Summary
The most critical subjects covered in our audit are the correct distribution of funds among the recipients, the security of the funds held inside the contract, and the property that the recipients will jointly receive all the funds they are entitled to.
Furthermore, we generally reviewed the code for functional correctness, access control, arithmetic precision, and gas efficiency.
We originally found multiple issues. Very minor risks regarding blacklistable tokens have been accepted. All remaining issues have been addressed in subsequent versions. Hence, no security concerns remain from our side.
It is important to note that security audits are time-boxed and cannot uncover all vulnerabilities. They complement but don't replace other vital measures to secure a project.
About Aave Vault Revenue Splitter
Aave implements ATokenVaultRevenueSplitterOwner a new contract that will act as the owner of an ATokenVault and split the fees and rewards generated by the ATokenVault among fixed recipients according to predefined shares.