Security research
HashEx audit evidence: recheck commits and residual findings
The ApeSwap IAZO artifact connects an initial revision to a recheck revision. Its outcome categories include resolved, partially resolved and acknowledged items. An acknowledged finding can remain relevant to a release decision even when a project accepts it. Read the affected behavior and compensating assumptions before treating the report as a closed checklist.
Read resolved, partially resolved and acknowledged separately
Use this question to examine the evidence below before carrying an earlier observation into a new engagement.
Separate the historical observation from a current decision
The older HashEx analysis described discounts and a free code recheck within two weeks after a report. These were historical commercial observations. A new engagement needs written retest terms, an allowance for changed scope and an agreed review window. The old composite score is not a current technical recommendation.
This editorial revision replaces unsupported general praise and does not reproduce the old aggregate rating. DSA has not assigned a new technical score.
ApeSwap IAZO: the evidence boundary
Read the source report. Audit completed (provider index): .
- Reviewed scope
- IAZO sale, factory, settings, locker, timelock and proxy contracts on Binance Smart Chain.
- Revision evidence
- 74a5d9f → 1fe0548
- Follow-up
- The PDF identifies the revision rechecked. The provider index lists 18 resolved, one partially fixed and four acknowledged findings.
- Limit of the observation
- Historical Solidity engagement. Counts retain the provider's status categories and do not establish present deployment safety.
Build the release decision around traceable evidence
- Pin the proposed source revision and identify the contracts and dependencies included in the review.
- Choose a material finding in the relevant report. Trace its affected code and record the final disposition.
- Compare the reviewed revision with the intended deployment. Document subsequent changes and unresolved assumptions.
- Confirm the retest scope, assigned reviewers and current commercial terms directly.
Use the HashEx profile for field-level sources and the fuzzing guide to plan the related technical checks. A tool result supplements the evidence packet; it does not replace a scoped audit.
Prepare an audit request with HashEx or compare other providers.
Sources
Checked . Local examples include their inputs and limits.
About this revision
Rebuilt the legacy company analysis around source scope, dated evidence and limits of historical claims. The URL is preserved. This is a DeFiSec editorial revision, not a new assessment by the provider or an expert committee.
Suggest a correction with evidence