Skip to main content

Security

Centrifuge has best-in-class security process, with highlights including

  • 16 security reviews to date for the Centrifuge protocol.
  • Launched on mainnet in 2019, 0 exploits.
  • Extensive invariant test suite.

The protocol codebase is fully immutable, and any emergency functions are locked behind a 72-hour timelock.

Security reviews

Protocol

AuditorScopeDateEngagementReport
MacroMerkle Proof ManagerJune 2025Security reviewPublic soon
ElectisecSpoke/VaultsJune 2025Security reviewPublic soon
SpearbitV3.0May 2025Security reviewPublic soon
burraSecGatewayMay 2025Security reviewReport
xmxanuelV3.0May 2025Security reviewReport
Alex the EntreprenerdV3.0Apr 2025Review + invariant testingReport
burraSecGatewayApr 2025Security reviewPart 1 Part 2
xmxanuelV3.0Mar 2025Security reviewReport
SpearbitV2.1Feb 2025Security reviewReport
ReconV2.0Jan 2025Invariant testingReport
SpearbitV2.0July 2024Security reviewReport
SpearbitMorpho integrationJune 2024Security reviewReport
Alex the EntreprenerdV2.0Mar - Apr 2024Review + invariant testingPart 1 Part 2
SpearbitV1.0Oct 2023Security reviewReport
SRLabsV1.0Sep 2023Security reviewReport
Code4renaV1.0Sep 2023Competitive auditReport

Operational securitiy

The core team contributing to Centrifuge has completed an operational security review with OPSEK.

Bug bounty

Centrifuge runs an active bug bounty program, available on https://centrifuge.io/security.