Revert v4lend Competition
@revert-financeLive
Total reward
$50,000
No deposit required
Status
Live
Findings submitted
90
Start date
6 Oct 2026
End date
3 Nov 2026
KYC
Required to join
You need to be logged in as a researcher in order to join.
v4lend is a Uniswap v4-native lending and automation codebase built by Revert Finance.
It includes:
- a lending vault that accepts Uniswap v4 LP NFTs as collateral,
- a two-source oracle for valuing LP positions using Chainlink-compatible feeds with Uniswap v3 TWAP verification,
- a Uniswap v4 hook for on-swap automation (auto exit, auto range, auto collect, auto lend, auto leverage),
- standalone operator-driven automators for the same strategies outside the hook path,
- vault transformers for atomic position management (range changes, compounding, leverage),
- liquidation helpers and shared swap/planning utilities.
The system is built around Uniswap v4 LP positions as the core primitive: positions can be valued, financed, transformed, and automatically managed.
Prize Distribution and Scoring
- Total Prize Pool: $50,000 USDC
Only High and Medium severity findings will be rewarded.
- Scoring described in the competition scoring page.
- Findings Severities described in detail on our docs page.
Documentation
- Revert v4lend README
- Hook hierarchy overview
- End-to-end hook demo: script/demo/UnichainForkHookathonE2E.s.sol
Scope
- Repository: revert-finance/v4lend
- Commit:
f6d0fb41b7487f60ce64e011312a956e184e2a75 - Files:
src/vault/V4Vault.sol— ERC4626 lending vault, LP-NFT collateral, borrow/repay/liquidatesrc/oracle/V4Oracle.sol— Chainlink + Uniswap v3 TWAP two-source oraclesrc/RevertHook.solandsrc/hook/**— swap-triggered automation hook and controllerssrc/automators/**— standalone operator-driven automatorssrc/vault/transformers/**— vault-managed position transformssrc/shared/**— shared math, planning, and swap helpers
Build Instructions
git clone https://github.com/revert-finance/v4lend.gitcd v4lendforge buildforge testMost of the suite runs against a mainnet fork. Fork tests read MAINNET_RPC_URL (falls back to a public RPC):
MAINNET_RPC_URL=<your archive RPC URL> forge testMandatory POC Rule
- The mandatory POC rule applies to this competition.
- All Critical/High/Medium findings require a valid coded POC before the end of the competition.
Out of Scope
- Tests, scripts, and documentation under
test/,script/, anddocs/— provided as context, not primary protocol scope. - Design behaviors the team has explicitly documented and accepted as intentional, including:
- whole-balance sweep / flat-after-success accounting in hook helpers, transformers, and automators
AutoLendholding ERC4626 vault shares while a position is in its lent state- hook-managed swaps having no default
amountOutMinfloor (bounded instead by the oracle window and oracle pool-deviation guard) —AUDIT-ACCEPTED-HOOK-SWAP-NO-SLIPPAGE-FLOOR - a direct (non-vault)
V4Utilsrange change leaving the replacement position without automation config —AUDIT-ACCEPTED-NONVAULT-REMINT-AUTOMATION-LOSS
- Centralization risks / trusted-role assumptions — vault owner, hook owner, approved automator operators, and approved transformers are explicitly trusted actors per the protocol's trust model.
- MEV, gas griefing, and frontrunning.
- Frontend or off-chain components.
Previous Audits
This is v4lend's first external security review — no prior audit reports exist yet.
Contact Us
For any issues or concerns regarding this competition, please reach out to the Cantina core team through the Cantina Discord.