Certora - Monthly Update

April 2025

Executive Summary

Governance Proposal Reviews

:eyes: Total proposals reviewed: 21

:white_check_mark: Proposals approved: 21

:writing_hand: Proposals rejected/modified: 0

:cross_mark: Issues requiring proposal cancellation: 1

:hammer_and_pick: Proposals required actions other than cancellation: 0

:police_car_light:Notes

  • One of AIP 299’s payloads was found to be misconfigured by BGD post-deployment. Together with BGD we verified that partial cancellation of the proposal (1/3 payloads) isn’t creating any security issues and worked to cancel the misconfigured payload.

Code Reviews Completed

:scroll: Total smart contracts reviewed: 34

:detective: Projects reviewed: 3

  1. Pool V3.4 - The review is finished. The report will be released soon along with the code.

    • A collection of security and UX upgrades to Aave core. A great elaborated post on the upgrade can be found in BGD’s thread.
  2. Risk Steward Additional Functionalities - Link to Security Report

    • Addition of emode update and pendle CAPO discount rate update functionalities to the risk steward
  3. Operational Payloads Controller - The review is finished. The report will be released soon along with the code.

    • An extension of the PayloadsController contract that introduces PayloadManager with permission to register a payload to be executed by a limited power Lv1 executor.
    • The objective is to allow trusted parties elevated yet limited power to affect change in low-risk parts of the protocol using similar processes to governance.
    • At launch, the executor will have permission to change the LM programs.