Skip to content

Audits & reviews

How we review Mimir's onchain program, and where external audit work stands.

Current status

WorkStatus
Internal security reviewOngoing, supported by the Argus-R framework and evidence-driven testing.
Formal verification & testingIn progress, targeting full Kani coverage alongside fuzzing and intensive testing on our private cluster.
External audit of Mimir's onchain programPlanned. Auditor, scope, schedule and report links will be added here once confirmed.

Internal review with Argus-R

We use Argus-R, our open-source security research framework, to support internal reviews of Mimir's onchain program. It helps us examine how the program validates accounts, handles authority and calculates prices.

The approach is evidence-first: trace how a failure could happen, establish its impact, challenge the conclusion, and require independent reproduction before treating a finding as robust.

Reviews cover account ownership, program-derived addresses (PDAs), cross-program calls and authority, token behavior, and account lifecycles.

Formal verification, fuzzing and cluster testing

Our verification goal combines three complementary approaches:

  • Kani formal verification. Target full coverage of the onchain program's defined security properties, checking them across the inputs and states described by each proof.
  • Fuzzing. Exercise a wide range of generated inputs and edge cases to find unexpected behavior.
  • Private-cluster testing. Put Mimir through intensive end-to-end testing, including feed creation, price refreshes and consumption by applications.

This work is in progress as part of Mimir's development goals. Formal proofs, generated test cases and cluster execution each examine a different aspect of the program.

Next: Mimir's manipulation safeguards.

Documentation v0.1.1 · Beta