Trail of Bits Review of Liquidium Cross-Chain Loans
An independent review of the ICP canisters behind Liquidium’s cross-chain lending infrastructure, including the systems that support Bitcoin-backed borrowing across chains.
Liquidium completed an independent Trail of Bits review of the ICP canisters powering its native cross-chain lending infrastructure. The review covered the canister systems behind loan logic, asset interactions, and protocol behavior across networks, including infrastructure used for Bitcoin-backed and cross-chain borrowing.
For borrowers, lenders, and partners, the key takeaway is simple: Liquidium is strengthening the security foundation before scaling access to more assets and chains. The review helped identify implementation risks early, verify remediation work, and increase confidence in the infrastructure behind cross-chain loans.
For more context, read our guide to cross-chain loans or learn how to use Liquidium.
Review Findings & Remediation
Across the codebase for our ICP canisters, a total of 25 findings were reported during the review process. We reviewed each finding carefully, implemented fixes, and submitted updates for verification. After this process:
- 24 of 25 findings have been resolved
- 1 remaining finding is informational in nature
This outcome reflects the remediation work completed after the review. With only one informational item remaining, the review provides a stronger basis for evaluating the protocol’s current security posture.
What This Means for Users
The Trail of Bits review gives users a clearer view into the infrastructure behind Liquidium’s cross-chain loans. These systems support borrowing against assets like native Bitcoin without relying on third-party bridges or centralized wrapped tokens.
The review provides an independent assessment of the ICP canister infrastructure powering Cross Chain Loans. The product lets users supply collateral such as native Bitcoin and borrow assets on other chains in a non-custodial way.
The underlying infrastructure is powered by the Internet Computer Protocol’s Chain Fusion technology, which allows ICP canisters to interact directly with other blockchain networks.
How We Approach Security
The Trail of Bits review was important, but any audit only captures a moment in time. We ship code every day, so security work has to happen every day too.
Across our critical repositories and dependencies, we run recurring deep security scans using frontier models from OpenAI, Anthropic, and Moonshot AI/Kimi. We also use dedicated review tools including CodeRabbit, Codex Security CLI, and Codex CLI reviews. Every pull request goes through multiple model reviews as well as mandatory human review.
Dependabot monitors our dependencies for known vulnerabilities so affected packages can be updated immediately. Before a change reaches production, it is tested in a full pre-production environment by our team, Playwright automations, and AI agents.
We also keep our core code closed source on purpose. It makes an attacker’s job harder. This does not replace outside scrutiny: an external partner firm reviews all changes to our canister and smart contract code.
Production changes require multiple signatures from multiple parties. No single person can push a canister or smart contract update alone.
AI is moving fast, and so are attackers. We continuously adopt new models, tools, and review methods as the security landscape changes.
If you want to see how Liquidium’s cross-chain loans work in practice, open the app or read the Bitcoin-backed loans page for the borrower-facing overview.
For the broader market vision behind the product, see Cross-Chain Loans: The Future of Unified Liquidity.
View the report here: https://github.com/trailofbits/publications/blob/master/reviews/2025-11-liquidium-cross-chain-lending-securityreview.pdf
