Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · May 2026

Solana Transaction Verification

for USDT0

Guardian's review of Solana Transaction Verification for USDT0, published May 2026. The report records 4 findings, including 1 medium and 3 informational.

Published
Review window
April 25, 2026
Chains
Ethereum, Arbitrum, Ink, Hyperliquid, Polygon, Monad, Solana, Stellar
Sector
Stablecoins
  • 0 Critical
  • 0 High
  • 1 Medium
  • 0 Low
  • 3 Informational

4 acknowledged

Findings 4

  1. M-01 Medium Solana XAUT0 Stable peer is not configured Warning Acknowledged
    Location
    -

    Description

    The XAUT0 config includes the Solana to/from Stable connection with the Canary DVN set. The corresponding Solana peer account is not configured. A direct confirmed RPC read of Stable peer PDA GAroeCTLbyHVZ2kv9caXoiEr3jbnTw1qKuBQ7H1YcFcG returned no account at slot 415630082. The expected peer value is 0x000000000000000000000000d8479f87686ed263d00ca7505f86327dbed4171a.

    Proposals #47 and #50 cover the receive and send ULN setConfig updates for Stable. They set the Stable ULN configs to the intended Canary DVN set and executor settings. They do not initialize or repair the missing peer account.

    #47 and #50 Safe transactions update Stable send and receive configs to the intended Canary target, but the peer remains absent because neither proposal contains a peer initialization instruction. Consequently, the Stable connection should not be treated as fully wired after this bundle.

    Recommendation

    Submit a follow-up Solana Squads proposal that initializes or repairs the Stable peer account before treating Stable as covered. The peer PDA should exist and decode to 0x000000000000000000000000d8479f87686ed263d00ca7505f86327dbed4171a.

  2. I-01 Informational Solana XAUT0 TON does not receive Canary DVN update Warning Acknowledged
    Location
    -

    Description

    The Solana to/from TON config still lists only the LayerZero and USDT0 DVNs. Proposals #34-#53 do not include a TON InitConfig, send setConfig, or receive setConfig instruction.

    Consequently, approving this Squads bundle updates the other covered Solana remotes to the three-DVN Canary set but leaves TON at two required DVNs. This is inconsistent with the stated goal of adding Canary as the third required DVN on every XAUT0 Solana connection.

    Recommendation

    Submit a follow-up Solana Squads proposal for TON that applies the intended send and receive ULN configs with the sorted required DVN set LayerZero, Canary, USDT0. If TON is intentionally excluded, remove it from the scoped Canary rollout and document the exclusion before signer approval.

  3. I-02 Informational Solana XAUT0 BSC and Monad setConfig updates are deferred Warning Acknowledged
    Location
    -

    Description

    The XAUT0 config includes Solana to/from Monad and Solana to/from BSC entries with the Canary DVN set. The live Squads bundle only includes InitConfig for those two remotes in proposals #34 and #35. It does not include the matching send or receive setConfig instructions.

    If signers treat #34-#53 as complete coverage, BSC and Monad will remain without the intended Solana Canary ULN configs until a second bundle is proposed and executed. The init proposals allocate state, but they do not apply the required DVN set.

    Recommendation

    Execute #34 and #35 only with an explicit follow-up requirement for the four missing BSC and Monad setConfig instructions. After the follow-up bundle is proposed, decode and simulate it with the same checks used for #34-#53 before approval.

  4. I-03 Informational Solana XAUT0 Squads has an undocumented seventh member Warning Acknowledged
    Location
    -

    Description

    The Solana XAUT0 scope identifies the Squads multisig BiFqKEtVL9iv2ZYBw4oE7qFysftof69G6N5LTpQ7xitp as a 3-of-6 Squads V4 account. The live account decodes with the expected threshold of 3, but it has 7 members.

    The live Squads member/owner addresses are:

    5jDc8Hp3uLzgpNo9cq8eUw45nDuojVqgMgfxRmWhvYHb  permissionsMask=7
    831ZwU7LvAF1Xt6BRdpX54UxdhJAuiS3S4xpcmYmRaHn  permissionsMask=5
    BgPzTQS5Rdkoqjq6ecz74vKe6Ljcd14fwsyTDYH4wYsB  permissionsMask=5
    GR9VreJzeV1r5iRjVmddvqHsB3Mo5mvLfTKtvPRi52JD  permissionsMask=7
    GTzaBWhq6h4zQSsqVjsD14ABWosjXy5g9xrzrqsLUyar  permissionsMask=7
    Gnn9hC32LHmTzaCqmH5rsvbSX3qCrbKFMzzQ6zkqnJED  permissionsMask=7
    Hr8YvdxTpc9u2QfDqo4Ve3ViVnG59EjBRRFfwrtWfURj  permissionsMask=7
    

    For Squads V4, permissionsMask=7 means Initiate, Vote, and Execute. permissionsMask=5 means Initiate and Execute. Therefore the live state is not the documented 3-of-6 owner set. It is seven members total, with five vote-enabled members.

    The intended owner addresses are not recoverable from the provided scope. The only documented intended state is a six-member Squads account with threshold 3.

    Recommendation

    Publish the intended six Squads member/owner addresses for BiFqKEtVL9iv2ZYBw4oE7qFysftof69G6N5LTpQ7xitp before treating #34-#53 as fully signer-verified. If the live 3-of-7 state is wrong, execute the required Squads config transaction to remove the unexpected member or correct its permissions. If the live state is intentional, update the Solana scope and verifier documentation from 3-of-6 to the exact live member set so future approval checks use the intended governance state.

More from USDT0

All 20 reports
  1. Stellar Deployment

    2 findings 2 findings: 2 informational
  2. Corn Network Delisting

    1 finding 1 finding: 1 low
  3. Canary Chain Configuration Verification

    4 findings 4 findings: 4 informational
  4. XAUT0 Wiring

    4 findings 4 findings: 2 low, 2 informational

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote