Spark ALM Curve Controller Audit for MakerDAO
Cantina Security Report
Organization
- @makerdao
Engagement Type
Cantina Reviews
Period
-
Repositories
Curve Liquidity Controller Review of MakerDAO Spark ALM
MakerDAO introduced the Spark ALM Controller to manage Curve liquidity positions across its stablecoin ecosystem, enabling capital-efficient participation and automated vault strategies. The controller interacts with Curve pools to deposit, withdraw, and swap assets using protocol-defined limits, slippage protections, and relayer-based execution.
To verify the integrity of these systems, MakerDAO engaged Cantina for a security audits review of the Spark ALM controller. The audit focused on slippage enforcement, virtual price misalignments, Curve rate limit configuration, and edge cases across liquidity functions—ensuring secure handling of sDAI and similar assets in low-liquidity conditions.
Cantina also supports stablecoin liquidity protocols like Spark with comprehensive solutions such as bug bounty programs, crowdsourced security competitions, and multisig security, reinforcing safe vault execution and governance-led liquidity strategies.
Findings
Medium Risk
3 findings
2 fixed
1 acknowledged
Low Risk
2 findings
1 fixed
1 acknowledged
Informational
2 findings
1 fixed
1 acknowledged
Gas Optimizations
1 findings
0 fixed
1 acknowledged