Security research
Hacken audit evidence: scope fields do not prove fixes
The existing DSA API study found 1,042 smart-contract records with both repository and commit fields nonempty in a dated subset of 1,123. Field presence is not the same as a valid commit, reachable source or deployment match. The study separately recorded placeholder values and syntactic commit checks. Keep those tests distinct from a technical review of the code.
A populated commit field is a starting point for verification
Use this question to examine the evidence below before carrying an earlier observation into a new engagement.
Separate the historical observation from a current decision
The earlier company analysis combined speed, media presence, price and report observations into one score. That composite does not isolate detection quality. Historic loss narratives also need a version-and-scope comparison before they can support a conclusion about a particular engagement.
This editorial revision replaces unsupported general praise and does not reproduce the old aggregate rating. DSA has not assigned a new technical score.
Tangible USDR Redemption v2: the evidence boundary
Read the source report. Final report: .
- Reviewed scope
- Fixed-rate redemption contracts on Polygon; Solidity.
- Revision evidence
- 4428548 → f59a0f5
- Follow-up
- The report lists initial and final revisions and five resolved findings.
- Limit of the observation
- Only the redemption v2 scope is represented. This does not assess the economics, reserves or complete history of USDR.
Inspect the Hacken API measurement method and frozen results before interpreting the counts. The corpus is a dated API response, not a census of every engagement or a success-rate measure.
Build the release decision around traceable evidence
- Pin the proposed source revision and identify the contracts and dependencies included in the review.
- Choose a material finding in the relevant report. Trace its affected code and record the final disposition.
- Compare the reviewed revision with the intended deployment. Document subsequent changes and unresolved assumptions.
- Confirm the retest scope, assigned reviewers and current commercial terms directly.
Use the Hacken profile for field-level sources and the static analysis guide to plan the related technical checks. A tool result supplements the evidence packet; it does not replace a scoped audit.
Prepare an audit request with Hacken or compare other providers.
Sources
Checked . Local examples include their inputs and limits.
About this revision
Rebuilt the legacy company analysis around source scope, dated evidence and limits of historical claims. The URL is preserved. This is a DeFiSec editorial revision, not a new assessment by the provider or an expert committee.
Suggest a correction with evidence