Assetera Docs
Smart contracts

Security reviews

Independent security reviews of the Assetera contracts. Nethermind Security reviewed the primary settlement router and reported no issues at any severity.

Nethermind Security reviewed the Assetera primary settlement router and found nothing. No critical, high, medium, low, informational or best-practice issues. The full report is public:

The review at a glance

ReviewerNethermind Security
ReportSecurity Review Report NM-1013
Final report8 September 2026
SubjectAsseteraPrimarySales, the primary-market settlement router, and the modules it is assembled from
MethodManual review of the code, plus automated analysis tooling
Issues reportedNone, at every severity
Documentation assessmentHigh
Test suite assessmentHigh

The report also records the project's own Foundry suite as the reviewer ran it. Every test passed. One test was skipped, a fork test that needs a live mainnet endpoint.

What was reviewed

The scope is the contract family that executes a buyer's first acquisition of an asset. Nine Solidity files, and the reviewer notes their comment-to-code ratio in the report.

FileWhat it does
AsseteraPrimarySales.solThe entry point. Verifies the signatures, burns the nonces, then hands the money path to the settler
VenueSettler.solThe money path. Pulls the buyer's debit, calls the venue, measures both balance legs, refunds and pays the fee
IntentGate.solThe settlement intent: signature recovery, buyer consent, nonce and deadline handling
SettlementLimits.solThe per-currency, per-transaction cap on the authorised debit, closed by default
PrimaryTypes.solThe signed payload shapes and the type hashes they are bound to
PrimaryStorage.solThe namespaced storage layout behind the proxy
ISettler.sol, ISettlementLimits.sol, IIntentGate.solThe events and errors an indexer and an integrator decode

The reviewer describes the design in their own words in the System Overview section, which is a useful independent read of how settlement works. See Settlement router for the same ground covered from our side.

Reading the report against the current code

A security review is a point in time. The report names the exact commit that was reviewed, and the contracts repository has continued to move since. Treat the report as evidence about the design and the code as reviewed, and read the current source for what is deployed today.

The repository is public and the review boundary is recorded in it, so the two can be compared directly:

DocumentWhat it is
AUDIT-SCOPE.mdThe combined review boundary, and the entry point to the two below
AUDIT-SCOPE-PRIMARY.mdThe primary router's scope, which is what this review covered
AUDIT-SCOPE-SECONDARY.mdThe order book and the targeted-offer book

Next

On this page