Security Report

Portfolio by Primitive™

Protocol

Portfolio

Audit Commit

v1.4.0-beta

As of

10.31.2023

Audits

Portfolio has been audited by by Spearbit, Trail of Bits, and ChainSecurity during development.

Spearbit audited the two latest versions of Portfolio, v1.3.0-beta and v1.4.0-beta. The most recent audit was completed on 07.31.2023 for v1.4.0-beta, which will be promoted to production.

Highlights

Spearbit discovered a critical issue related to the protocol pricing algorithm which was not caught by previous reviews.¹

¹ Spearbit audit.

spearbitlogotrailofbitslogochainsecuritylogo
Audit ByDate% Code CoveredIssues Found
Trail of BitsJanuary 29, 202350%
Spearbit #1March 31, 2023100%
Spearbit #2August 28, 2023100%

Risk Ratings

Portfolio is designed to be resistant to the five risk categories.

Risk Categories

Oracle. Portfolio scores immune because it does not use oracles.

Upgradability. Portfolio scores immune because it cannot be upgraded.

Centralization. Portfolio scores immune because its functionality cannot be controlled by any entity.

Complexity. Portfolio scores At Risk because of its novel architecture and reliance on mathematical precision.

Liveness. Portfolio scores Invulnerable because it is live as long as the underlying chain is live.

hidden

Ratings

Exposed

F

At Risk

D

Resistant

C

Invulnerable

B

Immune

A

Bug Bounty

Portfolio has an active bug bounty program to incentivize the community to find and report bugs.

immunefilogo

Maximum Bounty

$100,000.00

Disclaimer: This report is for informational purposes only. The information contained herein is not intended to be and should not be construed as legal, tax, investment, financial, or other advice. The information contained herein is not intended to be and should not be construed as an offer to provide investment advisory or other services by Primitive. The information contained herein is not intended to be and should not be construed as investment research. The information contained herein is not intended to be and should not be construed as a recommendation by Primitive to engage in any specific investment strategy.