MarianmarianDocs
Deep Dive

Security & Audits

Every Marian contract has been audited by at least two independent firms and formally verified where invariants are expressible. The bug-bounty program is one of the largest in DeFi, uncapped for critical severity.

Audit history

DateScopeFirmFindingsStatus
2025-Q1mLocker, RiskEngineTrail of Bits2 low, 4 infoAll resolved
2025-Q1BasketVault, DividendDistributorOpenZeppelin1 medium, 3 lowAll resolved
2025-Q2BorrowMarket, mUSDSpearbit1 high, 3 medium, 6 lowAll resolved
2025-Q2OracleRegistryZellic0 findingsComplete
2025-Q3Full re-review post-integrationChainSecurity1 medium, 2 lowAll resolved
2026-Q1mLocker v2 upgradeTrail of BitsIn progressPending

Formal verification

The RiskEngine invariants and BorrowMarket accounting were verified in Certora Prover. The most important proven invariants:

  • No debt creation without collateral: for every borrow tx, ΔD ≤ CF · ΔC.
  • Solvency: Σ Di ≤ Σ Σ ci,j · Lj · Pj after every state transition.
  • Dividend accumulator conservation: Σ userReward + unclaimed = Σ streamed (± 1 wei rounding).
  • Boost cap: for all i, bi ≤ 2.5.
  • Lock monotonicity: Tend is non-decreasing for any given lock NFT.

Bug bounty

SeverityPayout
Critical (funds loss)10% of at-risk TVL, min $500k, max $10M
High$100,000 – $500,000
Medium$25,000 – $100,000
Low$1,000 – $10,000

Operational security

  • Timelock — 48h for any parameter or upgrade action.
  • Guardian multisig — 4-of-7, may pause markets but cannot move user funds.
  • Oracle deviation freeze — automatic, no human intervention.
  • Circuit breaker — if 24h mUSD mint exceeds 20% of supply, mint is throttled.
Not risk-free
Marian positions can be liquidated. Smart-contract risk, oracle risk, and RWA custodian risk exist. Read the risk disclosures on the app before depositing. Nothing on this site is investment advice.