This audit was performed by Carlos (Bloqarl) as an external contractor at Composable Security, prior to or alongside founding Zealynx Security. It is not a Zealynx engagement, but is included here as part of Carlos’s professional security record.
This audit is part of the Zealynx portfolio. Full details are being prepared for publication. Engagement scope and outcome available on request in the meantime.
Rain Vaults
Zealynx reviewed Rain Vaults as an external contractor engagement for Composable Security. Rain Vaults are non-custodial strategy vaults for Rain prediction markets on Arbitrum One: a manager trades, depositors hold pro-rata shares, and the design goal is that the manager can never withdraw depositor funds, only trade through an allowlisted set of Rain market functions whose positions and proceeds accrue back to the vault. The review covered the VaultFactory and RainVault contracts: share accounting and NAV, the FIFO withdrawal queue and permissionless force-unwind, manager trading and delegated trading keys, and fee minting. The report is being prepared for publication.
Scope
2 files · 733 SLOCFindings
click any row for the full write-upTeam & approval
Disclaimer
This audit is not an endorsement and does not constitute investment advice. Zealynx reviewed the codebase at the commits listed in section 02 over the engagement window. Findings are limited to issues identified within that scope and do not preclude the existence of other vulnerabilities. Subsequent code changes are not covered by this report unless the engagement is explicitly extended.