Myso Finance

Myso Finance – Core V1

Security Audit

Download Audit Report
Summary

MYSO Finance implements a borrowing system which does not expose borrowers to liquidation risks. Each loan has the same duration and does not rely on any price oracle or curve-based pricing.The most critical subjects covered in our audit are asset solvency, functional correctness, access control, and precision of arithmetic operations. Security regarding all the aforementioned subjects is high. In the first iteration of the engagement, we uncovered a few medium-severity issues related to the functional correctness that were addressed in the updated codebase.

The general subjects covered are upgradeability, documentation, trustworthiness, gas efficiency and code complexity. The contracts in scope of this review are not upgradable and do not have any privileged account, hence the security regarding upgradeability and trustworthiness is high. The project has extensive documentation and inline code specification. We reported possibilities to improve the gas efficiency which were acknowledged by MYSO Finance but not adopted due to code size restrictions. Regarding code complexity, we highlighted a functionality that implements a complex logic to optimize storage costs and could be simplified.

About Myso Finance – Core V1

MYSO v1 is a DeFi protocol that allows users to borrow without liquidation risk. For borrowers, this makes it easier to understand and manage crypto loans, while for lenders this provides new and sustainable yield enhancement opportunities.

The way this is achieved is through “zero-liquidation loans”, a novel risk transfer mechanism in which borrowers are relieved from liquidation risk while lenders get exposure to a physically settled covered call strategy.

The protocol operates without relying on any trusted third parties or oracles. Moreover, lending pools are isolated from one another such that potentially bad collateral assets in one pool cannot compromise the integrity of the others.

MYSO v1 can help mitigate some of the systemic risks associated with liquidation-centered credit markets, such as cascading liquidations, externalities from liquidation related MEV and oracle manipulation.

ChainSecurity has been an invaluable partner for us, and we highly recommend them to anyone looking for a high-quality audit. Their in-depth experience from having audited many of the leading DeFi projects made them the ideal sparring partner for us and provided rigorous preventative quality-assurance for our codebase. We were deeply impressed by their level of expertise, professionalism and attention to detail. We'd like to thank ChainSecurity again for their support and look forward to working with them again in the future.
Aetienne Sardon, Founder Myso Finance