Wallet connections are unavailable in this build. Protocol data remains available.
Robinhood faucet stock tokens are active with simulated testnet prices. Review the test environment.
STONKBACKINGSTAKED— STONKVAULT RATE— STONKTREASURY$0.00
DocsSecurity program

Security owners & reviewers

Threat model, evidence requirements, release workflow and continuous operations.

2 min read

Security program

The security program treats contract correctness and launch safety as separate gates.

Scope

  • Kernel, modules, policies, STONK, StonkVault, Governor, and Timelock.
  • Deployment, manifests, configuration, Safe validation, and verification scripts.
  • Chainlink feeds and Robinhood tokenized assets.
  • Frontend, Privy, browser RPC, Cloudflare, DNS, and release credentials.
  • Governance signers, incident responders, monitoring, and public communications.

Threat model

Reviewers assume malicious users, market creators, governance proposals, calldata, RPCs, frontend releases, dependency updates, and compromised deployer or Safe signers. They also model stale or incorrect feeds, sequencer failure, token freeze/upgrade/blocklist behavior, illiquid reserves, concentrated votes, donation manipulation, rounding attacks, denial of service, and operational mistakes.

Required evidence

  1. Frozen release commit and reproducible toolchain.
  2. Clean formatting, build, unit, fuzz, invariant, coverage, local E2E, and production-fork results.
  3. Static analyzer, dependency advisory, license, secret, and supply-chain reports.
  4. Independent audit and retest of the exact candidate.
  5. Exact fork simulation and decoded production transaction review.
  6. Independent live verification output and manifest/runtime hashes.
  7. Production-origin wallet and transaction smoke test.
  8. Alert fire tests and incident exercise record.
  9. Signed economic, counterparty, and STK-001 decisions.

Severity policy

SeverityTypical impactLaunch treatment
Criticaldirect unbounded loss or permanent hostile controlmust fix
Highbounded but material loss, governance compromise, or core safety failurefix or signed time-bounded exception with exposure cap
Mediumlimited loss, important availability/integrity degradationowner and remediation plan required
Lowdefense-in-depth or low-impact correctness issuetrack and schedule

No issue is closed solely because market capacity is initially zero. Zero capacity is a compensating control, not remediation.

Review workflow

Changes to issuance, valuation, vault conversions, external-token handling, roles, Safe validation, deployment, governance, or frontend transaction construction require targeted threat review and executable regression evidence. ABI and canonical docs update in the same release.

Continuous operations

After launch, monitor backing, concentration, external assets, feeds, STONK supply, vault assets/shares/rate, markets and notes, roles and module state, governance and Timelock activity, Safe changes, frontend integrity, RPC divergence, and public-status delivery.

Security reports need a public contact, encrypted channel, safe-harbor terms, acknowledgement target, escalation owner, and funded bounty before public launch.

Launch authority

Only the mainnet launch gates determine whether a funded launch is authorized. The dated internal review and STK-001 record provide inputs but do not replace independent approval.