Think adversarially
For every critical component, we ask what could go wrong, including unlikely and worst-case scenarios, and design around those possibilities.
Protocol security
While no decentralized protocol can eliminate every vulnerability, there is a lot that can be done to reduce risk.
At Money On Chain, security means continuously questioning assumptions, examining worst-case scenarios, strengthening the protocol, and being prepared to act when something unexpected happens.
From protocol design and independent audits to an open bug bounty program and public incident reporting, security is treated as a continuous responsibility, not a one-time review.
01 / Our approach
Security is considered throughout the lifecycle of the protocol, from the assumptions behind a new feature to how the system should behave under unexpected conditions.
For every critical component, we ask what could go wrong, including unlikely and worst-case scenarios, and design around those possibilities.
Not every risk can be eliminated. The protocol includes mechanisms and operational procedures designed to contain potential failures and protect its core functions.
Security planning includes predefined procedures for evaluating incidents, coordinating a response, and communicating what is happening.
When a security concern appears, addressing it takes precedence over shipping new functionality.
02 / Continuous security
Challenge assumptions and consider adverse scenarios.
Review implementations through internal testing, external audits, and independent security research.
Turn findings into improvements to contracts, infrastructure, and operational procedures.
Follow protocol behavior and emerging risks after deployment.
Use established procedures and protocol safeguards when intervention becomes necessary.
Document incidents and use what was learned to strengthen the protocol.
“We assume that something can go wrong, and we design and operate the protocol accordingly.”
03 / Open research
Money On Chain maintains a public bug bounty program on Immunefi, inviting independent security researchers to identify vulnerabilities across smart contracts, applications, oracle infrastructure, and governance.
View bug bountyPublic bug bounty
04 / Independent review
External security reviews provide another layer of scrutiny to the protocol. Money On Chain works with independent auditors to identify potential vulnerabilities and strengthen its implementation.
View audit reports05 / Transparency
Security incidents and protective actions are documented publicly. This history provides a clear record of what happened, what was affected, and how the protocol responded.
Minting and redemption operations were temporarily affected after a protocol safeguard was activated.
No material losses occurred and protocol solvency was not affected.An issue affecting MOC staking rewards resulted in unintended value extraction over an extended period.
Protocol solvency and user collateral were not affected.
06 / Open governance
Protocol hardening does not only happen behind closed doors. Security-related improvements, governance discussions, and incident analyses are published through the Money On Chain governance forum, allowing the community to follow how the protocol continues to evolve.
Explore the governance forum07 / Resources
For every critical component, we ask what could go wrong, including unlikely and worst-case scenarios, and design around those possibilities.
Explore Immunefi ↗02Not every risk can be eliminated. The protocol includes mechanisms and operational procedures designed to contain potential failures and protect its core functions.
Read the documentation ↗03Security planning includes predefined procedures for evaluating incidents, coordinating a response, and communicating what is happening.
Visit governance forum ↗