AGP Picks
View all

Trusset protocol audit clears 17 findings

4 hours ago
By AI, Created 20:31 UTC, Jun 22, 2026, AGP -

softstack completed an independent security audit of Trusset’s core protocol on June 22, 2026, and resolved all 17 issues it found. The review covered smart contracts tied to tokenization, trading and credit for regulated real-world assets, giving Trusset a clean final audit result across four production repositories.

Why it matters: - The audit gives Trusset a key security checkpoint for a regulated tokenization stack built around real-world assets, trading and credit. - A zero-open-issues result can matter to institutions that need evidence of compliance, custody and contract safety before deploying capital or integrating infrastructure. - The findings covered areas that are especially sensitive in regulated finance, including identity checks, oracle integrity, upgrade controls and liquidation logic.

What happened: - softstack completed an independent security audit of the Trusset Core Protocol on June 22, 2026. - The review covered six smart contract suites across four Solidity codebases. - The audit identified 17 issues, and Trusset resolved all 17 in collaboration with softstack. - The final review verified fixes on the audited commits across four production repositories.

The details: - The audit used manual expert review and automated security testing. - The protocol areas reviewed included ERC-3643 transfer compliance, KYC/AML identity registry integration, UUPS upgradeability, oracle price integrity, overcollateralized lending, Dutch-auction liquidations, hybrid orderbook custody and ERC-20 transfer robustness. - softstack independently verified all eight of Trusset’s pre-audit security claims. - The stock token license suite includes ERC-3643 security tokens with corporate actions, sub-issuer controls and compliance-enforced force transfers. - The stock lending suite includes overcollateralized lending markets, an interest rate model, a price oracle, an insurance fund, Dutch-auction liquidations and a shared liquidation router. - The commodity token license suite includes ERC-20 commodity tokens with reserve-enforced minting and a primary market sale module. - The commodity orderbook license suite uses hybrid custody with off-chain matching, on-chain settlement and token-enforced compliance. - Two additional suites were covered by reference: Commodity Token Lending shares the audited Stock Lending codebase, and Stock Orderbook License shares the audited Commodity Orderbook codebase. - Every finding and mitigation applies equally to each paired suite. - The audit result broke down as 10 High, 5 Medium and 2 Low issues, all resolved. - No findings remain open or acknowledged without a fix. - Trusset said the audit mattered because regulated finance requires uncompromising review across every contract path. - softstack said tokenized securities and commodities are difficult systems because compliance, custody and credit all run on the same rails.

Between the lines: - The clean result suggests Trusset can point to third-party validation as it pushes a compliance-first infrastructure story for regulated assets. - The scope indicates the protocol is not just a token wrapper; it combines issuance, trading, lending and governance in one stack, which raises the security bar. - A verified fix set across high-severity findings is likely to be more meaningful to enterprise users than a simple pass/fail audit badge.

What's next: - Trusset will likely use the audit as part of its positioning with financial institutions evaluating on-chain tokenization infrastructure. - softstack remains available for security assessment inquiries at softstack.io. - Trusset directs readers to its company information for more details.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Technology Presswire Netherlands

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Technology Presswire Netherlands

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.