Back to Home

Smart Contract Security

Security Audit Report

AUREX (ARX) Token Presale System — March 2026

Download PDF

AUDIT PASSED

No Critical, High, Medium, or Low severity vulnerabilities found. The AUREX smart contract system is considered secure for mainnet deployment.

0

Critical

0

High

0

Medium

0

Low

4

Info

Advisory only

Audit Details

Audit TypePrivate Manual Security Review
Report DateMarch 2026
Scope4 Solidity Contracts
CompilerSolidity ^0.8.24
FrameworkHardhat + OpenZeppelin v5 + Chainlink
VerdictPASSED — No Actionable Findings

Contracts in Scope

Presale.sol

Core presale logic, stage management, purchases, bonus distribution

~430 lines
PresaleToken.sol

ARX ERC-20 token, transfer lock, allocation minting

~130 lines
TeamVesting.sol

Cliff-based vesting for team allocation (10% of supply)

~100 lines
LiquidityLock.sol

Time-locked liquidity storage (minimum 365 days)

~70 lines

Security Strengths

ReentrancyGuard on every external function — state updates precede all external calls

Immutable core addresses — no post-deploy oracle or token substitution possible

Bonus reserve accounting — admin cannot drain the pending bonus pool

Transfer lock exempts only protocol contracts — no insider EOA exemptions at deploy

Irrevocable vesting and liquidity locks — cliffEnd and unlockTime cannot be shortened

Comprehensive event emissions covering all critical state changes

Dual-treasury architecture with zero-address validation and mutual-exclusion checks

Robust Chainlink oracle integration with staleness, round validation, and non-negative checks

Informational Observations

Advisory only — no security risk. Optional future improvements.

I-01

Consider Ownable2Step

Two-step ownership transfer prevents accidental key loss. Advisory only.

I-02

Treasury routing inline docs

Add NatSpec clarifying ETH+USDT → treasury1, USDC → treasury2. Advisory only.

I-03

claimAllBonuses() gas docs

Document expected max stage count and gas estimate. Advisory only.

I-04

extcodesize on feed address

Add extcodesize check on ethUsdFeed constructor parameter. Advisory only.

Full Audit Report

Download the complete PDF — 10 pages covering all findings, methodology, and security analysis.