If you discover a security vulnerability, please:
- DO NOT open a public issue
- Email security concerns privately to the maintainers
- Include a detailed description of the vulnerability
- Allow reasonable time for a fix before public disclosure
| Version | Supported |
|---|---|
| 1.x | ✅ |
The TimeFi Protocol implements the following security measures:
- Access Controls: All admin functions require deployer authorization
- Input Validation: All parameters are validated against defined limits
- Time-Lock Protection: Vaults cannot be withdrawn before unlock time
- Fee Limits: Fees are capped at protocol constants
- This contract has not been audited. Use at your own risk.
- The protocol relies on
stacks-block-timefor time calculations - Bot approval uses
contract-hash?which requires contract principals
- Only deposit amounts you can afford to lock
- Verify the unlock time before creating a vault
- Test with small amounts first
- Keep your wallet keys secure
For security concerns, please contact the maintainers privately.