defirisk.co
rubric v1.7.0

Audit scope mismatch

Stargate Finance's assessment for RD-F-001 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Two v2 audit PDFs exist in the `audits/` folder of the GitHub repo (Zellic FINAL and OtterSec Final). Etherscan confirms StargatePoolUSDC at 0xc026395860Db2d07ee33e05fE50ed7bD583189C7 is source-verified at `v0.8.22+commit.4fc1097e` with "Exact Match." However, the Zellic report is inaccessible via web fetch (HTTP 403 on reports.zellic.io), so the specific commit SHA cited in the reports cannot be independently verified against the deployed bytecode. Zellic's public page confirms a June 2024 r...

Sources #

Methodology #

Check whether the commit SHA cited in the audit report matches the bytecode deployed at the production proxy/implementation address.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol stargate factor RD-F-001 score yellow collected_at 2026-04-28 01:38:41