
Evro Collateral Onboarding audit
A private security review of Evro Finance (EUR stablecoin), conducted with Sherlock and completed on 26th December 2025 over 5 days. 0xSimao disclosed 9 findings: 2 high severity, 4 medium and 3 low.
What Evro Finance is
Evro issues a euro stablecoin against overcollateralised troves, in the Liquity V2 mould: each collateral asset runs its own borrowing branch with a dedicated price feed, positions live as trove NFTs, and zappers bundle the wrapping and swap legs a deposit needs into one call.
Scope
The December review covered the collateral plumbing: price feeds for GNO, osGNO, sDAI, WBTC, WETH and wstETH, the eight-decimal WBTC wrapper and its zapper, the CoGNO adapter, the trove NFT and the Curve exchange leg.
High severity findings
- SDAIPriceFeed is vulnerable to donation attack via manipulatable vault rate
- WSTETHPriceFeed returns USD price Instead of EUR on oracle failure
Medium severity findings
- WBTCZapper decimal mismatch causes revert
- WBTCZapper approves wrong token for exchange
- WBTCZapper precision loss will lead to reverts
- API3 oracle future timestamp causes temporary DoS via underflow
Low severity findings
- SDAIPriceFeed missing constructor price feed check
- IWBTCZapper interface mismatches implementation
- TroveNFT Duplicates ERC721Enumerable Logic
The report