diff --git a/verify/1.md b/verify/1.md
index 71f681a..8fb4965 100644
--- a/verify/1.md
+++ b/verify/1.md
@@ -4,11 +4,7 @@ Chain ID: 1 · Bytecode-proven: **20/21** · Canonical: 1
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,34 +13,38 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0x0D52d06c…`](https://etherscan.io/address/0x0D52d06ceB8Dcdeeb40Cfd9f17489B350dD7F8a3) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `48762e01` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0xd9Fcd98c…`](https://etherscan.io/address/0xd9Fcd98c322942075A5C3860693e9f4f03AAE07b) | [`euler-governance`](https://github.com/euler-xyz/euler-governance) | 🏛 canonical | long-established (see note) | canonical 2021 token |
| eulOFTAdapter | [`0x3Bf1bD5D…`](https://etherscan.io/address/0x3Bf1bD5DB4457d22A85d45791B6291b98D0fC5b5) | [`evk-periphery@ccd2debc`](https://github.com/euler-xyz/evk-periphery/tree/ccd2debce48ed857c7766bb1955591cfac996d91) | ✅ `e74a0c71` | ≡ baseline | — |
-| eVaultFactory | [`0x29a56a1b…`](https://etherscan.io/address/0x29a56a1b8214D9Cf7c5561811750D5cBDb45CC8e) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0x8Ff1C814…`](https://etherscan.io/address/0x8Ff1C814719096b61aBf00Bb46EAd0c9A529Dd7D) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `8c001272` | +1/−1 vs baseline | one fee-share default parameter |
+| eVaultFactory | [`0x29a56a1b…`](https://etherscan.io/address/0x29a56a1b8214D9Cf7c5561811750D5cBDb45CC8e) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0x8Ff1C814…`](https://etherscan.io/address/0x8Ff1C814719096b61aBf00Bb46EAd0c9A529Dd7D) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `8c001272` | ≡ baseline (unit) | — |
| evc | [`0x0C9a3dd6…`](https://etherscan.io/address/0x0C9a3dd6b8F28529d72d7f9cE918D493519EE383) | [`ethereum-vault-connector@084b3228`](https://github.com/euler-xyz/ethereum-vault-connector/tree/084b32284ba643921f8d21bff3ddaf0c4e08d754) | ✅ `5b470906` | ≡ baseline | — |
| oracleRouterFactory | [`0x70B3f6F6…`](https://etherscan.io/address/0x70B3f6F61b7Bf237DF04589DdAA842121072326A) | [`evk-periphery@05b0acb8`](https://github.com/euler-xyz/evk-periphery/tree/05b0acb8bfb64e663293ab8b236c72c6b3df86ae) | ✅ `fd6ae566` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0x4cD6BF1D…`](https://etherscan.io/address/0x4cD6BF1D183264c02Be7748Cb5cd3A47d013351b) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0xf3e62139…`](https://etherscan.io/address/0xf3e621395fc714B90dA337AA9108771597b4E696) | [`evk-periphery@7a233058`](https://github.com/euler-xyz/evk-periphery/tree/7a23305815ccb4198c117c2d6fcfe8421fe336e3) | ✅ `8d4a5058` | ≡ baseline | — |
-| sequenceRegistry | [`0xEADDD216…`](https://etherscan.io/address/0xEADDD21618ad5Deb412D3fD23580FD461c106B54) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0xEADDD216…`](https://etherscan.io/address/0xEADDD21618ad5Deb412D3fD23580FD461c106B54) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0xB1C777BE…`](https://etherscan.io/address/0xB1C777BE7965dCdE810645497CC1e6e5997BD6C5) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `2fc2cdd1` | +3/−5 vs baseline | formatting only |
## Euler Earn
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerEarnFactory | [`0x59709B02…`](https://etherscan.io/address/0x59709B029B140C853FE28d277f83C3a65e308aF4) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +18/−18 vs baseline | import-path style only |
-| eulerEarnPublicAllocator | [`0x8fdCb80a…`](https://etherscan.io/address/0x8fdCb80a2894F0dC052c8d52D22544DC90274800) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnFactory | [`0x59709B02…`](https://etherscan.io/address/0x59709B029B140C853FE28d277f83C3a65e308aF4) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +16/−16 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0x8fdCb80a…`](https://etherscan.io/address/0x8fdCb80a2894F0dC052c8d52D22544DC90274800) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV1Factory | [`0xb013be1D…`](https://etherscan.io/address/0xb013be1D0D380C13B58e889f412895970A2Cf228) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Implementation | [`0xc35a0FDA…`](https://etherscan.io/address/0xc35a0FDA69e9D71e68C0d9CBb541Adfd21D6B117) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Periphery | [`0x208fF5Eb…`](https://etherscan.io/address/0x208fF5Eb543814789321DaA1B5Eb551881D16b06) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV2Factory | [`0xD0521333…`](https://etherscan.io/address/0xD05213331221fAB8a3C387F2affBb605Bb04DF5F) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0x8B0E044E…`](https://etherscan.io/address/0x8B0E044E364F2cE913799d53b300e15A6974DC97) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0xD3a349EE…`](https://etherscan.io/address/0xD3a349EE0A21eA0A7E9513ac236ae614b5FD513E) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0x5171Aed0…`](https://etherscan.io/address/0x5171Aed04Fa9551DB484F07c853F252Bc6F53b63) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0x5FcCB843…`](https://etherscan.io/address/0x5FcCB84363F020c0cADE052C9c654aABF932814A) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV1Factory | [`0xb013be1D…`](https://etherscan.io/address/0xb013be1D0D380C13B58e889f412895970A2Cf228) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +43/−24 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Implementation | [`0xc35a0FDA…`](https://etherscan.io/address/0xc35a0FDA69e9D71e68C0d9CBb541Adfd21D6B117) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +40/−21 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Periphery | [`0x208fF5Eb…`](https://etherscan.io/address/0x208fF5Eb543814789321DaA1B5Eb551881D16b06) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +3/−3 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV2Factory | [`0xD0521333…`](https://etherscan.io/address/0xD05213331221fAB8a3C387F2affBb605Bb04DF5F) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0x8B0E044E…`](https://etherscan.io/address/0x8B0E044E364F2cE913799d53b300e15A6974DC97) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0xD3a349EE…`](https://etherscan.io/address/0xD3a349EE0A21eA0A7E9513ac236ae614b5FD513E) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0x5171Aed0…`](https://etherscan.io/address/0x5171Aed04Fa9551DB484F07c853F252Bc6F53b63) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0x5FcCB843…`](https://etherscan.io/address/0x5FcCB84363F020c0cADE052C9c654aABF932814A) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -839,4 +839,4 @@ index 23a3c2fd..ec881e76 100644
- **EUL** (`0xd9Fcd98c322942075A5C3860693e9f4f03AAE07b`): Canonical EUL governance token: contract Eul (contracts/governance/Eul.sol) in euler-xyz/euler-governance — an OpenZeppelin-based ERC20 with Votes/Permit and AccessControl, plus a treasury mint restricted to at most 2.718% of supply per year. Deployed at the end of 2021 (last source change 2021-12-30, commit 1249ea8b) and in continuous use since; documented here as provenance context rather than re-proven from a commit pin. BailSec performed a retrospective re-audit of exactly the deployed revision in June 2025 (bailsec-eul-erc20-2025: 4 informational findings, all acknowledged — the deployed contract is immutable). This token is the lock/unlock asset held by the mainnet OFT adapter; the bridged EUL on all other chains is the separate ERC20BurnableMintable, bytecode-proven in those chains’ reports.
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/130.md b/verify/130.md
index 25e8e87..b34a545 100644
--- a/verify/130.md
+++ b/verify/130.md
@@ -4,11 +4,7 @@ Chain ID: 130 · Bytecode-proven: **21/21**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,13 +13,13 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0xFbD12fbC…`](https://unichain.blockscout.com/address/0xFbD12fbC91311A8f17598b935e35205EAF16Aa75) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `47294620` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0xE9C43e09…`](https://unichain.blockscout.com/address/0xE9C43e09C5FA733bCC2aEAa96063A4a60147AA09) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `0b021e3f` | ≡ baseline | — |
| eulOFTAdapter | [`0x41a11d85…`](https://unichain.blockscout.com/address/0x41a11d85577Bb21743E11Eca62e2b241DC1eD5C0) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `1036d1c0` | ≡ baseline | — |
-| eVaultFactory | [`0xbAd8b5BD…`](https://unichain.blockscout.com/address/0xbAd8b5BDFB2bcbcd78Cc9f1573D3Aad6E865e752) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0x71d72507…`](https://unichain.blockscout.com/address/0x71d7250732591C41D1BdeB1EA0Ee730E138E0c8b) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0x2A117696…`](https://unichain.blockscout.com/address/0x2A1176964F5D7caE5406B627Bf6166664FE83c60) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +58/−11 vs baseline | EVCUtil helper + signer-exclusion hardening |
+| eVaultFactory | [`0xbAd8b5BD…`](https://unichain.blockscout.com/address/0xbAd8b5BDFB2bcbcd78Cc9f1573D3Aad6E865e752) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0x71d72507…`](https://unichain.blockscout.com/address/0x71d7250732591C41D1BdeB1EA0Ee730E138E0c8b) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0x2A117696…`](https://unichain.blockscout.com/address/0x2A1176964F5D7caE5406B627Bf6166664FE83c60) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +4/−1 vs baseline | signer-exclusion hardening |
| oracleRouterFactory | [`0xE551288F…`](https://unichain.blockscout.com/address/0xE551288F0D82C10bBF517DBA66E15C60BF87FE8f) | [`evk-periphery@96b83f80`](https://github.com/euler-xyz/evk-periphery/tree/96b83f80ded9ac3f28bfce871b55917e360b9159) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0xdCD02E4e…`](https://unichain.blockscout.com/address/0xdCD02E4eA8cd273498D315AD8c047305f8480656) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0x1b0e3Da5…`](https://unichain.blockscout.com/address/0x1b0e3Da51b2517E09aE74CD31b708e46B9158E8b) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0x08799a00…`](https://unichain.blockscout.com/address/0x08799a00BC4a74890d65f77828cd2BFbBFcD96dB) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0x08799a00…`](https://unichain.blockscout.com/address/0x08799a00BC4a74890d65f77828cd2BFbBFcD96dB) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0x49eB1C5B…`](https://unichain.blockscout.com/address/0x49eB1C5B56AA221965C3130d472ac9318f01f934) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `2fc2cdd1` | +3/−5 vs baseline | formatting only |
## Euler Earn
@@ -31,20 +27,24 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
| eulerEarnFactory | [`0xD785adD5…`](https://unichain.blockscout.com/address/0xD785adD5F081F56616898E45b90dE307e3DC7d3E) | [`euler-earn@773453b1`](https://github.com/euler-xyz/euler-earn/tree/773453b1f4a6f1d27a1cd0c6d8f6ada572503b23) | ✅ `c9ee150e` | ≡ baseline | — |
-| eulerEarnPublicAllocator | [`0x68a823a4…`](https://unichain.blockscout.com/address/0x68a823a484a9D5A8daBB55c4d4d8006a45E557A9) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0x68a823a4…`](https://unichain.blockscout.com/address/0x68a823a484a9D5A8daBB55c4d4d8006a45E557A9) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV1Factory | [`0x45b146BC…`](https://unichain.blockscout.com/address/0x45b146BC07c9985589B52df651310e75C6BE066A) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Implementation | [`0xd91B0bfA…`](https://unichain.blockscout.com/address/0xd91B0bfACA4691E6Aca7E0E83D9B7F8917989a03) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Periphery | [`0xdAAF468d…`](https://unichain.blockscout.com/address/0xdAAF468d84DD8945521Ea40297ce6c5EEfc7003a) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV2Factory | [`0xf211d70E…`](https://unichain.blockscout.com/address/0xf211d70Ed785f0e981E9F3188804Af43734502F1) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0x144f1715…`](https://unichain.blockscout.com/address/0x144f1715c673dA83917B09A5B4C23E2d72c8D411) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0xAD335516…`](https://unichain.blockscout.com/address/0xAD335516c6E17815d9DD543fBCDFE325F8563E13) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0xeA96Ed68…`](https://unichain.blockscout.com/address/0xeA96Ed6896aB1F00e4Fc28C75D8e6655e56Cef85) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0x9D9ce154…`](https://unichain.blockscout.com/address/0x9D9ce1540b986eF77c02F8D40603193852D2E723) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV1Factory | [`0x45b146BC…`](https://unichain.blockscout.com/address/0x45b146BC07c9985589B52df651310e75C6BE066A) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +43/−24 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Implementation | [`0xd91B0bfA…`](https://unichain.blockscout.com/address/0xd91B0bfACA4691E6Aca7E0E83D9B7F8917989a03) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +40/−21 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Periphery | [`0xdAAF468d…`](https://unichain.blockscout.com/address/0xdAAF468d84DD8945521Ea40297ce6c5EEfc7003a) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +3/−3 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV2Factory | [`0xf211d70E…`](https://unichain.blockscout.com/address/0xf211d70Ed785f0e981E9F3188804Af43734502F1) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0x144f1715…`](https://unichain.blockscout.com/address/0x144f1715c673dA83917B09A5B4C23E2d72c8D411) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0xAD335516…`](https://unichain.blockscout.com/address/0xAD335516c6E17815d9DD543fBCDFE325F8563E13) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0xeA96Ed68…`](https://unichain.blockscout.com/address/0xeA96Ed6896aB1F00e4Fc28C75D8e6655e56Cef85) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0x9D9ce154…`](https://unichain.blockscout.com/address/0x9D9ce1540b986eF77c02F8D40603193852D2E723) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -508,7 +508,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) (evc):
-Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers — proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).
+Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions — the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -537,119 +537,6 @@ index 95009da..e6bc820 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -658,7 +545,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultImplementation + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -700,28 +587,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -1067,4 +932,4 @@ index 23a3c2fd..ec881e76 100644
if (deadline < block.timestamp) revert SwapVerifier_pastDeadline();
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/137.md b/verify/137.md
index 6cf6e56..e6e486a 100644
--- a/verify/137.md
+++ b/verify/137.md
@@ -4,7 +4,7 @@ Chain ID: 137 · Bytecode-proven: **10/10**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-**No attention items on this chain: every contract is bytecode-proven and matches or is reconciled to its audited baseline.**
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -12,13 +12,13 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
|----------|---------|--------|----------|---------------------|--------------|
| balanceTracker | [`0x0dCA20a4…`](https://polygonscan.com/address/0x0dCA20a43aD0DC9B6fAccf22dAF6c3CEF70971D8) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `da5a2a71` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0x995C71de…`](https://polygonscan.com/address/0x995C71de11C1f07836ef7d09aC803340BDd91367) | [`evk-periphery@8c946bb1`](https://github.com/euler-xyz/evk-periphery/tree/8c946bb15574c764bee054de79758b958d0130d4) | ✅ `0b021e3f` | +1/−1 vs baseline | mint() gains 'virtual' (no behavior change) |
-| eVaultFactory | [`0xB1771a13…`](https://polygonscan.com/address/0xB1771a13e2a13fCafA89B00335915E732B9466b7) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `3971bde2` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| eVaultImplementation | [`0xFac635be…`](https://polygonscan.com/address/0xFac635beB7d3B47d8E93B78ea6b43656Db84ffC8) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0x90811Dac…`](https://polygonscan.com/address/0x90811DacA4BD23Fc79A87FBdff7522bED2d24B4B) | [`ethereum-vault-connector@912b301f`](https://github.com/euler-xyz/ethereum-vault-connector/tree/912b301f51301e586e5a7f09e48cf52bd52e9a0e) | ✅ `f4ec7203` | +69/−22 vs baseline | set-size 10→100 (audited) + hardening |
+| eVaultFactory | [`0xB1771a13…`](https://polygonscan.com/address/0xB1771a13e2a13fCafA89B00335915E732B9466b7) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0xFac635be…`](https://polygonscan.com/address/0xFac635beB7d3B47d8E93B78ea6b43656Db84ffC8) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0x90811Dac…`](https://polygonscan.com/address/0x90811DacA4BD23Fc79A87FBdff7522bED2d24B4B) | [`ethereum-vault-connector@912b301f`](https://github.com/euler-xyz/ethereum-vault-connector/tree/912b301f51301e586e5a7f09e48cf52bd52e9a0e) | ✅ `f4ec7203` | +15/−12 vs baseline | set-size 10→100 (audited) + signer hardening |
| oracleRouterFactory | [`0xbf5F8524…`](https://polygonscan.com/address/0xbf5F852416deEdFaBACb8B2699b4e8568F20D889) | [`evk-periphery@96b83f80`](https://github.com/euler-xyz/evk-periphery/tree/96b83f80ded9ac3f28bfce871b55917e360b9159) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
-| protocolConfig | [`0xB7474ED2…`](https://polygonscan.com/address/0xB7474ED2418ee57976d5a22B3DE5aDed68867eBF) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `844a4ed8` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
+| protocolConfig | [`0xB7474ED2…`](https://polygonscan.com/address/0xB7474ED2418ee57976d5a22B3DE5aDed68867eBF) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `844a4ed8` | +1/−1 vs baseline | setLTV patch (audited ×2) + param |
| rEUL | [`0xAB1ca795…`](https://polygonscan.com/address/0xAB1ca795DDcACa7DF9ec350a4adA727e8B7212Bd) | [`evk-periphery@8c946bb1`](https://github.com/euler-xyz/evk-periphery/tree/8c946bb15574c764bee054de79758b958d0130d4) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0xf52C9ef4…`](https://polygonscan.com/address/0xf52C9ef48d4510487aA107a36b24e37ae1269F71) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `83359e00` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
+| sequenceRegistry | [`0xf52C9ef4…`](https://polygonscan.com/address/0xf52C9ef48d4510487aA107a36b24e37ae1269F71) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0x2FD1d2B8…`](https://polygonscan.com/address/0x2FD1d2B8a7ea813240dBf8A157903034c4920c95) | [`evk-periphery@eae25d38`](https://github.com/euler-xyz/evk-periphery/tree/eae25d382bb58aaaaa9f1a3a55567af993ce32be) | ✅ `9469decd` | predates (+158/−34 audited later) | pre-refactor state (audit-pinned) |
@@ -68,7 +68,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`912b301f`](https://github.com/euler-xyz/ethereum-vault-connector/tree/912b301f51301e586e5a7f09e48cf52bd52e9a0e) (evc):
-Polygon-only deployment: the yaudit-evc-2026-setsize state (SET_MAX_ELEMENTS 10→100 for the Gondor/Polymarket integration; 0 C/H/M/L findings, informational fixes included via PR #203). Descendant of the baseline; its delta = the 14-chain pin's delta plus exactly the set-size audit scope. The branch remains unmerged to master by design.
+Polygon-only deployment: the yaudit-evc-2026-setsize state (SET_MAX_ELEMENTS 10→100 for the Gondor/Polymarket integration; 0 C/H/M/L findings, informational fixes included via PR #203). Descendant of the baseline; its delta = the 14-chain pin's signer-exclusion hardening plus exactly the set-size audit scope. The branch remains unmerged to master by design.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -162,119 +162,6 @@ index 73cd28a..a8b2581 100644
function requireVaultStatusCheck() external payable;
/// @notice Forgives previously deferred vault status check.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -283,7 +170,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultFactory, eVaultImplementation, protocolConfig, sequenceRegistry + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -325,28 +212,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### oracleRouterFactory — baseline `11637ffe` ([yAudit (Electisec) (`yaudit-evk-periphery-2024`)](https://github.com/euler-xyz/evk-periphery/blob/3d3b4b96109c8468198ac70a71dc73d027467927/audits/yAudit%20EVK%20Periphery.pdf))
@@ -870,4 +735,4 @@ index 01ab58ef..00000000
-}
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/143.md b/verify/143.md
index 41a375b..708061b 100644
--- a/verify/143.md
+++ b/verify/143.md
@@ -4,7 +4,7 @@ Chain ID: 143 · Bytecode-proven: **16/16**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-**No attention items on this chain: every contract is bytecode-proven and matches or is reconciled to its audited baseline.**
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -13,29 +13,29 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0xa231DccE…`](https://monadvision.com/address/0xa231DccE58EA5A43E69EF351D89ea4212Ec0f30b) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `47294620` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0xDef72Af3…`](https://monadvision.com/address/0xDef72Af3fc69E1Dd5a094f7DDa08Ba203CD0438B) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `0b021e3f` | ≡ baseline | — |
| eulOFTAdapter | [`0x831257BF…`](https://monadvision.com/address/0x831257BFa5478111d2327e08c4068ec37Ac14B81) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `1036d1c0` | ≡ baseline | — |
-| eVaultFactory | [`0xba4Dd672…`](https://monadvision.com/address/0xba4Dd672062dE8FeeDb665DD4410658864483f1E) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0xef17750D…`](https://monadvision.com/address/0xef17750D3a162E28a302E266c474ff8989d60ECD) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0x7a9324E8…`](https://monadvision.com/address/0x7a9324E8f270413fa2E458f5831226d99C7477CD) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +58/−11 vs baseline | EVCUtil helper + signer-exclusion hardening |
+| eVaultFactory | [`0xba4Dd672…`](https://monadvision.com/address/0xba4Dd672062dE8FeeDb665DD4410658864483f1E) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0xef17750D…`](https://monadvision.com/address/0xef17750D3a162E28a302E266c474ff8989d60ECD) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0x7a9324E8…`](https://monadvision.com/address/0x7a9324E8f270413fa2E458f5831226d99C7477CD) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +4/−1 vs baseline | signer-exclusion hardening |
| oracleRouterFactory | [`0xdDA3cBC1…`](https://monadvision.com/address/0xdDA3cBC18e90606A83FBae6F798991af06dFA902) | [`evk-periphery@96b83f80`](https://github.com/euler-xyz/evk-periphery/tree/96b83f80ded9ac3f28bfce871b55917e360b9159) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0x94A2d1d1…`](https://monadvision.com/address/0x94A2d1d175F1d828935a374091e2009CF1cED858) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0xff074349…`](https://monadvision.com/address/0xff074349C8b89bB7362bD25c58742896D817A862) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0x39F81037…`](https://monadvision.com/address/0x39F81037f20AC6068CbCd30f748094c58bfE7d7b) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0x39F81037…`](https://monadvision.com/address/0x39F81037f20AC6068CbCd30f748094c58bfE7d7b) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0x24a00DaB…`](https://monadvision.com/address/0x24a00DaB8a85e70B59Cd03B4250Db80Fcd30bE5f) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `2fc2cdd1` | +3/−5 vs baseline | formatting only |
## Euler Earn
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerEarnFactory | [`0xF463d4Ac…`](https://monadvision.com/address/0xF463d4Acb650cc6C4E1D6cD4D0d1b0cb224094cF) | [`euler-earn@bece7172`](https://github.com/euler-xyz/euler-earn/tree/bece7172a87551e6943a52b08c9a0117eb02c6c3) | ✅ `c65c6dcf` | +18/−18 vs baseline | import-path style only |
-| eulerEarnPublicAllocator | [`0x65A66F24…`](https://monadvision.com/address/0x65A66F24a25E8CF651C9e31D296623298C80F742) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnFactory | [`0xF463d4Ac…`](https://monadvision.com/address/0xF463d4Acb650cc6C4E1D6cD4D0d1b0cb224094cF) | [`euler-earn@bece7172`](https://github.com/euler-xyz/euler-earn/tree/bece7172a87551e6943a52b08c9a0117eb02c6c3) | ✅ `c65c6dcf` | +16/−16 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0x65A66F24…`](https://monadvision.com/address/0x65A66F24a25E8CF651C9e31D296623298C80F742) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV1Factory | [`0x34f8F028…`](https://monadvision.com/address/0x34f8F028C6a446A464c10a135F44Fc6fB2CEe1A9) | [`euler-swap@5d270c76`](https://github.com/euler-xyz/euler-swap/tree/5d270c764204b896770e967c22c7b95959bf6660) | ✅ `7c9a247e` | +53/−30 vs baseline | licenses/events + natspec, import fix |
-| eulerSwapV1Implementation | [`0xBFD5C7bb…`](https://monadvision.com/address/0xBFD5C7bb1C208FEc761284Af7dB6fF1F4314372c) | [`euler-swap@5d270c76`](https://github.com/euler-xyz/euler-swap/tree/5d270c764204b896770e967c22c7b95959bf6660) | ✅ `20cae9a4` | +53/−30 vs baseline | licenses/events + natspec, import fix |
-| eulerSwapV1Periphery | [`0xd1F69cf9…`](https://monadvision.com/address/0xd1F69cf959c1a3AAe7BEE5ec677222d259585B27) | [`euler-swap@98c05c56`](https://github.com/euler-xyz/euler-swap/tree/98c05c56f7722887d293ef231accd689c2ea2493) | ✅ `703cfc72` | +56/−30 vs baseline | licenses/events + natspec/formatting |
+| eulerSwapV1Factory | [`0x34f8F028…`](https://monadvision.com/address/0x34f8F028C6a446A464c10a135F44Fc6fB2CEe1A9) | [`euler-swap@5d270c76`](https://github.com/euler-xyz/euler-swap/tree/5d270c764204b896770e967c22c7b95959bf6660) | ✅ `7c9a247e` | +47/−26 vs baseline | licenses/events + natspec, import fix |
+| eulerSwapV1Implementation | [`0xBFD5C7bb…`](https://monadvision.com/address/0xBFD5C7bb1C208FEc761284Af7dB6fF1F4314372c) | [`euler-swap@5d270c76`](https://github.com/euler-xyz/euler-swap/tree/5d270c764204b896770e967c22c7b95959bf6660) | ✅ `20cae9a4` | +43/−22 vs baseline | licenses/events + natspec, import fix |
+| eulerSwapV1Periphery | [`0xd1F69cf9…`](https://monadvision.com/address/0xd1F69cf959c1a3AAe7BEE5ec677222d259585B27) | [`euler-swap@98c05c56`](https://github.com/euler-xyz/euler-swap/tree/98c05c56f7722887d293ef231accd689c2ea2493) | ✅ `703cfc72` | +13/−6 vs baseline | licenses/events + natspec/formatting |
## EVault modules (unpacked from the implementation)
@@ -874,7 +874,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) (evc):
-Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers — proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).
+Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions — the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -903,119 +903,6 @@ index 95009da..e6bc820 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -1024,7 +911,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultImplementation + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -1066,28 +953,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -1433,4 +1298,4 @@ index 23a3c2fd..ec881e76 100644
if (deadline < block.timestamp) revert SwapVerifier_pastDeadline();
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/146.md b/verify/146.md
index 01c26a1..5fae944 100644
--- a/verify/146.md
+++ b/verify/146.md
@@ -4,11 +4,7 @@ Chain ID: 146 · Bytecode-proven: **21/21**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,13 +13,13 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0xe6E4687C…`](https://sonicscan.org/address/0xe6E4687C35429942391AfE42CDdECba857531492) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `47294620` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0x8e15C8D3…`](https://sonicscan.org/address/0x8e15C8D399e86d4FD7B427D42f06c60cDD9397e7) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `0b021e3f` | ≡ baseline | — |
| eulOFTAdapter | [`0x31aA7423…`](https://sonicscan.org/address/0x31aA74232A0b0E50e5bF95780b2116710a34c7E9) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `1036d1c0` | ≡ baseline | — |
-| eVaultFactory | [`0xF075cC86…`](https://sonicscan.org/address/0xF075cC8660B51D0b8a4474e3f47eDAC5fA034cFB) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0x11f95aaa…`](https://sonicscan.org/address/0x11f95aaa59F1AD89576c61E3C9Cd24DF1FdCF46f) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0x4860C903…`](https://sonicscan.org/address/0x4860C903f6Ad709c3eDA46D3D502943f184D4315) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +58/−11 vs baseline | EVCUtil helper + signer-exclusion hardening |
+| eVaultFactory | [`0xF075cC86…`](https://sonicscan.org/address/0xF075cC8660B51D0b8a4474e3f47eDAC5fA034cFB) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0x11f95aaa…`](https://sonicscan.org/address/0x11f95aaa59F1AD89576c61E3C9Cd24DF1FdCF46f) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0x4860C903…`](https://sonicscan.org/address/0x4860C903f6Ad709c3eDA46D3D502943f184D4315) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +4/−1 vs baseline | signer-exclusion hardening |
| oracleRouterFactory | [`0xc5b9B95a…`](https://sonicscan.org/address/0xc5b9B95a769C24c18c344c2659db61a0AdFB736E) | [`evk-periphery@96b83f80`](https://github.com/euler-xyz/evk-periphery/tree/96b83f80ded9ac3f28bfce871b55917e360b9159) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0xc2f9FE90…`](https://sonicscan.org/address/0xc2f9FE90bd17e017898b6EfDaa73c34Fddde299e) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0x09E6cab4…`](https://sonicscan.org/address/0x09E6cab47B7199b9d3839A2C40654f246d518a80) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0x6F417AaE…`](https://sonicscan.org/address/0x6F417AaEc1D41dB692307269acDA019Ce5F10b0e) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0x6F417AaE…`](https://sonicscan.org/address/0x6F417AaEc1D41dB692307269acDA019Ce5F10b0e) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0xbD0d0Fe1…`](https://sonicscan.org/address/0xbD0d0Fe1D6F655Aad80b360f46390d876f2d278f) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `2fc2cdd1` | +3/−5 vs baseline | formatting only |
## Euler Earn
@@ -31,20 +27,24 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
| eulerEarnFactory | [`0x3397ec7d…`](https://sonicscan.org/address/0x3397ec7d28cF645A017869Fe4B41c75f5B0b75a8) | [`euler-earn@773453b1`](https://github.com/euler-xyz/euler-earn/tree/773453b1f4a6f1d27a1cd0c6d8f6ada572503b23) | ✅ `c9ee150e` | ≡ baseline | — |
-| eulerEarnPublicAllocator | [`0x82b27b52…`](https://sonicscan.org/address/0x82b27b528DA0516E653e02e5f870853d22Cbc6Df) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0x82b27b52…`](https://sonicscan.org/address/0x82b27b528DA0516E653e02e5f870853d22Cbc6Df) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV1Factory | [`0x94041db6…`](https://sonicscan.org/address/0x94041db6deC15f79666B07846c13e6F7341b4a80) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Implementation | [`0x4D57F545…`](https://sonicscan.org/address/0x4D57F54582b333E4184A3cF40d1D61FE6D70c35D) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Periphery | [`0xb2237DC8…`](https://sonicscan.org/address/0xb2237DC86B184e50Fc2F8b028B2b7AE192ef2566) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV2Factory | [`0x46D23b2d…`](https://sonicscan.org/address/0x46D23b2d948b159859A5BB9C96c3190F4b43Ebb6) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0x1C266a98…`](https://sonicscan.org/address/0x1C266a986B6AfA7EbA68263c5323a0bF0fe4F2a4) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0x4e4e5246…`](https://sonicscan.org/address/0x4e4e524613d840D2D30B694F363b5b1931e82A75) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0x8653d1B5…`](https://sonicscan.org/address/0x8653d1B50AA6adaaD64Dc140588dBC8c11141581) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0x0601a383…`](https://sonicscan.org/address/0x0601a38324D3cde22EBD531c799Ad318a6B8CF93) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV1Factory | [`0x94041db6…`](https://sonicscan.org/address/0x94041db6deC15f79666B07846c13e6F7341b4a80) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +43/−24 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Implementation | [`0x4D57F545…`](https://sonicscan.org/address/0x4D57F54582b333E4184A3cF40d1D61FE6D70c35D) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +40/−21 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Periphery | [`0xb2237DC8…`](https://sonicscan.org/address/0xb2237DC86B184e50Fc2F8b028B2b7AE192ef2566) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +3/−3 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV2Factory | [`0x46D23b2d…`](https://sonicscan.org/address/0x46D23b2d948b159859A5BB9C96c3190F4b43Ebb6) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0x1C266a98…`](https://sonicscan.org/address/0x1C266a986B6AfA7EbA68263c5323a0bF0fe4F2a4) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0x4e4e5246…`](https://sonicscan.org/address/0x4e4e524613d840D2D30B694F363b5b1931e82A75) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0x8653d1B5…`](https://sonicscan.org/address/0x8653d1B50AA6adaaD64Dc140588dBC8c11141581) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0x0601a383…`](https://sonicscan.org/address/0x0601a38324D3cde22EBD531c799Ad318a6B8CF93) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -508,7 +508,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) (evc):
-Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers — proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).
+Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions — the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -537,119 +537,6 @@ index 95009da..e6bc820 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -658,7 +545,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultImplementation + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -700,28 +587,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -1067,4 +932,4 @@ index 23a3c2fd..ec881e76 100644
if (deadline < block.timestamp) revert SwapVerifier_pastDeadline();
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/1923.md b/verify/1923.md
index c329b0e..cf7a9a4 100644
--- a/verify/1923.md
+++ b/verify/1923.md
@@ -4,11 +4,7 @@ Chain ID: 1923 · Bytecode-proven: **21/21**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,13 +13,13 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0x9fb7215e…`](https://explorer.swellnetwork.io/address/0x9fb7215ef6297498D6807caf9f3aC8BA3154db29) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `48762e01` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0x80ccFBec…`](https://explorer.swellnetwork.io/address/0x80ccFBec4b8c82265abdc226Ad3Df84C0726E7A3) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `0b021e3f` | ≡ baseline | — |
| eulOFTAdapter | [`0xD0148dDB…`](https://explorer.swellnetwork.io/address/0xD0148dDB69f4d8182Ef863d6f81ED6519D8c83a2) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `1036d1c0` | ≡ baseline | — |
-| eVaultFactory | [`0x238bF86b…`](https://explorer.swellnetwork.io/address/0x238bF86bb451ec3CA69BB855f91BDA001aB118b9) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0x70f12862…`](https://explorer.swellnetwork.io/address/0x70f1286239228B28A047c727C2df390045299486) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0x08739CBe…`](https://explorer.swellnetwork.io/address/0x08739CBede6E28E387685ba20e6409bD16969Cde) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +58/−11 vs baseline | EVCUtil helper + signer-exclusion hardening |
+| eVaultFactory | [`0x238bF86b…`](https://explorer.swellnetwork.io/address/0x238bF86bb451ec3CA69BB855f91BDA001aB118b9) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0x70f12862…`](https://explorer.swellnetwork.io/address/0x70f1286239228B28A047c727C2df390045299486) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0x08739CBe…`](https://explorer.swellnetwork.io/address/0x08739CBede6E28E387685ba20e6409bD16969Cde) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +4/−1 vs baseline | signer-exclusion hardening |
| oracleRouterFactory | [`0x0135fC26…`](https://explorer.swellnetwork.io/address/0x0135fC2605ff2C89E550C2d4C7d75068A4782B43) | [`evk-periphery@96b83f80`](https://github.com/euler-xyz/evk-periphery/tree/96b83f80ded9ac3f28bfce871b55917e360b9159) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0x6682Af28…`](https://explorer.swellnetwork.io/address/0x6682Af2820633067A1de5bE99b2DCb2d38F1e241) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0x021694af…`](https://explorer.swellnetwork.io/address/0x021694af083d67950Ac994E63e0a70C30D913836) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0xC4589C61…`](https://explorer.swellnetwork.io/address/0xC4589C6199516F96B422D91020563Fe65b28918e) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0xC4589C61…`](https://explorer.swellnetwork.io/address/0xC4589C6199516F96B422D91020563Fe65b28918e) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0x605280f2…`](https://explorer.swellnetwork.io/address/0x605280f2F939255Ab36FaFdBC654dE3cfbD5c616) | [`evk-periphery@eae25d38`](https://github.com/euler-xyz/evk-periphery/tree/eae25d382bb58aaaaa9f1a3a55567af993ce32be) | ✅ `9469decd` | predates (+158/−34 audited later) | pre-refactor state (audit-pinned) |
## Euler Earn
@@ -31,20 +27,24 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
| eulerEarnFactory | [`0x3073e1B4…`](https://explorer.swellnetwork.io/address/0x3073e1B42f8Cc933f2d678DdA10acDE51F4E49a3) | [`euler-earn@773453b1`](https://github.com/euler-xyz/euler-earn/tree/773453b1f4a6f1d27a1cd0c6d8f6ada572503b23) | ✅ `c9ee150e` | ≡ baseline | — |
-| eulerEarnPublicAllocator | [`0x0a13C9fc…`](https://explorer.swellnetwork.io/address/0x0a13C9fc4613Cae202138F4E1C2b9125A20562E8) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0x0a13C9fc…`](https://explorer.swellnetwork.io/address/0x0a13C9fc4613Cae202138F4E1C2b9125A20562E8) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV1Factory | [`0x976dd856…`](https://explorer.swellnetwork.io/address/0x976dd85654B3b2f9fb66280ACE30Cab7C81a2130) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Implementation | [`0x3620dAb0…`](https://explorer.swellnetwork.io/address/0x3620dAb0DB5595479a4D5408595D48FbE48CeA2A) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Periphery | [`0x34932C04…`](https://explorer.swellnetwork.io/address/0x34932C04c3d27c2BD7aCd0B5d203bfd65a17f481) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV2Factory | [`0x980cd01d…`](https://explorer.swellnetwork.io/address/0x980cd01dB708C2B008cF8076aa856fcAeF60698c) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0xCB728171…`](https://explorer.swellnetwork.io/address/0xCB72817170a9d0f136fcB764f55BEEC638C25acb) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0x74F7726e…`](https://explorer.swellnetwork.io/address/0x74F7726eF6D8107403a6c581B985D27ED0561f9D) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0x6FB6C91e…`](https://explorer.swellnetwork.io/address/0x6FB6C91e369fD151eB343de3BE76F3617FbFfDf2) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0x33274281…`](https://explorer.swellnetwork.io/address/0x3327428147E0cE4Cb185A82F756CaE0D429dbd2c) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV1Factory | [`0x976dd856…`](https://explorer.swellnetwork.io/address/0x976dd85654B3b2f9fb66280ACE30Cab7C81a2130) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +43/−24 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Implementation | [`0x3620dAb0…`](https://explorer.swellnetwork.io/address/0x3620dAb0DB5595479a4D5408595D48FbE48CeA2A) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +40/−21 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Periphery | [`0x34932C04…`](https://explorer.swellnetwork.io/address/0x34932C04c3d27c2BD7aCd0B5d203bfd65a17f481) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +3/−3 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV2Factory | [`0x980cd01d…`](https://explorer.swellnetwork.io/address/0x980cd01dB708C2B008cF8076aa856fcAeF60698c) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0xCB728171…`](https://explorer.swellnetwork.io/address/0xCB72817170a9d0f136fcB764f55BEEC638C25acb) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0x74F7726e…`](https://explorer.swellnetwork.io/address/0x74F7726eF6D8107403a6c581B985D27ED0561f9D) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0x6FB6C91e…`](https://explorer.swellnetwork.io/address/0x6FB6C91e369fD151eB343de3BE76F3617FbFfDf2) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0x33274281…`](https://explorer.swellnetwork.io/address/0x3327428147E0cE4Cb185A82F756CaE0D429dbd2c) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -508,7 +508,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) (evc):
-Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers — proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).
+Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions — the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -537,119 +537,6 @@ index 95009da..e6bc820 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -658,7 +545,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultImplementation + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -700,28 +587,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -1269,4 +1134,4 @@ index 01ab58ef..00000000
-}
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/239.md b/verify/239.md
index 675b628..255e1fd 100644
--- a/verify/239.md
+++ b/verify/239.md
@@ -4,11 +4,7 @@ Chain ID: 239 · Bytecode-proven: **21/21**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,34 +13,38 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0x45ff89cD…`](https://explorer.tac.build/address/0x45ff89cD0e976392703048F4A4314A2010ee64b8) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `47294620` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0x38C04385…`](https://explorer.tac.build/address/0x38C043856A109066d64a60c82e07848a1C58e7Dc) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `0b021e3f` | ≡ baseline | — |
| eulOFTAdapter | [`0xe7c41548…`](https://explorer.tac.build/address/0xe7c415484348d14c0e6B8C18E110D72EcA17d306) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `1036d1c0` | ≡ baseline | — |
-| eVaultFactory | [`0x2b21621b…`](https://explorer.tac.build/address/0x2b21621b8Ef1406699a99071ce04ec14cCd50677) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0x1974899F…`](https://explorer.tac.build/address/0x1974899F5d6B5a1f8E63b2e8Ad60e14BAC3E7980) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0x01F594c6…`](https://explorer.tac.build/address/0x01F594c66A5561b90Bc782dD0297f294cD668b64) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +58/−11 vs baseline | EVCUtil helper + signer-exclusion hardening |
+| eVaultFactory | [`0x2b21621b…`](https://explorer.tac.build/address/0x2b21621b8Ef1406699a99071ce04ec14cCd50677) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0x1974899F…`](https://explorer.tac.build/address/0x1974899F5d6B5a1f8E63b2e8Ad60e14BAC3E7980) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0x01F594c6…`](https://explorer.tac.build/address/0x01F594c66A5561b90Bc782dD0297f294cD668b64) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +4/−1 vs baseline | signer-exclusion hardening |
| oracleRouterFactory | [`0x0512F7cb…`](https://explorer.tac.build/address/0x0512F7cbc4Fd9d8BC47FfFa3aA0372bA2375158E) | [`evk-periphery@96b83f80`](https://github.com/euler-xyz/evk-periphery/tree/96b83f80ded9ac3f28bfce871b55917e360b9159) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0x4C3D26D7…`](https://explorer.tac.build/address/0x4C3D26D7Eb6D5AA62CFD99624ad4Ff3351E4B129) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0xCf623E50…`](https://explorer.tac.build/address/0xCf623E50430CCb55214985F9C986a5Fa50aD7686) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0xF7a9F90b…`](https://explorer.tac.build/address/0xF7a9F90b5ACb4EE4Cd536940142A04522D28e0Aa) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0xF7a9F90b…`](https://explorer.tac.build/address/0xF7a9F90b5ACb4EE4Cd536940142A04522D28e0Aa) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0x6D83f642…`](https://explorer.tac.build/address/0x6D83f642A1F0206b08f4F035197F9Eee553AbFC9) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `2fc2cdd1` | +3/−5 vs baseline | formatting only |
## Euler Earn
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerEarnFactory | [`0x7670572a…`](https://explorer.tac.build/address/0x7670572aa76E6140400A948e7AAFAB0210a86d9f) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +18/−18 vs baseline | import-path style only |
-| eulerEarnPublicAllocator | [`0x4873ff8a…`](https://explorer.tac.build/address/0x4873ff8a70aA92443321Edb34a48f6aBfA7feB96) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnFactory | [`0x7670572a…`](https://explorer.tac.build/address/0x7670572aa76E6140400A948e7AAFAB0210a86d9f) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +16/−16 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0x4873ff8a…`](https://explorer.tac.build/address/0x4873ff8a70aA92443321Edb34a48f6aBfA7feB96) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV1Factory | [`0x6A721609…`](https://explorer.tac.build/address/0x6A72160963a562f21387B166aF31a92D154106fb) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Implementation | [`0xDFfaC13f…`](https://explorer.tac.build/address/0xDFfaC13fC142Fc1d8E55226dB9c98f4b66371a3c) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Periphery | [`0xAF596563…`](https://explorer.tac.build/address/0xAF596563109C753b9c5e73DD596DD4bB247964cA) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV2Factory | [`0xb0b53c1A…`](https://explorer.tac.build/address/0xb0b53c1A8046D92027B69D9f6D9C7cFC0f363933) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0x32Da74f7…`](https://explorer.tac.build/address/0x32Da74f7bC1988c1c39adB561b6e9D2a6F33D404) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0xD356C065…`](https://explorer.tac.build/address/0xD356C065777871B37Cb0D3C7761b8820c832BC57) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0xb7F14f64…`](https://explorer.tac.build/address/0xb7F14f649770fB7784A02A94946D14E80f79d660) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0xd3ee9112…`](https://explorer.tac.build/address/0xd3ee91128294Ca8231260891BEC6Da7d258De7B6) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV1Factory | [`0x6A721609…`](https://explorer.tac.build/address/0x6A72160963a562f21387B166aF31a92D154106fb) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +43/−24 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Implementation | [`0xDFfaC13f…`](https://explorer.tac.build/address/0xDFfaC13fC142Fc1d8E55226dB9c98f4b66371a3c) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +40/−21 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Periphery | [`0xAF596563…`](https://explorer.tac.build/address/0xAF596563109C753b9c5e73DD596DD4bB247964cA) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +3/−3 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV2Factory | [`0xb0b53c1A…`](https://explorer.tac.build/address/0xb0b53c1A8046D92027B69D9f6D9C7cFC0f363933) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0x32Da74f7…`](https://explorer.tac.build/address/0x32Da74f7bC1988c1c39adB561b6e9D2a6F33D404) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0xD356C065…`](https://explorer.tac.build/address/0xD356C065777871B37Cb0D3C7761b8820c832BC57) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0xb7F14f64…`](https://explorer.tac.build/address/0xb7F14f649770fB7784A02A94946D14E80f79d660) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0xd3ee9112…`](https://explorer.tac.build/address/0xd3ee91128294Ca8231260891BEC6Da7d258De7B6) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -498,7 +498,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) (evc):
-Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers — proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).
+Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions — the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -527,119 +527,6 @@ index 95009da..e6bc820 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -648,7 +535,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultImplementation + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -690,28 +577,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -1057,4 +922,4 @@ index 23a3c2fd..ec881e76 100644
if (deadline < block.timestamp) revert SwapVerifier_pastDeadline();
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/2818.md b/verify/2818.md
index 8fc17bf..db761e7 100644
--- a/verify/2818.md
+++ b/verify/2818.md
@@ -4,11 +4,7 @@ Chain ID: 2818 · Bytecode-proven: **18/18**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,31 +13,35 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0x7bF00B86…`](https://explorer.morph.network/address/0x7bF00B8638d0eBE917C82B286Fc07E86988F3A1C) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `47294620` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0x5E2901d2…`](https://explorer.morph.network/address/0x5E2901d24fc83eCE7589e7A7d3b1e6D80739789d) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `0b021e3f` | ≡ baseline | — |
| eulOFTAdapter | [`0x9895149F…`](https://explorer.morph.network/address/0x9895149F3324666d94664C159Af0cd026eb53761) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `1036d1c0` | ≡ baseline | — |
-| eVaultFactory | [`0x1a1bdF62…`](https://explorer.morph.network/address/0x1a1bdF62Fe7170c652f03fF153977C26fBe7b2E1) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0xC98f21E7…`](https://explorer.morph.network/address/0xC98f21E7b1F12ab225386226D022a67E65D8B0cE) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0xC7c31B1E…`](https://explorer.morph.network/address/0xC7c31B1E7Cac36478C62f876F357b95d9cAd9817) | [`ethereum-vault-connector@7b2f05f8`](https://github.com/euler-xyz/ethereum-vault-connector/tree/7b2f05f8f2fc093f679463209dea202e9af3b120) | ✅ `58879eba` | +59/−11 vs baseline | Morph deployment-branch additions |
+| eVaultFactory | [`0x1a1bdF62…`](https://explorer.morph.network/address/0x1a1bdF62Fe7170c652f03fF153977C26fBe7b2E1) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0xC98f21E7…`](https://explorer.morph.network/address/0xC98f21E7b1F12ab225386226D022a67E65D8B0cE) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0xC7c31B1E…`](https://explorer.morph.network/address/0xC7c31B1E7Cac36478C62f876F357b95d9cAd9817) | [`ethereum-vault-connector@7b2f05f8`](https://github.com/euler-xyz/ethereum-vault-connector/tree/7b2f05f8f2fc093f679463209dea202e9af3b120) | ✅ `58879eba` | +5/−1 vs baseline | Morph deployment-branch additions |
| oracleRouterFactory | [`0x1e809496…`](https://explorer.morph.network/address/0x1e80949625ab6b09a5749f00a63d48887ba3B696) | [`evk-periphery@96b83f80`](https://github.com/euler-xyz/evk-periphery/tree/96b83f80ded9ac3f28bfce871b55917e360b9159) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0x235597e3…`](https://explorer.morph.network/address/0x235597e32131A6681592Ac276c967a5b8c89dCb3) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0xA394128F…`](https://explorer.morph.network/address/0xA394128F6b04A0AbcA7feaa12145Da9Aa6B24686) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0x433438DD…`](https://explorer.morph.network/address/0x433438DD80353fB1893253348b7b14f821b4cCFB) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0x433438DD…`](https://explorer.morph.network/address/0x433438DD80353fB1893253348b7b14f821b4cCFB) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0xD38D4F98…`](https://explorer.morph.network/address/0xD38D4F982Ca00365e349dC128C833289be4774c9) | [`evk-periphery@eae25d38`](https://github.com/euler-xyz/evk-periphery/tree/eae25d382bb58aaaaa9f1a3a55567af993ce32be) | ✅ `9469decd` | predates (+158/−34 audited later) | pre-refactor state (audit-pinned) |
## Euler Earn
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerEarnFactory | [`0x4A6727aA…`](https://explorer.morph.network/address/0x4A6727aA2d1979C0366751c7a81615500f0186E4) | [`euler-earn@bece7172`](https://github.com/euler-xyz/euler-earn/tree/bece7172a87551e6943a52b08c9a0117eb02c6c3) | ✅ `c65c6dcf` | +18/−18 vs baseline | import-path style only |
-| eulerEarnPublicAllocator | [`0x776043C5…`](https://explorer.morph.network/address/0x776043C581c7b30164b92358be317b16489C510b) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnFactory | [`0x4A6727aA…`](https://explorer.morph.network/address/0x4A6727aA2d1979C0366751c7a81615500f0186E4) | [`euler-earn@bece7172`](https://github.com/euler-xyz/euler-earn/tree/bece7172a87551e6943a52b08c9a0117eb02c6c3) | ✅ `c65c6dcf` | +16/−16 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0x776043C5…`](https://explorer.morph.network/address/0x776043C581c7b30164b92358be317b16489C510b) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV2Factory | [`0x59652301…`](https://explorer.morph.network/address/0x5965230117acd46E88CA13e7D44E33cD166c1E44) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0xDA4d6a51…`](https://explorer.morph.network/address/0xDA4d6a51cdF37d93C84071192611B0544B4454d8) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0x9C0689e0…`](https://explorer.morph.network/address/0x9C0689e034D5bfDCc190F062b70c364c4764EF35) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0x2348C396…`](https://explorer.morph.network/address/0x2348C3967F61b235501Ea74eE8e95F84D752dDeA) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0xce4Ef4F4…`](https://explorer.morph.network/address/0xce4Ef4F4c590FE00c213e1A458743d12e7301268) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Factory | [`0x59652301…`](https://explorer.morph.network/address/0x5965230117acd46E88CA13e7D44E33cD166c1E44) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0xDA4d6a51…`](https://explorer.morph.network/address/0xDA4d6a51cdF37d93C84071192611B0544B4454d8) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0x9C0689e0…`](https://explorer.morph.network/address/0x9C0689e034D5bfDCc190F062b70c364c4764EF35) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0x2348C396…`](https://explorer.morph.network/address/0x2348C3967F61b235501Ea74eE8e95F84D752dDeA) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0xce4Ef4F4…`](https://explorer.morph.network/address/0xce4Ef4F4c590FE00c213e1A458743d12e7301268) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -438,119 +438,6 @@ index 95009da..df0e204 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -559,7 +446,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultImplementation + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -601,28 +488,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -1170,4 +1035,4 @@ index 01ab58ef..00000000
-}
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/42161.md b/verify/42161.md
index 4e40663..9ee2b8e 100644
--- a/verify/42161.md
+++ b/verify/42161.md
@@ -4,11 +4,7 @@ Chain ID: 42161 · Bytecode-proven: **21/21**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,34 +13,38 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0xbCD29c1B…`](https://arbiscan.io/address/0xbCD29c1B596d9fFAfaa6F90780956b4D3d47832f) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `47294620` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0x462cD9E0…`](https://arbiscan.io/address/0x462cD9E0247b2e63831c3189aE738E5E9a5a4b64) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `0b021e3f` | ≡ baseline | — |
| eulOFTAdapter | [`0x174834a9…`](https://arbiscan.io/address/0x174834a9DE4C2f0c13c7353e62C229E8D607c808) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `1036d1c0` | ≡ baseline | — |
-| eVaultFactory | [`0x78Df1CF5…`](https://arbiscan.io/address/0x78Df1CF5bf06a7f27f2ACc580B934238C1b80D50) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0x832fF401…`](https://arbiscan.io/address/0x832fF4011A3164ea76ceA06A313EE0B6CD72ba96) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0x6302ef0F…`](https://arbiscan.io/address/0x6302ef0F34100CDDFb5489fbcB6eE1AA95CD1066) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +58/−11 vs baseline | EVCUtil helper + signer-exclusion hardening |
+| eVaultFactory | [`0x78Df1CF5…`](https://arbiscan.io/address/0x78Df1CF5bf06a7f27f2ACc580B934238C1b80D50) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0x832fF401…`](https://arbiscan.io/address/0x832fF4011A3164ea76ceA06A313EE0B6CD72ba96) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0x6302ef0F…`](https://arbiscan.io/address/0x6302ef0F34100CDDFb5489fbcB6eE1AA95CD1066) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +4/−1 vs baseline | signer-exclusion hardening |
| oracleRouterFactory | [`0x22d51Db4…`](https://arbiscan.io/address/0x22d51Db42A59862D4F8c135C4406AEf9854ABFF3) | [`evk-periphery@96b83f80`](https://github.com/euler-xyz/evk-periphery/tree/96b83f80ded9ac3f28bfce871b55917e360b9159) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0x06c1Ab0A…`](https://arbiscan.io/address/0x06c1Ab0A1672E8FC7F7D10BD7B869B4116D18a2c) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0xFA31599a…`](https://arbiscan.io/address/0xFA31599a4928c2d57C0dd77DFCA5DA1E94E6D2D2) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0x924C73ab…`](https://arbiscan.io/address/0x924C73abAa350800fc22c11ffdFB09641106E3ce) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0x924C73ab…`](https://arbiscan.io/address/0x924C73abAa350800fc22c11ffdFB09641106E3ce) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0xdABeBFF7…`](https://arbiscan.io/address/0xdABeBFF75f047E725D9aC978770107491C100bbB) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `2fc2cdd1` | +3/−5 vs baseline | formatting only |
## Euler Earn
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerEarnFactory | [`0xB9B5d62B…`](https://arbiscan.io/address/0xB9B5d62B9fE9E1B505466e75817aB178A1D2ec9d) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +18/−18 vs baseline | import-path style only |
-| eulerEarnPublicAllocator | [`0x0161FE2C…`](https://arbiscan.io/address/0x0161FE2CA6ED39b5D0811a94b87AC628677Ae020) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnFactory | [`0xB9B5d62B…`](https://arbiscan.io/address/0xB9B5d62B9fE9E1B505466e75817aB178A1D2ec9d) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +16/−16 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0x0161FE2C…`](https://arbiscan.io/address/0x0161FE2CA6ED39b5D0811a94b87AC628677Ae020) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV1Factory | [`0x7949bE8B…`](https://arbiscan.io/address/0x7949bE8B154D7B5ce6E75cBfc646AeF3a25970E2) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Implementation | [`0x04671F89…`](https://arbiscan.io/address/0x04671F895c7d9EAbF33FF1dfF41269E6Fea835D1) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Periphery | [`0x804485f5…`](https://arbiscan.io/address/0x804485f5B6c293f8d63f697E9662CD4a8765858A) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV2Factory | [`0x138AB9B3…`](https://arbiscan.io/address/0x138AB9B33741B25bb7BcDa466175c8B2E2b96dc4) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0xAF6412D5…`](https://arbiscan.io/address/0xAF6412D58024874b0Ffc4138FfF95fc73b372977) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0x223c1a20…`](https://arbiscan.io/address/0x223c1a20A6992a0F1E7066eD924619c3156DDA15) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0xA6fCC47f…`](https://arbiscan.io/address/0xA6fCC47f8D930f096F8749C7C7D335871bc71C0D) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0x99C341F0…`](https://arbiscan.io/address/0x99C341F07098ba70aC1130c479103Dc2366dbBD7) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV1Factory | [`0x7949bE8B…`](https://arbiscan.io/address/0x7949bE8B154D7B5ce6E75cBfc646AeF3a25970E2) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +43/−24 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Implementation | [`0x04671F89…`](https://arbiscan.io/address/0x04671F895c7d9EAbF33FF1dfF41269E6Fea835D1) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +40/−21 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Periphery | [`0x804485f5…`](https://arbiscan.io/address/0x804485f5B6c293f8d63f697E9662CD4a8765858A) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +3/−3 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV2Factory | [`0x138AB9B3…`](https://arbiscan.io/address/0x138AB9B33741B25bb7BcDa466175c8B2E2b96dc4) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0xAF6412D5…`](https://arbiscan.io/address/0xAF6412D58024874b0Ffc4138FfF95fc73b372977) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0x223c1a20…`](https://arbiscan.io/address/0x223c1a20A6992a0F1E7066eD924619c3156DDA15) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0xA6fCC47f…`](https://arbiscan.io/address/0xA6fCC47f8D930f096F8749C7C7D335871bc71C0D) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0x99C341F0…`](https://arbiscan.io/address/0x99C341F07098ba70aC1130c479103Dc2366dbBD7) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -498,7 +498,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) (evc):
-Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers — proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).
+Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions — the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -527,119 +527,6 @@ index 95009da..e6bc820 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -648,7 +535,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultImplementation + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -690,28 +577,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -1057,4 +922,4 @@ index 23a3c2fd..ec881e76 100644
if (deadline < block.timestamp) revert SwapVerifier_pastDeadline();
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/43114.md b/verify/43114.md
index d496e74..a96014e 100644
--- a/verify/43114.md
+++ b/verify/43114.md
@@ -4,11 +4,7 @@ Chain ID: 43114 · Bytecode-proven: **21/21**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,34 +13,38 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0xAf565942…`](https://snowtrace.io/address/0xAf5659428FEF1F6a701FaB46d8f3aF8371A9913D) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `47294620` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0x9ceeD3A7…`](https://snowtrace.io/address/0x9ceeD3A7f753608372eeAb300486cc7c2F38AC68) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `0b021e3f` | ≡ baseline | — |
| eulOFTAdapter | [`0xF1A5F97A…`](https://snowtrace.io/address/0xF1A5F97AB84158Cf6d8ba8dEF68780Fc2Fd64310) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `1036d1c0` | ≡ baseline | — |
-| eVaultFactory | [`0xaf4B4c18…`](https://snowtrace.io/address/0xaf4B4c18B17F6a2B32F6c398a3910bdCD7f26181) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0x29E9b639…`](https://snowtrace.io/address/0x29E9b639e165d919FEcf02521F8A9dA0492D4f21) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0xddcbe30A…`](https://snowtrace.io/address/0xddcbe30A761Edd2e19bba930A977475265F36Fa1) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +58/−11 vs baseline | EVCUtil helper + signer-exclusion hardening |
+| eVaultFactory | [`0xaf4B4c18…`](https://snowtrace.io/address/0xaf4B4c18B17F6a2B32F6c398a3910bdCD7f26181) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0x29E9b639…`](https://snowtrace.io/address/0x29E9b639e165d919FEcf02521F8A9dA0492D4f21) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0xddcbe30A…`](https://snowtrace.io/address/0xddcbe30A761Edd2e19bba930A977475265F36Fa1) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +4/−1 vs baseline | signer-exclusion hardening |
| oracleRouterFactory | [`0x80528F01…`](https://snowtrace.io/address/0x80528F014E84658e85D3C6D4896A29Fa933Be696) | [`evk-periphery@96b83f80`](https://github.com/euler-xyz/evk-periphery/tree/96b83f80ded9ac3f28bfce871b55917e360b9159) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0x8564160f…`](https://snowtrace.io/address/0x8564160f30926eA1229DCcf24118c6De155D2e30) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0x2e3b3273…`](https://snowtrace.io/address/0x2e3b32730B4F6b6502BdAa9122df3B026eDE5391) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0x9C38f923…`](https://snowtrace.io/address/0x9C38f923baC407C818312EADEf69AdC116fd16FD) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0x9C38f923…`](https://snowtrace.io/address/0x9C38f923baC407C818312EADEf69AdC116fd16FD) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0x7e5893f9…`](https://snowtrace.io/address/0x7e5893f9Ad9865261299e543FD3fac814CC11804) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `2fc2cdd1` | +3/−5 vs baseline | formatting only |
## Euler Earn
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerEarnFactory | [`0x574B00f5…`](https://snowtrace.io/address/0x574B00f5a0C56D370F19fa887a5545d74F52fAC2) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +18/−18 vs baseline | import-path style only |
-| eulerEarnPublicAllocator | [`0x2524762d…`](https://snowtrace.io/address/0x2524762ddb853AB1e572B81E5E6377a8a1536aA5) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnFactory | [`0x574B00f5…`](https://snowtrace.io/address/0x574B00f5a0C56D370F19fa887a5545d74F52fAC2) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +16/−16 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0x2524762d…`](https://snowtrace.io/address/0x2524762ddb853AB1e572B81E5E6377a8a1536aA5) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV1Factory | [`0x8A1D3a48…`](https://snowtrace.io/address/0x8A1D3a4850ed7deeC9003680Cf41b8E75D27e440) | [`euler-swap@c7da2f33`](https://github.com/euler-xyz/euler-swap/tree/c7da2f330dff3efb98b0b4e998f9b9f498b37c30) | ✅ `f1652049` | +46/−27 vs baseline | licenses/events + solmate import fix |
-| eulerSwapV1Implementation | [`0x4F4FDeE3…`](https://snowtrace.io/address/0x4F4FDeE3568aC31C46634fb2Df3FF44A156Be351) | [`euler-swap@c7da2f33`](https://github.com/euler-xyz/euler-swap/tree/c7da2f330dff3efb98b0b4e998f9b9f498b37c30) | ✅ `222485e6` | +46/−27 vs baseline | licenses/events + solmate import fix |
-| eulerSwapV1Periphery | [`0x31F34124…`](https://snowtrace.io/address/0x31F34124a37f94efd17201A1B88d5008cD444c72) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV2Factory | [`0xd80e68B3…`](https://snowtrace.io/address/0xd80e68B39e4408cb7D6c8E3343Bde46587013F62) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0x2836825d…`](https://snowtrace.io/address/0x2836825daeC3D5d8fD3ad71d61f72345bB868110) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0x4fef2f71…`](https://snowtrace.io/address/0x4fef2f7146c0b4e6C0b1433badC6B7a2E1E7ECDb) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0x1C0e8b84…`](https://snowtrace.io/address/0x1C0e8b841DA677C685D2a8376773e8A872C1ce5C) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0xF9f2dF8A…`](https://snowtrace.io/address/0xF9f2dF8A5Cc71a0424dfA9EbdfdfF8A082C19184) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV1Factory | [`0x8A1D3a48…`](https://snowtrace.io/address/0x8A1D3a4850ed7deeC9003680Cf41b8E75D27e440) | [`euler-swap@c7da2f33`](https://github.com/euler-xyz/euler-swap/tree/c7da2f330dff3efb98b0b4e998f9b9f498b37c30) | ✅ `f1652049` | +44/−25 vs baseline | licenses/events + solmate import fix |
+| eulerSwapV1Implementation | [`0x4F4FDeE3…`](https://snowtrace.io/address/0x4F4FDeE3568aC31C46634fb2Df3FF44A156Be351) | [`euler-swap@c7da2f33`](https://github.com/euler-xyz/euler-swap/tree/c7da2f330dff3efb98b0b4e998f9b9f498b37c30) | ✅ `222485e6` | +40/−21 vs baseline | licenses/events + solmate import fix |
+| eulerSwapV1Periphery | [`0x31F34124…`](https://snowtrace.io/address/0x31F34124a37f94efd17201A1B88d5008cD444c72) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +3/−3 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV2Factory | [`0xd80e68B3…`](https://snowtrace.io/address/0xd80e68B39e4408cb7D6c8E3343Bde46587013F62) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0x2836825d…`](https://snowtrace.io/address/0x2836825daeC3D5d8fD3ad71d61f72345bB868110) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0x4fef2f71…`](https://snowtrace.io/address/0x4fef2f7146c0b4e6C0b1433badC6B7a2E1E7ECDb) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0x1C0e8b84…`](https://snowtrace.io/address/0x1C0e8b841DA677C685D2a8376773e8A872C1ce5C) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0xF9f2dF8A…`](https://snowtrace.io/address/0xF9f2dF8A5Cc71a0424dfA9EbdfdfF8A082C19184) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -728,7 +728,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) (evc):
-Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers — proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).
+Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions — the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -757,119 +757,6 @@ index 95009da..e6bc820 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -878,7 +765,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultImplementation + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -920,28 +807,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -1287,4 +1152,4 @@ index 23a3c2fd..ec881e76 100644
if (deadline < block.timestamp) revert SwapVerifier_pastDeadline();
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/56.md b/verify/56.md
index 1f54aba..917141a 100644
--- a/verify/56.md
+++ b/verify/56.md
@@ -4,11 +4,7 @@ Chain ID: 56 · Bytecode-proven: **21/21**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,34 +13,38 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0x2D13C46F…`](https://bscscan.com/address/0x2D13C46FE6c8B6c9ad3C5A78eD51b26733caE350) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `47294620` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0x2117E8b7…`](https://bscscan.com/address/0x2117E8b79e8E176A670c9fCf945d4348556bfFad) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `0b021e3f` | ≡ baseline | — |
| eulOFTAdapter | [`0x16332693…`](https://bscscan.com/address/0x1633269308F154fbECBb15F91d72D2aFA6af95B4) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `1036d1c0` | ≡ baseline | — |
-| eVaultFactory | [`0x7F53E275…`](https://bscscan.com/address/0x7F53E2755eB3c43824E162F7F6F087832B9C9Df6) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0xB236413f…`](https://bscscan.com/address/0xB236413f1A8Fd4C5D5545ecAaC5e64fF686afe4e) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0xb2E5a73C…`](https://bscscan.com/address/0xb2E5a73CeE08593d1a076a2AE7A6e02925a640ea) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +58/−11 vs baseline | EVCUtil helper + signer-exclusion hardening |
+| eVaultFactory | [`0x7F53E275…`](https://bscscan.com/address/0x7F53E2755eB3c43824E162F7F6F087832B9C9Df6) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0xB236413f…`](https://bscscan.com/address/0xB236413f1A8Fd4C5D5545ecAaC5e64fF686afe4e) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0xb2E5a73C…`](https://bscscan.com/address/0xb2E5a73CeE08593d1a076a2AE7A6e02925a640ea) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +4/−1 vs baseline | signer-exclusion hardening |
| oracleRouterFactory | [`0xbe83f65e…`](https://bscscan.com/address/0xbe83f65e5e898D482FfAEA251B62647c411576F1) | [`evk-periphery@96b83f80`](https://github.com/euler-xyz/evk-periphery/tree/96b83f80ded9ac3f28bfce871b55917e360b9159) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0xF524F75a…`](https://bscscan.com/address/0xF524F75ad063919B86d6c5D9242847A44337BFCe) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0x5e13d419…`](https://bscscan.com/address/0x5e13d41913aDF18bb2acAe34228E8D21f3c2f2Eb) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0x7fD287B3…`](https://bscscan.com/address/0x7fD287B3AE3Bf2F6C9871a44b6d9de208B0ABBE5) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0x7fD287B3…`](https://bscscan.com/address/0x7fD287B3AE3Bf2F6C9871a44b6d9de208B0ABBE5) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0x2d09e4C7…`](https://bscscan.com/address/0x2d09e4C7Ad9c21Cf093046Da69030Dc17d01deFC) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `2fc2cdd1` | +3/−5 vs baseline | formatting only |
## Euler Earn
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerEarnFactory | [`0xc456d04E…`](https://bscscan.com/address/0xc456d04E3F43597CC7E5a2AF284fF4C4AdDA0cb1) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +18/−18 vs baseline | import-path style only |
-| eulerEarnPublicAllocator | [`0xD5614794…`](https://bscscan.com/address/0xD561479477b03720bF485e91B76574374A646531) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnFactory | [`0xc456d04E…`](https://bscscan.com/address/0xc456d04E3F43597CC7E5a2AF284fF4C4AdDA0cb1) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +16/−16 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0xD5614794…`](https://bscscan.com/address/0xD561479477b03720bF485e91B76574374A646531) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV1Factory | [`0x3e378e5E…`](https://bscscan.com/address/0x3e378e5E339DF5e0Da32964F9EEC2CDb90D28Cc7) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Implementation | [`0x16BCa432…`](https://bscscan.com/address/0x16BCa43290b77409e6D1c92B929f7A09C0E4EE86) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Periphery | [`0xa8826Bb2…`](https://bscscan.com/address/0xa8826Bb29f875Db4c4b482463961776390774525) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV2Factory | [`0xA1F83E3d…`](https://bscscan.com/address/0xA1F83E3d1819C912122A1582B4B6D3d2a1E83bb7) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0x90Cb0b67…`](https://bscscan.com/address/0x90Cb0b67f189a3D914DA00f72070531152DBc85F) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0x4258A349…`](https://bscscan.com/address/0x4258A34923CccFa29948881Cf6Aa8FdAD6338485) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0x71dFB713…`](https://bscscan.com/address/0x71dFB7138192B19CDc73487212bf6BB1Ffe3b9A1) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0xBc0f4dd9…`](https://bscscan.com/address/0xBc0f4dd9B5A10b15e6fA65e939Dbb1f98E7B08B7) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV1Factory | [`0x3e378e5E…`](https://bscscan.com/address/0x3e378e5E339DF5e0Da32964F9EEC2CDb90D28Cc7) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +43/−24 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Implementation | [`0x16BCa432…`](https://bscscan.com/address/0x16BCa43290b77409e6D1c92B929f7A09C0E4EE86) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +40/−21 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Periphery | [`0xa8826Bb2…`](https://bscscan.com/address/0xa8826Bb29f875Db4c4b482463961776390774525) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +3/−3 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV2Factory | [`0xA1F83E3d…`](https://bscscan.com/address/0xA1F83E3d1819C912122A1582B4B6D3d2a1E83bb7) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0x90Cb0b67…`](https://bscscan.com/address/0x90Cb0b67f189a3D914DA00f72070531152DBc85F) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0x4258A349…`](https://bscscan.com/address/0x4258A34923CccFa29948881Cf6Aa8FdAD6338485) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0x71dFB713…`](https://bscscan.com/address/0x71dFB7138192B19CDc73487212bf6BB1Ffe3b9A1) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0xBc0f4dd9…`](https://bscscan.com/address/0xBc0f4dd9B5A10b15e6fA65e939Dbb1f98E7B08B7) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -498,7 +498,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) (evc):
-Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers — proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).
+Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions — the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -527,119 +527,6 @@ index 95009da..e6bc820 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -648,7 +535,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultImplementation + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -690,28 +577,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -1057,4 +922,4 @@ index 23a3c2fd..ec881e76 100644
if (deadline < block.timestamp) revert SwapVerifier_pastDeadline();
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/59144.md b/verify/59144.md
index 9312283..04bbbb3 100644
--- a/verify/59144.md
+++ b/verify/59144.md
@@ -4,11 +4,7 @@ Chain ID: 59144 · Bytecode-proven: **21/21**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,13 +13,13 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0xB9E491A3…`](https://lineascan.build/address/0xB9E491A3BB9d4B155d31a9cA6B9dE245CA16AAe6) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `8a4340d8` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0x3eBd0148…`](https://lineascan.build/address/0x3eBd0148BADAb9388936E4472C4415D5700478A5) | [`evk-periphery@21a169d7`](https://github.com/euler-xyz/evk-periphery/tree/21a169d7830f71fcfbee6f7ced12bf089f4fba20) | ✅ `d6078fb2` | +1/−1 vs baseline | mint() gains 'virtual' (no behavior change) |
| eulOFTAdapter | [`0xd048d4e3…`](https://lineascan.build/address/0xd048d4e39e13482ECcE115E7BB71128d26ca19f1) | [`evk-periphery@21a169d7`](https://github.com/euler-xyz/evk-periphery/tree/21a169d7830f71fcfbee6f7ced12bf089f4fba20) | ✅ `ee5f5661` | ≡ baseline | — |
-| eVaultFactory | [`0x84711986…`](https://lineascan.build/address/0x84711986Fd3BF0bFe4a8e6d7f4E22E67f7f27F04) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `57b01080` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0x58270C41…`](https://lineascan.build/address/0x58270C41552Bb2bef3Dc4e103b6f0c226032f007) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `86133ece` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0xd8CeCEe9…`](https://lineascan.build/address/0xd8CeCEe9A04eA3d941a959F68fb4486f23271d09) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `d1bce236` | +58/−11 vs baseline | EVCUtil helper + signer-exclusion hardening |
+| eVaultFactory | [`0x84711986…`](https://lineascan.build/address/0x84711986Fd3BF0bFe4a8e6d7f4E22E67f7f27F04) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `57b01080` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0x58270C41…`](https://lineascan.build/address/0x58270C41552Bb2bef3Dc4e103b6f0c226032f007) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `86133ece` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0xd8CeCEe9…`](https://lineascan.build/address/0xd8CeCEe9A04eA3d941a959F68fb4486f23271d09) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `d1bce236` | +4/−1 vs baseline | signer-exclusion hardening |
| oracleRouterFactory | [`0xf0125F63…`](https://lineascan.build/address/0xf0125F638c7134e6997e4F825b78c324CcF289aF) | [`evk-periphery@21a169d7`](https://github.com/euler-xyz/evk-periphery/tree/21a169d7830f71fcfbee6f7ced12bf089f4fba20) | ✅ `dd195cf0` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0x91868601…`](https://lineascan.build/address/0x91868601df03ED8E134EaAaB5E06F7183CC8383f) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `ae8cce18` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0xe15C5F31…`](https://lineascan.build/address/0xe15C5F31cd7B767883F5654CDD3aFac28966B0a9) | [`evk-periphery@21a169d7`](https://github.com/euler-xyz/evk-periphery/tree/21a169d7830f71fcfbee6f7ced12bf089f4fba20) | ✅ `2068798e` | ≡ baseline | — |
-| sequenceRegistry | [`0xcB1bB0A8…`](https://lineascan.build/address/0xcB1bB0A8A7ddeb09983dC1e7F880DCEdc39362BA) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `f8601f0f` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0xcB1bB0A8…`](https://lineascan.build/address/0xcB1bB0A8A7ddeb09983dC1e7F880DCEdc39362BA) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `f8601f0f` | ≡ baseline (unit) | — |
| swapVerifier | [`0xd356D057…`](https://lineascan.build/address/0xd356D0570F8Ae45Acf275A09789c67C9E412814e) | [`evk-periphery@e7337a33`](https://github.com/euler-xyz/evk-periphery/tree/e7337a33cb2339de7bf19d41a765c426cfe71be2) | ✅ `69658451` | +3/−5 vs baseline | formatting only |
## Euler Earn
@@ -31,20 +27,24 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
| eulerEarnFactory | [`0x377879A0…`](https://lineascan.build/address/0x377879A039343FEc7564e54616e519328951DA6D) | [`euler-earn@ba581a71`](https://github.com/euler-xyz/euler-earn/tree/ba581a71245ad004d35241918946b08ba63552cd) | ✅ `978dba08` | +5/−4 vs baseline | 24kB fit: setName/setSymbol commented out |
-| eulerEarnPublicAllocator | [`0x4148f90e…`](https://lineascan.build/address/0x4148f90e03facFF8D2d5EFb475E36F94b4Ab4994) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `055f4a97` | +18/−18 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0x4148f90e…`](https://lineascan.build/address/0x4148f90e03facFF8D2d5EFb475E36F94b4Ab4994) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `055f4a97` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV1Factory | [`0x970B065B…`](https://lineascan.build/address/0x970B065B572CC0118535Ad1101663CDBE7Db1e21) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `733771fc` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Implementation | [`0x2b07caff…`](https://lineascan.build/address/0x2b07caff83C15c5a70C4C0867DFE7A0BE01025B0) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `85a32379` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Periphery | [`0x0de305aB…`](https://lineascan.build/address/0x0de305aB93902914909951A00079ea1df3FD98eA) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `9b00707e` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV2Factory | [`0xB0cc1D8e…`](https://lineascan.build/address/0xB0cc1D8e6fAc157c76d2c08B7D55Eca1573BcBDF) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `0a646505` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0x476A2ad4…`](https://lineascan.build/address/0x476A2ad4a7c5Ac4DF1CaA429Cb70db865A160c11) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `06ec2a31` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0x57729d78…`](https://lineascan.build/address/0x57729d78650cA751C9dB41f2536cA86da0032351) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `69ef138e` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0xe3ac3685…`](https://lineascan.build/address/0xe3ac3685D607308D4b4e26546EaDf675c37dd3dE) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `e85194c7` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0xEA3050E8…`](https://lineascan.build/address/0xEA3050E8A25f56AD0dbc90C3dCf016d8f5EfFE25) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `507db702` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV1Factory | [`0x970B065B…`](https://lineascan.build/address/0x970B065B572CC0118535Ad1101663CDBE7Db1e21) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `733771fc` | +43/−24 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Implementation | [`0x2b07caff…`](https://lineascan.build/address/0x2b07caff83C15c5a70C4C0867DFE7A0BE01025B0) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `85a32379` | +40/−21 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Periphery | [`0x0de305aB…`](https://lineascan.build/address/0x0de305aB93902914909951A00079ea1df3FD98eA) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `9b00707e` | +3/−3 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV2Factory | [`0xB0cc1D8e…`](https://lineascan.build/address/0xB0cc1D8e6fAc157c76d2c08B7D55Eca1573BcBDF) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `0a646505` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0x476A2ad4…`](https://lineascan.build/address/0x476A2ad4a7c5Ac4DF1CaA429Cb70db865A160c11) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `06ec2a31` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0x57729d78…`](https://lineascan.build/address/0x57729d78650cA751C9dB41f2536cA86da0032351) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `69ef138e` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0xe3ac3685…`](https://lineascan.build/address/0xe3ac3685D607308D4b4e26546EaDf675c37dd3dE) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `e85194c7` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0xEA3050E8…`](https://lineascan.build/address/0xEA3050E8A25f56AD0dbc90C3dCf016d8f5EfFE25) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `507db702` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -554,7 +554,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) (evc):
-Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers — proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).
+Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions — the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -583,119 +583,6 @@ index 95009da..e6bc820 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -704,7 +591,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultImplementation + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -746,28 +633,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -1113,4 +978,4 @@ index 23a3c2fd..ec881e76 100644
if (deadline < block.timestamp) revert SwapVerifier_pastDeadline();
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/60808.md b/verify/60808.md
index 7334c37..4b67a7f 100644
--- a/verify/60808.md
+++ b/verify/60808.md
@@ -4,11 +4,7 @@ Chain ID: 60808 · Bytecode-proven: **21/21**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,13 +13,13 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0x5a3828be…`](https://explorer.gobob.xyz/address/0x5a3828beA292E5f29725Fa449F9113Cb5E60ADF8) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `47294620` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0xDe1763aF…`](https://explorer.gobob.xyz/address/0xDe1763aFA5eB658CfFFfD16835AfeB47e7aC0B8D) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `0b021e3f` | ≡ baseline | — |
| eulOFTAdapter | [`0x797964F9…`](https://explorer.gobob.xyz/address/0x797964F9eB3A733D443810820f56c9ebAab1d1c2) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `1036d1c0` | ≡ baseline | — |
-| eVaultFactory | [`0x046a9837…`](https://explorer.gobob.xyz/address/0x046a9837A61d6b6263f54F4E27EE072bA4bdC7e4) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0x32CFc569…`](https://explorer.gobob.xyz/address/0x32CFc56917C0025501b34C43f7FE767Ef1EDE3a2) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0x59f0FeEc…`](https://explorer.gobob.xyz/address/0x59f0FeEc4fA474Ad4ffC357cC8d8595B68abE47d) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +58/−11 vs baseline | EVCUtil helper + signer-exclusion hardening |
+| eVaultFactory | [`0x046a9837…`](https://explorer.gobob.xyz/address/0x046a9837A61d6b6263f54F4E27EE072bA4bdC7e4) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0x32CFc569…`](https://explorer.gobob.xyz/address/0x32CFc56917C0025501b34C43f7FE767Ef1EDE3a2) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0x59f0FeEc…`](https://explorer.gobob.xyz/address/0x59f0FeEc4fA474Ad4ffC357cC8d8595B68abE47d) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +4/−1 vs baseline | signer-exclusion hardening |
| oracleRouterFactory | [`0xEFCF1F2f…`](https://explorer.gobob.xyz/address/0xEFCF1F2f09163e3813f5C16346A9F2Aa21ABA74d) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0x94047C7d…`](https://explorer.gobob.xyz/address/0x94047C7daF06a6DE4049365cFa95fb4389a6F9Fe) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0x9f395F61…`](https://explorer.gobob.xyz/address/0x9f395F610Af9ffC98693A0769190446180dc7192) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0xf4C09771…`](https://explorer.gobob.xyz/address/0xf4C097718c64B6B0A75Cd9e0EF348fD6F176bE67) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0xf4C09771…`](https://explorer.gobob.xyz/address/0xf4C097718c64B6B0A75Cd9e0EF348fD6F176bE67) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0x585DAE97…`](https://explorer.gobob.xyz/address/0x585DAE976333DF77ec096c3BcEf1EBEC296476a4) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `2fc2cdd1` | +3/−5 vs baseline | formatting only |
## Euler Earn
@@ -31,20 +27,24 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
| eulerEarnFactory | [`0x8F01c664…`](https://explorer.gobob.xyz/address/0x8F01c6640A1c0a6085C79843F861fF0F89b9fED6) | [`euler-earn@773453b1`](https://github.com/euler-xyz/euler-earn/tree/773453b1f4a6f1d27a1cd0c6d8f6ada572503b23) | ✅ `c9ee150e` | ≡ baseline | — |
-| eulerEarnPublicAllocator | [`0xB5Daee4a…`](https://explorer.gobob.xyz/address/0xB5Daee4a8AD1388B3D72C1367b8BA63DfB4AAbf5) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0xB5Daee4a…`](https://explorer.gobob.xyz/address/0xB5Daee4a8AD1388B3D72C1367b8BA63DfB4AAbf5) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV1Factory | [`0xE25B3cdA…`](https://explorer.gobob.xyz/address/0xE25B3cdA6fccAcbD794aEA64eE1B496d7b441644) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Implementation | [`0x334eac29…`](https://explorer.gobob.xyz/address/0x334eac29ffAc27E6BC3484A738DAf520359698F0) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Periphery | [`0x199cC7C8…`](https://explorer.gobob.xyz/address/0x199cC7C8606088bc22D82CDae2D7EE7F5F99ec9F) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV2Factory | [`0xa077991e…`](https://explorer.gobob.xyz/address/0xa077991e2929d97f29fE39372E736FC118a4FAd3) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0x90bd38E8…`](https://explorer.gobob.xyz/address/0x90bd38E89726BdCf42E07D88B23c2A493cb3877a) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0xaEAab95e…`](https://explorer.gobob.xyz/address/0xaEAab95eE90196E20fD2a5348643cCa0EF2b038e) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0x6e5dF960…`](https://explorer.gobob.xyz/address/0x6e5dF960eccD2Bf8818526A88f6E7da99a5379d7) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0xf33F4e20…`](https://explorer.gobob.xyz/address/0xf33F4e20905801D55531b38749727954D0152d3D) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV1Factory | [`0xE25B3cdA…`](https://explorer.gobob.xyz/address/0xE25B3cdA6fccAcbD794aEA64eE1B496d7b441644) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +43/−24 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Implementation | [`0x334eac29…`](https://explorer.gobob.xyz/address/0x334eac29ffAc27E6BC3484A738DAf520359698F0) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +40/−21 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Periphery | [`0x199cC7C8…`](https://explorer.gobob.xyz/address/0x199cC7C8606088bc22D82CDae2D7EE7F5F99ec9F) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +3/−3 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV2Factory | [`0xa077991e…`](https://explorer.gobob.xyz/address/0xa077991e2929d97f29fE39372E736FC118a4FAd3) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0x90bd38E8…`](https://explorer.gobob.xyz/address/0x90bd38E89726BdCf42E07D88B23c2A493cb3877a) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0xaEAab95e…`](https://explorer.gobob.xyz/address/0xaEAab95eE90196E20fD2a5348643cCa0EF2b038e) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0x6e5dF960…`](https://explorer.gobob.xyz/address/0x6e5dF960eccD2Bf8818526A88f6E7da99a5379d7) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0xf33F4e20…`](https://explorer.gobob.xyz/address/0xf33F4e20905801D55531b38749727954D0152d3D) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -508,7 +508,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) (evc):
-Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers — proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).
+Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions — the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -537,119 +537,6 @@ index 95009da..e6bc820 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -658,7 +545,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultImplementation + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -700,28 +587,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -1067,4 +932,4 @@ index 23a3c2fd..ec881e76 100644
if (deadline < block.timestamp) revert SwapVerifier_pastDeadline();
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/80094.md b/verify/80094.md
index 2c60abc..cac7a43 100644
--- a/verify/80094.md
+++ b/verify/80094.md
@@ -4,11 +4,7 @@ Chain ID: 80094 · Bytecode-proven: **21/21**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,13 +13,13 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0x70Fb24bD…`](https://berascan.com/address/0x70Fb24bDa46E7cFD447C64bB32180Bc746ba3A71) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `47294620` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0xEb9b5f4E…`](https://berascan.com/address/0xEb9b5f4EB023aE754fF59A04c9C038D58606DAC6) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `0b021e3f` | ≡ baseline | — |
| eulOFTAdapter | [`0xc1d31b28…`](https://berascan.com/address/0xc1d31b2812Cc920341349a717d14bAdFb1BCab11) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `1036d1c0` | ≡ baseline | — |
-| eVaultFactory | [`0x5C13fb43…`](https://berascan.com/address/0x5C13fb43ae9BAe8470f646ea647784534E9543AF) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0x402598Ac…`](https://berascan.com/address/0x402598Ac4034D24f2cB37BDb0721A67365aD19BD) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0x45334608…`](https://berascan.com/address/0x45334608ECE7B2775136bC847EB92B5D332806A9) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +58/−11 vs baseline | EVCUtil helper + signer-exclusion hardening |
+| eVaultFactory | [`0x5C13fb43…`](https://berascan.com/address/0x5C13fb43ae9BAe8470f646ea647784534E9543AF) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0x402598Ac…`](https://berascan.com/address/0x402598Ac4034D24f2cB37BDb0721A67365aD19BD) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0x45334608…`](https://berascan.com/address/0x45334608ECE7B2775136bC847EB92B5D332806A9) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +4/−1 vs baseline | signer-exclusion hardening |
| oracleRouterFactory | [`0x809aB347…`](https://berascan.com/address/0x809aB347e6ECb46714917A7796E542c86f75FbF1) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0x51432af6…`](https://berascan.com/address/0x51432af61A715DB3D0f20A3691C1E25F9A2c6B05) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0x56C44d2F…`](https://berascan.com/address/0x56C44d2F484A61ce92Fa0BCc849feB37aBfeB59C) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0x0c9a75E0…`](https://berascan.com/address/0x0c9a75E05764775A0cF52bC6cbfE6Cb229bb3901) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0x0c9a75E0…`](https://berascan.com/address/0x0c9a75E05764775A0cF52bC6cbfE6Cb229bb3901) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0x562ADb2d…`](https://berascan.com/address/0x562ADb2d72C1836621B2E82bCb7599DFE9578203) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `2fc2cdd1` | +3/−5 vs baseline | formatting only |
## Euler Earn
@@ -31,20 +27,24 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
| eulerEarnFactory | [`0x9cbc3030…`](https://berascan.com/address/0x9cbc3030e6d133D1AAa148D598FD82D70263495c) | [`euler-earn@773453b1`](https://github.com/euler-xyz/euler-earn/tree/773453b1f4a6f1d27a1cd0c6d8f6ada572503b23) | ✅ `c9ee150e` | ≡ baseline | — |
-| eulerEarnPublicAllocator | [`0x4E7C0590…`](https://berascan.com/address/0x4E7C059099496D56e8662570426991EA63C63C85) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0x4E7C0590…`](https://berascan.com/address/0x4E7C059099496D56e8662570426991EA63C63C85) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV1Factory | [`0xD14c95dc…`](https://berascan.com/address/0xD14c95dc228E8851F63d9b83A0001F4D021B5DFf) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Implementation | [`0x0e05d236…`](https://berascan.com/address/0x0e05d236cb6c350935751A73e834A13111998e3c) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Periphery | [`0x46F95127…`](https://berascan.com/address/0x46F951278f52f4798542C51BfB8Df1c165199150) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV2Factory | [`0x1A4546b9…`](https://berascan.com/address/0x1A4546b988Ee133F72b7E27a4890355b0a341554) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0x9253a3EF…`](https://berascan.com/address/0x9253a3EF2cE8875b7D15Bd2bcd3a405b62a7b0E7) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0x5e044DB2…`](https://berascan.com/address/0x5e044DB2Fd14fbB48334b239CfD8530C9b03150B) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0xAe26ca82…`](https://berascan.com/address/0xAe26ca82da91a1157E3cC0B36a9A06f539f4DF24) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0x8D8B81F0…`](https://berascan.com/address/0x8D8B81F0c1be01fa3636d2cD6DeF07474d75e1e9) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV1Factory | [`0xD14c95dc…`](https://berascan.com/address/0xD14c95dc228E8851F63d9b83A0001F4D021B5DFf) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +43/−24 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Implementation | [`0x0e05d236…`](https://berascan.com/address/0x0e05d236cb6c350935751A73e834A13111998e3c) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +40/−21 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Periphery | [`0x46F95127…`](https://berascan.com/address/0x46F951278f52f4798542C51BfB8Df1c165199150) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +3/−3 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV2Factory | [`0x1A4546b9…`](https://berascan.com/address/0x1A4546b988Ee133F72b7E27a4890355b0a341554) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0x9253a3EF…`](https://berascan.com/address/0x9253a3EF2cE8875b7D15Bd2bcd3a405b62a7b0E7) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0x5e044DB2…`](https://berascan.com/address/0x5e044DB2Fd14fbB48334b239CfD8530C9b03150B) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0xAe26ca82…`](https://berascan.com/address/0xAe26ca82da91a1157E3cC0B36a9A06f539f4DF24) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0x8D8B81F0…`](https://berascan.com/address/0x8D8B81F0c1be01fa3636d2cD6DeF07474d75e1e9) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -508,7 +508,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) (evc):
-Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers — proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).
+Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions — the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -537,119 +537,6 @@ index 95009da..e6bc820 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -658,7 +545,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultImplementation + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -700,28 +587,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -1067,4 +932,4 @@ index 23a3c2fd..ec881e76 100644
if (deadline < block.timestamp) revert SwapVerifier_pastDeadline();
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/8453.md b/verify/8453.md
index 2b7dbe6..269626c 100644
--- a/verify/8453.md
+++ b/verify/8453.md
@@ -4,11 +4,7 @@ Chain ID: 8453 · Bytecode-proven: **21/21**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,34 +13,38 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0x029fDEe8…`](https://basescan.org/address/0x029fDEe85BEdB0553D6fdc538546586641DD7438) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `48762e01` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0xa153Ad73…`](https://basescan.org/address/0xa153Ad732F831a79b5575Fa02e793EC4E99181b0) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `0b021e3f` | ≡ baseline | — |
| eulOFTAdapter | [`0x9ff7ea0C…`](https://basescan.org/address/0x9ff7ea0Cf94b8665c2F5d17560Bd34Ab9BbAcd21) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `1036d1c0` | ≡ baseline | — |
-| eVaultFactory | [`0x7F321498…`](https://basescan.org/address/0x7F321498A801A191a93C840750ed637149dDf8D0) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0x30a9A965…`](https://basescan.org/address/0x30a9A9654804F1e5b3291a86E83EdeD7cF281618) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `8c001272` | +1/−1 vs baseline | one fee-share default parameter |
-| evc | [`0x5301c7dD…`](https://basescan.org/address/0x5301c7dD20bD945D2013b48ed0DEE3A284ca8989) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +58/−11 vs baseline | EVCUtil helper + signer-exclusion hardening |
+| eVaultFactory | [`0x7F321498…`](https://basescan.org/address/0x7F321498A801A191a93C840750ed637149dDf8D0) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0x30a9A965…`](https://basescan.org/address/0x30a9A9654804F1e5b3291a86E83EdeD7cF281618) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `8c001272` | ≡ baseline (unit) | — |
+| evc | [`0x5301c7dD…`](https://basescan.org/address/0x5301c7dD20bD945D2013b48ed0DEE3A284ca8989) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +4/−1 vs baseline | signer-exclusion hardening |
| oracleRouterFactory | [`0xA9287853…`](https://basescan.org/address/0xA9287853987B107969f181Cce5e25e0D09c1c116) | [`evk-periphery@96b83f80`](https://github.com/euler-xyz/evk-periphery/tree/96b83f80ded9ac3f28bfce871b55917e360b9159) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0x1D4b9e6A…`](https://basescan.org/address/0x1D4b9e6ACACdc82Dd9E903C3F4431558Af32C4A9) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0xE08e1f00…`](https://basescan.org/address/0xE08e1f00D388E201e48842E53fA96195568e6813) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0xfE9011FD…`](https://basescan.org/address/0xfE9011FD097cd35866b9e4740BBC88B4ef26E3ba) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0xfE9011FD…`](https://basescan.org/address/0xfE9011FD097cd35866b9e4740BBC88B4ef26E3ba) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0x93A732A1…`](https://basescan.org/address/0x93A732A1900697d5f51C77fe09275486BB0bb83D) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `2fc2cdd1` | +3/−5 vs baseline | formatting only |
## Euler Earn
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerEarnFactory | [`0x75F49a26…`](https://basescan.org/address/0x75F49a2621b6DeC6a5baB22ce961bF3e676EFAE6) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +18/−18 vs baseline | import-path style only |
-| eulerEarnPublicAllocator | [`0x0dFFc3A5…`](https://basescan.org/address/0x0dFFc3A53693bCd8e42FAd9be94fB8f1Fb64A8EE) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnFactory | [`0x75F49a26…`](https://basescan.org/address/0x75F49a2621b6DeC6a5baB22ce961bF3e676EFAE6) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +16/−16 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0x0dFFc3A5…`](https://basescan.org/address/0x0dFFc3A53693bCd8e42FAd9be94fB8f1Fb64A8EE) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV1Factory | [`0xf0CFe22d…`](https://basescan.org/address/0xf0CFe22d23699ff1B2CFe6B8f706A6DB63911262) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Implementation | [`0x3Ce63C16…`](https://basescan.org/address/0x3Ce63C16CB719a0c755DA25cd5dD35170A00424f) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Periphery | [`0x18e5F5C1…`](https://basescan.org/address/0x18e5F5C1ff5e905b32CE860576031AE90E1d1336) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV2Factory | [`0x6C5f4c23…`](https://basescan.org/address/0x6C5f4c239ceD289447737EAB8eEA64523bd9c05E) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0x6F1C1a3e…`](https://basescan.org/address/0x6F1C1a3eAFbB1b345AD5662b0374a9Bf0E4785af) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0xA564dAe6…`](https://basescan.org/address/0xA564dAe65eA7B1ce049AbACFC4Cb1A32C93e127c) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0x78bCCFA3…`](https://basescan.org/address/0x78bCCFA312432cE84d0B818796eE33f9192A284d) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0x35D410A5…`](https://basescan.org/address/0x35D410A5052c7362eCdD72cFb65651A71adFaf61) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV1Factory | [`0xf0CFe22d…`](https://basescan.org/address/0xf0CFe22d23699ff1B2CFe6B8f706A6DB63911262) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +43/−24 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Implementation | [`0x3Ce63C16…`](https://basescan.org/address/0x3Ce63C16CB719a0c755DA25cd5dD35170A00424f) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +40/−21 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Periphery | [`0x18e5F5C1…`](https://basescan.org/address/0x18e5F5C1ff5e905b32CE860576031AE90E1d1336) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +3/−3 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV2Factory | [`0x6C5f4c23…`](https://basescan.org/address/0x6C5f4c239ceD289447737EAB8eEA64523bd9c05E) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0x6F1C1a3e…`](https://basescan.org/address/0x6F1C1a3eAFbB1b345AD5662b0374a9Bf0E4785af) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0xA564dAe6…`](https://basescan.org/address/0xA564dAe65eA7B1ce049AbACFC4Cb1A32C93e127c) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0x78bCCFA3…`](https://basescan.org/address/0x78bCCFA312432cE84d0B818796eE33f9192A284d) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0x35D410A5…`](https://basescan.org/address/0x35D410A5052c7362eCdD72cFb65651A71adFaf61) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -498,7 +498,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) (evc):
-Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers — proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).
+Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions — the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -527,119 +527,6 @@ index 95009da..e6bc820 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -985,4 +872,4 @@ index 23a3c2fd..ec881e76 100644
if (deadline < block.timestamp) revert SwapVerifier_pastDeadline();
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/9745.md b/verify/9745.md
index 53db3d2..f2eb925 100644
--- a/verify/9745.md
+++ b/verify/9745.md
@@ -4,11 +4,7 @@ Chain ID: 9745 · Bytecode-proven: **21/21**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,34 +13,38 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0x6e6e1e4F…`](https://plasmascan.to/address/0x6e6e1e4FB3Ee6C074f10d3f80E0d3541accf7c2b) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `47294620` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0xca632FA5…`](https://plasmascan.to/address/0xca632FA58397391C750c13F935DAA61AbBe0BaA6) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `0b021e3f` | ≡ baseline | — |
| eulOFTAdapter | [`0x78F50C52…`](https://plasmascan.to/address/0x78F50C520E7fCE30410516B72A48bD4fc5d974b5) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `1036d1c0` | ≡ baseline | — |
-| eVaultFactory | [`0x42388213…`](https://plasmascan.to/address/0x42388213C6F56D7E1477632b58Ae6Bba9adeEeA3) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0x8346BeBa…`](https://plasmascan.to/address/0x8346BeBaA0789Eb92CFfCC07033b8bF9f3eFdcAB) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0x7bdbd0A7…`](https://plasmascan.to/address/0x7bdbd0A7114aA42CA957F292145F6a931a345583) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +58/−11 vs baseline | EVCUtil helper + signer-exclusion hardening |
+| eVaultFactory | [`0x42388213…`](https://plasmascan.to/address/0x42388213C6F56D7E1477632b58Ae6Bba9adeEeA3) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0x8346BeBa…`](https://plasmascan.to/address/0x8346BeBaA0789Eb92CFfCC07033b8bF9f3eFdcAB) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0x7bdbd0A7…`](https://plasmascan.to/address/0x7bdbd0A7114aA42CA957F292145F6a931a345583) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +4/−1 vs baseline | signer-exclusion hardening |
| oracleRouterFactory | [`0x7e539159…`](https://plasmascan.to/address/0x7e539159a06CFe0A9f855d22dD82aD95eDf8C2F1) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0x593Ab8A0…`](https://plasmascan.to/address/0x593Ab8A0182f752c6f1af52CA2A0E8B9F868f64A) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0xe2011F2b…`](https://plasmascan.to/address/0xe2011F2bF6556863c3bacE991Efc8DaC26CD84c2) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0x3cf6e4c1…`](https://plasmascan.to/address/0x3cf6e4c11333b30f0D0CEAe6B78f53a660df357c) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0x3cf6e4c1…`](https://plasmascan.to/address/0x3cf6e4c11333b30f0D0CEAe6B78f53a660df357c) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0x84Fd34E9…`](https://plasmascan.to/address/0x84Fd34E9dd12f8D6Cb884f93277d146BDbDF35B5) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `2fc2cdd1` | +3/−5 vs baseline | formatting only |
## Euler Earn
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerEarnFactory | [`0xA3843A73…`](https://plasmascan.to/address/0xA3843A73e6a9F81309B931237Ca4759B3B02ff0E) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +18/−18 vs baseline | import-path style only |
-| eulerEarnPublicAllocator | [`0x667aD135…`](https://plasmascan.to/address/0x667aD135188d95a32A4E743Aebe5a5b503cb9038) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnFactory | [`0xA3843A73…`](https://plasmascan.to/address/0xA3843A73e6a9F81309B931237Ca4759B3B02ff0E) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +16/−16 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0x667aD135…`](https://plasmascan.to/address/0x667aD135188d95a32A4E743Aebe5a5b503cb9038) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV1Factory | [`0xD7aA0310…`](https://plasmascan.to/address/0xD7aA03104c2CCaC58acB00CbE90865FA64BbE77D) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Implementation | [`0x7F6ff62e…`](https://plasmascan.to/address/0x7F6ff62e7ECED715a2f4E5Ebe14eC9d32a44EFDc) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV1Periphery | [`0x1472ebB0…`](https://plasmascan.to/address/0x1472ebB000190275B5e28733e45a2614F1C3F41C) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +45/−26 vs baseline | SPDX licenses + event hoisting |
-| eulerSwapV2Factory | [`0x29FAFDbf…`](https://plasmascan.to/address/0x29FAFDbf952e7b5c0A6Cd26957829334d54E872A) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0xdAdBb7a0…`](https://plasmascan.to/address/0xdAdBb7a06638e3345A341002e956324A46d1c28c) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0x741Fc7A9…`](https://plasmascan.to/address/0x741Fc7A904c9F810cbc4a21DE7D07B51B5Da853C) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0x8ec298B4…`](https://plasmascan.to/address/0x8ec298B473D17e04F819453C72747c3d4d6B7848) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0x8D6A81Ec…`](https://plasmascan.to/address/0x8D6A81Ec8f5680849dCFBa47c710Dd9DA02aDaea) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV1Factory | [`0xD7aA0310…`](https://plasmascan.to/address/0xD7aA03104c2CCaC58acB00CbE90865FA64BbE77D) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `7c9a247e` | +43/−24 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Implementation | [`0x7F6ff62e…`](https://plasmascan.to/address/0x7F6ff62e7ECED715a2f4E5Ebe14eC9d32a44EFDc) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `20cae9a4` | +40/−21 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV1Periphery | [`0x1472ebB0…`](https://plasmascan.to/address/0x1472ebB000190275B5e28733e45a2614F1C3F41C) | [`euler-swap@b948f405`](https://github.com/euler-xyz/euler-swap/tree/b948f4052d7ab3116235ec754368b7125dbd5082) | ✅ `703cfc72` | +3/−3 vs baseline | SPDX licenses + event hoisting |
+| eulerSwapV2Factory | [`0x29FAFDbf…`](https://plasmascan.to/address/0x29FAFDbf952e7b5c0A6Cd26957829334d54E872A) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0xdAdBb7a0…`](https://plasmascan.to/address/0xdAdBb7a06638e3345A341002e956324A46d1c28c) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0x741Fc7A9…`](https://plasmascan.to/address/0x741Fc7A904c9F810cbc4a21DE7D07B51B5Da853C) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0x8ec298B4…`](https://plasmascan.to/address/0x8ec298B473D17e04F819453C72747c3d4d6B7848) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0x8D6A81Ec…`](https://plasmascan.to/address/0x8D6A81Ec8f5680849dCFBa47c710Dd9DA02aDaea) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -498,7 +498,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) (evc):
-Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers — proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).
+Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions — the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -527,119 +527,6 @@ index 95009da..e6bc820 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -648,7 +535,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultImplementation + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -690,28 +577,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -1057,4 +922,4 @@ index 23a3c2fd..ec881e76 100644
if (deadline < block.timestamp) revert SwapVerifier_pastDeadline();
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/999.md b/verify/999.md
index 13e5392..6ac24f2 100644
--- a/verify/999.md
+++ b/verify/999.md
@@ -4,11 +4,7 @@ Chain ID: 999 · Bytecode-proven: **18/18**
Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), metadata stripped, immutables masked, embedded child-metadata digests zeroed. The block explorer is never in the trust path. Each proven pin is then diffed against its component's audited baseline — the fixes-included state of the component's most recent audit — so every deployed source delta beyond audited code is shown below as a real diff. Re-run: see the repository README.
-## ⚠️ Requires attention
-
-- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
- > **Assessment**
- > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+**All contracts on this chain are bytecode-proven against their pinned commits.**
## Core lending protocol
@@ -17,31 +13,35 @@ Verification = on-chain runtime bytecode ≡ compile(repo@commit, profile), meta
| balanceTracker | [`0x05d14f4e…`](https://hyperevmscan.io/address/0x05d14f4eDFA7Cbfb90711C2EC5505bcbd49b9cD2) | [`reward-streams@9eb7b8a7`](https://github.com/euler-xyz/reward-streams/tree/9eb7b8a7fa31c275d688063c4abd07165b50b89f) | ✅ `47294620` | +55/−13 vs baseline | claim return values + isRewardEnabled view |
| EUL | [`0x3A41f426…`](https://hyperevmscan.io/address/0x3A41f426E55ECdE4BC734fA79ccE991b94aFf711) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `0b021e3f` | ≡ baseline | — |
| eulOFTAdapter | [`0x976666e0…`](https://hyperevmscan.io/address/0x976666e0ae74A8A4059cF1acf706891aDE98C3d1) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `1036d1c0` | ≡ baseline | — |
-| eVaultFactory | [`0xcF555258…`](https://hyperevmscan.io/address/0xcF5552580fD364cdBBFcB5Ae345f75674c59273A) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | +1/−1 vs baseline | one fee-share default parameter |
-| eVaultImplementation | [`0x05de079A…`](https://hyperevmscan.io/address/0x05de079A28386135E048369cdf0Bc4D326d5EBDF) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +15/−8 vs baseline | setLTV patch (audited ×2) + param |
-| evc | [`0xceAA7cdC…`](https://hyperevmscan.io/address/0xceAA7cdCD7dDBee8601127a9Abb17A974d613db4) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +58/−11 vs baseline | EVCUtil helper + signer-exclusion hardening |
+| eVaultFactory | [`0xcF555258…`](https://hyperevmscan.io/address/0xcF5552580fD364cdBBFcB5Ae345f75674c59273A) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `3971bde2` | ≡ baseline (unit) | — |
+| eVaultImplementation | [`0x05de079A…`](https://hyperevmscan.io/address/0x05de079A28386135E048369cdf0Bc4D326d5EBDF) | [`euler-vault-kit@422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) | ✅ `8c001272` | +1/−7 vs baseline | setLTV patch (audited ×2) + param |
+| evc | [`0xceAA7cdC…`](https://hyperevmscan.io/address/0xceAA7cdCD7dDBee8601127a9Abb17A974d613db4) | [`ethereum-vault-connector@a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) | ✅ `b12f6d72` | +4/−1 vs baseline | signer-exclusion hardening |
| oracleRouterFactory | [`0x1CefA54e…`](https://hyperevmscan.io/address/0x1CefA54ebBCb6c9Aa7347196B03364aFe9A89f7e) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `d7881094` | +10/−1 vs baseline | EVC constructor pass-through |
| protocolConfig | [`0x43144f09…`](https://hyperevmscan.io/address/0x43144f09896F8759DE2ec6D777391B9F05A51128) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `844a4ed8` | +1/−1 vs baseline | one fee-share default parameter |
| rEUL | [`0x14DCA654…`](https://hyperevmscan.io/address/0x14DCA6543Ef03b932cBD801FBfd70e42a9b6122b) | [`evk-periphery@392c7bd0`](https://github.com/euler-xyz/evk-periphery/tree/392c7bd035c6fa1f50388fe4b3f3f3cd04df09d8) | ✅ `ea6d1628` | ≡ baseline | — |
-| sequenceRegistry | [`0x47618E4C…`](https://hyperevmscan.io/address/0x47618E4CBDcFBf5f21D6594A7e3a4f4683719994) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | +1/−1 vs baseline | one fee-share default parameter |
+| sequenceRegistry | [`0x47618E4C…`](https://hyperevmscan.io/address/0x47618E4CBDcFBf5f21D6594A7e3a4f4683719994) | [`euler-vault-kit@9e3c760e`](https://github.com/euler-xyz/euler-vault-kit/tree/9e3c760e051f5d769f7c6edb9be30198a55117d4) | ✅ `83359e00` | ≡ baseline (unit) | — |
| swapVerifier | [`0x11F6386A…`](https://hyperevmscan.io/address/0x11F6386A84b04E83Ecd647Cb1f492a66B7A3Be33) | [`evk-periphery@edaf96e3`](https://github.com/euler-xyz/evk-periphery/tree/edaf96e32ebe6cb96ae30add934d74fa1d092ff6) | ✅ `2fc2cdd1` | +3/−5 vs baseline | formatting only |
## Euler Earn
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerEarnFactory | [`0x587DD828…`](https://hyperevmscan.io/address/0x587DD8285c01526769aB4803e4F02433ddbBc00E) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +18/−18 vs baseline | import-path style only |
-| eulerEarnPublicAllocator | [`0xc00ae658…`](https://hyperevmscan.io/address/0xc00ae658ce425Bb668A5Ed96c8ECa9C988706939) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +18/−18 vs baseline | import-path style only |
+| eulerEarnFactory | [`0x587DD828…`](https://hyperevmscan.io/address/0x587DD8285c01526769aB4803e4F02433ddbBc00E) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `c9ee150e` | +16/−16 vs baseline | import-path style only |
+| eulerEarnPublicAllocator | [`0xc00ae658…`](https://hyperevmscan.io/address/0xc00ae658ce425Bb668A5Ed96c8ECa9C988706939) | [`euler-earn@b2fd6e69`](https://github.com/euler-xyz/euler-earn/tree/b2fd6e699ee20bcfe7459f375b3cee5d2fa53345) | ✅ `a6bee3db` | +7/−7 vs baseline | import-path style only |
## EulerSwap
+- **eulerSwapV2ProtocolFeeConfig** — post-audit functionality change ([diff below](#component-euler-swap-v2)):
+ > **Assessment**
+ > The deployed V2 release (tag eulerswap-2.0) post-dates the September 2025 Cantina review baseline. Within that delta, protocol-fee handling was redesigned: the reviewed model (fee parameters fixed into each pool at install, 10–25% bounds, permissionless enablement after one year) was replaced by the EulerSwapProtocolFeeConfig singleton, which pools query live on every swap. The fee-config admin can set a default fee and per-pool overrides taking effect immediately, up to MAX_PROTOCOL_FEE = 15% of the LP fee amount (lower than the previously reviewed 25% maximum); zero is allowed. Pre-release hardening is included: the admin and fee recipients may not be known EVC sub-accounts, and configuration events are emitted. Curve and quote math are unchanged by this mechanism. It post-dates the September 2025 review and is not yet listed in the audit registry.
