Security

Audit

The auction subsystem, the settlement path, and the claim contracts have completed independent third-party review. The report is published in full, including findings that were acknowledged rather than fixed and the reasoning behind each decision.

In scope Covers
Auction round Deposit accounting, entry conversion, window state exclusivity, the clearing test.
Waterfilling Cap enforcement, convergence of the iterative path, largest-remainder conservation.
Settlement Leaf construction, root immutability, proof verification, replay and re-entrancy.
Graduation Proceeds conversion and Canonical LP creation.
Fee routing & staking Split arithmetic and per-pool reward isolation.

The Invariant Suite

Independently of the audit, the implementation proves a set of release-blocking properties on every build — an implementation that violates any one of them does not ship:

  • 7 invariants covering state exclusivity, cap enforcement, conservation, refund non-negativity, entry-conversion integrity, proof integrity, and failure atomicity
  • a randomized fuzz suite on the order of 10,000+ runs over 1–120 addresses with randomized deposit sizes
  • zero tolerance — the counted incidence of negative refunds, over-cap allocations, over-principal allocations, and conservation violations must each be exactly zero

Full list on Invariants.

Two different guarantees

The invariant suite proves the allocation mathematics is correct. The audit reviews everything the mathematics sits on top of — access control, external calls, upgrade surface, economic assumptions. Neither substitutes for the other, and the docs treat them as separate claims.

Reporting a Vulnerability

Report suspected vulnerabilities to SECURITY_CONTACT. Please include the affected contract address, a description of the impact, and reproduction steps.

Item Commitment
Acknowledgement Within 24 hours.
Initial assessment Within 72 hours.
In scope All contracts listed on Contracts & Addresses.
Out of scope Front-end issues without on-chain impact, and third-party infrastructure.

Please do not disclose publicly before a fix is deployed. Reports made in good faith under this policy will not be pursued.

results matching ""

    No results matching ""