Security & Audits

Status page — updated August 2026

Audit first, launch second — always. No $VANTA contract goes live before an independent third-party audit, and every report is published here in full, including findings we didn't like.

Audit pipeline

StageScopeStatus
Internal security reviewToken, vesting, staking, marketplace escrowComplete
Economic simulation10,000 simulated seasons — emissions, sinks, attack scenariosComplete
Third-party smart-contract auditAll on-chain contracts + payout pipelineEngagement in progress
Audit report publicationFull findings + remediations, published on this pageBefore TGE
Public bug bountyContracts, payout pipeline, custody integrationOpens at TGE

The auditing firm is announced at engagement, and the report is published here before the token generation event. If remediation is required, the TGE moves — the audit never does.

What gets audited

Game security posture

Responsible disclosure

Found a vulnerability — in the game, the site, or a contract? Report it to security@projectvanta.io. Good-faith researchers acting within scope will never face legal action from Vanta Studios, and qualifying reports are eligible for bounty rewards once the program opens.

Published reports

No reports published yet — the third-party audit report will appear here before TGE.