During the Autonomint audit conducted alongside Sherlock, 0xSimao stood out for his remarkable expertise. He completely understood how the codebase works and uncovered 52% of the confirmed issues, a clear indication of his exceptional eye for detail and robust auditing capability. His proactive role in the remediation review further brought additional issues to light. We definitely recommend working with 0xSimao.
Autonomint
What it is
Autonomint issues a hedged stablecoin: borrowers post collateral and take downside protection, and a CDS side takes the other half of that trade and is paid for it.
What was reviewed
One competition, December 2024, first place, over the borrowing, CDS and cross-chain accounting contracts.
What was found
38 findings, 26 of them high severity, which is the largest set from any single engagement on this site.
Featured finding
Autonomint pays borrowers in a token they redeem later for their share of the yield. The redemption burned the caller’s tokens but worked the payout out from a different account’s record, so a caller could redeem against somebody else’s position.
As designedA borrower redeems their yield token↓Their own record says what they are owed↓Their tokens are burned and their share is paid
The path the bug allowedA caller redeems their yield token↓The payout is worked out from a different account’s record↓The caller’s tokens are burned, but somebody else’s yield is paid out↓A caller can drain a position that is not theirs