Guardian's review of Iris Protocol for iris.credit, published September 2026. The report records 11 findings across 2 review rounds, including 6 medium and 3 low.
- Published
- Review window
- August 27 to September 25, 2026
- Rounds
- Main Review, Remediation Review
- Language
- Solidity
- Chains
- Ethereum
- Sector
- Lending
- 0 Critical
- 0 High
- 6 Medium
- 3 Low
- 2 Informational
Scope
11 files in scope · 953 nSLOC
| File | nSLOC | Lines |
|---|---|---|
src/adapters/AaveV3Adapter.sol | 70 | 98 |
src/adapters/MorphoBlueAdapter.sol | 92 | 138 |
src/blm/Blm.sol | 28 | 46 |
src/blm/WhitelistBlm.sol | 35 | 54 |
src/interfaces/IBlm.sol | 9 | 17 |
src/interfaces/IIris.sol | 86 | 95 |
src/interfaces/IPod.sol | 5 | 8 |
src/interfaces/IVenueAdapter.sol | 6 | 10 |
src/interfaces/IWhitelistBlm.sol | 5 | 11 |
src/Iris.sol | 592 | 921 |
src/Pod.sol | 25 | 35 |
Findings 11
Main Review
9 findings-
M-01 Medium Liquidation Charges Fixed and Floating Business logic errors Resolved
Description
Iris promises borrowers a fixed-rate obligation: the borrower should pay principal plus fixed interest, while the solver bond absorbs venue floating interest above that fixed amount.
That accounting breaks after a venue liquidation. When a liquidator repays venue debt using seized borrower collateral, the repayment can include accrued floating interest.
_rebase()then reads only the remaining venue debt and clamps or removes the floating leg that was already paid through the liquidation. The paid floating cost is treated as if it never existed, so it is no longer charged against the solver bond.Root Cause
_rebase()derives the position's floating exposure from the live venue debt after liquidation. It does not separately track realized venue funding costs that were already paid by borrower collateral. As a result, when venue debt is reduced or fully repaid by liquidation,_rebase()can reducefloatingLegto the remaining debt and erase the portion of floating interest that was economically funded by the borrower through seized collateral.Example
Consider a position at maturity with:
100principal10floating interest5fixed interest- collateral worth
121debt tokens - enough solver bond to cover the
5negative spread
In an 86% LLTV Morpho market, the position is liquidatable. A liquidator can repay the full
110venue debt, seize about114.82of collateral including the venue liquidation bonus, and leave about6.18collateral in the Pod.M-01Liquidation Charges Fixed and Floating C O N T I N U E DAfter
_rebase(), Iris records zero principal and zero floating interest while preserving the5fixed-interest claim. The solver bond remains untouched. Because collateral remains, the borrower must still pay5throughrepay()before callingescape(). Ignoring the venue's ordinary liquidation bonus, the borrower funded110through seized collateral and another5through Iris. The borrower pays115despite the promised fixed obligation being105. The erased10floating interest is shifted away from the solver bond.Impact
The borrower can overpay relative to the fixed-rate obligation, while the solver and fee recipient can still receive the fixed settlement and the solver can recover an unslashed bond. This contradicts the fixed-rate design, where solver backing is supposed to absorb venue floating costs above the borrower's fixed obligation.
Recommendation
Track realized venue funding costs separately from outstanding venue debt. When liquidation uses borrower collateral to retire floating interest, preserve that realized floating cost for settlement instead of deleting it during
_rebase()Resolution
iris.credit Team: Fixed at https://github.com/iris-credit/iris-core/pull/27
-
M-02 Medium Delayed Rebase Falsely Slashes Solver Bond Business logic errors Acknowledged
Description
Iris calls
_accrueLegs()before_rebase()when updating a position. If Morpho partially liquidates a Pod between Iris calls, Iris calculates interest using the old debt before reading the reduced Morpho debt. Debt already repaid through the Morpho liquidation is therefore treated as outstanding until Iris is updated. When the floating rate exceeds the fixed rate, this creates excess negative spread and can make a healthy solver bond liquidatable.The Iris borrower can profit because Morpho recognizes the Pod, rather than the Iris borrower, as its borrower and allows arbitrary callers to perform partial liquidations. The borrower can liquidate the Pod, wait without another Iris update, call liquidateBond() with a controlled receiver, and then call escape(). Calling rebase() promptly prevents this, but no onchain deadline or protocol-enforced keeper guarantees that it will be called when the Morpho liquidation happens.
