Trail of Bits
Comprehensive review of the Rust/Anchor programs, the SP1 Solana verifier, and the SEV-SNP attestation flow. 4,100 lines of Rust, zero critical findings.
View Full ReportWe treat security as a core protocol primitive, not an afterthought. Multiple independent audits, an active bug bounty, and zero incidents since mainnet launch.
Every line of protocol code has been reviewed by at least two independent auditors.
Comprehensive review of the Rust/Anchor programs, the SP1 Solana verifier, and the SEV-SNP attestation flow. 4,100 lines of Rust, zero critical findings.
View Full ReportSolana-focused audit covering the registry PDA, SPL Token-2022 transfer-fee hooks, and Wormhole VAA verification for inbound bridged collateral.
View Full ReportAnchor-program review covering the operator bond vault, slashing instruction authority, and Realms governance CPI permissions.
View Full ReportOur bug bounty program covers every Anchor program deployed on Solana mainnet-beta, the agent runtime, and the SP1 verifier pipeline.
Remote code execution, fund theft, consensus manipulation, or permanent freezing of funds.
Temporary freezing of funds, unauthorized state changes, or proof verification bypass.
Griefing attacks, denial of service on non-critical paths, or information disclosure.
Best practice violations, informational findings, or minor UI/UX issues with security implications.
A transparent timeline of our security milestones since going live in June 2024.
NexusForge protocol goes live with initial security measures and monitoring infrastructure.
First major third-party audit of the Anchor programs completed with zero critical findings.
Public bug bounty launched with up to $50,000 in rewards for critical vulnerabilities.
Solana-specific audit of the Wormhole VAA verifier and SPL Token-2022 fee hooks completed with all findings remediated.
Most comprehensive audit to date covering the full proof generation and verification stack.
Continuous monitoring, regular penetration testing, and active bug bounty program.
We take every report seriously. Please disclose responsibly and we'll work with you to resolve issues quickly.
Please do not disclose vulnerabilities publicly before we've had a chance to investigate and remediate. We commit to responding within 24 hours and keeping you updated throughout the process.