Resources

Audits and security disclosures

Two independent audits, published in full including the findings we argued about. Nothing is summarised away.

Reports

AuditorScopeDateFindingsReport
OpenZeppelinVault core, share accountingMay 20262 medium, 5 low — all resolvedPDF
SpearbitOrder router, risk engineJune 20261 medium, 4 low — all resolvedPDF
InternalFee accrual and high-water markJuly 20263 low — 1 accepted, documentedNotes
Resolved means fixed and re-reviewed. The one accepted finding is a gas trade-off documented in the report, not an open vulnerability.

Bug bounty

$100,000Maximum payout, critical severity
No exclusionsAll core contracts in scope
ImmunefiTriage and payout partner
24h triageFirst response target

Keys and upgrades

ControlSetting
Admin multisig4-of-7, independent signers, published addresses
Timelock48 hours on every upgrade, announced before it starts
Emergency pauseDeposits only — withdrawals can never be paused
Proof of reservesChainlink-attested, refreshed hourly
Report a vulnerability to security@loaf.com or through Immunefi. Please do not open a public issue or test against mainnet funds.