Reference
Security
Principal-first design, allowlisted destinations, honest audit status.
- Audit status
- Not yet audited — independent audits planned before mainnet launch.
- Bug bounty
- Planned before significant TVL.
HoodFold makes no claim of an audit or bounty that has not happened.
Design principles
- User principal cannot be arbitrarily withdrawn by protocol operators.
- Strategy destinations are allowlisted in an on-chain registry.
- Hard allocation caps per destination.
- Oracle deviation protection constrains or pauses strategy actions.
- A guardian can pause; a pause can only make HoodFolds safer, and withdrawals stay open.
- Strategy and parameter changes go through a timelock and multisig where possible.
- Independent audits before production TVL; public bug bounty before significant TVL.