Protocol Security
The security of the Flat Money protocol is our top priority.
Security Practices
The Flat Money team’s security practices include fuzzing, unit testing, and routine peer reviews of the codebase. External measures include professional security reviews, contests, and pre/post-deployment bounties.
The protocol has in-built invariant checks on every user order execution. These checks ensure the integrity and accounting within the overall system at all times.
At launch, the Flat Money protocol will be audited with a bug bounty program in place, which will be managed through Immunefi. After Flat Money launches, measures will be taken to implement circuit breakers in the Flat Money smart contracts; any new features will undergo security reviews before they are put into production.
For more details, see the sections below.
Smart Contract Audits
The Flat Money team has worked with Sherlock to audit the protocol’s codebase multiple times. The audits along with their reports can be found below:
January 2024 - Flat Money Sherlock audit contest
April 2024 - Flat Money Sherlock fix review audit contest
January 2025 - Flat Money Sherlock Security Review
Sherlock is an incentive-aligned auditing protocol that provides a hybrid audit, which combines the benefits of a legacy audit and an audit competition. The end result is more experienced eyes on the Flat Money codebase.
The Flat Money team is working with the Sherlock team to purchase bug bounty coverage to incentivize responsible disclosures and provide protection in the event an exploit were to occur.
Bug Bounty Program
Flat Money runs an ongoing bug bounty program with Sherlock, where ethical hackers help secure DeFi contracts by identifying vulnerabilities in exchange for rewards based on severity.
Critical
USD $50,000
Flat Money Sherlock Bug Bounty
Exposure to Third Party Infrastructure
The Flat Money protocol is designed to have no exposure to third-party protocols and limited exposure to outside infrastructure.
The protocol does use Pyth Network for the protocol’s primary oracle infrastructure to accurately price rETH and avoid user frontrunning of the oracle. There is also oracle redundancy in place with a Chainlink price feed as a final price sanity check to increase the security of Flat Money’s oracle infrastructure.
The only asset used within the Flat Money protocol is Rocket Pool ETH (rETH). No other crypto assets are used within the protocol.
Last updated