Lombard has launched an on-chain vault system where risk curators and asset managers offer Bitcoin yield products to users through a single vault deposit. Veridise audited the smart contracts behind that vault infrastructure, the strategy logic, blocklist, converters, shards, and validator, pairing manual review with property-based fuzz testing. The review found one high-severity bug, since fixed, and fixed 14 findings overall.
- Audit includes Lombard’s strategy, blocklist, converter, shard, and validator contracts, reviewed over 12 person-days.
- Manual review combined with OrCa fuzz testing against specifications of intended behavior.
- One high-severity migration-pricing bug was fixed; 14 findings fixed overall.
Twelve Person-Days on Five Contracts
Two Veridise analysts, Benjamin Mariano and Ajinkya Rajput, reviewed the contracts over six days between May 18 and May 26, 2026, a combined 12 person-days across five components: the ERC-20 share contract, the blocklist oracle, the asset converters, the shards that route capital externally, and the validator that constrains what shards can execute. This is the infrastructure behind Lombard’s first strategy product that launched with Flow Traders and CAP Protocol, where LBTC underwrites a Flow Traders borrow position and yield flows back to depositors.
The review combined manual line-by-line analysis with property-based fuzz testing: specifications for rounding direction, fee accrual, redemption fulfillment, and price rate-limiting, tested with OrCa, AuditHub’s specification-guided fuzzer. Manual review covered what a fuzzer can’t ask alone: whether the validator’s rulesets could contradict each other, and whether privileged roles were scoped tightly. The report doesn’t break findings down by technique.
The Bug That Could Have Reset Share Prices
The review’s findings spanned every severity level except critical: one high, three medium, ten low, four warning, two informational. Fourteen were fixed. The full audit report has the complete list, including the acknowledged items and Lombard’s stated rationale for each.
The high-severity bug sat in migrate, the function that brings an existing vault onto the new contract. It reset the migrated vault’s share price to a flat constant instead of carrying over the real price. Lombard fixed it by adding a migrator-specified price argument.
Two other fixed bugs show what a multi-asset vault produces: a medium-severity Chainlink converter whose rounding could zero out a $100,000 deposit under one mix of token and feed decimals, and a low-severity fee formula that minted shares against pre-fee supply instead of the post-fee fraction it owed. A few lower-severity issues were acknowledged instead of fixed, including a NAV-reconciliation branch that can let fee-share mints inflate reported assets until the next price update, an effect Lombard says self-corrects.
Why Catching This Early Matters for Depositors
Strategy shares are claims on Bitcoin-denominated collateral. A mispriced migration or an inflated NAV stay invisible until someone is already exposed to them, not the kind of bug a team catches in a post-mortem. Fixing them before the contracts carry real TVL matters to depositors and to partners like Flow Traders and CAP Protocol relying upon the strategy system. It also matters to Lombard, which engages multiple auditors on every upgrade before it ships. Matt Marshall, Head of Product at Lombard, described the engagement this way:
The end-to-end cycle was very seamless, from initial engagement through to project delivery. The level of interaction and collaboration with the team makes it almost feel like an extension of our day-to-day work, and that’s what gives us trust in the quality of the results.
Lombard is already live with its first strategy product, and the tools used in this engagement remain available through AuditHub as the contracts evolve. If your protocol converts between assets with different decimals and different Chainlink feed precisions, the same class of bug could be sitting in your code, since rounding and feed-decimal mismatches rarely show up in a diff review. If you want a second pair of eyes before your next deploy, talk to us; more on Lombard at Lombard (https://www.lombard.finance/).
What Did the Lombard Strategy Contracts Audit Find? The Takeaway
Veridise’s audit found one high-severity migration-pricing bug among a broader set of issues in the smart contracts behind Lombard’s vault infrastructure. Fourteen are fixed, the rest acknowledged with a stated rationale. Lombard runs the contracts in production behind its first strategy product.