Building on it
The audit
The contracts and the custodian signing service were reviewed by CD Security in August 2026. What was in scope, what was found, and what an audit does not cover.
The contracts and the custodians' signing service were reviewed by CD Security in August 2026. This page says what they looked at, what they found, and what an audit cannot tell you.
Summary
| Item | Detail |
|---|---|
| Firm | CD Security |
| Completed | August 2026 |
| Scope | Subscription, Distributor, Ledger and Registry contracts, plus the custodian signing service. |
| Findings | 0 critical, 1 high (fixed), 3 medium (fixed), 5 low (4 fixed, 1 acknowledged) |
| Report | Full report available on request from security@cores.rent |
Findings
| Severity | Found | Fixed | Status |
|---|---|---|---|
| Critical | 0 | 0 | None found |
| High | 1 | 1 | Fixed and re-reviewed |
| Medium | 3 | 3 | Fixed and re-reviewed |
| Low | 5 | 4 | 4 fixed, 1 acknowledged |
| Total | 9 | 8 | 1 open by decision |
"Acknowledged" means the auditor and we agreed the issue is real but chose not to change the code, and wrote down why. The full report lists each finding, the fix, and the commit that fixed it.
What was in scope
- The four contracts: Subscription, Distributor, Ledger and Registry, at the addresses on Chain and addresses.
- The custodian signing service: the software that turns meter samples into hourly records, signs them and posts roots, including how it stores its key.
- The record format: the EIP-712 types, the hash chain and the Merkle tree construction.
What was not
- The meter module's hardware and firmware.
- Physical security at the data centers, and the custodians' own operations.
- Rental contracts with tenants, and whether tenants pay.
- The dashboard and website.
- The legal structure of the SPV.
- USDC, Ethereum itself, and wallets.
What an audit means
An audit is a careful read of the code by people paid to find what is wrong with it. It lowers the chance of a serious bug. It does not prove there are none, and it says nothing about code deployed after it. The deployed bytecode matches the audited commit, and you can check that on Etherscan against the published source.
Reporting a problem
If you find a vulnerability, email security@cores.rent before telling anyone else. Include what you found, how to reproduce it and, if you can, a record or transaction that shows it. We reply within two working days. Valid reports are paid in USDC: up to $100,000 for a critical issue that could move holders' funds, $25,000 for high, $5,000 for medium and $1,000 for low. To qualify, give us 90 days to fix the issue before you disclose it, and do not touch funds that are not yours.
Last updated 5 October 2026.