Consider 10,000 USDC principal, a solver-selected 305.67 USDC bond, 90% bond LLTV, a 5% annual fixed rate, and a high-utilization 86% LLTV Morpho market. The bond is ten times the current public BLM minimum of 30.567 USDC:
10,000 × (30 × 0.00010184 + 0.0000015) = 30.567. Iris allows the solver to post any bond at or above this minimum.At 26 days, 8 hours, and 4 minutes into the 30-day loan, Iris is updated immediately before the Morpho liquidation. Negative net is 273.224847 USDC, below the 275.103000 USDC bond boundary. A price move makes the Pod liquidatable, and the borrower liquidates 90% of its borrow shares. The remaining Morpho position is healthy at approximately 53.84% LTV. If
rebase()is called immediately after the Morpho liquidation, negative net two hours later is 273.417762 USDC and the bond remains healthy. Ifrebase()is not called during those two hours, Iris instead records 275.122214 USDC whenliquidateBond()is called and allows the bond liquidation.The correct path leaves 32.606187 USDC of solver bond. The delayed path leaves only 15.264286 USDC, pays the borrower a 15.283500 USDC bounty, and reduces the borrower’s closing cost by 17.341901 USDC. This equals the additional solver bond consumed. If Iris had been
M-02Delayed Rebase Falsely Slashes Solver Bond C O N T I N U E Dupdated immediately, the bond would not become liquidatable until 18 hours, 57 minutes, and 18 seconds after the Morpho liquidation. The bug therefore makes it liquidatable 16 hours, 57 minutes, and 18 seconds early.
Recommendation
Prevent a delayed rebase from increasing the amount taken from the solver’s bond. When _rebase() detects that Morpho liquidated part of the position, Iris should not charge the solver as though the repaid debt remained outstanding until the rebase call.Since Morpho’s current balance does not show when the liquidation happened, affected positions should be handled separately instead of estimating the missing interest.
Resolution
iris.credit Team: Acknowledged with an additional comment followed by the remediation (PR) link
-
M-03 Medium _accrueLegsView() over-accrues surplus on pre- liquidation Aave collateral and _rebase() converts the overage into solver owned yield Business logic errors Acknowledged
Description
_accrueLegsView() com putes surplus from stalestored(pos.collateral + pos.surplus) b eforelivevenue collateral is synced.
_accrueLegs()persists that inflated amount. Then_rebase()uses the inflated total inliquidated = (pos.collateral + pos.surplus) -venueCollateral, while only clampingsurplusifvenueCollateral <= pos.surplus. That keepspos.collateral + pos.surplusequal to the live venue balance, but the split is wrong after a partial Aave liquidation: yield is accrued on collateral that was already seized. The excess is paid out later as solversurplus, and the borrower’s remaining principal collateral is reduced instead.Example: 1. Borrower opens an Aave-backed loan with
collateral = 100,surplus = 0. 2. Aave partially liquidates40collateral /30debt, leaving60live collateral. 3. Before the first Iris sync, Aave income grows20%, so live collateral becomes72. 4. Any later path starting with_accrueLegs()books20surplus from the stale100base;_rebase()then reduces principal to52. 5. On close, the solver receives20collateral as surplus and the borrower can only escape52. 6. Correct accounting was solver12, borrower60;8borrower collateral is silently reassigned.This issue is Aave specific; Morpho collateral does not accrue via a collateral index
Recommendation
When a liquidation is being rebased, recompute
surplusfrom livevenueCollateralinstead of preserving the pre-rebase accrual, or subtract the accrued yield attributable to the liquidated collateral slice before storingpos.surplusM-_accrueLegsView() over-accrues surplus on pre-liquidation Aave collateral C O N T I N U E D03and _rebase() converts the overage into solver owned yieldResolution
iris.credit Team: Acknowledged with an additional comment followed by the remediation (PR) link
-
M-04 Medium setAuthorizationWithSig() lets stale signed grants restore revoked operators Signatures Resolved
Description
setAuthorizationWithSig()only checks whether a nonce has never been used, then writes the signed boolean directly. A signer who later revokes an operator withsetAuthorization()or a newer signed revoke does not invalidate older unusedisAuthorized=truesignatures, so the former operator can replay the stale grant and regain access. From there it can use the normal auth-gated sinks inwithdrawBond(),claim(),withdrawCollateral(), orescape()to redirect assets to itselfRecommendation
Use a monotonic per-authorizer authorization version and advance it on every direct authorization change, so a later revoke invalidates all older signed grants.
