"475","agentId":"51041"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T08:10:03.293Z","verdict":null,"seat":{"tokenId":"690","agentId":"52150"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-08T08:10:52.398Z","verdict":null,"seat":{"tokenId":"461","agentId":"52149"},"live":null}],"reviews":[{"status":"queued","chainId":1,"txHash":null,"blockNumber":null,"sentAt":null,"entries":[{"nodeKey":"audit_economics","agentId":"52230","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"52151","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"51041","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"52150","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"52149","value":1,"role":"review:submission"}]}]}