$1,000,000 in security audit grants are live now, Apply here →

← Case Studies

Orderly

Security review case study

“As a security audit company, Keel Formal's approach to security and overall effectiveness is truly exceptional. Working with them has been a revelation – their auditors are among the best we've ever collaborated with.”

Slava GerashankoOrderly Network

Overview

This document serves as an exposition of the Keel Formal security review process, detailing an engagement between the Keel Formal team and Orderly Network.

Get a quote

Keel Formal

Keel Formal is a Smart Contract security service provider re-imagining the traditional audit model with two competing internal Keel Formal teams, Smart Contract fuzzing, and a Pay-Per-Vulnerability pricing alternative. Keel Formal’s novel approach effectively incentivizes their security team to uncover as many vulnerabilities as possible and leave no stone unturned.

Orderly

Orderly is a white label Orderbook trading infrastructure on the NEAR, Arbitrum, and Optimism networks boasting over $500,000,000 in total trading volume and 70,000+ active traders.

Why Keel Formal?

Keel Formal boasts a security team with extensive experience in banking, DeFi, economics, trading, and software correctness. As Orderly Network was launching the Smart Contract infrastructure for their EVM compatible perpetual derivatives offering, it was paramount to engage a team with rigorous experience with perpetual products. Having spent over a year performing security analysis on the GMX V2 perpetuals system among other perpetual derivatives protocols, Keel Formal was a clear choice.

Some of the best auditors we have worked with. The team is very prompt with communication, their domain expertise in DeFi, specifically derivatives, is unparalleled.

Slava GerashankoOrderly Network

The Report

View the report

Dissecting The Security Review

In the 2 week period from October 1st to October 13th, Orderly engaged Keel Formal to perform a security review of their perpetuals protocol utilizing an off-chain order book. During the engagement 3 security researchers spent a total of 6 person weeks to uncover multiple Critical & High severity findings in the project.

The Kickoff Call

The engagement officially began on October 1st with a kickoff call between Keel Formal and Orderly. During the kickoff call, members from Orderly Network shared an overview of the perpetuals system and answered probing questions from Keel Formal security researchers.

While on the kickoff call, members from Keel Formal confirmed the first finding with the Orderly team, a Critical logic error in the system Ledger contract, LGR-1.

“During the kickoff, the Keel Formal team came prepared with precise questions, instilling confidence in their capabilities.”

Slava GerashankoOrderly Network

The Research

Following the kickoff call, the Keel Formal team focused first on gaining a deep understanding of the codebase, constructing diagrams and carrying out internal discussions on the behavior of the system.

Following these discussions, Keel Formal identified several key points in the Orderly system which were vulnerable to exploitation. These findings were immediately shared with the Orderly team using a shared Notion database for the engagement.

The Testing

After gaining a strong understanding of the logic of Orderly’s Smart Contract system and having battle tested it against manual efforts, Keel Formal elected to conduct further assurance on the system with both stateful and stateless fuzzing efforts.

Keel Formal’s fuzzing efforts proved to be fruitful as they uncovered more findings such as ATPH-2 & ATPH-4 which were promptly shared with the Orderly team.

The Remediation

While Keel Formal continued to conduct the security review, Orderly engineers were able to implement the recommendations made — as these findings and recommendations were shared throughout the engagement.

After completing the two week period focusing on the frozen commit, Keel Formal conducted a comprehensive review of the remediations made by Orderly. Systematically, Keel Formal verified that the remediations made resolved the issues uncovered and did not introduce any new issues.

”From the very beginning, it was a seamless process. Within just a few days, they uncovered all issues, and their rapid review of fixes further underscores their efficiency.”

Slava GerashankoOrderly Network

Results

Throughout the 2 week engagement, Keel Formal uncovered 3 Critical, 2 High, 17 Medium, and 19 Low findings which were remediated by the Orderly team and promptly reviewed by Keel Formal.

Keel Formal’s attention to detail and immense verification efforts were key in preparing the codebase for a successful launch, garnering 8 figures of TVL seamlessly.

Get a quote

“Keel Formal’s swift and clear communication is a testament to their commitment, and their unparalleled domain expertise in DeFi sets them apart.”

Slava GerashankoOrderly Network