Public Report

// audit details
Finalized public report

EquitX

Synthetic on-chain real-world equities

code review
November 17, 2025SorobanCode Review Audit

Critical / High

4Highest severity

Medium

3Moderate risk

Low / Informative

9Lower severity

Report files

1Downloadable assets

Audit lifecycle

Public reports represent completed engagements with finalized deliverables.

Completed
1

Completed

Scheduled

Scope, timeline, and review plan were agreed.

2

Completed

In Progress

Manual review and verification work were carried out.

Current stage

Completed

The engagement wrapped with a published final report.

Executive Summary

High-level assessment and conclusions

A concise overview of the audit scope, core findings, and the key outcomes from the engagement.

EquitX engaged Runtime Verification Inc. to perform a security audit of its smart contracts. The audit was conducted between October 13 and November 17, 2025. The objective was to assess the correctness and security of the EquitX on-chain implementation, identify vulnerabilities or design inconsistencies, and provide actionable recommendations to strengthen the protocol ahead of mainnet deployment.

EquitX enables the creation, management, and exchange of xAssets—synthetic on-chainrepresentations of real-world equities. Users can deposit collateral, mint xAssets, trade them, manage collateralized debt positions (cDPs), participate in stability pools, and access real-time analytics directlyfrom their wallet. The protocol aims to make traditionally inaccessible financial instruments globally available through a decentralized, transparent, and fully on-chain model.

The audit consisted of a manual code review of the smart contract codebase. No fuzzing, formalverification, or backend review was included in the scope of this engagement. Runtime Verification’s analysis focused on contract logic, authorization flows, invariant correctness, token handling, collateralization mechanics, and other components critical to the safety of user positions and protocol funds.

Overall, code quality was strong, with clear structure, consistent patterns, and readable implementation. During the course of the engagement, the EquitX team responded promptly to all reported issues, andremediated them in a timely and effective manner. The fixes applied by the team generallydemonstrated a solid understanding of the underlying risks and resulted in meaningful improvements tothe protocol’s safety.

Reports

Download the audit artifacts

Access the published PDF deliverables associated with this engagement.

1 file

PDF report 1

20251210 EquitX.pdf

Download the published report for this engagement.

Download PDF