| title | Security |
|---|---|
| description | Audit status, how to report a vulnerability, and what SO4 does and does not guarantee about contract safety. |
| updated | 2026-09-04 |
| status | stable |
SO4's Soroban contracts have not been audited by a third party. No audit has been commissioned, none is in progress, and none has a scheduled date. If you are evaluating whether to deposit real value, treat the protocol as unaudited software and weigh that accordingly — see Risk for the full list of what can go wrong beyond contract defects specifically.
| Contract | Audited | By | Date | Report |
|---|---|---|---|---|
exchange-router |
No | — | — | — |
synthetics-reader |
No | — | — | — |
order-vault |
No | — | — | — |
glv-router |
No — not yet deployed | — | — | — |
test-faucet / test-token |
No (testnet utilities, not production contracts) | — | — | — |
Current deployments are testnet-only — see Contract addresses. This table will be updated, contract by contract, the moment any audit is commissioned, in progress, or complete; until then every row reads "No" because that is the accurate answer.
Do not open a public GitHub issue for a suspected vulnerability. A public issue discloses the problem to anyone before a fix exists.
Report privately instead, by messaging the project maintainer directly: t.me/ibrahimijai. Include:
- What you found and why it's a vulnerability rather than unexpected behavior.
- Steps to reproduce, or a proof of concept if you have one.
- The affected contract, file, or endpoint.
- Your assessment of severity and impact, if you have one — helpful, not required.
You will never be asked for your secret key, seed phrase, or any wallet credential to report or verify a vulnerability. A reproduction that needs a test account you control is normal; a request for your production keys is not part of any legitimate SO4 process.
In scope: the Soroban contracts in packages/contracts, the apps/web trading interface, the apps/s03-indexer indexer, and this documentation site's build pipeline — any of them being made to behave in a way that loses funds, bypasses an authorization check, or serves incorrect data as though it were verified.
Out of scope: third-party infrastructure SO4 depends on but does not control (Stellar network consensus, RPC provider availability, wallet extensions), and issues requiring physical access to a user's device.
There is no formally committed SLA yet. As a working expectation: acknowledgment within a few days of a report reaching the maintainer directly. This section will be updated with a firmer commitment once the disclosure process has been exercised enough times to make one honestly.
Good-faith security research conducted within the scope above — without exploiting a finding beyond what's needed to demonstrate it, without accessing data that isn't yours, and reported privately rather than disclosed publicly first — will not be treated as a hostile act by the project. This is not a substitute for legal advice about your own jurisdiction.
There is no bug bounty program. Reports are still welcome and will be credited (with permission) once a fix ships, but there is currently no monetary reward structure — this section will say so plainly if that changes.
- No independent audit (above) — the largest single caveat on this page.
- Oracle dependence. Pricing relies on external oracle feeds; a stale, manipulated, or unavailable feed can affect liquidations and execution prices. See Risk.
- Testnet-only deployment. Current contract addresses are testnet; testnet tokens and state carry no real value and can be reset.
- Interface trust. The interface prepares transactions for your wallet to sign; a compromised build of the interface, not only the contracts, could construct a malicious transaction. Always review what you're signing in your wallet, not only in the browser UI.
- Rapidly changing code. The protocol and interface are under active development; behavior documented today can change before an equivalent audit or review catches up.
The full, longer list of what can go wrong — market, liquidation, oracle, contract, network, interface, and custody risk — lives at /concepts/risk; this page covers the security-process side specifically (audits, disclosure, scope), not the trading-risk side.