Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · December 2025

Vault Updates

for Fun.xyz

Guardian's review of Vault Updates for Fun.xyz, published December 2025. The report records 3 findings, including 1 low and 2 informational.

Published
Review window
December 9 to 11, 2025
Sector
Payments
  • 0 Critical
  • 0 High
  • 0 Medium
  • 1 Low
  • 2 Informational

3 acknowledged

Scope

Findings 3

  1. L-01 Low Misleading Tick Functions Validation Acknowledged

    Description

    The functions in the VaultDepositooorV2 contract such as getMinimumDepositForTick, validateAmountForTick, and the validation performed in the _applyTickRounding function do not account for the minimum deposit nor the maximum deposit cap that is carried out in the lighter deposit contract.

    For each asset, lighter configures an assetConfig.minDepositTicks and assetConfig.depositCapTicks. For example, the min deposit ticks is 100_000 for ETH, meaning that in fact the minimum deposit is 1e14 (100,000 gwei).

    Any deposit that is below the minimum or would put the asset above it's cap is not allowed. This may be misleading for consumers of the view functions within the VaultDepositooorV2 contract and may lead to unexpected failure of bridging & depositing actions.

    Recommendation

    Consider if the minimum and cap should be factored into any of these view functions or even the validation in the _applyTickRounding function.

  2. I-01 Informational depositBatch Is Incompatible Warning Acknowledged
    Location
    Global

    Description

    The depositBatch function on the AdditionalZkLighter deposit contract is not compatible with Fun’s just-in-time amount splicing since it includes several dynamic types in the function signature, with the _amount parameter itself being a dynamic type.

    Recommendation

    Only whitelist the deposit function and not the depositBatch function for invocation on the lighter deposit contract through the wrapper.

  3. I-02 Informational Some deposits could be DoS’d DoS Acknowledged
    Location
    Global

    Description

    The lighter deposit contract has a cap per asset for the amount that can be deposited into the contract. If a deposit through the Fun system would put the lighter contract at or slightly below such a cap, a malicious actor could frontrun this deposit while the cross-chain deposit is in-flight and cause the deposit to instead put the system over the cap causing it to revert.

    Recommendation

    Simply be aware of this risk as it is unlikely and serves no straightforward benefit to the malicious actor, though it may happen benignly in practice.

More from Fun.xyz

  1. OFT

    12 findings1 critical · 2 high 12 findings: 1 critical, 2 high, 2 medium, 5 low, 2 informational
  2. Vault Wrapper

    12 findings 12 findings: 5 low, 7 informational

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote