Skip to content

Audits & Security

Audits

Rheo has conducted 10+ external audits to date by several firms, with plans to continuously review code.

DateVersionAuditorScope/ Description
2025-06-23v1.8OmnisciaIncremental audit, fix review
2025-06-23v1.8HashlockIncremental audit, fix review
2025-06-14v1.8-rcCantinaIncremental audit, user vaults
2025-05-26v1.8-rcCustodia SecurityIncremental audit, deploy scripts
2025-02-26v1.7CantinaFull codebase
2025-02-12v1.6.1Custodia SecurityIncremental audit, copy trading
2024-12-10v1.5.1Chain DefendersIncremental audit, fallback oracle
2024-11-13v1.5Custodia SecurityIncremental audit, cross-market liquidity
2024-06-10v1.0Code4renaFull codebase, $200k competition pot
2024-06-08v1.0-rcSpearbitFull codebase
2024-03-26v1.0-betaSolidifiedFull codebase

Audits for Very Liquid Vaults

DateVersionAuditorScope/ Description
2025-09-11v0.1.0ObsidianFull codebase
2025-07-26v0.0.1Open ZeppelinFull codebase

Internal Audits and Tests

In addition to security audits, we have conducted several internal reviews and taken various measures to ensure that our coding practices meet the highest standards:

  1. 93% test coverage (Test-to-Code > 3x)
  2. Stateful Invariant Tests (Echidna, Medusa, Foundry 38 properties)
  3. Stateless Fuzz Tests (Foundry)
  4. Static Analyzers (Slither, Solhint, LightChaserV3)
  5. Formal Verification (Halmos)
  6. Auditable protocol upgrades with Foundry scripts

Bug Bounty

A $50k bug bounty is live on Cantina.

This protocol has adopted the SEAL Safe Harbor Agreement for Whitehats, which empowers approved security researchers to intervene during active exploits to rescue funds. Full adoption details, scope, and bounty terms are publicly available here.

Get in Touch

security (at) rheo.xyz

Built with VitePress