THERM
Security

Security

Audit status, bug bounty and contract addresses.

Audit status#

Therm has not been audited. No independent security firm has reviewed the contracts, and no contracts are deployed. The interactive app on this site runs entirely against a simulator in your browser; it never asks you to sign a transaction.

We will not ask anyone to deposit real funds before at least one full audit has been completed and published in full, including any findings we chose not to fix and why. This page will be updated with the auditor's name, the commit hash reviewed, the report itself, and the diff between the audited commit and the deployed bytecode.

Until then, treat every statement in these docs about contract behaviour as a specification, not a guarantee.

Scope of review#

The audit will cover every contract that holds or moves value.

ContractResponsibility
ThermPoolSells passes, prices the quote curve, holds ETH, tracks coverage
ThermCreditThe THERM ERC-20; mint restricted to the pool, burn restricted to the paymaster
ThermPaymasterERC-4337 paymaster: validation, reservation, burn in postOp, hourly cap, circuit breaker
ThermBackstopTHRM staking, pro-rata spread accounting, cooldown, liquidation
ThermPolicyRegistryProtocol sponsorship policies and their allowlists and caps
ThermTimelockDelay on every parameter and allowlist change

Areas of particular concern, which we will ask reviewers to focus on:

  • Paymaster griefing. Operations that pass validation but consume far more gas in postOp than reserved, or that exploit the reservation to lock other users out.
  • Spread accounting. Rounding in the pro-rata accumulator over millions of small burns, and ordering between burns, stakes and withdrawals.
  • Quote manipulation. Whether the trailing average or coverage can be pushed within a block to buy therms below the intended rate.
  • Liquidation mechanics. Sandwiching and price impact when backstop THRM is sold for ETH.
  • Allowlist bypass. Calls that reach a non-allowlisted target through an allowlisted one.

Bug bounty#

A public bug bounty will open before mainnet deposits are enabled.

SeverityExampleReward
CriticalTheft or permanent freezing of pool ETH, staked THRM or user thermsTBD
HighMinting therms without payment; burning another address's thermsTBD
MediumBypassing the hourly cap or allowlist; griefing sponsorship for othersTBD
LowAccounting drift that does not put funds at riskTBD

Until the program is live, report vulnerabilities privately by email to the address in the site footer with the subject line SECURITY. Include a description, affected contracts or components, and reproduction steps. Do not open a public issue. We will acknowledge within 48 hours and will not pursue legal action against good-faith research that avoids privacy violations, data destruction and service disruption.

Contract addresses#

No contracts are deployed. Addresses will be published here, and only here, at deployment. Do not trust addresses from any other source, including social media replies and direct messages.

ContractRobinhood Chain addressVerified source
ThermPoolTBDTBD
ThermCredit (THERM)TBDTBD
ThermPaymasterTBDTBD
ThermBackstopTBDTBD
ThermPolicyRegistryTBDTBD
ThermTimelockTBDTBD
THRM tokenTBDTBD
EntryPoint (canonical v0.7)0x0000000071727De22E5E9d8BAf0edAc6f37da032Canonical deployment

Operational security#

  • Parameter changes, allowlist changes and upgrades go through a timelock. The delay and the multisig's signer set will be published here before launch.
  • The paymaster's EntryPoint deposit is kept small relative to the pool and refilled automatically, so a paymaster bug cannot drain more than one refill interval's worth of ETH.
  • The pool-wide circuit breaker can pause sponsorship. It cannot move funds, and it cannot pause withdrawals from the backstop once a cooldown has completed.