Security
Defense-in-depth architecture protecting every swap from wallet to chain. Cold custody, multi-sig governance, continuous penetration testing, and a public bug bounty.
Security Architecture
Velox operates a layered security model designed to protect user assets at every stage of the swap lifecycle. From wallet key management through on-chain settlement, every component is hardened, monitored, and independently tested.
The platform does not custody user funds — swaps settle atomically via smart contract directly to the user's wallet. However, the gas reserve and operational infrastructure require their own security guarantees, which we detail below with full transparency.
Security Controls
Every layer of the Velox infrastructure is protected by controls that have been reviewed and tested by independent security auditors.
Multi-Signature Governance
All protocol upgrades, fee parameter changes, and gas reserve withdrawals require a 4-of-7 multi-sig threshold. Signers are geographically distributed and use hardware security modules.
Hardware Security Modules
Operational signing keys are stored in FIPS 140-2 Level 3 HSMs. Private keys never leave the secure enclave — all signing operations occur within tamper-resistant hardware.
DDoS Protection
Layer 7 traffic is routed through Cloudflare's enterprise-grade Web Application Firewall with rate-based DDoS mitigation. Origin IP addresses are never exposed publicly.
Two-Factor Authentication
All administrative access to infrastructure, dashboards, and CI/CD pipelines requires hardware-backed WebAuthn 2FA. SMS-based recovery is disabled. U2F/FIDO2 keys are mandatory for all team members.
Rate Limiting & Abuse Detection
API endpoints are protected by per-key and per-IP rate limiters. Anomaly detection triggers automatic circuit breakers when swap patterns deviate from baseline. No single actor can degrade service for others.
Immutable Audit Logs
Every administrative action, configuration change, and key operation is logged to an append-only, cryptographically verifiable audit trail. Logs are shipped off-site in real time and retained for a minimum of seven years.
Wallet Custody Model
Velox does not custody user funds — swaps are non-custodial by design. However, the protocol maintains operational wallets for gas sponsorship and fee collection. These are secured under a tiered custody model.
| Wallet Tier | Purpose | Custody Type | Signing Threshold | Funds Exposure | Rotation |
|---|---|---|---|---|---|
| Gas Hot Wallet | Sponsors user transaction fees on TRON | Hot | Single-sig (HSM) | ~15,000 TRX max (~$4,950) | Daily auto-top-up from warm |
| Gas Warm Wallet | Refills the hot wallet as needed | Warm | 2-of-3 multi-sig | ~150,000 TRX max (~$49,500) | Quarterly key rotation |
| Fee Collection | Receives platform fee revenue | Cold | 4-of-7 multi-sig | Accumulates; swept monthly | Annual rotation |
| Treasury Reserve | Long-term protocol reserves | Cold | 4-of-7 multi-sig | Majority of protocol assets | Annual rotation |
Cold-to-Hot Ratio
Over 92% of protocol-managed assets are held in cold storage (4-of-7 multi-sig with geographically distributed hardware wallets). Hot and warm wallets are capped and automatically replenished — their compromise cannot drain more than the cap allows.
Penetration Testing
Velox undergoes recurring penetration tests covering the full attack surface: web application, API endpoints, WebSocket infrastructure, and cloud environment. Tests are conducted by external firms on a fixed cadence, with supplementary internal red-team exercises between engagements.
External Penetration Test — Cure53 (Jan 2026)
Full-scope black-box test against production infrastructure. Two medium-severity findings related to CSP header configuration were remediated within 48 hours. No high or critical findings.
All Findings ResolvedInternal Red Team Exercise (Apr 2026)
Simulated insider-threat scenario targeting CI/CD pipeline and key management infrastructure. Led to improvements in build attestation and deployment signing. Zero production impact.
Improvements DeployedExternal Penetration Test — Upcoming (Sep 2026)
Next scheduled third-party test covering the SwapRouter v2.1 deployment, WebSocket upgrade, and new API authentication flow. Scope and firm to be announced.
ScheduledBug Bounty Program
Velox maintains a public bug bounty program hosted on Immunefi. Researchers who identify and responsibly disclose vulnerabilities are compensated based on severity and asset impact. The program covers smart contracts, backend infrastructure, and the web application.
| Severity | Smart Contract | Web / API | Example |
|---|---|---|---|
| Critical | $50,000 — $150,000 | $15,000 — $50,000 | Direct loss of user funds, unauthorized contract upgrade, private key extraction |
| High | $15,000 — $50,000 | $5,000 — $15,000 | Manipulation of swap rate, gas reserve drain, authentication bypass |
| Medium | $5,000 — $15,000 | $1,000 — $5,000 | Fee calculation error under specific conditions, CSRF in sensitive endpoint |
| Low | $500 — $2,000 | $250 — $1,000 | Gas inefficiency, missing input validation, information disclosure (non-sensitive) |
Submissions are triaged within 24 hours and resolved on a timeline commensurate with severity. The full bounty scope, rules of engagement, and safe harbor provisions are published at immunefi.com/velox. Researchers are protected from legal action when operating within the published scope.
Incident Response
Velox maintains a documented, tested incident response plan covering security breaches, smart contract anomalies, and infrastructure outages. The plan defines escalation paths, communication protocols, and recovery procedures.
Detection & Triage
24/7 monitoring via on-chain event watchers, API anomaly detectors, and infrastructure health probes. Alerts are triaged by the on-call security engineer within 15 minutes. Critical alerts page the full incident response team.
Containment
Circuit breakers can pause the swap engine within one block (~3 seconds) via multi-sig. Gas reserve access is automatically throttled when anomalous withdrawal patterns are detected. System-wide pause requires 2-of-7 signers.
Communication
Status-page updates within 30 minutes of confirmed incident. Detailed post-mortem published within 5 business days of resolution. Direct notification to institutional partners via dedicated channels. Transparency is non-negotiable.
Recovery & Post-Mortem
After root cause is confirmed and remediated, service is restored under heightened monitoring for 72 hours. A blameless post-mortem is conducted, published, and all action items are tracked to completion in the public changelog.