If you don’t want to do it yourself, or want an expert set of eyes, we offer Permissions Audits.
We map your permission architecture, identify vulnerabilities and critical control paths, and provide recommendations to strengthen your configurations.
Show more
You can see the methodology applied to weETH and USD3.
Each report maps the permissions and dependencies behind the asset, including supply, governance, holder, price, signer, and bridge controls.
Explore the reports and the methodology:
Show more
Bridge control
What additional control assumptions are introduced when assets move across chains?
Bridges can introduce new upgrade, minting, pausing, signer, and validator permissions. Those dependencies become part of the asset’s overall security model.
Show more
Signers
Who can exercise privileged permissions in practice?
Review signer thresholds, independence, key management, and who can change the signer set. A multisig can still represent a concentrated dependency if control ultimately sits with a small group.
Show more
Price control
Who controls the price inputs the protocol relies on?
Oracle selection, configuration, fallbacks, and admin permissions can affect liquidations, borrowing, minting, redemptions, and other economically sensitive actions.
Show more
Holder controls
What authority do privileged actors have over individual holders?
Freeze, blocklist, seizure, burn, and pause permissions can determine whether holders retain unrestricted control over their assets and who can intervene.
Show more
Governance & protocol control
Who can change how the protocol works?
Upgrades, parameter changes, privileged roles, timelocks, and emergency powers determine who can alter the system and what safeguards constrain that authority.
Show more
Supply control
Who can change the supply of an asset, and under what conditions?
Minting, burning, supply caps, and the permissions that govern them can directly affect dilution, solvency, and the economic security of an asset.
Show more
It’s critical to routinely review access control and permission configurations.
Permissions accumulate and change over time. New integrations, roles, and dependencies can introduce new vulnerabilities.
We published our audit methodology so you can use it as a checklist ↓
Show more