Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · August 2025

mUSD

for M0

M0 engaged Guardian to review the security of their M0 mUSD. From the 8th of August to the 11th of August, a team of 3 auditors reviewed the source code in scope.

Published
Review window
August 8 to 11, 2025
Language
Solidity
Chains
Ethereum, Arbitrum, Optimism
Sector
Stablecoins
  • 0 Critical
  • 0 High
  • 0 Medium
  • 0 Low
  • 1 Informational

1 resolved

Scope

Overview

M0 engaged Guardian to review the security of their M0 mUSD. From the 8th of August to the 11th of August, a team of 3 auditors reviewed the source code in scope.

Findings 1

  1. I-01 Informational Inconsistent Freeze Checks In Transfers Validation Resolved
    Location
    MUSD.sol: 166

    Description

    beforeTransfer checks if from, to, or sender is frozen before allowing a transfer. However, forceTransfer does not check if the receiver is frozen.

    This breaks the invariant that frozen accounts should not be able to receive tokens, though forceTransfer is intended for trusted roles.

    Recommendation

    Either add frozen account checks to forceTransfer for consistency, or explicitly document that forceTransfer bypasses this restriction due to its trusted nature.

    Resolution

    M0 Team: The issue was resolved in PR#14.

More from M0

All 10 reports
  1. Liquidity Delivery Updates

    4 findings 4 findings: 1 low, 3 informational
  2. PYUSDX

    21 findings 21 findings: 8 low, 13 informational
  3. Liquidity Delivery

    59 findings3 critical · 5 high 59 findings: 3 critical, 5 high, 10 medium, 14 low, 27 informational
  4. M Extensions Updates

    16 findings 16 findings: 1 medium, 5 low, 10 informational

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote