Security reviews
Independent security reviews of the Assetera contracts. Nethermind Security reviewed the primary settlement router and reported no issues at any severity.
Nethermind Security reviewed the Assetera primary settlement router and found nothing. No critical, high, medium, low, informational or best-practice issues. The full report is public:
The review at a glance
| Reviewer | Nethermind Security |
| Report | Security Review Report NM-1013 |
| Final report | 8 September 2026 |
| Subject | AsseteraPrimarySales, the primary-market settlement router, and the modules it is assembled from |
| Method | Manual review of the code, plus automated analysis tooling |
| Issues reported | None, at every severity |
| Documentation assessment | High |
| Test suite assessment | High |
The report also records the project's own Foundry suite as the reviewer ran it. Every test passed. One test was skipped, a fork test that needs a live mainnet endpoint.
What was reviewed
The scope is the contract family that executes a buyer's first acquisition of an asset. Nine Solidity files, and the reviewer notes their comment-to-code ratio in the report.
| File | What it does |
|---|---|
AsseteraPrimarySales.sol | The entry point. Verifies the signatures, burns the nonces, then hands the money path to the settler |
VenueSettler.sol | The money path. Pulls the buyer's debit, calls the venue, measures both balance legs, refunds and pays the fee |
IntentGate.sol | The settlement intent: signature recovery, buyer consent, nonce and deadline handling |
SettlementLimits.sol | The per-currency, per-transaction cap on the authorised debit, closed by default |
PrimaryTypes.sol | The signed payload shapes and the type hashes they are bound to |
PrimaryStorage.sol | The namespaced storage layout behind the proxy |
ISettler.sol, ISettlementLimits.sol, IIntentGate.sol | The events and errors an indexer and an integrator decode |
The reviewer describes the design in their own words in the System Overview section, which is a useful independent read of how settlement works. See Settlement router for the same ground covered from our side.
Reading the report against the current code
A security review is a point in time. The report names the exact commit that was reviewed, and the contracts repository has continued to move since. Treat the report as evidence about the design and the code as reviewed, and read the current source for what is deployed today.
The repository is public and the review boundary is recorded in it, so the two can be compared directly:
| Document | What it is |
|---|---|
AUDIT-SCOPE.md | The combined review boundary, and the entry point to the two below |
AUDIT-SCOPE-PRIMARY.md | The primary router's scope, which is what this review covered |
AUDIT-SCOPE-SECONDARY.md | The order book and the targeted-offer book |
Next
Settlement router
AsseteraPrimarySales in detail: what is signed and by whom, and how a settlement is judged on measured balances.
Primary issuance
The end-to-end flow a buyer goes through, and what an integrator has to build.
Source on GitHub
The public contracts repository: MIT licensed Solidity, Foundry tests and the audit scope documents.