Security

Audits

Treat V1 as experimental until an external audit is published for the deployed bytecode. In-repo tests help catch regressions; they are not a substitute for review.

Before using real funds, confirm verified source matches the addresses your app uses, the verifier matches your proving setup, and admin / team wiring is correct.

Report vulnerabilities privately before public disclosure.