Resolution
iris.credit Team: Fixed at https://github.com/iris-credit/iris-core/pull/22
-
M-05 Medium Borrowers can flash-wash tracked collateral to steal solver Aave yield accounting bypass Resolved
Description
Aave permits anyone to supply collateral on behalf of a Pod. Iris ignores excess live Aave collateral above its tracked
Position.collateral.An overcollateralized borrower can supply collateral directly to Aave for the Pod, then withdraw the same amount through
Iris.withdrawCollateral(). The direct supply temporarily raises the live venue balance, allowing the Iris withdrawal to return the supplied tokens. The Pod's actual Aave collateral remains unchanged, but Iris decreasespos.collateral. Future Aave collateral-index growth on the washed amount is no longer booked asPosition.surplus, so the borrower can later recover that hidden yield throughescape()instead of paying it to the solver and fee recipient.Root Cause
withdrawCollateral()and_rebase()do not reconcile or classify direct Aave collateral donations before reducing tracked collateral.When live collateral exceeds Iris accounting:
_rebase()ignores the upward discrepancy.withdrawCollateral()allows the borrower to withdraw tokens.- Iris decrements
pos.collateral. - the raw Aave aToken balance can remain economically unchanged.
This lets the borrower reduce the accounting base used by
_accrueLegsView()to compute solver-owned surplus, without reducing venue safety or committing lasting capital.Attack Path
- The borrower opens an Aave-backed Iris position with excess collateral.
- The borrower supplies
Dcollateral directly to Aave on behalf of the Pod. - The Pod's live Aave collateral increases by
D, but Iris does not attribute that increase to
pos.collateral .M-05Borrowers can flash-wash tracked collateral to steal solver Aave yield C O N T I N U E D- The borrower calls
withdrawCollateral(D)through Iris. - Aave returns
D, leaving the Pod's live venue collateral effectively unchanged from the pre-attack state. - Iris still reduces
pos.collateralbyD. - Over time, the full live Aave collateral balance earns yield, but Iris computes surplus only on the reduced
tracked base. 8. On repayment and
escape(), the borrower receives the yield earned by the untracked collateral base.Impact
The borrower can divert collateral yield that the fixed-rate quote economics allocate to the solver and fee recipient. The attack can be capital-neutral with flash liquidity, does not reduce venue health, and scales with the washed collateral amount, venue APY, loan term, and number of positions
Recommendation
Reconcile/classify live collateral donations before tracked withdrawals, e.g. checkpoint scaled aToken shares and separate principal/donation buckets, or cap withdrawal accounting by the actual Pod live-balance decrease. Accrue surplus from economically attributed live collateral rather than nominal Position.collateral after donation-assisted withdrawal.
Before permitting a tracked withdrawal, reconcile live Aave collateral above Iris accounting
Resolution
iris.credit Team: Fixed at https://github.com/iris-credit/iris-core/pull/25
-
L-01 Low Off-ledger venue repay can stale Iris debt and let the borrower extract the solver bond Business logic errors Acknowledged
Description
Summary
Iris can keep
pos.debtmaterially higher than the real debt owed on the underlying venue.This happens when venue debt is reduced outside of Iris, either through direct repayment or through a venue liquidation whose collateral loss is hidden or understated. In those cases,
_rebase()does not fully reconcile the lower live venue debt into Iris storage. The stalepos.debtthen continues accruing floating interest through_accrueLegsView(). Later,liquidateBond()can treat the position as unhealthy based on the inflated internal debt, while resolving the venue side against the smaller live debt reported by the adapter. This can let the borrower slash the solver bond and potentially receive an unjustified liquidation incentive. Afterward, the borrower can callescape()and recover the remaining collateral by paying only the smaller live venue debt.Root Cause
_rebase()compares Iris accounting against live venue balances, but it only reconciles debt reductions when they are associated with visible collateral loss. If live venue debt falls while collateral remains unchanged,_rebase()returns early and leavespos.debtstale. If collateral loss is visible but understated,_rebase()only credits debt reduction up to the value of that collateral delta. This can also leavepos.debtabove the true venue debt.This affects both Morpho and Aave:
L-Off-ledger venue repay can stale Iris debt and let the borrower extract C O N T I N U E D01the solver bond-Morpho allows a borrower to directly callrepay(onBehalf = pod), reducing venue debt while leaving
venue collateral unchanged
.-Aave also allows direct repayment on behalf of the Pod.-Aave entry/refinance flows can introduce small collateral rounding mismatches.When this happens,
_rebase()may interpret the external repay as a tiny liquidation and only credit a tiny debt reduction, leaving most repaid debt stale.Attack Path
- 1
.The borrower opens an Iris position and receives the borrowed debt tokens. - 2
.The borrower uses those tokens to repay the underlying venue directly on behalf of the Pod. - 3
.The venue debt decreases, but Iris does not fully sync the repayment. - 4
.pos.debtremains materially overstated. - 5
.Floating interest continues accruing on the stale internal debt. - 6
.The position eventually appears to create a solver bond shortfall. - 7
.The borrower callsliquidateBond() . - 8
.liquidateBond()slashes the solver bond and may pay the borrower a liquidation incentive. - 9
.The borrower callsescape()and recovers the remaining collateral by paying only the residual live venue
debt
.Impact
-Solver bond value can be consumed by debt that no longer exists on the venue.-The borrower can receive an unjustified liquidation reward.-The borrower can close the position more cheaply than the fixed-rate trade intended.-Iris accounting can diverge materially from the underlying venue state.
