Derive
September 2024
Bounty Meridian reviewed Derive, formerly Lyra, with focus on liquidation pathways, manager health checks, account state, and protocol accounting. The case study is useful for derivatives and margin protocol teams where edge-case health logic can turn into loss or denial-of-service risk.
Engagement snapshot
Bounty Meridian conducted a security review of Derive (formerly Lyra) focusing on liquidation pathways, account health checks, and accounting consistency. The report spotted multiple high-severity/high issues and supporting /low/informational findings that influence liquidation safety and operational resilience. Remediation recommendations target prevention of loss-inducing edge cases and stronger safeguards in manager and liquidation flows.
By the numbers
Total findings
25
High + severe findings
6
Scope we covered
-
Liquidation logic
Liquidator behavior, bid mechanics, and conditions that can affect fund safety.
-
Account health checks
Manager-side health logic and denial-of-service resilience.
-
Protocol accounting
Consistency of state transitions and balance assumptions across intricate flows.
Related services
Related notes
Looking for a security audit?
Book a scoping talk