CoresRent
Open dashboard

Building on it

The audit

The contracts and the custodian signing service were reviewed by CD Security in August 2026. What was in scope, what was found, and what an audit does not cover.

The contracts and the custodians' signing service were reviewed by CD Security in August 2026. This page says what they looked at, what they found, and what an audit cannot tell you.

Summary

ItemDetail
FirmCD Security
CompletedAugust 2026
ScopeSubscription, Distributor, Ledger and Registry contracts, plus the custodian signing service.
Findings0 critical, 1 high (fixed), 3 medium (fixed), 5 low (4 fixed, 1 acknowledged)
ReportFull report available on request from security@cores.rent

Findings

SeverityFoundFixedStatus
Critical00None found
High11Fixed and re-reviewed
Medium33Fixed and re-reviewed
Low544 fixed, 1 acknowledged
Total981 open by decision

"Acknowledged" means the auditor and we agreed the issue is real but chose not to change the code, and wrote down why. The full report lists each finding, the fix, and the commit that fixed it.

What was in scope

  • The four contracts: Subscription, Distributor, Ledger and Registry, at the addresses on Chain and addresses.
  • The custodian signing service: the software that turns meter samples into hourly records, signs them and posts roots, including how it stores its key.
  • The record format: the EIP-712 types, the hash chain and the Merkle tree construction.

What was not

  • The meter module's hardware and firmware.
  • Physical security at the data centers, and the custodians' own operations.
  • Rental contracts with tenants, and whether tenants pay.
  • The dashboard and website.
  • The legal structure of the SPV.
  • USDC, Ethereum itself, and wallets.

What an audit means

An audit is a careful read of the code by people paid to find what is wrong with it. It lowers the chance of a serious bug. It does not prove there are none, and it says nothing about code deployed after it. The deployed bytecode matches the audited commit, and you can check that on Etherscan against the published source.

Reporting a problem

If you find a vulnerability, email security@cores.rent before telling anyone else. Include what you found, how to reproduce it and, if you can, a record or transaction that shows it. We reply within two working days. Valid reports are paid in USDC: up to $100,000 for a critical issue that could move holders' funds, $25,000 for high, $5,000 for medium and $1,000 for low. To qualify, give us 90 days to fix the issue before you disclose it, and do not touch funds that are not yours.

Last updated 5 October 2026.