Variants
1. Morpho direct repayment
The borrower directly repays Morpho debt with
repay(onBehalf = pod) .Venue debt decreases, collateral remains unchanged, and_rebase()returns before reducingpos.debt .The stale internal debt then accrues floating interest and can later be used to slash the solver bond.2. Aave direct repayment with rounding mismatch
The borrower directly repays Aave debt on behalf of the Pod
.If Iris
’s expected collateral balance differs slightly from the live Aave balance due to entry or refinance rounding,_rebase()may treat the mismatch as a small liquidation.ItL-Off-ledger venue repay can stale Iris debt and let the borrower extract C O N T I N U E D01the solver bondthen credits debt reduction only up to the value of that tiny collateral delta, leaving most of the externally repaid debt in
pos.debt .3. Morpho liquidation with collateral returned to the Pod
The same issue can occur through an actual Morpho liquidation
.A liquidator can reduce the Pod
’s Morpho debt and return the seized collateral to the Pod during the liquidation callback.From Iris’s perspective, collateral appears unchanged while debt is lower._rebase()therefore skips the debt reduction and leaves stalepos.debt .4. Partial venue liquidation followed by price movement
A partial venue liquidation can reduce both collateral and debt
.If the oracle price drops before_rebase()runs, the computed value of the collateral loss is lower.As a result,_rebase()syncs the collateral loss but only credits debt reduction up to the later, lower value of the collateral delta.This can leavepos.debtabove the live Morpho debt.The phantom principal then accrues floating interest and can later be used to slash the solver bond.5. Morpho full-debt liquidation masked by collateral resupply
If a loan is opened at or near LLTV, a small interest tick can make the Pod externally liquidatable even though Iris still records the original principal
.The borrower, or a cooperating liquidator, can liquidate all Morpho borrow shares and then resupply the seized collateral to the Pod
.Live venue debt becomes zero, while live collateral again matches Iris’s stored collateral expectation.Because_rebase()sees no collateral shortfall, it skips the debt reduction.Iris keeps phantom principal inpos.debt, which continues accruing floating interest untilliquidateBond()can slash the solver bond.6. Aave full-wipe masking variant
After Aave wipes a Pod to zero collateral and zero debt, the borrower can directly resupply collateral on behalf of the Pod up to Iris
’s stale expected collateral balance.BecauseAaveV3Adapterreports the raw aToken balance,_rebase()sees no collateral shortfall and returns before reconciling the zero live debt.This preserves stale debt, floating loss, and the inflated bond requirement.The borrower can then callliquidateBond()against the stale negative net position, collect the bond incentive, and later recover the injected collateral throughescape()L-Off-ledger venue repay can stale Iris debt and let the borrower extract C O N T I N U E D01the solver bondRecommendation
Make
_rebase()fully reconcile external venue debt reductions, even when there is no collateral lossResolution
iris.credit Team: Acknowledged, severity disputed to Low. Direct venue repays are documented as out of scope and left unreconciled (Iris.sol header 100-102, 116-118). The bond liquidation path only opens if the variable rate stays above the fixed rate long enough for the stale debt to eat through the bond, which the borrower cannot control, and the direct repayment is lost if it does not.
