bnq.me

Security

Security & audits

bnq's security rests on three pillars: an extensively audited foundation, a small and fully disclosed modification surface, and fail-closed operational design.

01

Audited foundation

The Aave v3 lending engine, secured by eleven third-party audit and formal-verification reports.

02

Disclosed surface

~1,550 lines of bnq-specific Solidity, fully documented — no hidden changes to lending math.

03

Fail-closed design

No fresh price ⇒ the asset halts. Caps bound exposure. New reserves stay frozen until feeds prove out.

Inherited from Aave v3

bnq's lending engine is Aave v3, unmodified in its core logic — aTokens, debt tokens, interest-rate strategies, and health-factor and liquidation math are exactly the audited upstream code that secures tens of billions of dollars today.

DateAuditorScopeReport
Nov 2021OpenZeppelinAave v3 corePublished
Jan 2022Trail of BitsAave v3 corePublished
Jan 2022ABDKAave v3 corePublished
Jan 2022PeckShieldAave v3 corePublished
Jan 2022Sigma PrimeAave v3 corePublished
Dec 2022PeckShieldAave v3.0.1Published
Dec 2022Sigma PrimeAave v3.0.1Published
Apr 2023Sigma PrimeAave v3.0.2Published
Jan 2022CertoraFormal verificationPublished
Dec 2022CertoraFormal verification v3.0.1Published
Mar 2023CertoraFormal verification v3.0.2Published

Stable-rate borrowing — the subject of Aave's 2023 incident, later removed upstream — is disabled on every bnq reserve.

What bnq built on top

The audits above do not cover bnq's additions. In the interest of full transparency, here is the complete modification surface:

SoulBoundToken

Non-transferable ERC-721-based access token. Roles: Member (supply + borrow), Liquidator, FlashLoaner. Revoking a token with an open position is blocked on-chain; emergency revocation is multisig-gated.

PermissionedLendingPool

Extends the Aave v3 Pool: every action checks the caller's access token. No lending math is modified.

AaveOracle (modified)

Adds RedStone as the primary price source with a staleness threshold, Pyth as a bounded backstop, and fail-closed behavior — no fresh price, no action.

bnqPriceFeed

bnq-operated feed for assets without third-party coverage on Hemi. Hard min/max bounds, a per-update deviation cap, owner-only re-anchoring.

Independent audit — scheduled. bnq's additions (~1,550 lines — the access token, permissioned pool, and oracle adaptations) have completed internal review and are covered by an automated test suite. An independent third-party audit of this layer is scheduled ahead of scaling, and its report will be published here.

Responsible disclosure

Found a vulnerability? Email support@bnq.me — please don't open a public issue. Good-faith reports are appreciated and will be acknowledged.