Skip to main content
Every Tori contract went through independent review before deployment. Both reports are public: Every finding across both audits was either fixed in code or formally acknowledged with a documented rationale.

Who audited

Sherlock is a smart contract security platform that has historically secured over $50 billion in assets across Web3 protocols. Nethermind is a blockchain research and engineering firm whose security practice pairs manual analysis with automated tooling and rates risk on OWASP principles. The audits covered the core protocol contracts, the trUSD token, strUSD staking and unstaking, access control, and the oracle integration.

Bug bounty

The bounty runs continuously and pays by severity: In scope: all deployed smart contracts, integration vulnerabilities, economic attack vectors, and access control issues. Out of scope: already-known issues, third-party protocols, frontend and UI issues (a separate program), and theoretical attacks without a proof of concept.

Reporting a vulnerability

Email [email protected]. A useful report has a clear description of the issue, steps to reproduce, a proof of concept where applicable, and your read on the impact. A suggested fix is welcome but not required. What happens next:
Please do not disclose a vulnerability publicly before it has been addressed, exploit it beyond what is needed to demonstrate the issue, or access other users’ data. We take no legal action against good-faith researchers, and we credit reporters after fixes ship if they want the credit.

After the audit

An audit is a snapshot, so review does not stop at deployment. Major updates trigger a re-audit of the changed components, new features are audited before they ship, and Hypernative monitors the deployed contracts in production. Issues that surface get patched promptly and communicated openly.

Limitations

Important to understand:
  • Audits reduce risk but don’t eliminate it
  • New vulnerabilities may be discovered after audits
  • Economic attacks may not be caught by code audits
  • Third-party dependencies carry their own risks
Please review our complete Risk Disclosures.

Verify it yourself

The audit PDFs above are hosted by the auditors, not by us. Contract source is verified on Etherscan, with every address listed on the contracts page. The bounty is live; write to [email protected].

Next steps

Security overview

The full stack: audits, monitoring, attestation, custody

Roles and timelocks

Who holds which key, and what the timelock gates

Contracts

Verified addresses on mainnet

Risks

The complete risk disclosures