-
L-02 Low Liquidations Lack Execution Bounds liquidation economics / MEV Resolved
Description
Iris’s
liquidate()function provides no maximum repayment, minimum collateral output, or deadline. An authorized borrower can therefore front run a pending overdue liquidation and materially worsen its execution without making it revert. Aftermaturity + overduePeriod,withdrawCollateral()reserves tracked collateral only against principal and accrued fixed obligations. It excludesbadBondand the liquidation incentive. On Aave, accrued collateral yield is recorded as surplus belonging to the solver. This surplus supports venue health but is unavailable to the liquidator. The borrower can therefore withdraw tracked principal to Iris’s LLTV boundary while the venue remains healthy. The pending liquidation still chargespos.debt + pos.fixedLeg + badBond, but collateral output is silently capped at the reducedpos.collateral. A transaction that was profitable when submitted can execute at a principal loss. The borrower keeps the withdrawn collateral while the solver retains the surplus.The loss results from borrower controlled state changes between transaction submission and execution, rather than from a liquidator knowingly accepting an unprofitable position. Because
liquidate()has no caller supplied execution bounds, the transaction proceeds under materially worse terms instead of reverting.Recommendation
Add maxRepaid, minSeized, and deadline parameters to liquidate(). Validate them after accrual and rebase but before pulling funds from the liquidator. Optionally disable collateral withdrawals after liquidation eligibility or reserve collateral against the complete liquidation exposure.
Resolution
iris.credit Team: Fixed at https://github.com/iris-credit/iris-core/pull/23
-
L-03 Low Self-Liquidation Erases Future Fixed Interest state synchronization Acknowledged
Description
Iris.repay accrues, rebases a two-sided venue liquidation, then settles the fixed overlay. _rebase subtracts venue-repaid principal from pos.debt; _settleLegs computes residual fixed interest through maturity only on the reduced debt. A borrower-controlled address can trigger permissionless Morpho liquidation while the overlay remains live, then repay Iris and bypass the fixed obligation on the liquidated principal.
Impact: The borrower group can capture the liquidation proceeds while avoiding the remaining fixed interest on the retired principal. The correct economic comparison uses actual debt-token debits: the normal Iris repayment versus the Morpho liquidation payment plus the attacked Iris repayment, with external fees and gas included. In the prompt early-liquidation witness, accrued floating interest is negligible, so the normal payment exceeds the attacked path by almost the remaining fixed face. The solver loses the corresponding contracted return, and the protocol loses its performance fee on that return.
Recommendation
Preserve the fixed-term obligation on principal recognized as repaid by an underlying venue liquidation: track venue-repaid principal separately or add residual fixed interest through maturity before reducing pos.debt. Add partial/full Aave and Morpho liquidation-then-repay tests to ensure fixed charges are invariant to venue liquidation ordering.
Resolution
iris.credit Team: Acknowledged, severity disputed to Low. The fixed residual is reserved in withdrawCollateral, so a borrower cannot reach the venue liquidation threshold without an exogenous price move of at least the residual, not atomically exploitable.
-
I-01 Informational First Aave Borrow Can Desync Debt Index Business logic errors Acknowledged
Description
Iris snapshots Aave's normalized variable-debt index before entering the venue. If a reserve has zero scaled variable debt, a positive stored currentVariableBorrowRate, and a meaningful idle interval, Aave's view function projects an index above the stored index. This state can occur when the reserve has a nonzero configured base variable rate.
During the first subsequent borrow, Aave does not persist the projected index because scaled variable debt is still zero when the reserve indexes are updated. The Pod's debt is therefore minted using the lower stored index, while Iris has already recorded the higher projected index.
Iris consequently stores a debt-index baseline above the index used to mint the Pod's debt. Accrue-first actions revert until the live index catches up. After catch-up, Iris omits the intervening venue interest even though repay() must still fund the full live Aave debt. In an affected configuration, the difference could be drawn from pooled assets backing unrelated bonds or claims.
This is a latent configuration risk, not a currently executable production loss. The deployed Iris BLMs admit USDC, USDT, and WETH debt. Their Aave reserves have nonzero aggregate debt and reset to a zero base rate if debt reaches zero, preventing the required idle-index projection.
The PoC uses tBTC and a configured dormant-reserve state to demonstrate the underlying index behavior. That configuration cannot currently be originated through deployed Iris. The condition would become relevant only if Iris later admits an Aave reserve with zero scaled variable debt and a positive stored currentVariableBorrowRate.
