Softstack Audited DMD Diamonds Core Smart Contracts

Softstack Completes Core Smart Contract Audit for DMD Diamond’s DMDv4 EVM Base Layer.

Softstack Audited DMD Diamonds

Client

DMD Diamond

Project

Enterprise grade PoS blockchain

Industry 

Web3

Service

Smart Contract Audit

DMD Diamond is not a new name in crypto. As an enterprise-grade Proof-of-Stake blockchain built on the HBBFT-POSDAO consensus, it first launched its original mainnet back in 2013, and most recently upgraded to the DMDv4 EVM mainnet on October 13, 2025, bringing instant finality, DAO governance, and a modern smart-contract stack to the network. DMD is positioning itself as a secure, scalable base layer for decentralized innovation.

To support that vision, the DMD Diamond Association engaged Softstack to perform an in-depth security audit of the core smart contract stack – including staking, validator set management, block rewards, DAO governance and the claiming contracts used for legacy DMD v3 migration.

What We Audited

The scope of the audit covered three main components:

  • Core consensus & staking logic – contracts such as StakingHbbft, ValidatorSetHbbft, BlockRewardHbbft, ConnectivityTrackerHbbft, and related libraries.

  • DAO & governance contracts – the DiamondDao stack, quorum and proposal handling, and treasury governance.

Claiming / migration contracts – the ClaimContract used to migrate legacy DMD v3 coins to the new network through a trustless, signature-based mechanism.

Altogether, the review included more than 6,000 normalized lines of Solidity, multiple OpenZeppelin upgradeable components, and several custom libraries powering DMD’s validator rotation, bonus score system, and governance engine.

How Softstack Audited DMD Diamonds

Three independent Softstack experts reviewed the contracts in isolation, combining:

  • Line-by-line manual code review

  • Automated analysis (symbolic execution, static analysis, coverage checks)

  • Scenario-based testing around validator lifecycles, reward distribution, epoch transitions and DAO proposals

The team focused on:

  • Epoch & validator rotation – ensuring safe transitions, correct handling of disconnected validators, and no unexpected liveness failures.

  • Reward & pot distribution – validating the allocation of block rewards to deltaPot, reinsertPot and governancePot, with protections against overflow and unauthorized withdrawals.

  • Bonus score system – checking that performance incentives cannot be gamed or inflated.

  • Staking safety – confirming secure stake deposits, withdrawals, delegation and pool-level reward sharing.

Governance controls – verifying upgrade paths, treasury spending and parameter changes can only be triggered through properly authorized DAO processes.

Key Findings and Resolutions

Across the entire codebase, the audit identified 48 findings ranging from high to informational severity. These included:

  • Two high-severity issues

  • Fourteen medium-severity issues

  • Seventeen low-severity findings

  • Fifteen informational or best-practice observations

All findings were documented with clear impact analysis, proof-of-concept scenarios, and recommended fixes.

The DMD Diamond team then iterated closely with Softstack’s auditors, implementing code changes, adding protections and tightening edge-case handling wherever necessary. After remediation, the full codebase was re-checked twice, confirming that all issues had been successfully mitigated and that no regressions were introduced.

What This Means for the DMD Ecosystem

For validators, delegators and builders, the completed audit provides three key assurances:

  1. Resilient Consensus & Staking
    Epoch transitions, validator rotation, and reward distribution are designed and now additionally verified to behave deterministically even under edge conditions such as disconnected nodes or sudden stake shifts.

  2. Governance Ready for Growth
    With DAO-driven upgrades, proposal handling and treasury control living on-chain, the robustness of the governance contracts is critical. The audit strengthens confidence that parameter changes and protocol upgrades will be executed only through the intended governance flows.

Secure Migration from Legacy DMD
The claiming pipeline, which uses ECDSA signatures and Bitcoin-style addresses for legacy v3 holders, has been hardened against replay, signature-malleability and input-validation issues – helping protect both the old and new communities during migration.

About DMD Diamond

DMD Diamond is a fully launched, modular Proof-of-Stake blockchain platform powered by HBBFT-POSDAO consensus. It offers instant finality, energy-efficient validation and an on-chain DAO that has the power to upgrade the contracts and treasury allocation. The mainnet is live with staking, delegation, governance and legacy asset migration.

About Softstack

Softstack is a leading Web3 security and software engineering partner, with more than 1,200 smart contract audits and a zero-exploit rate, delivered for ecosystems such as Ripple, Tezos, TON, BitGo, Fetch.ai and others. The company specializes in deep protocol reviews, infrastructure deployments and production-grade Web3 development across EVM, SVM, Cosmos SDK, Substrate and L2 stacks.

Together, DMD Diamond and Softstack are raising the security bar for BFT-based Proof-of-Stake networks – proving that serious infrastructure deserves serious review.

Ready to get started?

📞 Book a free consultation at https://calendly.com/softstack

OR

📤 Email hello@softstack.io with a link to your code repository so we can review your codebase and get you an accurate quotation.

Would you recommend Softstack to fellow Web3 builders?

Join our Service Partner Program (SPP) and provide your network with a trustworthy partner.

✅ Fast tracked onboarding
✅ Heavily discounted rates
✅ Over 1 million dollars in partner savings via https://deals.softstack.io
✅ Lead sharing and co marketing support

👉 https://softstack.io/service-partner-program-spp

Services we provide

Softstack Case Studies

Click through our success stories and see how we have helped other companies
achieve their Web3 goals.

Smart Contract Audit for Strobe Finance Cross-Chain Money Market on XRPL EVM

Softstack Finalizes Smart Contract Audit for Strobe Protocol’s Cross-Chain Money Market on XRPL EVM.

Smart Contract Audit

Project

Cross Chain Money Market XRPL EVM

Industry 

Web3

Service

Smart Contract Audit

Strobe Protocol is redefining DeFi for XRP holders, bridging the XRPL ecosystem with EVM-compatible environments using secure cross-chain communication via Axelar. The platform enables users to lend, borrow, and participate in vault-based yield strategies while preserving full composability across chains.

🔍 Key Audit Focus Areas

The audit covered mission-critical components of the protocol including:

⚙️ Cross-Chain Messaging Integrity
Auditing Axelar-based GMP flows to ensure state consistency, prevent spoofing, and avoid fund desyncs.

💸 Lending & Borrowing Logic
Reviewing all withdrawal, borrow, repay, and liquidation flows for security and accounting accuracy.

🔐 Oracle & Interest Rate System
Validating price feed integrity and interest rate curve enforcement to ensure proper risk management.

⚠️ Edge-Case Defense
Testing DoS risks, state reentrancy, and gas-scaling impacts on core pool functions.

Key Findings and Resolutions

✅ All vulnerabilities were remediated with appropriate mitigations

Notable findings and fixes include:

  • Cross-chain state handling safeguard to prevent ledger inconsistencies on failed token transfers

  • Oracle validation and staleness checks to avoid price manipulation or liquidation errors

  • Post-liquidation reserve accounting bug patched

  • ERC-20 decimals check added to avoid DoS on reserves

This collaboration reinforces the importance of security in DeFi. With Softstack’s audit complete, Strobe Protocol is now ready to enter production with improved resilience and cross-chain safety.

 

📄 Read the full audit report here
🌐 Learn more about Strobe: https://strobe.finance

Services we provide

Softstack Case Studies

Click through our success stories and see how we have helped other companies
achieve their Web3 goals.