Deep Dive
Security & Audits
Every Marian contract has been audited by at least two independent firms and formally verified where invariants are expressible. The bug-bounty program is one of the largest in DeFi, uncapped for critical severity.
Audit history
| Date | Scope | Firm | Findings | Status |
|---|---|---|---|---|
| 2025-Q1 | mLocker, RiskEngine | Trail of Bits | 2 low, 4 info | All resolved |
| 2025-Q1 | BasketVault, DividendDistributor | OpenZeppelin | 1 medium, 3 low | All resolved |
| 2025-Q2 | BorrowMarket, mUSD | Spearbit | 1 high, 3 medium, 6 low | All resolved |
| 2025-Q2 | OracleRegistry | Zellic | 0 findings | Complete |
| 2025-Q3 | Full re-review post-integration | ChainSecurity | 1 medium, 2 low | All resolved |
| 2026-Q1 | mLocker v2 upgrade | Trail of Bits | In progress | Pending |
Formal verification
The RiskEngine invariants and BorrowMarket accounting were verified in Certora Prover. The most important proven invariants:
- No debt creation without collateral: for every borrow tx, ΔD ≤ CF · ΔC.
- Solvency: Σ Di ≤ Σ Σ ci,j · Lj · Pj after every state transition.
- Dividend accumulator conservation: Σ userReward + unclaimed = Σ streamed (± 1 wei rounding).
- Boost cap: for all i, bi ≤ 2.5.
- Lock monotonicity: Tend is non-decreasing for any given lock NFT.
Bug bounty
| Severity | Payout |
|---|---|
| Critical (funds loss) | 10% of at-risk TVL, min $500k, max $10M |
| High | $100,000 – $500,000 |
| Medium | $25,000 – $100,000 |
| Low | $1,000 – $10,000 |
Operational security
- Timelock — 48h for any parameter or upgrade action.
- Guardian multisig — 4-of-7, may pause markets but cannot move user funds.
- Oracle deviation freeze — automatic, no human intervention.
- Circuit breaker — if 24h mUSD mint exceeds 20% of supply, mint is throttled.
Not risk-free
Marian positions can be liquidated. Smart-contract risk, oracle risk, and RWA custodian risk exist. Read the risk disclosures on the app before depositing. Nothing on this site is investment advice.