Smart Contract Security
Have the smart contracts been audited?
Yes. All Tori smart contracts are independently audited by Sherlock and Nethermind, two leading smart contract security firms. Sherlock protects over $50 billion in assets across Web3.View Audit Reports
Read our complete audit reports and findings
Is there a bug bounty program?
Yes. We maintain an active bug bounty program. Security researchers can earn rewards for responsibly disclosing vulnerabilities.
Report vulnerabilities to: [email protected]
How often are contracts audited?
Are the contracts upgradeable?
Yes. Contracts use upgradeable proxy patterns to allow security fixes and improvements. Safeguards in place:- Multi-signature approval required for upgrades
- Time locks on sensitive changes
- Transparent upgrade process
Asset Security
Where are assets held?
On-Chain Assets
Audited smart contracts with multi-signature controls and time locks
Off-Chain Assets
Qualified institutional custodians with segregated accounts
Is trUSD/strUSD insured?
No. trUSD and strUSD are not insured by:- Any government agency (like FDIC)
- Private insurance companies
Who are the custodians?
We work exclusively with qualified institutional custodians and partners that meet our rigorous due diligence standards:Can the team access protocol assets?
The protocol is designed with strict access controls:Verification & Transparency
How can I verify reserves?
Three ways to verify:1
Proof of Reserves
Check real-time attestations from Accountable for independent, third-party verification
2
On-Chain Data
Verify smart contract balances directly on Etherscan
3
Token Supply
Compare total trUSD supply against backing
How often are reserves verified?
Real-time. Proof of Reserves from Accountable updates continuously, not monthly or quarterly like traditional finance.Where can I see the Proof of Reserves?
Monitoring & Incident Response
How is the protocol monitored?
Hypernative provides AI-powered 24/7 threat detection:What happens during a security incident?
Our incident response process:1
Detection
Automated monitoring identifies the issue immediately
2
Assessment
Rapid triage to understand severity and potential impact
3
Containment
Immediate steps to limit damage (may include pausing operations)
4
Communication
Transparent updates through official channels
5
Remediation
Fix the underlying issue
6
Post-Mortem
Analysis and implementation of preventive measures
Can the protocol be paused?
Yes. Emergency pause capabilities exist for critical situations. This is a protective measure to prevent further damage during security incidents.Protecting Yourself
How can I stay safe?
Verify URLs
Only use app.tori.finance. Bookmark it to avoid phishing sites.
Verify Contracts
Check addresses on our Contracts page before interacting.
Secure Your Wallet
Never share private keys or seed phrases with anyone. Ever.
Stay Cautious
Be skeptical of DMs, airdrops, and “support” messages.
What are common scams to watch for?
What will Tori team NEVER do?
The Tori team will NEVER:- ❌ Ask for your seed phrase or private keys
- ❌ DM you first on social media
- ❌ Ask you to send tokens to “verify” your wallet
- ❌ Offer exclusive deals via DM
- ❌ Ask you to download software outside the official app
What security features should I use?
Reporting Issues
How do I report a security vulnerability?
Email: [email protected] Please include:- Clear description of the vulnerability
- Steps to reproduce
- Proof of concept (if applicable)
- Potential impact assessment
Responsible disclosure: Please don’t publicly disclose vulnerabilities before they’ve been addressed. We commit to
acknowledging reports within 24 hours.
How do I report a scam or phishing attempt?
Email [email protected] with:- Screenshots of the scam
- URLs involved
- Any other relevant details
I think my wallet was compromised
If you suspect unauthorized activity:- Stop - Don’t make any more transactions
- Move assets - Transfer remaining tokens to a new, secure wallet
- Report - Create a ticket on our Discord for support
- Document - Save transaction hashes and screenshots
Security Approach
How does Tori approach security?
Security is multi-layered. We don’t rely on any single protection:What are the limitations?
No system can guarantee perfect security. We’re transparent about this:- Audits are point-in-time assessments
- New attack vectors can emerge
- DeFi is experimental by nature
More Questions?
For security-related inquiries: [email protected] For general support: Join our DiscordSecurity Overview
Our comprehensive security approach
Audit Reports
View detailed audit reports
Risk Disclosures
Understand all risks involved
Contracts
Verify contract addresses