Skip to main content

Security Audits

Olla's core contracts have been independently audited by Pashov Audit Group. The full report is available as a PDF:

Download the Olla Security Review (PDF)

About Pashov Audit Group

Pashov Audit Group consists of 40+ freelance security researchers, who are well proven in the space -- most have earned over $100k in public contest rewards, are multi-time champions or have truly excelled in audits with us. We only work with proven and motivated talent.

With over 300 security audits completed -- uncovering and helping patch thousands of vulnerabilities -- the group strives to create the absolute very best audit journey possible.

While 100% security is never possible to guarantee, we do guarantee you our team's best efforts for your project.

Check out their previous work here or reach out on Twitter @pashovkrum.

Disclaimer

A smart contract security review can never verify the complete absence of vulnerabilities. This is a time, resource and expertise bound effort where we try to find as many vulnerabilities as possible. We can not guarantee 100% security after the review or even if the review will find any problems with your smart contracts. Subsequent security reviews, bug bounty programs and on-chain monitoring are strongly recommended.

Executive Summary

A time-boxed security review of the ollafinance/core repository was done by Pashov Audit Group, during which ast3ros, DemoreXTess, TejasWarambhe, trtrth, ValvesSecurity engaged to review Olla. A total of 58 issues were uncovered.

Project NameOlla
Protocol TypeERC7540 liquid staking protocol
TimelineApril 8th 2026 - April 21st 2026
Review commitf9c8502
Fixes review commit5be8601

Scope

ContractContract
OllaCore.solRewardsAccumulator.sol
IOllaCore.solIRewardsAccumulator.sol
GovernanceLib.solIOllaGovernance.sol
OllaGovernance.solISafetyModule.sol
SafetyModule.solRolesLib.sol
StakingManager.solStakingProviderRegistry.sol
IAztecRollup.solIAztecRollupRegistry.sol
IStakingManager.solIStakingProviderRegistry.sol
AztecTypes.solBN254Lib.sol
QueueLib.solOllaVault.sol
StAztec.solWithdrawalQueue.sol
IOllaVault.solIStAztec.sol
IWithdrawalQueue.sol

Reporting a Vulnerability

Please follow the Security Policy for responsible disclosure.

warning

Do not open a public GitHub issue or pull request for security vulnerabilities.