Omniscia Sova Network Audit
Fountfi Protocol Security Audit
Audit Report Revisions
| Commit Hash | Date | Audit Report Hash |
|---|---|---|
| fca2fe922e | June 16th 2025 | e64eb80ca7 |
| e4d6885477 | June 25th 2025 | 3b208e36df |
| 08da17ef72 | July 4th 2025 | 779260c973 |
| 5816458210 | July 7th 2025 | a4b35960dd |
Audit Overview
We were tasked with performing an audit of the Sova Network codebase and in particular their Fountfi Protocol module.
The system is meant to implement a modular RWA tokenization system revolving around the EIP-4626 standard with various security measures as well as integration modules for restricting the inflow and outflow of funds in RWA instances.
Over the course of the audit, we identified, among other noteworthy issues, a critical vulnerability that would permit all funds approved to the singleton Conduit of the system to be siphoned effectively compromising any and all approvals toward the RWA vaults meant for deposits.
Furthermore, we observed certain implementation components that are meant to be integrated by strategies of unknown implementation. To ensure validation of the codebase has been performed to the utmost extent possible, we strongly advise reference strategy implementations to be introduced to the audit scope or a strictly defined specification sheet as to how strategies are expected to integrate with the system.
We advise the Sova Network team to closely evaluate all minor-and-above findings identified in the report and promptly remediate them as well as consider all optimizational exhibits identified in the report.
Post-Audit Conclusion
The Sova Network team iterated through all findings within the report and provided us with a revised commit hash to evaluate all exhibits on.
We evaluated all alleviations performed by Sova Network and have identified that certain exhibits have not been adequately dealt with. We advise the Sova Network team to revisit the following exhibits: POR-01M, REE-02M
Additionally, the following informational findings remain unaddressed and should be revisited: BSY-01C, RSY-01C, REE-01C, RWA-02C
Post-Audit Conclusion (08da17ef72)
The Sova Network team evaluated our follow-up recommendations and provided us with a new commit hash where additional remediations were located.
We confirmed that all exhibits except for POR-01M have been adequately alleviated or acknowledged, rendering the POR-01M exhibit to be the sole remaining unattended item in the audit report.
Post-Audit Conclusion (5816458210)
The Sova Network team evaluated the latest chapter of the POR-01M exhibit and proceeded to address all concerns fully by adhering to our recommendations.
We consider all outputs of the audit report properly consumed by the Sova Network team with no outstanding remediative actions remaining.
Audit Synopsis
| Severity | Identified | Alleviated | Partially Alleviated | Acknowledged |
|---|---|---|---|---|
![]() | 0 | 0 | 0 | 0 |
![]() | 32 | 29 | 0 | 3 |
![]() | 4 | 3 | 0 | 1 |
![]() | 4 | 2 | 0 | 2 |
![]() | 1 | 1 | 0 | 0 |
During the audit, we filtered and validated a total of 2 findings utilizing static analysis tools as well as identified a total of 39 findings during the manual review of the codebase. We strongly recommend that any minor severity or higher findings are dealt with promptly prior to the project's launch as they can introduce potential misbehaviours of the system as well as exploits.
Total Alleviations
The list below covers each segment of the audit in depth and links to the respective chapter of the report:




