Audits
KIMP smart contract audits are scheduled before mainnet. Reports will be published in the docs and announced on X.
KIMP holds user collateral and publishes a price index that settles contracts. Independent review of the contracts is a precondition for mainnet. Audits are scheduled before mainnet. No audit has been completed at the time of writing, and no audit firm is named on this page.
Scope#
The audit scope covers every contract deployed on day one:
| Contract | Focus areas |
|---|---|
KimpIndex | Median calculation, quorum, circuit guard, staleness, source switch |
KimpReporterRegistry | Bonding, unbonding, flagging, slashing, dispute resolution |
KimpMarket | Margin, P&L, settlement TWAP, liquidation, position limits |
KimpPool | NAV accounting, kLP minting and burning, withdrawal queue, OI caps |
KimpVerifiedGate | DojangScroll integration, revocation handling |
KimpStaking | Fee share accounting, unstake cooldown |
KimpBuyback | Rate limit, TWAP price guard, burn |
Access control is reviewed across all contracts. Every parameter setter is onlyTimelock, and pause is onlyGuardian. See Admin keys and timelock.
Process#
- 1Internal review and full test suite, including fuzz and invariant tests on NAV, margin and settlement.
- 2Testnet rehearsal on GIWA Sepolia with the full reporter set and live markets.
- 3Independent external audit of the frozen codebase.
- 4Remediation of findings and a review of the fixes.
- 5Publication of the report and the audited commit hash.
Contracts deployed to mainnet will match the audited commit. Any change after the audit is either re-reviewed or deferred to a later version.
Publication#
Audit reports will be published in these docs and announced on X at @KimpGiwa. Each report will list the commit it covers, all findings by severity, and the resolution of each finding.
Core contracts are non-upgradeable#
Core contracts are non-upgradeable. There are no proxies that could swap the logic of audited code after deployment. New versions deploy side by side and users migrate through governance. This means audited logic cannot be swapped after deployment.
Limits of audits#
Audits review code against a specification at a point in time. They do not guarantee the absence of bugs, and they do not cover economic conditions, source-exchange behavior, or the GIWA chain itself. Read Risks before using the protocol.