Security
Audit status, bug bounty and contract addresses.
Audit status#
Therm has not been audited. No independent security firm has reviewed the contracts, and no contracts are deployed. The interactive app on this site runs entirely against a simulator in your browser; it never asks you to sign a transaction.
We will not ask anyone to deposit real funds before at least one full audit has been completed and published in full, including any findings we chose not to fix and why. This page will be updated with the auditor's name, the commit hash reviewed, the report itself, and the diff between the audited commit and the deployed bytecode.
Until then, treat every statement in these docs about contract behaviour as a specification, not a guarantee.
Scope of review#
The audit will cover every contract that holds or moves value.
| Contract | Responsibility |
|---|---|
| ThermPool | Sells passes, prices the quote curve, holds ETH, tracks coverage |
| ThermCredit | The THERM ERC-20; mint restricted to the pool, burn restricted to the paymaster |
| ThermPaymaster | ERC-4337 paymaster: validation, reservation, burn in postOp, hourly cap, circuit breaker |
| ThermBackstop | THRM staking, pro-rata spread accounting, cooldown, liquidation |
| ThermPolicyRegistry | Protocol sponsorship policies and their allowlists and caps |
| ThermTimelock | Delay on every parameter and allowlist change |
Areas of particular concern, which we will ask reviewers to focus on:
- Paymaster griefing. Operations that pass validation but consume far more gas in
postOpthan reserved, or that exploit the reservation to lock other users out. - Spread accounting. Rounding in the pro-rata accumulator over millions of small burns, and ordering between burns, stakes and withdrawals.
- Quote manipulation. Whether the trailing average or coverage can be pushed within a block to buy therms below the intended rate.
- Liquidation mechanics. Sandwiching and price impact when backstop THRM is sold for ETH.
- Allowlist bypass. Calls that reach a non-allowlisted target through an allowlisted one.
Bug bounty#
A public bug bounty will open before mainnet deposits are enabled.
| Severity | Example | Reward |
|---|---|---|
| Critical | Theft or permanent freezing of pool ETH, staked THRM or user therms | TBD |
| High | Minting therms without payment; burning another address's therms | TBD |
| Medium | Bypassing the hourly cap or allowlist; griefing sponsorship for others | TBD |
| Low | Accounting drift that does not put funds at risk | TBD |
Until the program is live, report vulnerabilities privately by email to the address in the site footer with the subject line SECURITY. Include a description, affected contracts or components, and reproduction steps. Do not open a public issue. We will acknowledge within 48 hours and will not pursue legal action against good-faith research that avoids privacy violations, data destruction and service disruption.
Contract addresses#
No contracts are deployed. Addresses will be published here, and only here, at deployment. Do not trust addresses from any other source, including social media replies and direct messages.
| Contract | Robinhood Chain address | Verified source |
|---|---|---|
| ThermPool | TBD | TBD |
| ThermCredit (THERM) | TBD | TBD |
| ThermPaymaster | TBD | TBD |
| ThermBackstop | TBD | TBD |
| ThermPolicyRegistry | TBD | TBD |
| ThermTimelock | TBD | TBD |
| THRM token | TBD | TBD |
| EntryPoint (canonical v0.7) | 0x0000000071727De22E5E9d8BAf0edAc6f37da032 | Canonical deployment |
Operational security#
- Parameter changes, allowlist changes and upgrades go through a timelock. The delay and the multisig's signer set will be published here before launch.
- The paymaster's EntryPoint deposit is kept small relative to the pool and refilled automatically, so a paymaster bug cannot drain more than one refill interval's worth of ETH.
- The pool-wide circuit breaker can pause sponsorship. It cannot move funds, and it cannot pause withdrawals from the backstop once a cooldown has completed.