Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · November 2025

SY Genesis Vaults

for Nunchi

Nunchi engaged Guardian to review the security of their Nunchi SY & Genesis Vaults. From the 3rd of November to the 5th of November, an auditor reviewed the source code in scope.

Published
Review window
November 3 to 5, 2025
Language
Solidity
Chains
Hyperliquid
Sector
Yield and vaults, Perpetuals
  • 0 Critical
  • 2 High
  • 0 Medium
  • 4 Low
  • 0 Informational

5 resolved · 1 acknowledged

Scope

Overview

Nunchi engaged Guardian to review the security of their Nunchi SY & Genesis Vaults. From the 3rd of November to the 5th of November, an auditor reviewed the source code in scope.

Findings 6

  1. H-01 High exchangeRate Doesn’t Follow ERC5115 Standard Unexpected Behavior Resolved
    Location
    NunchiHyperbeatVaultSY.sol

    Description

    As described in the ERC 5115 ERC document: https://eips.ethereum.org/EIPS/eip-5115 The exchangeRate function MUST return ExchangeRate(t_now) such that ExchangeRate(t_now) * syBalance / 1e18 = assetBalance.

    And, that the exchangeRate method updates and returns the latest exchange rate, which is the exchange rate from SY token amount into asset amount, scaled by a fixed scaling factor of 1e18.

    The PRICER contract however returns a rate with 8 decimals of precision, and the SY token balances are using 6 decimals as derived from the vault token decimals of 6.

    Therefore the exchangeRate function is non-compliant and will almost always round to zero if adjusted by a scaling factor of 1e18.

    Recommendation

    Consider scaling the exchangeRate result by 1e10 to be compliant with the ERC 5115 standard.

    Resolution

    Nunchi Team: The issue was resolved in PR#26.

  2. H-02 High Incorrect Interface Bricks The System DoS Resolved
    Location
    Global

    Description

    The IDepositor interface includes a deposit function interface that is supposed to include returndata for a uint256 value, however the implementation of the DEPOSITOR at the address 0x0868A605661440e5D58453f16BDB64795B2Da176 on HyperEVM does not return anything.

    This ultimately results in a decoding revert as no return data was provided while some was expected, thus DoSing the entire deposit flow.

    Recommendation

    Remove the uint256 return value from the IDepositor interface.

    Resolution

    Nunchi Team: The issue was resolved in PR#26.

  3. L-01 Low Native Value Not Handled Validation Resolved
    Location
    SYBaseUpgV2.sol

    Description

    The deposit function in the SYBaseUpgV2 contract is payable, however the overridden _deposit function in the NunchiHyperbeatVaultSY contract does not handle msg.value.

    Recommendation

    Add a validation in the _deposit function to revert if nonzero msg.value has been provided.

    Resolution

    Nunchi Team: The issue was resolved in PR#26.

  4. L-02 Low getTokensIn Is Hardcoded Configuration Acknowledged
    Location
    NunchiHyperbeatVaultSY.sol

    Description

    getTokensIn() returns a static array [VAULT_TOKEN, USDC, USDT0] for simplicity while deposit validation uses DEPOSITOR.isDepositToken().

    If DEPOSITOR changes supported tokens, integrators relying on getTokensIn may route deposits to unsupported tokens and revert, degrading UX and composability.

    Recommendation

    Keep getTokensIn synchronized with DEPOSITOR.isDepositToken, or remove/hard-deprecate the static list and instead expose a function that queries the depositor’s current set. Document that getTokensIn is non-authoritative if kept.

    Resolution

    Nunchi Team: Acknowledged.

  5. L-03 Low No Rescue Functionality Warning Resolved
    Location
    NunchiHyperbeatVaultSY.sol

    Description

    The SYBaseUpgV2 contract implements a receive function, however there is no rescue logic to recover any Ether that may have been accidentally sent to the contract.

    Recommendation

    Consider if a rescue function should be implemented.

    Resolution

    Nunchi Team: The issue was resolved in PR#26.

  6. L-04 Low PreviewDeposit Misleading Result Warning Resolved
    Location
    Global

    Description

    The previewDeposit function does not take into account the deposit cap that is implemented on the underlying Depositor contract, and as a result this can be misleading for any consumers of this function.

    Recommendation

    Consider checking the Depositor for the deposit cap to surface to the user whether the requested deposit will fail.

    Resolution

    Nunchi Team: The issue was resolved in PR#26.

More from Nunchi

  1. Migration

    20 findings5 high 20 findings: 5 high, 5 medium, 6 low, 4 informational
  2. Genesis Vaults Updates

    18 findings2 high 18 findings: 2 high, 9 medium, 5 low, 2 informational
  3. Protocol Review

    27 findings4 high 27 findings: 4 high, 7 medium, 6 low, 10 informational

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote