Clave

Smart Contract Audit for Clave Wallet

Cantina Security Report

Organization

@getclave

Engagement Type

Cantina Reviews

Period

-


Non-Custodial Wallet Infrastructure Review of Clave

The Clave protocol delivers a modular, non-custodial smart wallet built on Account Abstraction principles.
It leverages secure enclaves like Android TrustZone to streamline user onboarding and key management across mobile devices.

To ensure secure extensibility and fault-tolerant design, Clave partnered with Cantina for a detailed review of its zkSync-based smart contract suite.
The audit included wallet logic, recovery modules, paymasters, and validator hooks—each contributing to the safe execution of account-based workflows.

By proactively engaging in security audits, Clave demonstrates its commitment to resilient wallet infrastructure.

Cantina complements this work with services like multisig security, bug bounty programs, and crowdsourced security competitions to support long-term security and user trust.


Findings

High Risk

3 findings

3 fixed

0 acknowledged

Medium Risk

4 findings

4 fixed

0 acknowledged

Low Risk

4 findings

3 fixed

1 acknowledged

Informational

10 findings

10 fixed

0 acknowledged

Gas Optimizations

3 findings

3 fixed

0 acknowledged