Skip to content

Latest commit

 

History

History
61 lines (40 loc) · 4.58 KB

File metadata and controls

61 lines (40 loc) · 4.58 KB
title Security
description Audit status, how to report a vulnerability, and what SO4 does and does not guarantee about contract safety.
updated 2026-08-25
status stable

SO4's Soroban contracts have not been audited by a third party. No audit has been commissioned, none is in progress, and none has a scheduled date. If you are evaluating whether to deposit real value, treat the protocol as unaudited software and weigh that accordingly — see Risk for the full list of what can go wrong beyond contract defects specifically.

Audit status

Contract Audited By Date Report
exchange-router No — — —
synthetics-reader No — — —
order-vault No — — —
glv-router No — not yet deployed — — —
test-faucet / test-token No (testnet utilities, not production contracts) — — —

Current deployments are testnet-only — see Contract addresses. This table will be updated, contract by contract, the moment any audit is commissioned, in progress, or complete; until then every row reads "No" because that is the accurate answer.

Reporting a vulnerability

Do not open a public GitHub issue for a suspected vulnerability. A public issue discloses the problem to anyone before a fix exists.

Report privately instead, by messaging the project maintainer directly: t.me/ibrahimijai. Include:

  • What you found and why it's a vulnerability, not just unexpected behavior.
  • Steps to reproduce, or a proof of concept if you have one.
  • The affected contract, file, or endpoint.
  • Your assessment of severity and impact, if you have one — helpful, not required.

You will never be asked for your secret key, seed phrase, or any wallet credential to report or verify a vulnerability. A reproduction that needs a test account you control is normal; a request for your production keys is not part of any legitimate SO4 process.

Scope

In scope: the Soroban contracts in packages/contracts, the apps/web trading interface, the apps/s03-indexer indexer, and this documentation site's build pipeline — any of them being made to behave in a way that loses funds, bypasses an authorization check, or serves incorrect data as though it were verified.

Out of scope: third-party infrastructure SO4 depends on but does not control (Stellar network consensus, RPC provider availability, wallet extensions), and issues requiring physical access to a user's device.

Response time

There is no formally committed SLA yet. As a working expectation: acknowledgment within a few days of a report reaching the maintainer directly. This section will be updated with a firmer commitment once the disclosure process has been exercised enough times to make one honestly.

Safe harbour

Good-faith security research conducted within the scope above — without exploiting a finding beyond what's needed to demonstrate it, without accessing data that isn't yours, and reported privately rather than disclosed publicly first — will not be treated as a hostile act by the project. This is not a substitute for legal advice about your own jurisdiction.

Bug bounty

There is no bug bounty program. Reports are still welcome and will be credited (with permission) once a fix ships, but there is currently no monetary reward structure — this section will say so plainly if that changes.

Known limitations and accepted risks

  • No independent audit (above) — the largest single caveat on this page.
  • Oracle dependence. Pricing relies on external oracle feeds; a stale, manipulated, or unavailable feed can affect liquidations and execution prices. See Risk.
  • Testnet-only deployment. Current contract addresses are testnet; testnet tokens and state carry no real value and can be reset.
  • Interface trust. The interface prepares transactions for your wallet to sign; a compromised build of the interface (not just the contracts) could construct a malicious transaction. Always review what you're signing in your wallet, not just in the browser UI.
  • Rapidly changing code. The protocol and interface are under active development; behavior documented today can change before an equivalent audit or review catches up.

The full, longer list of what can go wrong — market, liquidation, oracle, contract, network, interface, and custody risk — lives at /concepts/risk; this page covers the security-process side specifically (audits, disclosure, scope), not the trading-risk side.