Security
Security & audits
bnq's security rests on three pillars: an extensively audited foundation, a small and fully disclosed modification surface, and fail-closed operational design.
Audited foundation
The Aave v3 lending engine, secured by eleven third-party audit and formal-verification reports.
Disclosed surface
~1,550 lines of bnq-specific Solidity, fully documented — no hidden changes to lending math.
Fail-closed design
No fresh price ⇒ the asset halts. Caps bound exposure. New reserves stay frozen until feeds prove out.
Inherited from Aave v3
bnq's lending engine is Aave v3, unmodified in its core logic — aTokens, debt tokens, interest-rate strategies, and health-factor and liquidation math are exactly the audited upstream code that secures tens of billions of dollars today.
| Date | Auditor | Scope | Report |
|---|---|---|---|
| Nov 2021 | OpenZeppelin | Aave v3 core | Published |
| Jan 2022 | Trail of Bits | Aave v3 core | Published |
| Jan 2022 | ABDK | Aave v3 core | Published |
| Jan 2022 | PeckShield | Aave v3 core | Published |
| Jan 2022 | Sigma Prime | Aave v3 core | Published |
| Dec 2022 | PeckShield | Aave v3.0.1 | Published |
| Dec 2022 | Sigma Prime | Aave v3.0.1 | Published |
| Apr 2023 | Sigma Prime | Aave v3.0.2 | Published |
| Jan 2022 | Certora | Formal verification | Published |
| Dec 2022 | Certora | Formal verification v3.0.1 | Published |
| Mar 2023 | Certora | Formal verification v3.0.2 | Published |
Stable-rate borrowing — the subject of Aave's 2023 incident, later removed upstream — is disabled on every bnq reserve.
What bnq built on top
The audits above do not cover bnq's additions. In the interest of full transparency, here is the complete modification surface:
SoulBoundToken
Non-transferable ERC-721-based access token. Roles: Member (supply + borrow), Liquidator, FlashLoaner. Revoking a token with an open position is blocked on-chain; emergency revocation is multisig-gated.
PermissionedLendingPool
Extends the Aave v3 Pool: every action checks the caller's access token. No lending math is modified.
AaveOracle (modified)
Adds RedStone as the primary price source with a staleness threshold, Pyth as a bounded backstop, and fail-closed behavior — no fresh price, no action.
bnqPriceFeed
bnq-operated feed for assets without third-party coverage on Hemi. Hard min/max bounds, a per-update deviation cap, owner-only re-anchoring.
Independent audit — scheduled. bnq's additions (~1,550 lines — the access token, permissioned pool, and oracle adaptations) have completed internal review and are covered by an automated test suite. An independent third-party audit of this layer is scheduled ahead of scaling, and its report will be published here.
Responsible disclosure
Found a vulnerability? Email support@bnq.me — please don't open a public issue. Good-faith reports are appreciated and will be acknowledged.