Security is
not a feature.
It's the floor.

ASSET-LOSS INCIDENTS
0
Since mainnet launch · as of 2026.08
HIGH-RISK INCIDENTS
0
High 1 / Medium 6 / Low 13
BUG BOUNTY
$1M
Immunefi programme
INSURANCE FUND
$12.4M
Growing steadily · verifiable on-chain
01 · FOUR LAYERS

From bytecode to the data centre, every layer is defended

From Bytecode to Bedrock.
L1 · CORE PROTOCOL L2 · WALLET L3 · TRADING L4 · INFRASTRUCTURE
L1 / 01AUDITED

Core protocol securityCore Protocol Security

  • The core protocol has been audited by several independent security firms (names withheld at the auditors' request)
  • Critical paths are formally verified with the Coq / Isabelle theorem provers
  • Modular least-privilege design; moving funds requires a multi-signature threshold
  • $1M Immunefi bug bounty · the on-chain settlement program is open source
  • Contract upgrades go through a 72h time lock, giving the community a window to review
L2 / 02CUSTODY

Asset custody securityAsset Custody Security

  • Deposited USDC/USDT is held with an enterprise-grade digital asset custodian using separated cold / warm / hot storage
  • Client funds are strictly segregated from platform operating funds and accounted for separately
  • Accounts hold MUSD pegged 1:1 to custodied assets, with total issuance reconciled against the custody balance 24/7
  • Large withdrawals can enable an address allowlist plus a 24-hour time lock
  • Everything you sign is shown in full in the dialog — no blind signing
  • For email-registered accounts, on-chain signing runs through the Privy MPC service, so key shares are stored separately and the private key never exists in plaintext at any single point
L3 / 03MEV-RESISTANT

Trading protectionTrading Protection

  • Multi-source quote aggregation with a median algorithm, so manipulating any one source doesn't move your fill price
  • Orders never enter the public mempool, structurally avoiding front-running and sandwich attacks
  • You can set your own maximum slippage; beyond it, the order doesn't fill
  • AI risk controls on abnormal orders, with extreme orders automatically delayed for manual review
  • A $12.4M insurance fund covers exposure in extreme markets
L4 / 0499.99% SLA

Infrastructure securityInfrastructure Security

  • Cloud-native distributed microservices, active-active across regions, with no single point of dependency
  • Multi-layer DDoS protection that automatically filters the vast majority of malicious requests
  • End-to-end TLS and encryption throughout, with zero plaintext storage of sensitive data
  • Active-active data centres plus cross-region backups, failing over within 60s
  • A 24/7 SOC team with real-time alerting on both on-chain and off-chain events
02 · AUDIT REPORTS

Audited by multiple independent firms

Independently Audited. Firms Undisclosed by Request.
MULTIPLE AUDITS · ALL RESOLVED ALL PUBLIC UPON REQUEST
// NOTE

The Mullet core protocol has completed several rounds of independent third-party security audits covering the core protocol contracts, the liquidation and settlement engine, the oracle aggregation layer and other critical modules. At the auditors' request their names are not disclosed publicly; all identified issues (High / Medium / Low) have been fixed. To request the full audit reports, contact security@mullet.top.

// FINDINGS · ALL RESOLVED
CRITICAL0
HIGH1
MEDIUM6
LOW13
03 · BUG BOUNTY

$1M bounty · guarded together with the community

Immunefi Bug Bounty Program.
PROGRAM HOSTED ON IMMUNEFI LIVE SINCE 2025.10
// HOW TO TAKE PART
Visit immunefi.com/bounty/mullet to submit a vulnerability report · Submit vulnerability reports through the Immunefi platform · review and bounty payment are handled by Immunefi
// SCOPE
In scope: Mullet core on-chain programs / liquidation and settlement engine / oracle aggregation / bridge integrations

Out of scope: website UI defects / third-party wallets / phishing and social engineering / known issues
// CONTACT
security@mullet.top
CRITICAL
$250K - $1M

Could cause major loss of protocol funds / arbitrary contract upgrade / total system outage

HIGH
$50K - $250K

Loss of funds for a single user / critical feature outage / critical data exposure

MEDIUM
$5K - $50K

Non-critical malfunction / limited loss of funds / partial data exposure

LOW
$1K - $5K

Low-probability or narrowly scoped security risk / improvement suggestions

The figures are bounty ranges. Exact amounts are determined by the Immunefi rating committee based on severity, exploitability and impact. Bounties are paid in USDC by Immunefi under its own platform rules.
04 · INSURANCE FUND

A backstop for extreme markets

Insurance Fund · Last Line of Defense.
CURRENT · $12.4M FUNDED FROM CLEARING + PROFITS ON-CHAIN VERIFIABLE
// WHAT THE FUND DOES
If the liquidation engine can't keep up in extreme conditions (a flash crash or a liquidity vacuum, for example), the fund absorbs user losses.
// WHERE THE MONEY COMES FROM
A clearing fee accrual (0.1% of the liquidated amount) / a fixed share of platform profits / team contributions
// ON-CHAIN ADDRESS
5xKp...m9Tx · verifiable live on Solscan
Current size
$12.4M
Snapshot 2026.05.18
Monthly growth
+$2.1M
Added in May
Times drawn on
0
Never triggered to date

Insurance Fund Growth

$4.0M2025.12$5.8M2026.01$7.5M2026.02$9.6M2026.03$11.0M2026.04$12.4M2026.05
05 · INCIDENT RESPONSE

If it ever happens · here's what we do

If The Worst Happens.
T+0
DetectDETECT

The 24/7 SOC team monitors for anomalies, and any on-chain trading pattern deviating from baseline raises an alert. Maximum detection delay: 60 seconds.

RESPONSE TIMET+0
T+5min
TriageTRIAGE

The incident response group assembles within 5 minutes, assigns a severity level (P0-P3) and decides whether to trigger an emergency halt.

RESPONSE TIMET+5min
T+10min
ContainCONTAIN

For P0/P1 incidents, multi-sig triggers a protocol-level emergency pause — liquidation, deposits and withdrawals freeze immediately to protect user assets.

RESPONSE TIMET+10min
T+30min
NotifyNOTIFY

The first incident notice is published on our official X / Discord, with progress updates every hour and full transparency throughout.

RESPONSE TIMET+30min
T+24h
Post-mortemPOST-MORTEM

A preliminary root cause analysis is published within 24 hours, together with the fix, any compensation plan and long-term improvements.

RESPONSE TIMET+24h
T+1w
AuditAUDIT

An independent third party is invited to audit the fix. Only once that audit passes is the emergency pause lifted and service resumed.

RESPONSE TIMET+1w
06 · OUR COMMITMENT

Our security commitments

What We Owe You.
/ 01
TRANSPARENCY

Security disclosure

The size of the insurance fund and its on-chain address are verifiable at any time; major security incidents and fund changes are announced immediately.

/ 02
CONTINUOUS AUDIT

Continuous auditing

Every major release must pass at least one independent audit beforehand. Key changes to the on-chain settlement program are published as diffs; for security reasons the off-chain trading and market data systems are not open source and are instead assessed independently by a third party in a controlled environment.

/ 03
USER FIRST

Users first

In extreme situations, protecting user assets comes first. The insurance fund, emergency halt and compensation mechanisms are written into the protocol, not just promised verbally.