Revert v4lend Competition

Revert v4lend Competition

@revert-finance
Live

Total reward

$50,000

No deposit required

Status

Live

Findings submitted

90

Start date

6 Oct 2026

End date

3 Nov 2026

KYC

Required to join

v4lend is a Uniswap v4-native lending and automation codebase built by Revert Finance.

It includes:

  • a lending vault that accepts Uniswap v4 LP NFTs as collateral,
  • a two-source oracle for valuing LP positions using Chainlink-compatible feeds with Uniswap v3 TWAP verification,
  • a Uniswap v4 hook for on-swap automation (auto exit, auto range, auto collect, auto lend, auto leverage),
  • standalone operator-driven automators for the same strategies outside the hook path,
  • vault transformers for atomic position management (range changes, compounding, leverage),
  • liquidation helpers and shared swap/planning utilities.

The system is built around Uniswap v4 LP positions as the core primitive: positions can be valued, financed, transformed, and automatically managed.

Prize Distribution and Scoring

  • Total Prize Pool: $50,000 USDC

Only High and Medium severity findings will be rewarded.

Documentation

Scope

  • Repository: revert-finance/v4lend
  • Commit: f6d0fb41b7487f60ce64e011312a956e184e2a75
  • Files:
    • src/vault/V4Vault.sol — ERC4626 lending vault, LP-NFT collateral, borrow/repay/liquidate
    • src/oracle/V4Oracle.sol — Chainlink + Uniswap v3 TWAP two-source oracle
    • src/RevertHook.sol and src/hook/** — swap-triggered automation hook and controllers
    • src/automators/** — standalone operator-driven automators
    • src/vault/transformers/** — vault-managed position transforms
    • src/shared/** — shared math, planning, and swap helpers

Build Instructions

git clone https://github.com/revert-finance/v4lend.gitcd v4lendforge buildforge test

Most of the suite runs against a mainnet fork. Fork tests read MAINNET_RPC_URL (falls back to a public RPC):

MAINNET_RPC_URL=<your archive RPC URL> forge test

Mandatory POC Rule

  • The mandatory POC rule applies to this competition.
    • All Critical/High/Medium findings require a valid coded POC before the end of the competition.

Out of Scope

  • Tests, scripts, and documentation under test/, script/, and docs/ — provided as context, not primary protocol scope.
  • Design behaviors the team has explicitly documented and accepted as intentional, including:
    • whole-balance sweep / flat-after-success accounting in hook helpers, transformers, and automators
    • AutoLend holding ERC4626 vault shares while a position is in its lent state
    • hook-managed swaps having no default amountOutMin floor (bounded instead by the oracle window and oracle pool-deviation guard) — AUDIT-ACCEPTED-HOOK-SWAP-NO-SLIPPAGE-FLOOR
    • a direct (non-vault) V4Utils range change leaving the replacement position without automation config — AUDIT-ACCEPTED-NONVAULT-REMINT-AUTOMATION-LOSS
  • Centralization risks / trusted-role assumptions — vault owner, hook owner, approved automator operators, and approved transformers are explicitly trusted actors per the protocol's trust model.
  • MEV, gas griefing, and frontrunning.
  • Frontend or off-chain components.

Previous Audits

This is v4lend's first external security review — no prior audit reports exist yet.

Contact Us

For any issues or concerns regarding this competition, please reach out to the Cantina core team through the Cantina Discord.