# Security Review - disORDerly --- ## Scope | | | |---|---| | **Mode** | ALL five production Solidity contracts; supplementary local review | | **Files reviewed** | `Disorderly721.sol`, `PayoutDistributor.sol`, `ProposalRegistry.sol`
`RoyaltyRouter.sol`, `DisorderlyAgentCollection.sol` (all under `contracts/contracts/`) | | **Confidence threshold (1-100)** | 80; reproduction required before a production fix | | **Source** | `audit-2026-09-12-remediation` -> `1b1291126d26cdc974aac9e77807fcc53ca15981` | | **Workflow** | [Pashov Solidity Auditor v3](https://github.com/pashov/skills/tree/c577eb7799c349de0acb187ba00ca98e14e436fd/solidity-auditor), pinned commit `c577eb7799c349de0acb187ba00ca98e14e436fd` | | **Method** | Nine specialist agents in batches, then three coordinator specialty passes after worker limits; all twelve specialties covered. Same AI model family/context lineage, not twelve independent audits. | | **Trust assumptions** | Tagged `docs/AUDIT-BRIEF.md` and `AGENTS.md`; trusted Safe signers, controlled application, configured oracle/WETH/registry dependencies, disclosed reveal and valuation assumptions | ## Findings **No new exploitable vulnerability was confirmed within the stated trust model. No production contract was changed.** This is a bounded review result, not evidence that no vulnerabilities exist. The original tagged contract suite passed **232 tests**. The final combined run passed **259 tests**, including **27 added local regression and limitation checks**. Specialist test counts overlap and must not be summed. The server suite, live host, Safe configuration and full secondary application scope were not re-audited in this run. The [evidence index](docs/audits/pashov-2026-09-10/README.md) contains source hashes, twelve coverage reports, exact reproduction instructions, final test output and the [candidate dispositions](docs/audits/pashov-2026-09-10/TRIAGE.md). --- Findings List | # | Confidence | Title | |---|---|---| | - | - | No confirmed in-model vulnerability; no production remediation applied | --- ## Leads No unresolved in-model exploit was established. Retain these qualified observations for the firm's assessment: - **Recipient gas exhaustion - `RoyaltyRouter.release` / `_send`.** Reproduced locally: two distinct recipients that exhaust forwarded gas prevent release at a supplied budget of 16,777,216 gas; all 10 ETH remain pending and the healthy third recipient is unpaid. Ordinary recipient reverts are isolated, arbitrary gas exhaustion is not. Production uses trusted Safe recipients, and no outsider path to install this behavior was established. The tested gas budget is not a live-network cap attestation. Disposition: conditional hardening/dependency note; review intended Safe handlers and decide whether arbitrary recipient behavior must be supported. Reproducer: `contracts/test/pashov/07-recipient-gas.test.js`. - **Nonuniform rotations - `Disorderly721.setStartingIndex` / `metadataId`.** Even assuming uniform raw residues 0..1110, council shift 1 has 13 preimages, shifts 2..10 have 12, and the other 90 have 11. Operator shift 1 has 3, shifts 2..99 have 2, and the other 912 have 1. Each tier remains a bijection; this does not establish uniform assignment probabilities. No concrete value-extraction scenario with the final artwork was demonstrated. Disposition: fairness/design question for the firm, alongside the already disclosed blockhash assumptions. Reproducer: `contracts/test/pashov/10-cross-lens.test.js`. The raw gas lead is preserved in the evidence and explicitly classified, rather than omitted. The coordinator corrected an arithmetic error in a raw reveal note through an initially failing test; the counts above are the tested values. No governance, quorum, tie, supervisor or reveal-policy change was made silently. --- > This review was performed by an AI assistant using Pashov's open-source workflow. It was not performed or endorsed by Pashov's human team. AI analysis cannot establish the absence of vulnerabilities. The independent firm's contract and agreed application-boundary review remains necessary before launch.