Skip to content

Commission an external smart-contract security audit before mainnet #837

Description

@joelpeace48-cell

Epic: Mainnet Readiness & Financial Safety

Summary

Engage a reputable Soroban/Rust auditor to review both contracts and publish the report.

Background & Problem

The contracts hold user points redeemable for real assets. 182 unit tests + fuzzing + Kani are strong but are not a substitute for an independent audit before custody of value.

Impact / Why it matters

Audit is table-stakes for mainnet credibility and for most grant/exchange integrations.

Proposed Approach

  • Prepare an audit-ready snapshot (frozen commit, threat model, docs).
  • Solicit quotes from Soroban-experienced firms/independent auditors.
  • Track findings as issues; re-audit deltas.

Acceptance Criteria

  • Audit report published under docs/audits/.
  • All critical/high findings resolved or accepted with rationale.

Filed as part of the mainnet-readiness & world-class roadmap. Scope is intentionally small enough for one focused PR; comment to claim.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave programarea: contractsSoroban smart contractsfinancial-safetyFunds custody, reserve, redemption integritymainnetCritical for mainnet launchpriority: criticalMust-fix before mainnet / money at risksecuritySecurity hardening and scanning

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions