Skip to main content
Reflect Banner

Audits

Reflect’s onchain programs have been independently reviewed by Offside Labs and by Adevar Labs. The number of reviews differs by program, since some were added more recently than others, so each program’s history is listed below. Reports are published in full rather than summarised, in the audits repository, and findings were addressed before publication. The Adevar Labs reports are being prepared and will be linked here.

Programs And Their Reviews

Core: Yield Routing

Directs and manages yield across every product.Offside Labs, September 2025 · Offside Labs, February 2026 · Adevar Labs

Core: Indexes

Builds and maintains baskets of collateral behind a single token.Adevar Labs

Tranches

Splits a yield-bearing asset into senior and junior positions and enforces the loss waterfall.Offside Labs · Adevar Labs

Whitelabel

Issues branded, yield-bearing tokens against collateral in Reflect, including the zero-fee swap path for retail-sized transactions.Offside Labs, November 2025 · Adevar Labs
Reviews without a link above have reports awaiting publication.

Two Kinds Of Review

Code security audits

Line-by-line review of the programs themselves, looking for exploitable flaws: access control gaps, unvalidated accounts, arithmetic errors, privilege escalation, and anything that could move funds where they should not go.

Economic security audits

Review of the strategy rather than the code. Simulation and backtesting of how a strategy behaves under stress, including scenarios well outside normal conditions, carried out by firms specialising in financial rather than software review.

What An Audit Does And Does Not Tell You

  • It is a point in time. Each report reviews specific code as it stood on a specific date. Code changed afterwards is outside that report’s scope, which is part of why programs are reviewed more than once.
  • It is not a warranty. A clean report means reviewers found no unresolved issues in what they examined. It is not a statement that no flaw exists.
  • Code review and strategy review are separate. A code audit says nothing about whether a strategy is economically sound, and an economic audit says nothing about whether the code implementing it is safe. Both matter, which is why both happen.
  • It covers Reflect’s programs, not everyone else’s. Reserves sit in third-party lending markets with their own code and their own audit histories. Those are worth reading separately, and are covered under Risk.

Next

Risk

What can go wrong, what reduces it, and what you can do.

Compliance

How the architecture affects your regulatory position.