Audits & testing
Audit status of the wagers program and how it is tested.
Audit status
No external audit report has been published yet. Reports will be linked here as soon as they are available, together with the program version they cover.
How the program is tested
Every change to the program runs in CI:
-
Unit and property tests of the fee, payout and split math on the host (
cargo test), with generated inputs. -
Integration tests of every instruction and failure path against the compiled program in LiteSVM: double joins, overpaying, settling with a non-settler key, paying a non-entrant, the timeout refund, pause, backing and commerce idempotency.
-
Invariant fuzzing. Every CI run throws thousands of random user, settler, admin and attacker actions at the compiled program. Attackers try to drain other users' vaults, redirect payouts, forge settlements and spend someone else's balance. After every step:
- No USDC is created or lost: wallets, vaults, escrows, treasury and rewards always add up to the starting total.
- No vault goes down without its owner's signature, so neither the admin nor the settler can move a user's funds.
- Every attack fails, and a valid withdrawal always works, even while the program is paused.
Each sequence ends by releasing every escrow after its timeout and withdrawing every vault, which proves no funds can get stuck.
-
End-to-end tests of the full stack (API, worker and web app) against the same compiled program.
-
Verified builds for every release. See Program & verified builds.
Bug reports
Found something? Email [email protected]. We credit reporters who disclose responsibly.