Audit report published Jan 2026. SVM · Rust (Anchor).
| Severity | Count |
|---|---|
| Medium | 3 |
| Low | 7 |
| Informational | 5 |
| Total | 15 |
Safe Edges reviewed version 2 of Clique's SVM programs, covering the merkle distributor, the lock hook and vesting streams, in January 2026. Fifteen issues were identified: three Medium, seven Low and five Informational. The Medium issues concern pre-funded accounts blocking claim initialisation, mints with a freeze authority, and a missing account in the ATA creation CPI that breaks the claim flow. The original report does not record a resolution status for any finding.
M-01 Attacker Can Block Token Distribution RecipientsM-02 Accepting Mints With Freeze Authority Enables Post-Claim FreezesM-03 Operator Can Break Claim Flow RecipientL-01 Revocation Forfeits Vested but Unclaimed Tokens to Revoke AuthorityL-02 Dynamic Recipient Toggle Bricks Pending ClaimsL-03 Vault Parameter Should Use SystemAccount TypeL-04 Base Account Constraint Prevents Protocol IntegrationL-05 Insufficient Timestamp Validation Allows Vesting Bypass via Instant or Pre-Vested StreamsL-06 Missing Chain Identifier Enables Cross-Chain Signature Replay AttacksL-07 Caller Can Redirect NFT Mint To Incorrect Token AccountI-01 Mutable Mint Allows Token Swap After Root PublicationI-02 No Fee Caps Allow Unbounded Fee ExtractionI-03 set_mint Lacks Mint Account Validation and Legacy Token EnforcementI-04 Frontrunning can pre-create stream ATA and DoS create_stream and create_nft_bound_streamI-05 Misspelled Helper Function receover_signer Hurts ClaritySend the repository and a commit hash through the contact form, message @bugtester25 on Telegram, or book a 30-minute scoping call. 200+ protocols audited · $4B+ secured · 0 hacks post-audit. Prefer email? info@safeedges.in.