Audits & Bug Bounty
Multyr contracts are deployed on Arbitrum One. The system is currently in validation phase. Deposits are not open to the public. Behavior described on this page reflects the protocol's designed behavior; some mechanisms are active in shadow testing, others become active at public launch. See the Status page for details.
Security audits and external review are part of the protocol's security lifecycle.
Audits
| Scope | Auditor | Status | Report |
|---|---|---|---|
| MTRY token, PreMTRYSale contract (incl. on-chain KYC gating), preMTRY to MTRY conversion | HackenProof | Completed August 2026 — all findings remediated | Report PDF |
| Protocol core (Strategy Vaults, Allocation Vault) | HackenProof | Contracted. Scheduled for Q4 2026 | — |
Audits follow the protocol's launch sequence: the token and presale contracts were audited first, because they are what the presale sells. The core audit has not started. It is contracted, and scheduled for Q4 2026 including the fixes. It will be finished before public deposits open. Reports are published in full, unedited.
Bug Bounty
A bug bounty program on Immunefi is planned ahead of public launch, following the protocol core audit.
Tier structure and scope will be announced at launch. In the interim, responsible disclosure is welcome through:
Continuous Security
Security is not a one-time process. It includes:
- external audits
- internal testing (289 files, 3,500+ test functions — see Testing Deep Dive)
- on-chain and off-chain monitoring (see Monitoring & Automation)
- community review and responsible disclosure
Disclaimer
Audits and testing reduce risk but do not eliminate it. Users should assume that interacting with smart contracts carries inherent risk.