Level · Vulnerability Disclosure

Level Vulnerability Disclosure

Vulnerability disclosure

Level publishes a vulnerability disclosure policy for reporting security issues.

CompanyStablecoinsDeFiCryptocurrencyFinancial-ServicesBlockchainEthereumSmart ContractsYield
Program:

Disclosure Policy

Policy
Policy
Policy

Security Contact

Source

Vulnerability Disclosure

level-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: https://level-money.gitbook.io/level-documentation/technical-documentation/security
program: bug-bounty
platform: Cantina
policy:
- https://cantina.xyz/code/c463283d-b278-4d95-8d9c-e3e4cb0f8f63
- https://cantina.xyz/bounties/c463283d-b278-4d95-8d9c-e3e4cb0f8f63
- https://level-money.gitbook.io/level-documentation/technical-documentation/security
contact: []
security_txt: null
audits:
- firm: Pashov
  scope: Level v2
  date: '2025-04'
  url: https://storage.googleapis.com/level-public/audits/%5BPashov%5D%20Level%20v2%20Security%20Review.pdf
- firm: 0xMacro
  scope: Level v2
  date: '2025-04'
  url: https://storage.googleapis.com/level-public/audits/%5B0xMacro%5D%20Level%20v2%20Security%20Review.pdf
- firm: Spearbit Cantina
  scope: LevelReserveLens, BoringVault
  date: '2025-02'
  url: https://storage.googleapis.com/level-public/audits/LevelReserveLens%20%2B%20BoringVault%20-%20Spearbit%20Cantina.pdf
- firm: Spearbit Cantina
  scope: lvlUSD v1.1 + Staked lvlUSD
  date: '2024-10'
  url: https://storage.googleapis.com/level-public/audits/lvlUSD%20v1.1%20%2B%20Staked%20lvlUSD%20-%20Spearbit%20Cantina.pdf
- firm: Spearbit Cantina
  scope: lvlUSD v1
  date: '2024-09'
  url: https://storage.googleapis.com/level-public/audits/lvlUSD%20v1%20-%20Spearbit%20Cantina
- firm: Zellic
  scope: Stablecoin Points Farm
  date: '2024-09'
  url: https://storage.googleapis.com/level-public/audits/Points%20Farm%20-%20Zellic%20Audit%20Report%20(1).pdf
controls:
- Admin multisig is a 5-of-8 Gnosis Safe with cold-wallet signers, including external security firms (Spearbit).
- Operator multisig is a separate 2-of-5 Gnosis Safe limited to low-risk tasks and cannot move protocol
  funds.
- Protocol treasury multisig is a separate 3-of-4 Gnosis Safe.
- On-chain monitoring by Hexagate with automatic contract pausing on critical issues (turned off from
  October 2025 as part of the shutdown).
evidence:
- source: https://level-money.gitbook.io/level-documentation/technical-documentation/security
  kind: security-page
  keywords: [bug bounty, cantina, audits, multisig, on-chain monitoring]
- source: https://level-money.gitbook.io/level-documentation/technical-documentation/audits
  kind: audits-page
  keywords: [bug bounty, spearbit, zellic, pashov, 0xmacro]

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/level-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.