M0 engaged Guardian to review the security of their M0 mUSD. From the 8th of August to the 11th of August, a team of 3 auditors reviewed the source code in scope.
- Published
- Review window
- August 8 to 11, 2025
- Language
- Solidity
- Chains
- Ethereum, Arbitrum, Optimism
- Sector
- Stablecoins
- 0 Critical
- 0 High
- 0 Medium
- 0 Low
- 1 Informational
Scope
Overview
M0 engaged Guardian to review the security of their M0 mUSD. From the 8th of August to the 11th of August, a team of 3 auditors reviewed the source code in scope.
Findings 1
-
I-01 Informational Inconsistent Freeze Checks In Transfers Validation Resolved
Description
beforeTransferchecks iffrom,to, orsenderis frozen before allowing a transfer. However,forceTransferdoes not check if the receiver is frozen.This breaks the invariant that frozen accounts should not be able to receive tokens, though
forceTransferis intended for trusted roles.Recommendation
Either add frozen account checks to
forceTransferfor consistency, or explicitly document thatforceTransferbypasses this restriction due to its trusted nature.Resolution
M0 Team: The issue was resolved in PR#14.
No findings match.
More from M0
All 10 reports-
Liquidity Delivery Updates
4 findings 4 findings: 1 low, 3 informational -
PYUSDX
21 findings 21 findings: 8 low, 13 informational -
Liquidity Delivery
59 findings3 critical · 5 high 59 findings: 3 critical, 5 high, 10 medium, 14 low, 27 informational -
M Extensions Updates
16 findings 16 findings: 1 medium, 5 low, 10 informational
Put your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.
