For the complete documentation index, see llms.txt. This page is also available as Markdown.

πŸ“‹Audits & Compliance

Security through transparency.

The Vishwa protocol undergoes rigorous third-party security audits to ensure the highest standards of safety. Our commitment to security goes beyond code review and includes formal verification, continuous monitoring, and comprehensive risk assessment.

Completed Security Audits

Auditor
Audit scope
Date
Status
Report

FuzzLand

Token contracts

08/20/2025

Completed βœ…

FuzzLand

BTC ZK-circuits

08/20/2025

Completed βœ…

FuzzLand

Light client

08/20/2025

Completed βœ…

FuzzLand Security Audit

Completion date: August 2025

Audit duration: 4 weeks

Techniques employed: static analysis, fuzz testing, formal verification, and manual code review

Summary: 25 unit tests written, all code manually reviewed, 3 issues found (all resolved)

FuzzLand Security Audit - Agent Product

Delivered: 10 June 2026

Scope: Veta TEE Engine (vishwanetwork/veta-server), Vishwa MCP Server (vishwanetwork/vishwa-cli), and Vishwa Agent Service (vishwanetwork/agent-api), each audited at a pinned commit

Effort: 12 person-days - 4 engineers over 3 days

Techniques employed: static analysis, fuzz testing, formal verification, and manual code review

Findings: 14 issues - 5 Medium, 9 Low, no High or Critical. Findings centered on pre-sign intent binding, x402 payment handling, and gateway authentication.

Remediation: fix commits for the Vishwa MCP Server and Agent Service are recorded in the report. The Veta TEE Engine is off-chain code, so no on-chain fix-commit hash applies.

ExVul Security Audit - Vishwa Proof Token

Completion date: June 2026

Scope: Vishwa Proof Token contracts - BTCvp (0x79D154287DDC77e5C10127E68c2df1a942a330BB) and Cfvc (0xa3b81AA35A2462c588639483EBe68a856Cb32b0d), from vishwanetwork/lightclient-verifier at a pinned commit

Techniques employed: OWASP-based risk assessment - static analysis, manual review, and business-logic scrutiny

Findings: 5 issues - 0 Critical, 0 High, 3 Medium, 2 Low. Four are fixed; one Medium (arbitrary srcRef bytes not canonically constrained on-chain) is acknowledged.

Result: audit passed.

Disclaimer

No audit guarantees the absence of vulnerabilities. Audits are point-in-time reviews of pinned commits; they complement, rather than replace, ongoing security practices. A public bug bounty program has not yet opened.

PDF Β· 473KB
Open

Last updated