Omniscia Sova Network Audit

Fountfi Protocol Security Audit

Audit Report Revisions

Commit HashDateAudit Report Hash
fca2fe922eJune 16th 2025e64eb80ca7
e4d6885477June 25th 20253b208e36df
08da17ef72July 4th 2025779260c973
5816458210July 7th 2025a4b35960dd

Audit Overview

We were tasked with performing an audit of the Sova Network codebase and in particular their Fountfi Protocol module.

The system is meant to implement a modular RWA tokenization system revolving around the EIP-4626 standard with various security measures as well as integration modules for restricting the inflow and outflow of funds in RWA instances.

Over the course of the audit, we identified, among other noteworthy issues, a critical vulnerability that would permit all funds approved to the singleton Conduit of the system to be siphoned effectively compromising any and all approvals toward the RWA vaults meant for deposits.

Furthermore, we observed certain implementation components that are meant to be integrated by strategies of unknown implementation. To ensure validation of the codebase has been performed to the utmost extent possible, we strongly advise reference strategy implementations to be introduced to the audit scope or a strictly defined specification sheet as to how strategies are expected to integrate with the system.

We advise the Sova Network team to closely evaluate all minor-and-above findings identified in the report and promptly remediate them as well as consider all optimizational exhibits identified in the report.

Post-Audit Conclusion

The Sova Network team iterated through all findings within the report and provided us with a revised commit hash to evaluate all exhibits on.

We evaluated all alleviations performed by Sova Network and have identified that certain exhibits have not been adequately dealt with. We advise the Sova Network team to revisit the following exhibits: POR-01M, REE-02M

Additionally, the following informational findings remain unaddressed and should be revisited: BSY-01C, RSY-01C, REE-01C, RWA-02C

Post-Audit Conclusion (08da17ef72)

The Sova Network team evaluated our follow-up recommendations and provided us with a new commit hash where additional remediations were located.

We confirmed that all exhibits except for POR-01M have been adequately alleviated or acknowledged, rendering the POR-01M exhibit to be the sole remaining unattended item in the audit report.

Post-Audit Conclusion (5816458210)

The Sova Network team evaluated the latest chapter of the POR-01M exhibit and proceeded to address all concerns fully by adhering to our recommendations.

We consider all outputs of the audit report properly consumed by the Sova Network team with no outstanding remediative actions remaining.

Audit Synopsis

SeverityIdentifiedAlleviatedPartially AlleviatedAcknowledged
0000
322903
4301
4202
1100

During the audit, we filtered and validated a total of 2 findings utilizing static analysis tools as well as identified a total of 39 findings during the manual review of the codebase. We strongly recommend that any minor severity or higher findings are dealt with promptly prior to the project's launch as they can introduce potential misbehaviours of the system as well as exploits.

Total Alleviations

The list below covers each segment of the audit in depth and links to the respective chapter of the report: