What you will accomplish
- Confirm the report date and exact contracts reviewed
- Read the findings and informational notes
- See what the audit does not cover
- Know what must still be monitored
Before you begin
- The June 25, 2026 audit PDF
- Access to Ethereum, XDC, and Polygon explorers
- The technical overview for architecture context
Verify the report identity and date
Confirm the title, review date, version, publisher, and source URL. Quote.Trade’s report titled “V5 Primary Funding Contracts and V1 Fallback/Hotwallet Architecture” is dated June 25, 2026. Save a hash or archived copy for institutional records.
List the contracts the report covers
The report covers V5 funding on Ethereum and XDC, the constrained V1 Ethereum fallback/hotwallet, and PositionManager on Polygon and XDC. Record the network and address, whether the source code is verified, whether the contract is upgradeable, and what the contract does.
Understand what PASS means
The report lists no Critical, High, Medium, or Low findings and six informational items. PASS applies only to the reviewed public contracts and the assumptions stated in the report; it does not mean the entire platform has no risk.
Review the protections described in the report
The report describes role separation, three time-spaced snapshots before withdrawals, cooldowns, hourly and daily withdrawal caps, replay protection, liquidity checks, emergency freeze, signer rotation, and public events.
Read what the audit excludes
The report does not cover private code, the matching and risk engine, databases, APIs, pricing, liquidation logic, signer custody, penetration testing, legal or compliance analysis, accounting, proof of reserves, or solvency. Those systems and controls must be reviewed separately.
Check what the report could not verify
The report did not verify the private engine or server code, signer custody, infrastructure security, solvency, legal matters, or a live V5 withdrawal sample. Treat those as separate checks.
Recheck after any contract or architecture change
Recheck the contract addresses, administrator roles, source verification, upgradeability, withdrawal activity, emergency events, and a small deposit-withdrawal test after any material contract or architecture change.
Common problems and fixes
Does the audit cover the entire Quote.Trade platform?
No. Apply the audit conclusion only to the contracts and evidence listed in the report. The private matching and risk engine, infrastructure, signer custody, solvency, and legal analysis are outside the stated scope.
What if a production contract changes?
Do not rely on the prior report for the new deployment until the migration and any updated review are documented.
What if the XDC source is verified later?
Record the new evidence separately or obtain a dated supplemental review. Do not silently treat the older report as if it covered the later change.
Does a later successful withdrawal change the audit?
No. It is useful live evidence, but it does not change what the report reviewed on its stated date.