Skip to main content

Current Audit Status

Audit in Progress

Zenland V2 smart contracts are undergoing security review.
ItemStatus
Internal Security Review✅ Complete
Automated Analysis (Slither, etc.)✅ Complete
External Audit🔄 In Progress
Bug Bounty Program📋 Planned

Security Practices

Code Quality

  • Solidity 0.8+ — Built-in overflow protection
  • OpenZeppelin contracts — Battle-tested libraries
  • Comprehensive tests — Unit, integration, fuzz, invariant
  • No floating pragma — Exact compiler versions

Review Process

Before deployment:
  1. ✅ 100% test coverage target
  2. ✅ Internal security review
  3. ✅ Automated vulnerability scanning
  4. 🔄 External audit by reputable firm
  5. 📋 Testnet deployment and testing
  6. 📋 Mainnet deployment

Audit Reports

Once complete, audit reports will be published here:
AuditorScopeDateReport
TBDEscrowFactory, EscrowImpl, AgentRegistry, FeeManagerPendingPending

Known Limitations

The following are known behaviors, not bugs:
Tokens that charge fees on transfer will cause escrow amount mismatches. Only use whitelisted stablecoins.
Tokens that change balance over time (like stETH) are not supported.
This is intentional behavior for 2-of-2 escrows, not a vulnerability.
Once created, escrow rules cannot change. This is a security feature.

Vulnerability Disclosure

Found a security issue? Please report responsibly.
Do NOT disclose vulnerabilities publicly before they are fixed.

How to Report

  1. Email: [email protected]
  2. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact assessment
    • Your suggested fix (optional)

What to Expect

TimeframeAction
24 hoursAcknowledgment of your report
72 hoursInitial assessment and severity rating
7-14 daysFix development (for critical issues)
After fixCoordinated disclosure and credit

Bug Bounty (Coming Soon)

We’re planning a bug bounty program with rewards based on severity:
SeverityPotential Reward
Critical (fund loss)Up to $50,000
High (frozen funds)Up to $10,000
Medium (DoS, griefing)Up to $2,000
Low (UI, informational)Up to $500
Exact amounts TBD. Check back for official program launch.

Security Contacts