Security First: Consensys Diligence Audits STRATO's Native Bridge and Timelock Governance

Earn real yield on gold, silver & crypto — live on STRATO.
Launch AppCross-chain bridges are some of the most security-sensitive systems in all of DeFi. Before shipping native token bridging on STRATO, we did what we believe every serious platform should do: we put the code in front of independent experts and published the results.
Today we're releasing the engagement summary from Consensys Diligence — the security research team that has been auditing Ethereum smart contracts since 2017 — covering their review of STRATO's native token bridging contracts and timelock-based governance changes.
Download the audit engagement summary (PDF)
What Was Reviewed
Consensys Diligence conducted a two-week engagement from May 4 to May 15, 2026, with a total effort of 20 person-days across two auditors, George Kobakhidze and Martin Ortner. The review focused on two changesets:
Native token bridging (PR #6913) — four new contracts supporting native token bridging between STRATO and an external EVM environment:
StratoNativeBridge.solStratoNativeCustodyVault.solStratoNativeRepresentationBridge.solStratoNativeRepresentationToken.sol
Timelock governance (PR #6932) — timelocked action queuing and configurable instant-execution paths in the AdminRegistry governance contract, plus a full review of the MercataBridge contract.
What Was Found
The initial review produced 30 findings — 1 Critical, 10 Major, 6 Medium, 8 Minor, and 5 Informational — concentrated in four areas:
- Bridge lifecycle and custody. Tightening the multi-step deposit and withdrawal state machine so intermediate states can't be bypassed by transaction ordering, gating abort and recovery paths against external-chain settlement, and hardening custody accounting against token implementations with transfer callbacks.
- Timelock correctness. The integrity of the new timelock execution path, the initialization surface of the registry, self-governance and whitelist semantics, and consistent event emission for administrative actions.
- Role separation. Places where distinct privileged roles were collapsed onto a single address, and recommendations for clearer separation between operational and administrative roles.
- Monitoring and operational clarity. Event coverage, lifecycle metadata, and documentation of design assumptions relevant to relayers and monitoring.
How We Responded
We treated the findings as a roadmap, not a report card. The STRATO team completed a remediation pass addressing the key and prioritized findings — and Consensys Diligence reviewed that remediation too. Code changes included:
- Reentrancy protections in the native custody vault
- Simplifications to the withdrawal lifecycle
- Restrictions on the post-confirmation abort window
- Representation token management improvements
- Hardening of
AdminRegistryinitialization - Reordering of queued state invalidation ahead of external calls in governance execution
- Improved event coverage across several areas
Role separation on the external representation bridge was addressed through deployment runbook procedures, and a set of design assumptions and operational responsibilities was documented for STRATO operators.
Why We're Publishing This
At STRATO, "Verify Everything" applies to our own code just as much as it applies to the metal in our vaults. Bridges fail when teams treat audits as a checkbox. We'd rather show you the scope, the findings, and the fixes — and keep inviting scrutiny as the platform evolves.
As Consensys Diligence notes, this was a time-boxed review of selected changesets, and security is never "done." Continued review, testing, and operational monitoring are part of how we ship.
Download the audit engagement summary (PDF) — and if you'd like a copy of the full report, contact the STRATO team.
Ready to put audited infrastructure to work? Head to STRATO to get started, or join the conversation on Telegram.
Start earning on STRATO
Bridge crypto, borrow against gold and silver, and put your assets to work.
Launch App