# Audits & Bug Bounties

Kiln aims to provide a secured and enhanced experience of staking through the different Kiln On-Chain smart contract platforms.

On-Chain products have been audited multiple time by various security firms and are under exhaustive monitoring and security practices to limit security risks as much as possible. &#x20;

## Kiln Onchain Dedicated Staking v1

### Resources

| Resource                              | Link                                                                                                                                                                   |
| ------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Source Code (Smart Contracts only)    | <https://github.com/kilnfi/staking-contracts/tree/master>                                                                                                              |
| Ledger Live mainnet                   | [https://etherscan.io/address/0x1e68238ce926dec62b3fbc99ab06eb1d85ce0270](https://etherscan.io/address/0x1e68238ce926dec62b3fbc99ab06eb1d85ce0270?utm_source=immunefi) |
| Ledger Live testnet                   | <https://goerli.etherscan.io/address/0xe8Ff2a04837aac535199eEcB5ecE52b2735b3543>                                                                                       |
| Other mainnet and testnet deployments | <https://github.com/kilnfi/staking-contracts/tree/master/deployments>                                                                                                  |

### Audits

| Security firm                               | Audit link                                                                                           | Scope                                                                      | Date                                     |
| ------------------------------------------- | ---------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------- | ---------------------------------------- |
| [Ledger Donjon](https://donjon.ledger.com/) | not available                                                                                        | [Smart Contracts](https://github.com/kilnfi/staking-contracts/tree/master) | <p>July 21st 2022<br>March 15th 2023</p> |
| [Halborn](https://www.halborn.com/)         | [Report](https://github.com/kilnfi/staking-contracts/blob/master/audits/halborn/audit.pdf)           | [Smart Contracts](https://github.com/kilnfi/staking-contracts/tree/master) | July 22nd 2022                           |
| [Spearbit](https://spearbit.com/)           | [Report](https://github.com/kilnfi/staking-contracts/blob/master/audits/spearbit/audit.27_07_23.pdf) | [Smart Contracts](https://github.com/kilnfi/staking-contracts/tree/master) | July 27th 2023                           |
| [Ledger Donjon](https://donjon.ledger.com/) | not available                                                                                        | [Ledger Nano Plugin](https://github.com/LedgerHQ/app-plugin-kiln)          | <p>July 21st 2022<br>March 15th 2023</p> |

### Bug Bounty

* [Cantina](https://cantina.xyz/bounties/607dd012-08ad-4080-bf4a-78dc1c28faa9)
* [Immunefi](https://cantina.xyz/bounties/607dd012-08ad-4080-bf4a-78dc1c28faa9)

A $1,000,000 max bounty program is live since 21 August 2023. All bug reports must come with a working PoC impacting asset listed in the "Assets in Scope" section of the program which only addresses smart contracts.

## Kiln Onchain Platform ("v2")

| Security firm                     | Audit link                                                                | Date           |
| --------------------------------- | ------------------------------------------------------------------------- | -------------- |
| [Spearbit](https://spearbit.com/) | Audit report is available upon request [here](https://security.kiln.fi/). | July 27th 2023 |

## Kiln Operator Infrastructure

Kiln is **SOC 2 Type I** and **SOC 2 Type II** certified and has been undergoing multiple penetration testings and audits from third parties.

Certifications and audits reports are available upon request [here](https://security.kiln.fi/).

### Bug Bounty

* [Cantina](https://cantina.xyz/bounties/185c683c-77e7-4b71-822d-95e1a98fee9e)
* Immunefi

A $500,000 max bounty program is live since September 9th 2024. All bug reports must come with a working PoC impacting asset listed in the "Assets in Scope" section of the program which only addresses smart contracts.
