Agentic DeFi Security Checklist
24 audit checks for AI systems that can recommend, approve, route, or execute DeFi actions across wallets, vaults, governance, and market infrastructure.
🚨 Agentic DeFi Threat Landscape
Agentic DeFi systems combine LLM ambiguity with financial authority. The decisive question is not whether the agent can answer incorrectly, but whether it can spend, approve, route, vote, or leak information in ways that move money or governance power.
• Financial sinks wallet execution, token approvals, vault withdrawals, bridge routing, and governance actions create direct loss paths
• Mixed-trust market data signals, proposals, docs, Discord, and social feeds can steer execution logic
• Credential concentration API keys, signing devices, session tokens, and relayers often collapse into one agent workflow
• MEV and timing risk latency, stale prices, and public transaction flow create attackable execution windows
• Approval theatre human approvals are often too coarse to validate amounts, recipients, routes, or calldata
• Governance spillover agents that can recommend or prepare actions can still shape treasury and protocol control
CATEGORIES
Financial Authority Inventory
CriticalThe audit enumerates every action the agent can recommend, prepare, sign, submit, or trigger that affects funds or governance
Recommendation vs Execution Separation
CriticalAdvisory outputs are cleanly separated from executable actions and signing authority
Argument-Level Human Review
CriticalApprovals validate recipients, assets, amounts, routes, deadlines, and calldata, not just the high-level action label
Per-Action Spend Limits
CriticalThe system enforces explicit limits for notional size, asset class, protocol exposure, leverage, and approval scope
Wallet Key Isolation
CriticalPrivate keys and signing devices are isolated from the reasoning runtime wherever possible
Approval and Allowance Hygiene
CriticalToken approvals are minimal, time-bounded, and revocable, with protections against broad or stale allowances
Signer Policy Attestation
HighSigning policies are versioned, reviewable, and tamper-evident
Multisig and Threshold Validation
HighWhen agents interact with multisigs, thresholds, modules, guards, and simulation layers are included in scope
Transaction Simulation Fidelity
CriticalAll high-impact actions are simulated with the same state assumptions and route parameters used for final submission
Route and Adapter Validation
CriticalRouters, bridges, vault adapters, and protocol connectors are allowlisted and pinned by expected semantics
Slippage, Deadline, and Retry Controls
HighExecution controls prevent unsafe retries, stale deadlines, and excessive slippage expansion during volatile conditions
State-Dependent Action Guardrails
HighAgents cannot trigger sensitive flows when insolvency, oracle outage, paused protocol state, or collateral degradation conditions are present
Cross-Chain Settlement Awareness
HighThe system models bridge delay, asynchronous settlement, destination chain failures, and partial completion risk
Market Data Provenance
CriticalPrices, liquidity, governance status, and risk signals are sourced from validated channels with freshness checks
Prompt-to-Trade Path Review
CriticalUntrusted text inputs cannot steer trade parameters, target protocols, or risk posture without explicit validation
Oracle and AMM Manipulation Resilience
HighThe agent accounts for manipulable on-chain prices, thin liquidity, MEV, and adversarial timing
Model Confidence Is Not a Control
MediumThe system does not treat model certainty or fluent rationale as evidence of market correctness
Governance Proposal Validation
CriticalProposal summaries, calldata, and vote recommendations are validated against canonical proposal content
Treasury Action Segmentation
CriticalTreasury management flows are segmented from research, social listening, and content-processing components
Emergency Pause and Revocation
HighOperators can pause execution, revoke approvals, disable connectors, and rotate credentials quickly
Financial Action Logging
HighEach recommendation, simulation, approval, signed payload, submitted tx, and post-trade outcome is recorded durably
Post-Execution Reconciliation
HighBalances, positions, receipts, and protocol state are reconciled after action completion
Loss Scenario Testing
CriticalThe audit explicitly tests scenarios involving bad fills, wrong approvals, wrong recipients, manipulated routes, and stuck funds
Operator Betrayal Scenarios
CriticalThe audit tests whether the system can leak strategy, front-run itself, or take actions contrary to treasury intent
Need an Agentic DeFi audit?
Zealynx audits AI systems with financial authority across wallets, trading flows, vaults, governance, and treasury operations.