Security

Security at Origin

Origin’s security program applies to all its smart contracts, operational systems, and responsible disclosure.

No program completely eliminates risk, but we reduce it through pre-launch review, strict controls on operations, rapid response to reports, and transparent communication with our stakeholders.


Security by design

Security review continues after deployment as products, integrations, and operating conditions change.

Origin’s smart contracts have been in production since 2020. The team maintains rigorous security practices to meet the standards capital allocators demand.

01

Engineering Review

Changes are reviewed by at least two engineers for various attack vectors before deployment.

02

External Audits

Specialist firms review new contracts and material protocol changes.

03

Operational Security

Multisigs, timelocks, and strict permissions constrain sensitive operations.

04

Continuous Reviews

Independent researchers can report eligible vulnerabilities through Origin’s Immunefi program.

05

Transparent Records

Audit reports are published in Origin’s public security repository.

Independent reviewers

Selected firms that have reviewed Origin code and protocol changes

01
02
03
04
05
06
07

From code to production

Every release passes through defined review gates.

Contract changes move through a fixed sequence of technical checks, independent review, and verified remediation before production.

  1. Tests pass
  2. Findings triaged
  3. Internal sign-off
  4. Audit complete
  5. Fixes verified

Defense Across the Stack

Protocol security and the operational perimeter

Risk is managed across the contracts that hold authority and the systems that support them.

Onchain security

01

Bounded code and authority

  • Material contract changes receive focused engineering review and external audits.
  • Multisigs, timelocks, and strict permissions constrain sensitive operations.
  • Accounting, oracles, liquidity, integrations, and upgrade paths are reviewed as connected risks.

Operational security

02

Protected systems and processes

  • Least-privilege access and separation of duties reduce single points of failure.
  • Dependency checks and change review protect software supply chains and releases.
  • Hypernative monitoring and incident procedures support rapid investigation and containment.

Public bug bounty

Independent researchers are part of the security model.

Origin’s public Immunefi program gives researchers a private channel for eligible reports. Origin’s public Immunefi program publishes the eligible smart-contract and web/application scope, impact criteria, and reward terms.

Up to

$1M

in bug bounty rewards

$50K
Minimum for critical smart-contract vulnerabilities
$138K+
Paid to qualified researchers
8 hours
Average first response time

Transparent security work

Security claims should be inspectable.

Help keep Origin secure.

Review the published security materials, evaluate the risks relevant to your use case, or submit an eligible vulnerability report through Immunefi.