$1,000,000 in security audit grants are live now, Apply here →

← Case Studies

Dolomite

Security review case study

“The Keel Formal team’s attention to detail is top-notch. Sometimes when you get an audit done, you wonder how closely the team looked at your code and considered all surface area for attacks. We sleep soundly at night knowing that Keel Formal went through every detail of our codebase rigorously.”

Dolomite

Overview

This document serves as an exposition of the Keel Formal security review process, detailing the engagement between the Keel Formal team and Dolomite protocol.

Get a quote

Keel Formal

Keel Formal is a Smart Contract security service provider re-imagining the traditional audit model with two competing internal Keel Formal teams, Smart Contract fuzzing, and a Pay-Per-Vulnerability pricing alternative. Keel Formal’s novel approach effectively incentivizes their security team to uncover as many vulnerabilities as possible and leave no stone unturned.

Dolomite

Dolomite is a next-generation decentralized money market protocol and DEX that offers broad token support and capital efficiency with its virtual liquidity system. Dolomite is capable of offering over-collateralized loans, margin trading, spot trading and other financial instruments.

Why Keel Formal?

Keel Formal boasts a security team with extensive experience in banking, DeFi, economics, trading, and software correctness. With a module as complex as Dolomite’s GM pools, it was paramount that Dolomite engaged a highly specialized team offering rigorous attention to detail. Keel Formal was exactly that team.

“Keel Formal is amongst the most effective teams in the whole industry. They have a clear attention to detail that most auditors don’t have.”

Dolomite

The Report

View the report

Dissecting The Security Reviews

In November of 2023 Keel Formal conducted a security assessment of Dolomite’s GMX V2 module. The auditing approach championed manual analysis to uncover novel exploits and heavy usage of Dolomite’s test suite to construct corner case tests and PoC’s.

A team of four security researchers, with two Lead Security Researchers, began a 2-week Keel Formal review on the 1st of November. The review began with a kickoff call, where the Dolomite team detailed the GMX V2 integration and the Keel Formal team stress tested the design with precise questions.

Throughout the review, findings and recommendations were shared with the Dolomite team as they were uncovered by Keel Formal. Explicit written PoC (proof-of-concept) tests accompanied High and Critical issues. Keel Formal and Dolomite teams maintained continuous communication throughout the audit to discuss the findings uncovered, potential remediations, and design improvements.

During the 2 week review a total of 2 Critical, 4 High, 13 Medium, and 15 Low findings were uncovered by Keel Formal, confirmed and promptly remediated by Dolomite, and these remediations were finally reviewed again by Keel Formal.

“S-tier! Extremely professional and they know their practice really well.”

Dolomite

Results

During the review a total of 2 Critical, 4 High, 13 Medium, and 15 Low findings were reported and remediated. Keel Formal takes the fix review process extremely seriously, uncovering a newly introduced Critical vulnerability from the remediations. After engaging with Keel Formal, the Dolomite team is much more confident in the security of their codebase.

Get a quote

“Our team feels really good about the state of the system because of the degree of scrutiny it has gone under for the audit”

Corey CaplanDolomite