Security
How the contracts were reviewed and tested, how to report a vulnerability, and what can be done, by whom and how fast, when something goes wrong.
Review
What was checked, and how.
- Code
- Every contract at the tag contracts-v2, commit cceba7e: the code deployed today.
- Reviewed
- By the project's auditor, and signed off on 27 September 2026.
- Deployed
- PrismPerpSettlement at 0xd1FBe9aBEe40ace83e708AD0383B8435E57e60d9 on Robinhood Chain Testnet, chain 46630, with the vault, oracle, skew engine, market registry and position manager it names; all verified on the explorer.
- Static analysis
- Slither over every contract: all 105 of its results triaged, and a new one fails the build.
- Tests
- 290 Foundry tests, 7 of them invariants, covering 98.8% of lines and 88.7% of branches.
- Fuzzing
- Each of the seven invariants over 2,048 runs of 1,000 random calls in Foundry, 14,336,000 calls in all, and again in Medusa, a second engine, over 2,006,955 calls: no breach in either.
- Differential
- One order sequence through the contracts and through the relayer's own ledger, every balance compared to the micro-USDG: 21 of 21.
Bug bounty
Found a way to lose, freeze or take funds, or to settle against the rules? Tell us privately, first.
How to report
Send a direct message to @prismperptrade on X with a one-line summary and no details. We answer with a private channel for the full report. Please do not post details anywhere public until a fix is out.
In scope
- The contracts at the tag contracts-v2, as deployed
- The relayer: settlement, the keeper, the liquidator and the indexer
- The API and this site
- The Python, TypeScript and Rust SDKs
Out of scope
- Third parties: Robinhood Chain, the option and funding venues, wallets
- The $PRP token contract, launched on ponsfamily.com
- Anything that needs the owner's key or a relayer signing key
- Volumetric denial of service, spam and social engineering
- Scanner output without a working impact
Rewards
Paid by severity and impact, at the project's discretion, to the first report of an issue.
- Critical
- Funds lost or taken; a signature forged or bypassed; the pool's reserve for open positions broken.
- High
- Funds frozen beyond the documented pauses; the oracle moved outside its band; an open-interest cap bypassed.
- Medium and low
- The rest, by impact: griefing that costs traders money, a relayer stalled by a single request.
Safe harbour
Research in good faith within these terms is authorised, and we will not pursue it. Test against a local fork of the chain (anvil --fork-url) rather than the live contracts, touch no one else's funds or data, stop at a proof of concept, and give us reasonable time to fix an issue before disclosing it.
When something goes wrong
The owner's levers, what each stops and what it leaves working. Each was drilled, pulled and put back: on 27 September 2026, and through the Safe on 30 September.
| Lever | Stops | Keeps working | Drilled |
|---|---|---|---|
| Pause new positions | Every open, on every market | Closes, partial closes, added margin, stops and targets, liquidations, deposits and withdrawals | In effect 2.9 s after sending, on the live contracts; 1.4 s through the Safe, on a fork |
| Close one market | Opens on that market | Everything else, exits on that market included | 2.8 s, on the live contracts; 0.9 s through the Safe, on a fork |
| Pause withdrawals | Withdrawals from the vault, for at most three days; the contract then refuses another pause for three days | Trading, closes and deposits; balances stay in the vault | 1.2 s, on a fork of the live chain; 1.1 s through the Safe |
| Revoke a keeper or the relayer | That key's oracle readings, or its settlement of signed orders | Everything a trader sends in a transaction of their own | 1.0 s and 0.4 s, on a fork of the live chain; the same through the Safe |
No lever moves a trader's balance. Without the relayer, anyone can close their own position from their wallet while its feed is fresh, liquidate one past its maintenance threshold, and, after a day of feed silence, settle a stranded position at its market's last level. The owner is a Safe that acts on two of its three owners' signatures, since 30 September 2026: each lever is one Safe transaction.
Keys
How the relayer signs.
- One key per role: the keeper, three oracle signers, the settler and the liquidator. The relayer will not start with a role missing or two roles on one key, and a sending key low on gas pages an operator.
- Every one of them can be held in AWS KMS, which signs without ever exposing the key: moving a role there is a configuration change, and a rotation runbook covers each key.
- The settler can only submit what traders signed. It cannot forge an order, move a balance or withdraw; one oracle signer alone cannot set the price, which is the median of three.
Open the terminal
Charts, books and quotes need no wallet. To trade, deposit USDG into PrismPerpVault; after one session signature, orders settle on-chain with no wallet prompt each.
