Firepan · Continuous Audit Report · FP-AUDT-2026-0001
Curve twocrypto-ng: V1.0 → V2.0 Continuous Review
Firepan's continuous review of Curve Finance's twocrypto-ng AMM, tracking findings from V1.0 (commit 1ee2471, 2026-04-21) through V2.0 (commit d737d45, 2026-05-18). Issued 2026-05-26.
Status Summary
- F-7 (High) — donation-protection arming soundness defect: discovered post-ship by external security researcher Zero (zknpr.xyz), independently re-verified by Firepan as resolved at commit d737d45. Baseline-subtraction analysis found no asymmetric value capture in any tested attack shape; honest LP principal was not at risk. Exact mechanism, reproduction steps, and per-pool exposure figures are redacted from this public report at Curve's request, since the same class of rounding behavior touches live deployed pools.
- F-1 (Medium) — withdrawal quote views overquote after an admin-fee claim: fix-claimed.
- F-2, F-3, F-8, F-9 (Low): dust-donation griefing, third-party surplus capture (clarification request), allowlist scope mismatch, and admin donation-parameter discontinuity — all fix-claimed.
- Three governance recommendations (GOV-1, GOV-2, GOV-3) from V1.0 independently verified resolved at V2.0.
Run a free surface scan on your own contracts →
Read the companion case study at firepan.com/case-studies/curve/.