Skip to main content

Audits & Security

T3tris is non-custodial. Your shares stay in your wallet, and you authorize every action yourself. That power comes with responsibility.

Audits

The protocol has been independently reviewed by multiple security firms and researchers before deployment.

Human-led audits:

AI-assisted audits:

warning

An audit reduces risk, it does not remove it. Smart contracts can still contain undiscovered issues. Audits don't cover a curator's off-chain conduct or a strategy's performance.

Wallet and transaction safety

  • Verify the domain. Only connect on the official app URL, bookmark it, and watch for look-alikes and ads.
  • Read every signature. Check the token, amount, and destination your wallet shows before confirming. Approve only what you intend to deposit.
  • Beware of impersonation. T3tris will never message you first, ask for your seed phrase, or ask you to "validate" your wallet. Never share your seed phrase with anyone.
  • Use a hardware or multisig wallet for significant amounts.

Extra advice for curators

If you operate a vault, you also hold powerful admin keys.

  • Keep the vault admin on a secure wallet, ideally a multisig for production vaults.
  • Apply least privilege: grant operators only the roles they need, use a separate hot wallet for routine settlement.
  • Treat admin transfers like moving funds. The two-step accept flow exists for a reason.
  • Report honest, timely valuations, and settle on a clear cadence.

Deploying or integrating at scale

If you plan to deploy production vaults or build on the protocol, get your own deployment and integration reviewed. Audits of the core protocol don't cover your specific configuration or surrounding code.

Reporting a vulnerability

If you find a security issue, report it through the project's official channels. Don't disclose it publicly: contact@t3tris.finance.