Security & Verification

Responsible Disclosure & Security

Security architecture, smart contract audit posture, and guidelines for ethical vulnerability submissions to safeguard generational user wealth. Last updated: September 2026.

1. Security Architecture & Invariants

Cadence is architected to eliminate the primary vulnerability vectors of traditional estate planning and on-chain dead man's switches:

Zero Plaintext Storage
All beneficiary identities and split percentages are encrypted client-side using ECIES-secp256k1 before committing the double-hashed Merkle root (allocationRoot).
Quorum Attestation
A 2-of-3 threshold is enforced in GuardianRegistry.sol. No single guardian or rogue signer can initiate vault settlement.
Gasless EIP-712 Dismissal
Living owners can abort false-alarm triggers during the 14-day grace period with zero gas cost, eliminating forensic on-chain wallet linkage.
Stylus WASM Verification
Merkle allocation verification in Rust compiled to WASM delivers sub-cent gas execution with bit-for-bit equivalence to OpenZeppelin Solidity.

2. Smart Contract Scope

The following production smart contracts are in-scope for responsible disclosure submissions:

  • VaultFactory.sol & CadenceVault.sol (Deterministic vault deployment & deposit custody)
  • GuardianRegistry.sol & ConsensusEngine.sol (Proof-of-life attestations & quorum logic)
  • CadenceStream.sol & Aave v3 yield integration (Autonomous per-second stream distribution)
  • stylus_merkle (Arbitrum Stylus WASM Merkle verification module)
  • notifications/ (Sentinel proof-of-life daemon & EIP-712 notification webhook relays)

3. Anti-Drainer Protections

To protect grieving families from phishing drainers, Cadence Streams provide on-chain circuit breakers:

Designated guardians or pre-registered cold backup addresses can call pauseStream() or redirectStream(). If an heir's wallet is compromised after settlement begins, unvested funds are immediately frozen or routed to cold storage without protocol loss.

4. Reporting Guidelines & Response SLA

If you discover a potential vulnerability in Cadence contracts or frontend infrastructure:

  1. Email Securely: Submit vulnerability details and reproduction steps to security@cadenceprotocol.io.
  2. SLA Commitment: The core engineering team will acknowledge your report within 24 hours and provide triage status within 72 hours.
  3. Coordinated Disclosure: Do not publicly disclose or exploit vulnerabilities until a patch is verified and deployed across active testnets.

5. Safe Harbor Guarantee

Cadence considers security researchers who submit vulnerability reports in compliance with these guidelines to be acting in good faith. Cadence commits not to pursue legal action, law enforcement referrals, or DMCA copyright claims against white-hat researchers who adhere to responsible disclosure.