Kann Audits / Security Review

Arche

Arche Yield Aggregator Security Review

Review of Arche’s Ethereum yield infrastructure for the USDC-backed arUSD ERC-4626 vault.

EthereumSolidityVyperERC-4626May 3, 2026
Download Report Open Report
Audit period
April 28–30, 2026
Researchers
3 listed
Scope
2 scoped paths
Technologies
Solidity, Vyper, ERC-4626
Findings
0 documented

Executive summary

What was reviewed

Review of Arche’s Ethereum yield infrastructure for the USDC-backed arUSD ERC-4626 vault.

This page reflects only the scope and review context disclosed in the published report. Fields the report does not provide are omitted rather than inferred; the PDF remains the source of record for issue detail and limitations.

Security is contextual. This report does not guarantee that the protocol is free from vulnerabilities. It applies to the review context documented in the report.

Scope & record

Engagement dossier

Audit period
April 28–30, 2026
Researchers
Kann, Lyubo, Sang
Codebase Repository
github.com/yieldarche/arche-contracts-audit
Audited commit
ac1519f
Final commit
ac1519f
Technologies
Solidity, Vyper, ERC-4626
Chain / ecosystem
Ethereum
Category
Yield Aggregator

Files and paths in scope

  • src/Yearn V3 Vault.vy
  • src/HealthCheckAccountant.sol

Findings overview

Severity distribution

The counts below are transcribed from the published report. Status and issue detail remain subject to that report’s exact terminology.

FINDINGS00Documented in the published report
No documented findings
SeverityCount
Critical0
High0
Medium0
Low0
Informational0

Published findings

Review outcome

No findings were identified in the published report.

That result applies only to the review context and limitations documented in the report.

Methodology

How Kann Audits reviews code

Kann Audits reports describe independent researcher review followed by collaborative analysis of findings and attack paths. The standard review foundation includes:

  1. 01Architecture and trust-boundary analysis
  2. 02Independent manual review
  3. 03State-transition and invariant analysis
  4. 04Access-control and integration review
  5. 05Adversarial testing and attack-path analysis
  6. 06Fix verification and regression review

Audit team

Researchers listed in the report

KannLyuboSang

Final assessment

Documented outcome

No critical, high, medium, or low-severity vulnerabilities were identified in the scoped contracts.

The assessment applies only to the review context and limitations documented in the published report. Missing details are not inferred, and later changes require separate analysis.

Start a conversation

Planning your next release?

Share the system, fixed scope, and target date. Build enough time into the plan for review, remediation, and verification.