Overview
Security audits are a critical component of Tori’s security infrastructure. All smart contracts undergo rigorous review by leading security firms before deployment.Audit Partners
Sherlock
Sherlock
Leading smart contract security platform protecting over $50 billion in assets across Web3 protocols.
- Thorough audit methodology
- Team of experienced security researchers
- Proven track record with major DeFi protocols
Nethermind
Nethermind
Leading blockchain research and software engineering firm providing security audits, infrastructure, and tooling across the Web3 ecosystem.
- Deep expertise in EVM smart contract security
- Thorough manual analysis combined with automated tooling
- Risk rating methodology based on OWASP principles
- Proven track record with major DeFi and infrastructure protocols
Audit Scope
Our audits cover all critical protocol components:Audit Reports
Available Reports
Findings Summary
All issues across both audits have been addressed, every finding was either fixed in code or formally acknowledged with a documented rationale.Bug Bounty Program
In addition to formal audits, we maintain an active bug bounty program.How It Works
1
Discover
Security researchers identify potential vulnerabilities in our smart contracts.
2
Report
Submit findings through our responsible disclosure process.
3
Verify
Our team verifies the validity and severity of the finding.
4
Reward
Valid findings receive rewards based on severity.
Severity Levels
Scope
The bug bounty covers:- All deployed smart contracts
- Integration vulnerabilities
- Economic attack vectors
- Access control issues
- Already known issues
- Third-party protocols
- Frontend/UI issues (separate program)
- Theoretical attacks without PoC
Reporting Vulnerabilities
Email: [email protected]What to Include
A good vulnerability report includes:- Clear description of the issue
- Step-by-step reproduction instructions
- Proof of concept (if applicable)
- Potential impact assessment
- Suggested remediation (optional)
Response Timeline
Ongoing Security
Security is not a one-time event. We maintain continuous security through:Re-Audits
Continuous Monitoring
Hypernative provides 24/7 monitoring of all protocol activity:- Anomaly detection
- Threat identification
- Automated alerting
- Risk scoring
Security Updates
We commit to:- Prompt patching of identified issues
- Transparent communication about security events
- Regular security status updates
Limitations
Verification
You can verify our security measures:Next Steps
Security Overview
Our comprehensive security approach
Contracts
View verified contract addresses
Backing
How trUSD is backed
Risks
Understand the risks