+
| Contract | Address | Source | Bytecode | vs audited baseline | What changed |
|----------|---------|--------|----------|---------------------|--------------|
-| eulerSwapV2Factory | [`0xFbF2a49C…`](https://hyperevmscan.io/address/0xFbF2a49CB0cc50F4ccd4eAc826eF1A76D99D29Eb) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Implementation | [`0xC00F0B7d…`](https://hyperevmscan.io/address/0xC00F0B7d7B4F7cA3d3f79f3892069f41C142dB84) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Periphery | [`0x61aFC386…`](https://hyperevmscan.io/address/0x61aFC386b47a11F8721b67Eb1607cFBd9ccE48B1) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2ProtocolFeeConfig | [`0x434b1072…`](https://hyperevmscan.io/address/0x434b1072d96ea24967CDe289D3d4d81d2BAD4F30) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
-| eulerSwapV2Registry | [`0x7E1Efb6A…`](https://hyperevmscan.io/address/0x7E1Efb6A2009A1FDaDee1c5d6615260AD70c14Fb) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +444/−267 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Factory | [`0xFbF2a49C…`](https://hyperevmscan.io/address/0xFbF2a49CB0cc50F4ccd4eAc826eF1A76D99D29Eb) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `4bdd5d47` | +276/−202 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Implementation | [`0xC00F0B7d…`](https://hyperevmscan.io/address/0xC00F0B7d7B4F7cA3d3f79f3892069f41C142dB84) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `408124d9` | +263/−186 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Periphery | [`0x61aFC386…`](https://hyperevmscan.io/address/0x61aFC386b47a11F8721b67Eb1607cFBd9ccE48B1) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `f98bd760` | +5/−2 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2ProtocolFeeConfig | [`0x434b1072…`](https://hyperevmscan.io/address/0x434b1072d96ea24967CDe289D3d4d81d2BAD4F30) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `83e2e2c4` | +147/−0 vs baseline | fee-config redesign + code-size refactor |
+| eulerSwapV2Registry | [`0x7E1Efb6A…`](https://hyperevmscan.io/address/0x7E1Efb6A2009A1FDaDee1c5d6615260AD70c14Fb) | [`euler-swap@81cf6dc9`](https://github.com/euler-xyz/euler-swap/tree/81cf6dc988468fd56f690e6bc0e338a5be02d034) | ✅ `42c58b74` | +185/−17 vs baseline | fee-config redesign + code-size refactor |
## EVault modules (unpacked from the implementation)
@@ -268,7 +268,7 @@ _Last full-scope audit of the broadly-deployed EVC lineage: yAudit's combined Ca
Deployed pin [`a7d3c29e`](https://github.com/euler-xyz/ethereum-vault-connector/tree/a7d3c29ef7e4964736e47675e0588630d6afbfd7) (evc):
-Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers — proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).
+Descendant of the baseline and the last commit ever to touch src/ on origin/master — the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions — the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.
> **Assessment** · severity: **low**
> The multichain pin (and Polygon’s set-size descendant) includes PRs #178/#179: isSignerValid excludes the EIP-7587 precompile range and the 0x42 predeploy address space from acting as message signers. Proactive, restrictive-only hardening (five lines) added ahead of the Nov-2024 multichain deployment; it maps to no registered audit finding.
@@ -297,119 +297,6 @@ index 95009da..e6bc820 100644
}
/// @notice Computes the permit hash for a given set of parameters.
-diff --git a/src/utils/EVCUtil.sol b/src/utils/EVCUtil.sol
-index cf57295..dc4e432 100644
---- a/src/utils/EVCUtil.sol
-+++ b/src/utils/EVCUtil.sol
-@@ -29,7 +29,7 @@ abstract contract EVCUtil {
-
- /// @notice Returns the address of the Ethereum Vault Connector (EVC) used by this contract.
- /// @return The address of the EVC contract.
-- function EVC() external view returns (address) {
-+ function EVC() external view virtual returns (address) {
- return address(evc);
- }
-
-@@ -49,6 +49,18 @@ abstract contract EVCUtil {
- _;
- }
-
-+ /// @notice Ensures a standard authentication path on the EVC allowing the account owner or any of its EVC accounts.
-+ /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
-+ /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-+ /// @dev This modifier must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This modifier must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ modifier onlyEVCAccount() virtual {
-+ _authenticateCallerWithStandardContextState(false);
-+ _;
-+ }
-+
- /// @notice Ensures a standard authentication path on the EVC.
- /// @dev This modifier checks if the caller is the EVC and if so, verifies the execution context.
- /// It reverts if the operator is authenticated, control collateral is in progress, or checks are in progress.
-@@ -59,7 +71,7 @@ abstract contract EVCUtil {
- /// @dev This modifier can be used on access controlled functions to prevent non-standard authentication paths on
- /// the EVC.
- modifier onlyEVCAccountOwner() virtual {
-- _onlyEVCAccountOwner();
-+ _authenticateCallerWithStandardContextState(true);
- _;
- }
-
-@@ -121,6 +133,29 @@ abstract contract EVCUtil {
- return sender;
- }
-
-+ /// @notice Retrieves the message sender, ensuring it's any EVC account meaning that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccount() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(false);
-+ }
-+
-+ /// @notice Retrieves the message sender, ensuring it's the EVC account owner and that the execution context is in a
-+ /// standard state (not operator authenticated, not control collateral in progress, not checks in progress).
-+ /// @dev It assumes that if the caller is not the EVC, the caller is the account owner.
-+ /// @dev This function must not be used on functions utilized by liquidation flows, i.e. transfer or withdraw.
-+ /// @dev This function must not be used on checkAccountStatus and checkVaultStatus functions.
-+ /// @dev This function can be used on access controlled functions to prevent non-standard authentication paths on
-+ /// the EVC.
-+ /// @return The address of the message sender.
-+ function _msgSenderOnlyEVCAccountOwner() internal view returns (address) {
-+ return _authenticateCallerWithStandardContextState(true);
-+ }
-+
- /// @notice Calls the current external function through the EVC.
- /// @dev This function is used to route the current call through the EVC if it's not already coming from the EVC. It
- /// makes the EVC set the execution context and call back this contract with unchanged calldata. msg.sender is used
-@@ -159,12 +194,14 @@ abstract contract EVCUtil {
- }
- }
-
-- /// @notice Ensures that the function is called only by the EVC account owner
-+ /// @notice Ensures that the function is called only by the EVC account owner or any of its EVC accounts
- /// @dev This function checks if the caller is the EVC and if so, verifies that the execution context is not in a
-- /// special state (operator authenticated, collateral control in progress, or checks in progress). If the owner was
-- /// already registered on the EVC, it verifies that the onBehalfOfAccount is the owner.
-- /// @dev Reverts if the caller is not the EVC or if the execution context is in a special state.
-- function _onlyEVCAccountOwner() internal view {
-+ /// special state (operator authenticated, collateral control in progress, or checks in progress). If
-+ /// onlyAccountOwner is true and the owner was already registered on the EVC, it verifies that the onBehalfOfAccount
-+ /// is the owner. If onlyAccountOwner is false, it allows any EVC account of the owner to call the function.
-+ /// @param onlyAccountOwner If true, only allows the account owner; if false, allows any EVC account of the owner
-+ /// @return The address of the message sender.
-+ function _authenticateCallerWithStandardContextState(bool onlyAccountOwner) internal view returns (address) {
- if (msg.sender == address(evc)) {
- EC ec = EC.wrap(evc.getRawExecutionContext());
-
-@@ -173,11 +210,18 @@ abstract contract EVCUtil {
- }
-
- address onBehalfOfAccount = ec.getOnBehalfOfAccount();
-- address owner = evc.getAccountOwner(onBehalfOfAccount);
-
-- if (owner != address(0) && owner != onBehalfOfAccount) {
-- revert NotAuthorized();
-+ if (onlyAccountOwner) {
-+ address owner = evc.getAccountOwner(onBehalfOfAccount);
-+
-+ if (owner != address(0) && owner != onBehalfOfAccount) {
-+ revert NotAuthorized();
-+ }
- }
-+
-+ return onBehalfOfAccount;
- }
-+
-+ return msg.sender;
- }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -418,7 +305,7 @@ _Last full-scope audited state of EVK: yAudit's combined Cantina-competition fix
Deployed pin [`422bf244`](https://github.com/euler-xyz/euler-vault-kit/tree/422bf2447047d32aa9f4e5bab4be16ab3ea67ec2) (eVaultImplementation + the 8 EVault modules):
-The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.
+The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) — reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv — plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.
```diff
diff --git a/src/EVault/modules/Governance.sol b/src/EVault/modules/Governance.sol
@@ -460,28 +347,6 @@ index c0f2ce7..71fd403 100644
}
/// @inheritdoc IProtocolConfig
-diff --git a/src/Synths/ESynth.sol b/src/Synths/ESynth.sol
-index cece73c..e059d29 100644
---- a/src/Synths/ESynth.sol
-+++ b/src/Synths/ESynth.sol
-@@ -177,4 +177,17 @@ contract ESynth is ERC20EVCCompatible, Ownable {
- }
- return total;
- }
-+
-+ /// @dev Leaves the contract without owner. It will not be possible to call `onlyOwner` functions. Can only be
-+ /// called by the current owner.
-+ /// NOTE: Renouncing ownership will leave the contract without an owner, thereby disabling any functionality that is
-+ /// only available to the owner.
-+ function renounceOwnership() public virtual override onlyEVCAccountOwner {
-+ super.renounceOwnership();
-+ }
-+
-+ /// @dev Transfers ownership of the contract to a new account (`newOwner`). Can only be called by the current owner.
-+ function transferOwnership(address newOwner) public virtual override onlyEVCAccountOwner {
-+ super.transferOwnership(newOwner);
-+ }
- }
```
### evk — baseline `1dad88bd` ([yAudit (`yaudit-evk-2024-comp-fixes`)](https://github.com/euler-xyz/euler-vault-kit/blob/5b98b42048ba11ae82fb62dfec06d1010c8e41e6/audits/yAudit_competition_fixes_report.pdf))
@@ -827,4 +692,4 @@ index 23a3c2fd..ec881e76 100644
if (deadline < block.timestamp) revert SwapVerifier_pastDeadline();
```
-_Generated by euler-verifier @ feat/p2-manifests; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
+_Generated by euler-verifier @ master; inputs: verify/manifest.json, verify/audits.json, verify/baselines.json._
diff --git a/verify/baselines.json b/verify/baselines.json
index a92c4b4..40e0852 100644
--- a/verify/baselines.json
+++ b/verify/baselines.json
@@ -1,5 +1,5 @@
{
- "$comment": "Component audit baselines. ONE baseline per component: the fixes-included state of the component's LAST audit \u2014 derived by tracing post-review fix commits (fix commits are usually not stated in reports). Every deployed pin is diffed against this single baseline, restricted to componentPaths. Pins that predate the baseline carry a naturalBaseline: the audit whose fixes-included state the deployed code actually matches, plus the audits that reviewed the pin\u2192baseline delta. Derivations reference PRs/commits/tags verifiable in the public repos.",
+ "$comment": "Component audit baselines. ONE baseline per component: the fixes-included state of the component's LAST audit \u2014 derived by tracing post-review fix commits (fix commits are usually not stated in reports). Every deployed pin is diffed against this single baseline, restricted to componentPaths \u2014 git pathspecs, where :(exclude) entries scope out source files that are not part of any deployed contract's compilation unit. Pins that predate the baseline carry a naturalBaseline: the audit whose fixes-included state the deployed code actually matches, plus the audits that reviewed the pin\u2192baseline delta. Derivations reference PRs/commits/tags verifiable in the public repos.",
"generated": "2026-07-25",
"components": [
{
@@ -9,7 +9,8 @@
"evc"
],
"componentPaths": [
- "src/"
+ "src/",
+ ":(exclude)src/utils/EVCUtil.sol"
],
"lastAudit": {
"id": "yaudit-evc-2024-comp-fixes",
@@ -27,12 +28,12 @@
"summary": "Equals the baseline \u2014 the mainnet EVC deployment IS the audited fixes-included commit."
},
"a7d3c29ef7e4964736e47675e0588630d6afbfd7": {
- "summary": "Descendant of the baseline and the last commit ever to touch src/ on origin/master \u2014 the 14-chain EVC equals current master source. Delta vs baseline: the EVCUtil onlyEVCAccountOwner enhancement (PRs #175/#177; pre-reviewed 'no issues spotted' in the comp-fixes report, and not part of the deployed EVC singleton's own runtime) and the PR #178/#179 isSignerValid exclusions (EIP-7587 precompile + 0x42 predeploy address space barred from being message signers \u2014 proactive hardening ahead of the Nov-2024 multichain deployment, mapped to no audit finding).",
- "label": "EVCUtil helper + signer-exclusion hardening"
+ "summary": "Descendant of the baseline and the last commit ever to touch src/ on origin/master \u2014 the 14-chain EVC equals current master source. Delta vs baseline: the PR #178/#179 isSignerValid exclusions \u2014 the EIP-7587 precompile range and the 0x42 predeploy address space barred from being message signers. Proactive, restrictive-only hardening added ahead of the Nov-2024 multichain deployment; it maps to no audit finding.",
+ "label": "signer-exclusion hardening"
},
"912b301f51301e586e5a7f09e48cf52bd52e9a0e": {
- "summary": "Polygon-only deployment: the yaudit-evc-2026-setsize state (SET_MAX_ELEMENTS 10\u2192100 for the Gondor/Polymarket integration; 0 C/H/M/L findings, informational fixes included via PR #203). Descendant of the baseline; its delta = the 14-chain pin's delta plus exactly the set-size audit scope. The branch remains unmerged to master by design.",
- "label": "set-size 10\u2192100 (audited) + hardening"
+ "summary": "Polygon-only deployment: the yaudit-evc-2026-setsize state (SET_MAX_ELEMENTS 10\u2192100 for the Gondor/Polymarket integration; 0 C/H/M/L findings, informational fixes included via PR #203). Descendant of the baseline; its delta = the 14-chain pin's signer-exclusion hardening plus exactly the set-size audit scope. The branch remains unmerged to master by design.",
+ "label": "set-size 10\u2192100 (audited) + signer hardening"
},
"7b2f05f8f2fc093f679463209dea202e9af3b120": {
"summary": "Morph deployment: tip of the public origin/deployment-morph branch (\u201cfacilitate Morph deployment\u201d, 2025-02-13); descendant of the baseline, compiled at 0.8.24/runs 20000/cancun.",
@@ -51,7 +52,8 @@
],
"coversModules": true,
"componentPaths": [
- "src/"
+ "src/",
+ ":(exclude)src/Synths/"
],
"lastAudit": {
"id": "yaudit-evk-2024-comp-fixes",
@@ -70,7 +72,7 @@
"label": "one fee-share default parameter"
},
"422bf2447047d32aa9f4e5bab4be16ab3ea67ec2": {
- "summary": "The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) \u2014 reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv \u2014 plus the same one-line parameter default and the ESynth onlyEVCAccountOwner guards (PR #273; a src/ file outside the deployed contract set). Zero src/ changes exist after this pin: it equals origin/master's contract tree.",
+ "summary": "The 15-chain deployment; descendant of the baseline, shipping WITH the setLTV patch. Delta vs baseline: the Governance.sol setLTV change (PR #288) \u2014 reviewed in full by both m4rio-evk-2025-setltv and electisec-evk-2025-setltv \u2014 plus the same one-line parameter default. Zero src/ changes exist after this pin: it equals origin/master's contract tree.",
"label": "setLTV patch (audited \u00d72) + param"
}
}
@@ -82,7 +84,8 @@
"balanceTracker"
],
"componentPaths": [
- "src/"
+ "src/",
+ ":(exclude)src/StakingRewardStreams.sol"
],
"lastAudit": {
"id": "cantina-reward-streams-2024",