Security
Formal verification, audits, stress testing, and more
18
View Audits
External Audits
View Audits
4
View Formal Verifications
Formal Verifications Completed
View Formal Verifications
3 Years
Go To Github
Live in Production Without Incident
Go To Github
Overview
Security Components
Smart Contracts
Kamino Lend and Peripheral Contracts
Frontend
Kamino App, Web UI, Client Libraries
Middleware
API, Databases, Cron Jobs, etc.
Risk Monitoring
Risk Dashboard, Risk Consultants, Risk Curators
Operational Infrastructure
Cranks, Bots, Keepers, Liquidators
Third Party Dependencies
Libraries, Oracles, Exchanges, Price Feeds
Security Measures
Open Source
Formal Verification
Bug Bounty
Security Audits
Oracle Security
Redundancy & Fallbacks
Liquidation Stress Tests
Market Risk
Fuzzing (By Ackee)
Verifiable Build
Disclaimer
Open Source
Formal Verification
Ottersec Formal Verification - Kamino Lend
6 October 2025
View Report
Ottersec Formal Verification - Kamino Lend
6 October 2025
View Report
Certora Verification - Kamino Earn Vaults
27 June 2025
View Report
Certora Verification - Kamino Lend
13 May 2025
View Report
Certora Verification - Kamino Limit Orders
21 February 2025
View Report
Bug Bounty ($1.5m)
Kamino has a $1.5M bug bounty program that rewards security researchers for finding and reporting vulnerabilities in the codebase. This is an important part of Kamino’s security strategy, as it allows us to leverage the expertise of the wider community to find and fix issues before they can be exploited.
Security Audits
Total Audits
18
Auditors
5
Critical Vulnerabilities
0
Kamino Lend
Kamino Earn Vaults
Sec3 Audit - Kamino Vaults
6 February 2025
View Report
Offside Labs Audit - Kamino Vaults
12 April 2025
View Report
OtterSec Audit - Kamino Vaults
9 December 2024
View Report
Certora Verification - Kamino Vaults
27 June 2025
View Report
Scope Oracle
Sec3 Audit - Scope
16 December 2024
View Report
OtterSec Audit - Scope
16 December 2023
View Report
Offside Labs Audit - Scope
8 December 2023
View Report
Liquidity Vaults
Farms
OtterSec Audit - Farms
13 October 2023
View Report
Offside Labs Audit - Farms
8 December 2023
View Report
Limit Orders
Sec3 Audit - Limit Orders
29 January 2025
View Report
OtterSec Audit - Limit Orders
7 November 2024
View Report
Offside Labs Audit - Limit Orders
29 November 2024
View Report
Certora Verification - Limit Orders
13 May 2025
View Report
Rolling Code Audits
Oracle Security & Resilience
Kamino Scope
Audits Completed
8
Volume Processed
$19.33B
Oracle Exploits
0
Redundancy & Fallbacks
RPC Redundancy
Cloud Provider Redundancy
Oracle Redundancy
Liquidator Redundancy
Oracle Crank Redundancy
Liquidation Stress Tests
Liquidations Volume
$120M+
# Liquidations
100k+
Bad Debt
$0
Market & Protocol Risk Assessment
Kamino has a dedicated team of risk consultants and curators who monitor the market and protocol risks associated with the protocol's system. These contributors assess the risks of different assets, market conditions, and potential vulnerabilities in the protocol. This helps us to proactively identify and mitigate risks before they can impact the system.
Fuzzing (By Ackee)
Fuzzing is a technique used to find vulnerabilities in our code by providing random or unexpected inputs to the system. We instrument instruction handlers end-to-end to run fuzzing as large-scale property based tests, run invariants on an entire protocol level, and detect regressions between different versions.
Verifiable Build
In addition to being open source and formally verified, Kamino Lend and Kamino Earn have been Verifiably Built. Verified builds ensure that the executable program deployed on Solana network is cryptographically proven to match Kamino's audited source code. This means that the program running onchain corresponds exactly to Kamino's audited source code, enhancing trust and transparency.
Disclaimer