Skip to main content

Overview

Security audits are a critical component of Tori’s security infrastructure. All smart contracts undergo rigorous review by leading security firms before deployment.

Audit Partners

Sherlock

Sherlock

Leading smart contract security platform protecting over $50 billion in assets across Web3 protocols.
Why Sherlock:
  • Thorough audit methodology
  • Team of experienced security researchers
  • Proven track record with major DeFi protocols

Nethermind

Nethermind

Leading blockchain research and software engineering firm providing security audits, infrastructure, and tooling across the Web3 ecosystem.
Why Nethermind:
  • Deep expertise in EVM smart contract security
  • Thorough manual analysis combined with automated tooling
  • Risk rating methodology based on OWASP principles
  • Proven track record with major DeFi and infrastructure protocols

Audit Scope

Our audits cover all critical protocol components:

Audit Reports

Available Reports

Findings Summary

All issues across both audits have been addressed, every finding was either fixed in code or formally acknowledged with a documented rationale.

Bug Bounty Program

In addition to formal audits, we maintain an active bug bounty program.

How It Works

1

Discover

Security researchers identify potential vulnerabilities in our smart contracts.
2

Report

Submit findings through our responsible disclosure process.
3

Verify

Our team verifies the validity and severity of the finding.
4

Reward

Valid findings receive rewards based on severity.

Severity Levels

Scope

The bug bounty covers:
  • All deployed smart contracts
  • Integration vulnerabilities
  • Economic attack vectors
  • Access control issues
Out of scope:
  • Already known issues
  • Third-party protocols
  • Frontend/UI issues (separate program)
  • Theoretical attacks without PoC

Reporting Vulnerabilities

Email: [email protected]

What to Include

A good vulnerability report includes:
  • Clear description of the issue
  • Step-by-step reproduction instructions
  • Proof of concept (if applicable)
  • Potential impact assessment
  • Suggested remediation (optional)

Response Timeline

Ongoing Security

Security is not a one-time event. We maintain continuous security through:

Re-Audits

Continuous Monitoring

Hypernative provides 24/7 monitoring of all protocol activity:
  • Anomaly detection
  • Threat identification
  • Automated alerting
  • Risk scoring

Security Updates

We commit to:
  • Prompt patching of identified issues
  • Transparent communication about security events
  • Regular security status updates

Limitations

Important to understand:
  • Audits reduce risk but don’t eliminate it
  • New vulnerabilities may be discovered after audits
  • Economic attacks may not be caught by code audits
  • Third-party dependencies carry their own risks
Please review our complete Risk Disclosures.

Verification

You can verify our security measures:

Next Steps

Security Overview

Our comprehensive security approach

Contracts

View verified contract addresses

Backing

How trUSD is backed

Risks

Understand the risks