Audit report published Nov 2025. SVM · Rust (Anchor).
| Severity | Count |
|---|---|
| High | 1 |
| Medium | 4 |
| Low | 5 |
| Informational | 4 |
| Total | 14 |
Safe Edges reviewed Clique's merkle distributor program for SVM chains, written in Rust with Anchor, in November 2025. Fourteen issues were identified: one High, four Medium, five Low and four Informational. The High issue charged the claim fee on the gross allocation rather than the claimable amount, so incremental claims were overcharged. All fourteen were fixed.
H-01 Claimer Can Be Overcharged During Claim — ResolvedM-01 Base Account Constraint Prevents Protocol Integration — ResolvedM-02 Accepting Mints With Freeze Authority Enables Post-Claim Freezes — ResolvedM-03 Missing Chain Identifier Enables Cross-Chain Signature Replay Attacks — ResolvedM-04 Mutable Mint Allows Token Swap After Root Publication — ResolvedL-01 No Fee Caps Allow Unbounded Fee Extraction — ResolvedL-02 Misleading comment — ResolvedL-03 set_mint Lacks Mint Account Validation and Legacy Token Enforcement — ResolvedL-04 Dynamic Recipient Toggle Bricks Pending Claims — ResolvedL-05 Missing event emission for a critical state update function — ResolvedI-01 Unused Imports — ResolvedI-02 Missing State Change Guards — ResolvedI-03 Vault Parameter Should Use SystemAccount Type — ResolvedI-04 Misspelled Helper Function receover_signer Hurts Clarity — ResolvedSend the repository and a commit hash through the contact form, message @bugtester25 on Telegram, or book a 30-minute scoping call. 200+ protocols audited · $4B+ secured · 0 hacks post-audit. Prefer email? info@safeedges.in.