Every finding across both audits was either fixed in code or formally acknowledged with a
documented rationale.
Who audited
Sherlock is a smart contract security platform that has historically secured over $50 billion in assets across Web3 protocols. Nethermind is a blockchain research and engineering firm whose security practice pairs manual analysis with automated tooling and rates risk on OWASP principles. The audits covered the core protocol contracts, the trUSD token, strUSD staking and unstaking, access control, and the oracle integration.Bug bounty
The bounty runs continuously and pays by severity:
In scope: all deployed smart contracts, integration vulnerabilities, economic attack vectors, and
access control issues. Out of scope: already-known issues, third-party protocols, frontend and UI
issues (a separate program), and theoretical attacks without a proof of concept.
Reporting a vulnerability
Email [email protected]. A useful report has a clear description of the issue, steps to reproduce, a proof of concept where applicable, and your read on the impact. A suggested fix is welcome but not required. What happens next:After the audit
An audit is a snapshot, so review does not stop at deployment. Major updates trigger a re-audit of the changed components, new features are audited before they ship, and Hypernative monitors the deployed contracts in production. Issues that surface get patched promptly and communicated openly.Limitations
Verify it yourself
The audit PDFs above are hosted by the auditors, not by us. Contract source is verified on Etherscan, with every address listed on the contracts page. The bounty is live; write to [email protected].Next steps
Security overview
The full stack: audits, monitoring, attestation, custody
Roles and timelocks
Who holds which key, and what the timelock gates
Contracts
Verified addresses on mainnet
Risks
The complete risk disclosures