Gauntlet · Vulnerability Disclosure

Gauntlet Vulnerability Disclosure

Vulnerability disclosure

Gauntlet runs an active bug bounty program through Immunefi for responsible disclosure of vulnerabilities in its Aera V3 vault protocol. The vault contracts have been independently reviewed by Spearbit, OpenZeppelin, and Cantina. No /.well-known/security.txt is published (probed 404 on www/api/docs hosts).

Gauntlet publishes a vulnerability disclosure policy for reporting security issues.

CompanyCrypto DataDeFiRisk ManagementYieldVaultsBlockchainWeb3Financial Modeling
Program:

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: false
source: https://docs.gauntlet.xyz/guides/concepts/security
description: >-
  Gauntlet runs an active bug bounty program through Immunefi for responsible
  disclosure of vulnerabilities in its Aera V3 vault protocol. The vault contracts
  have been independently reviewed by Spearbit, OpenZeppelin, and Cantina. No
  /.well-known/security.txt is published (probed 404 on www/api/docs hosts).
policy:
  - https://docs.gauntlet.xyz/guides/concepts/security
bug_bounty:
  - platform: Immunefi
    scope: Aera V3 vault protocol
audits:
  - firm: Spearbit
    scope: Comprehensive review of BaseVault, hooks, provisioner, and guardian patterns
    date: 2025-06
  - firm: OpenZeppelin
    scope: Core vault and access-control logic
  - firm: Cantina
    scope: Community security competition with multiple independent reviewers
evidence:
  - {source: https://docs.gauntlet.xyz/guides/concepts/security, kind: security-page}
  - {source: Immunefi, kind: bug-bounty}