Re treats independent security review as a standing requirement, not a one-time milestone. Sherlock recently completed a security audit of the NAV oracle stack, which publishes the daily onchain value of reUSD and reUSDe.
The Importance of Oracle Audits
Oracles are a critical component of DeFi infrastructure. An oracle is the connection between a protocol and the outside world: the mechanism that brings offchain price data onchain for smart contracts to act on.
Lending Markets: need to know what a borrower's collateral is worth.Perpetuals Exchanges: require the price of the asset being traded.Stablecoins: must continually track the value of the reserves behind them.
That data doesn't exist onchain on its own; an oracle reports it, and every contract downstream treats that report as a source of truth.
That very importance of oracles also makes them a constant target. A protocol's smart contracts will act automatically on any price they're handed, so they can be targeted via oracle exploits even if they're written and audited perfectly. If an exploit corrupts the price that an oracle reports, the contract has no way to know it. It executes exactly as designed, but it does so on a number that is false, with the potential for the protocol to be drained of millions of dollars in the process.
That threat is real, not hypothetical. DeFi protocols were drained of roughly $40 million via oracle exploits in July alone, and one affected protocol was forced to shut down operations entirely. For any protocol that prices assets onchain, oracle security is a continuous and existential concern. Any responsible engineering team stays diligent as a matter of course, but that diligence has a limit: a team can test only for the failures it can foresee. Independent auditors are a critical bulwark to cover anything that the team may have missed.
About the Audit
As the means by which the daily mint and redeem price for reUSD and reUSDe are published onchain, Re's NAV oracle is the most consequential pricing component in the protocol. That published figure is the reference integrators read from and the value that the protocol's smart contracts use when minting and redeeming.
The oracle is therefore one of the highest-value surfaces an attacker can reach: if the published figure were wrong, everything downstream that trusted it would be wrong alongside it. That makes independent review essential, and Re treats it that way.
Toward this end, Re contracted with Sherlock [1], a security firm built around adversarial review, structured so that independent researchers are rewarded for the vulnerabilities they surface. For this engagement, security researchers KupiaSec and vinica_boy examined the NAV oracle stack from July 15 to 18, 2026.
The Results
Sherlock sorts audit findings into three categories:
High: directly exploitable security vulnerabilities that require urgent attentionMedium: security vulnerabilities that may not be directly exploitable or may be exploitable only under certain conditions, and must be addressedLow/Informational: non-exploitable, informational findings that do not pose a security risk or impact the system's integrity, and are not considered a priority for remediation
Re's audit produced zero High, one Medium, and five Low/Informational findings.
The single Medium finding was not exploitable by an unprivileged outside attacker; it required control of an authorized NAV-submission key. Even with that key, however, an attacker could only have raised the NAV slightly beyond the system's intended cap by splitting one increase into several smaller steps, rather than moved it freely. The underlying issue was a gap between how the system behaved and how its documentation described it.
The Low/Informational findings were all minor edge cases, none of them exploitable by an outside attacker.
All issues were addressed before the audit report was published, as confirmed by the report itself. The report may be viewed here [2].
A Commitment to Security and Transparency
This audit adds to an existing record rather than beginning a new one. Re maintains an ongoing commitment to security and transparency.
Re's smart contracts have been audited [3] by Hacken and Certora across multiple engagements and formally verified by Certora. The protocol's reserves are attested daily by The Network Firm and published onchain through Chainlink. The Sherlock audit brings the newest and most price-critical component of the system under the same discipline. The onchain component of Re's business is held to the same scrutiny the offchain reinsurance side has always required: no one extends trust to an unexamined balance sheet. All audit results are available to users on the Re App (https://app.re.xyz).
About Re
Re is the onchain protocol connecting real-world reinsurance capital with decentralized finance. Its flagship product, reUSD, is a deposit token issued by Resilience Foundation Cayman LLC and made available to non-U.S. persons in specific geographies. The Re ecosystem brings together the onchain "re" protocol at re.xyz, operated by Resilience Foundation Cayman LLC, with the regulated reinsurance business under the "Cover Re" brand at coverre.com, operated by Cover Reinsurance SPC Ltd., a Cayman Islands Class B(iii) licensed exempted segregated portfolio company. Resilience Foundation, Resilience (BVI) Ltd, and Resilience Inv SPC do not provide insurance or reinsurance services and do not hold an insurance license. Learn more at re.xyz.
About Sherlock
Sherlock provides complete lifecycle security for onchain systems, from development through launch and live operations. Its work spans private audits, contests, AI-native security reviews, bug bounties, and exploit coverage, giving teams different ways to pressure-test code before and after it reaches production. For Re, Sherlock conducted a private audit of the NAV oracle stack, focusing on the contracts and integrations responsible for pricing reUSD and reUSDe onchain. Learn more at sherlock.xyz.
Learn More
For a full accounting of protocol metrics, visit the Re App. For more on the protocol, visit the Re docs.
Visit the Re App: https://app.re.xyz
#reinsurance #CryptoSecurity #AuditReport Sources
https://sherlock.xyzhttps://sherlock-files.ams3.digitaloceanspaces.com/reports/2026.07.25%20-%20Final%20-%20Re.xyz%20Collaborative%20Audit%20Report%201784984640.pdfhttps://docs.re.xyz/transparency-and-data-show-me-the-receipts/audits-attestations-custody-structure
Disclosures
This blog post is for informational and educational purposes only and does not constitute investment, legal, tax, or financial advice. Nothing in this article should be construed as an offer or solicitation to buy or sell any security, token, or financial product.
Affiliate disclosure. The "re" brand, the re protocol, and re.xyz are operated by Resilience Foundation Cayman LLC ("Resilience Foundation"), an Exempted Limited Guarantee Foundation Company incorporated in the Cayman Islands with Limited Liability with registered number IC-414560, together with its affiliate Resilience (BVI) Ltd and Resilience Inv SPC. Resilience Foundation, Resilience BVI, and Resilience Inv do not provide insurance or reinsurance services, do not act as insurance broker or agent, and do not hold an insurance license. All regulated reinsurance activities are conducted exclusively by Cover Reinsurance SPC Ltd. ("Cover Re SPC"), a Class B(iii) licensed exempted segregated portfolio company in the Cayman Islands, operating under the "Cover Re" brand at coverre.com.
Risk disclosure. Digital assets and blockchain-based products involve significant risk, including the potential loss of principal, smart contract vulnerabilities, liquidity constraints, and regulatory uncertainty. Any references to APR, returns, or performance are not guaranteed, and past performance is not a reliable indicator of future results.
Regulatory environment. The regulatory environment for digital assets, stablecoins, tokenized real-world assets, and onchain financial products is dynamic and continues to evolve across jurisdictions. The information in this post reflects the understanding as of the date of publication and may not reflect subsequent legal or regulatory developments. Readers should consult qualified legal, tax, and financial professionals before making any decisions.
Terms apply. For full terms, disclosures, and risk disclaimers, please see the Re website (https://re.xyz), Terms of Service (https://re.xyz/terms), and Disclaimers (https://docs.re.xyz/disclaimers).