Reports
| Auditor | Scope | Date | Findings | Report |
|---|---|---|---|---|
| OpenZeppelin | Vault core, share accounting | May 2026 | 2 medium, 5 low — all resolved | |
| Spearbit | Order router, risk engine | June 2026 | 1 medium, 4 low — all resolved | |
| Internal | Fee accrual and high-water mark | July 2026 | 3 low — 1 accepted, documented | Notes |
Resolved means fixed and re-reviewed. The one accepted finding is a gas
trade-off documented in the report, not an open vulnerability.
Bug bounty
$100,000Maximum payout, critical severity
No exclusionsAll core contracts in scope
ImmunefiTriage and payout partner
24h triageFirst response target
Keys and upgrades
| Control | Setting |
|---|---|
| Admin multisig | 4-of-7, independent signers, published addresses |
| Timelock | 48 hours on every upgrade, announced before it starts |
| Emergency pause | Deposits only — withdrawals can never be paused |
| Proof of reserves | Chainlink-attested, refreshed hourly |
Report a vulnerability to security@loaf.com or through Immunefi.
Please do not open a public issue or test against mainnet funds.