Audits & reviews
How we review Mimir's onchain program, and where external audit work stands.
Current status
| Work | Status |
|---|---|
| Internal security review | Ongoing, supported by the Argus-R framework and evidence-driven testing. |
| Formal verification & testing | In progress, targeting full Kani coverage alongside fuzzing and intensive testing on our private cluster. |
| External audit of Mimir's onchain program | Planned. Auditor, scope, schedule and report links will be added here once confirmed. |
Internal review with Argus-R
We use Argus-R, our open-source security research framework, to support internal reviews of Mimir's onchain program. It helps us examine how the program validates accounts, handles authority and calculates prices.
The approach is evidence-first: trace how a failure could happen, establish its impact, challenge the conclusion, and require independent reproduction before treating a finding as robust.
Reviews cover account ownership, program-derived addresses (PDAs), cross-program calls and authority, token behavior, and account lifecycles.
Formal verification, fuzzing and cluster testing
Our verification goal combines three complementary approaches:
- Kani formal verification. Target full coverage of the onchain program's defined security properties, checking them across the inputs and states described by each proof.
- Fuzzing. Exercise a wide range of generated inputs and edge cases to find unexpected behavior.
- Private-cluster testing. Put Mimir through intensive end-to-end testing, including feed creation, price refreshes and consumption by applications.
This work is in progress as part of Mimir's development goals. Formal proofs, generated test cases and cluster execution each examine a different aspect of the program.