Skip to main content
Panoply
HomeSignal FlowsChartsTiersAbout
Sign InGet Started

Independent assessment

Panoply Security Review

Independent Smart Contract Security Assessment

Auditor
Obsidian Audits
Review period
March 18, 2026

Assessment outcome

No evidence of intentionally malicious functionality was identified within the reviewed codebase. Subject to the remediation of the findings presented in the report, the reviewed Panoply codebase demonstrates a security posture suitable for progression toward production deployment.

The protocol demonstrates a strong architectural foundation with a clear emphasis on transparency, modularity, and risk-aware design.

The auditor

About Obsidian Audits

Obsidian Audits is a blockchain security research organization specializing in decentralized finance (DeFi), smart contract security, protocol architecture, and digital asset infrastructure.

The team provides comprehensive security assessments for protocols deployed across EVM-compatible blockchains and emerging decentralized ecosystems. Every audit combines automated analysis, manual code review, threat modeling, and adversarial testing to identify vulnerabilities before deployment.

The objective of every engagement is to improve protocol security, protect user assets, and strengthen the reliability of decentralized applications through independent verification and actionable remediation guidance.

Objective

What was assessed for

The review focused on identifying vulnerabilities that could impact:

  • User funds
  • Protocol integrity
  • Access control
  • Asset accounting
  • Smart contract execution
  • Oracle integrations
  • Strategy execution
  • Portfolio valuation
  • Cross-chain operations
  • Vault security
  • Administrative permissions

Coverage

Audit scope

The assessment covered the core smart contract ecosystem, protocol architecture, and supporting infrastructure that power the Panoply platform.

Core Protocol

  • Vault Management Contracts
  • Portfolio Management Engine
  • Strategy Execution Engine
  • Signal Intelligence Engine
  • Risk Management Engine
  • Treasury Management Contracts
  • User Registry
  • Access Control Framework
  • Governance Contracts

Financial Infrastructure

  • Asset Accounting
  • Portfolio Valuation
  • Yield Distribution
  • Performance Fee Logic
  • Deposit and Withdrawal Mechanisms
  • Reward Distribution

External Integrations

  • Oracle Integrations
  • Multi-Chain Infrastructure
  • Wallet Authentication
  • Identity Verification (KYC) Interfaces
  • External Analytics Providers

Supporting Infrastructure

  • Administrative Roles
  • Emergency Controls
  • Upgradeability Mechanisms
  • Configuration Management
  • Event Logging
  • Monitoring Hooks

How it was done

Review methodology

Architecture Review

Evaluation of protocol design, contract interactions, and trust assumptions.

Manual Code Review

Line-by-line inspection of all contracts to identify logic flaws, unsafe assumptions, authorization issues, and state-transition errors.

Automated Analysis

Static analysis tools were used to detect known vulnerability patterns, insecure coding practices, and dependency risks.

Threat Modeling

Potential attack scenarios were modeled to evaluate protocol resilience against malicious actors.

Economic Analysis

Protocol incentives, vault accounting, portfolio valuation, and strategy execution were reviewed for manipulation risks.

Access Control Review

Administrative privileges, governance permissions, and privileged execution paths were evaluated for abuse potential.

Oracle Validation

Price feeds and external data dependencies were analyzed to ensure resistance against manipulation and stale data.

Cross-Chain Security

Cross-chain interactions, bridge assumptions, and asynchronous settlement mechanisms were reviewed for consistency and safety.

Classification

Severity levels

Findings are categorized by potential impact and likelihood of exploitation. The report does not publish per-severity counts.

SeverityDescriptionRecommended action
CriticalMay lead to immediate and severe compromise of protocol security - direct theft of user funds, complete protocol compromise, permanent denial of service, or unauthorized control of privileged functions.Resolve before deployment
HighSignificant security risk that could result in substantial financial loss under realistic attack conditions - major accounting inconsistencies, access control weaknesses, oracle manipulation, or privilege escalation.High priority remediation
MediumMay not directly compromise protocol security but can expose users or administrators to meaningful operational or financial risk - edge-case logic failures, incorrect validation, or misconfigured permissions.Resolve before major release
LowMinor security weaknesses, best-practice violations, or defensive improvements - minor validation issues, gas inefficiencies, event inconsistencies, or configuration improvements.Address during development cycle
InformationalNot exploitable vulnerabilities, but opportunities to improve code readability, documentation, maintainability, testing, developer experience, and operational processes.Consider for future improvements

Findings

Recommendations made

Several recommendations were made to strengthen:

  • Access control validation
  • Input validation
  • Emergency recovery procedures
  • Oracle dependency management
  • Strategy execution safeguards
  • Administrative controls
  • Event consistency
  • Documentation quality
  • Automated testing coverage

Observed

During the engagement

  • Clear separation of responsibilities between core modules.
  • Well-defined administrative boundaries.
  • Transparent accounting mechanisms.
  • Comprehensive event logging.
  • Modular contract architecture.
  • Strong consideration for operational risk.

Principles applied

Asset SafetyLeast PrivilegeDeterministic State TransitionsTransparent AccountingAccurate Portfolio ValuationReliable Oracle UsageSecure Cross-Chain CommunicationDefense in DepthFail-Safe DefaultsOperational Transparency

Ongoing

Security is not a one-time event

As with all decentralized financial systems, the auditor recommends:

  • Continuous security monitoring.
  • Independent audits for major upgrades.
  • Expanded automated testing.
  • Formal verification of critical financial logic where feasible.
  • Regular dependency reviews.
  • Bug bounty programs.
  • Periodic penetration testing.
  • Governance security assessments.

Disclaimer

This assessment reflects the security posture of the reviewed codebase at the time of the audit. While extensive testing and manual review were performed, no audit can guarantee the complete absence of vulnerabilities. Security is an ongoing process, and continuous monitoring, testing, and periodic reassessment are recommended as the Panoply protocol evolves.

This page summarizes the assessment reported by Obsidian Audits for the review period ending March 18, 2026. It is one component of a broader, continuous security program and is not a guarantee against loss.

Your keys, your crypto.

Panoply never takes custody of your assets. Every strategy runs non-custodially.

Get Started
Panoply

Product

FeaturesSignal FlowsVaultsPortfolio Builder

Platform

AboutSecurityTiers

Legal

Privacy PolicyTerms of ServiceDisclaimer

Panoply is operated by a company incorporated in the United Arab Emirates (Licence 35886) and a company incorporated in Saint Lucia (Reg. 2025-00579). Client funds are held by the Saint Lucia entity. Full details in our Terms of Service.

© 2026 Panoply. All rights reserved.