πAudits & Compliance
Security through transparency.
The Vishwa protocol undergoes rigorous third-party security audits to ensure the highest standards of safety. Our commitment to security goes beyond code review and includes formal verification, continuous monitoring, and comprehensive risk assessment.
Completed Security Audits
FuzzLand Security Audit
Completion date: August 2025
Audit duration: 4 weeks
Techniques employed: static analysis, fuzz testing, formal verification, and manual code review
Summary: 25 unit tests written, all code manually reviewed, 3 issues found (all resolved)
FuzzLand Security Audit - Agent Product
Delivered: 10 June 2026
Scope: Veta TEE Engine (vishwanetwork/veta-server), Vishwa MCP Server (vishwanetwork/vishwa-cli), and Vishwa Agent Service (vishwanetwork/agent-api), each audited at a pinned commit
Effort: 12 person-days - 4 engineers over 3 days
Techniques employed: static analysis, fuzz testing, formal verification, and manual code review
Findings: 14 issues - 5 Medium, 9 Low, no High or Critical. Findings centered on pre-sign intent binding, x402 payment handling, and gateway authentication.
Remediation: fix commits for the Vishwa MCP Server and Agent Service are recorded in the report. The Veta TEE Engine is off-chain code, so no on-chain fix-commit hash applies.
ExVul Security Audit - Vishwa Proof Token
Completion date: June 2026
Scope: Vishwa Proof Token contracts - BTCvp (0x79D154287DDC77e5C10127E68c2df1a942a330BB) and Cfvc (0xa3b81AA35A2462c588639483EBe68a856Cb32b0d), from vishwanetwork/lightclient-verifier at a pinned commit
Techniques employed: OWASP-based risk assessment - static analysis, manual review, and business-logic scrutiny
Findings: 5 issues - 0 Critical, 0 High, 3 Medium, 2 Low. Four are fixed; one Medium (arbitrary srcRef bytes not canonically constrained on-chain) is acknowledged.
Result: audit passed.
Disclaimer
No audit guarantees the absence of vulnerabilities. Audits are point-in-time reviews of pinned commits; they complement, rather than replace, ongoing security practices. A public bug bounty program has not yet opened.
Last updated