AUDIT STATUS · STATED EXACTLY

Is BlazePhoenix audited?

Not yet by an external firm — that audit is scheduled — and every merge is already gated by symbolic proofs, static analysis, adversarial suites and an open bounty whose confirmed findings are published as numbered, credited advisories.

That is the whole answer, stated at its exact strength: engineering evidence is not an audit, and an audit is not a guarantee. Below is the pipeline that runs today, each element linked to its living evidence — judge it by what you can reproduce.

Open bug bounty, running

A 50,000,000 BZPX research pool with private disclosure, multiple completed waves, and nine credited external researchers — every confirmed finding fixed, documented or bounded before publication.

See the evidence ›

Numbered advisories

The BPX register: permanent ids, results-level summaries, OSV-format mirrors — the discipline of protocols that expect to be checked.

See the evidence ›

Adversarial test suites

Invariant suites and regression tests gate every merge in CI; the counts and the harness are public in the repositories.

See the evidence ›

Live self-verification

The protocol checks itself in your browser: solvency reads, quote cross-checks, the /api/verify surface over proof-carrying facts.

See the evidence ›

Until the audit lands

The pre-launch rule printed on the swap page applies: test with a low amount first. Nothing custodies your funds and every swap settles under a minimum you sign — but the honest advice before a new release is to prove the path with a small trade.

The full safety walkthrough ›