Recommendation
No immediate remediation is required for the currently supported markets. Reassess this condition before admitting any additional Aave debt asset, particularly a reserve with zero scaled variable debt and a positive stored currentVariableBorrowRate.
I-01First Aave Borrow Can Desync Debt Index C O N T I N U E DResolution
iris.credit Team: Acknowledged with an additional comment followed by the remediation (PR) link
Remediation Review
2 findings-
M-01 Medium Post-wipe collateral supply makes the solver bond claimable by the borrower Business logic errors Resolved
Description
The M-01 fix added logic to
_rebase()that refunds the borrower when collateral sold during a venue liquidation repays more than the recorded principal and fixed interest. Fully wiped positions are excluded from this refund, but Iris recognizes a wipe only when the venue’s current collateral and debt balances are both exactly zero.Following a complete Morpho liquidation, any liquidator can resupply one unit of the seized collateral on behalf of the Pod. Iris consequently observes positive collateral and zero debt. This prevents the wipe from being recognized while leaving
bondRequirementactive. Whenrebaseis called, Iris accounts for the liquidated collateral as repayment, settles the fixed leg, and credits any remaining excess from the solver bond to the borrower. Without the additional collateral, the same liquidation resolves the position without creating a borrower refund. Any liquidator can supply the collateral and callrebaseduring Morpho’s liquidation callback, forcing the bond transfer without authorization from the borrower or solver. The resulting claim belongs to the borrower. If the liquidator is controlled or authorized by the borrower, it can also claim the refund during the callback and use it toward the repayment Morpho collects afterward.Depending on the liquidated collateral value and accumulated floating interest, the borrower can receive up to the position’s full remaining bond. The loss is limited to each affected position but can occur independently across multiple loans.
Recommendation
Ensure that collateral supplied after a terminal venue liquidation cannot change how Iris resolves the position or make the solver bond refundable.
M-Post-wipe collateral supply makes the solver bond claimable by the C O N T I N U E D01borrowerResolution
-
I-01 Informational Resolved loans permanently lose partial collateral withdrawals after the original deadline Business logic errors Acknowledged
Description
While the loan is active, the borrower may withdraw part of the collateral.
The code permits partial withdrawals only until the loan's deadline (maturity plus grace). After that deadline, an unresolved loan can be liquidated, so allowing collateral withdrawals could let the borrower strip value before liquidation.
However, a loan can also become resolved. Bond liquidation ends the solver's side, zeroes the borrower's Iris debt and interest, and leaves the borrower with the underlying venue position at a variable rate. In that resolved state, Iris's liquidate(), liquidateBond(), repay(), and rebase() revert. The underlying venue debt can still exist and remains subject to the venue's own rules.
The bug is that withdrawCollateral() still applies the original fixed-loan deadline check at line 613 without checking whether the loan is resolved.
Once that deadline passes, even a healthy resolved position can never make a partial collateral withdrawal again, although the fixed-rate Iris obligation has ended and Iris liquidation is no longer possible.
The only remaining route is escape(), which requires funding the entire live venue debt and closes the whole position. Recovery is therefore all or nothing.
Impact: The borrower loses the ability to manage the continuing venue position through partial withdrawals and must fully repay and exit to recover any collateral. This is a persistent functional restriction caused by applying a guard against Iris liquidation to a state in which that liquidation cannot occur.
Reproduction
- Open a loan and resolve it through bond liquidation while a healthy collateralized venue position remains
I-Resolved loans permanently lose partial collateral withdrawals after the C O N T I N U E D01original deadline- Advance beyond the original maturity-plus-grace deadline
- Attempt an otherwise valid partial collateral withdrawal
- Observe that the deadline check reverts despite resolution; recovering collateral through escape() requires
fully repaying the live venue debt and exiting
Summary
collateral withdrawals retain the fixed-loan deadline after resolution into a variable-rate position
Healthy borrowers can lose partial-withdrawal access and need full debt repayment to exit
Recommendation
Apply the maturity-plus-grace withdrawal deadline only to unresolved loans. Preserve borrower authorization and the existing collateral and venue health constraints for withdrawals from resolved positions.
Resolution
iris.credit Team: https://github.com/iris-credit/iris-core/commit/b13a527dff9d6c5b0a25357377841e9f9b152c6a
just add comments.
Deadline represents the period during which Iris manages the loan. Therefore, after the deadline, the borrower is expected to exit through escape().
No findings match.
Put your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.
