Skip to main content

Audits

BOB Mainnetโ€‹

BOB is based on the OP Stack and relies on the extensive security reviews conducted for the OP Stack infrastructure by the Optimism Collective.

Our dispute game differs from the standard OP Stack implementation by using Kailua, a hybrid zk rollup framework that enables validity proofs for dispute resolution and on-demand fast withdrawals. The Kailua framework has undergone multiple security audits:

Veridiseโ€‹

  • February 2025: Kailua Security Audit. Report
  • May 2025: Kailua Security Audit. Report
  • June 2025: Kailua Security Audit. Report

BOB Gatewayโ€‹

BOB's most novel product is our intent-based Bitcoin bridge, called "BOB Gateway." The reports below show the results of audits for every major release so far.

Cure53โ€‹

  • April 2024: BOB Onramp Smart Contract Audit. Report

Common Prefixโ€‹

  • April 2024: BOB Onramp Smart Contract Audit. Report

Pashovโ€‹

  • April 2024: BOB Onramp Smart Contract Security Review. Report
  • August 2024: BOB Gateway V2 Smart Contract Security Review. Report
  • September 2024: BOB Gateway V3 Smart Contract Security Review. Report

USDC Bridgeโ€‹

We contracted several auditing firms to evaluate BOB's implementation of the USDC bridge from Ethereum mainnet to BOB.

Cure53โ€‹

  • April 2024: BOB Modified USDC Bridge Library. Report

Pashovโ€‹

  • April 2024: BOB USDC Bridge Security Review. Report

FusionLock Contractโ€‹

BOB's "Fusion Season One" campaign preceded our mainnet launch. Users had the option of depositing their tokens into a FusionLock.sol smart contract with the intention of bridging those assets to BOB mainnet once it went live. In preparation for that campaign, we contracted reviews of the FusionLock contract from several auditing firms.

Ottersecโ€‹

  • March 2024: FusionLock Smart Contract Audit. Report

Common Prefixโ€‹

  • March 2024: FusionLock Smart Contract Audit. Report

Trail of Bitsโ€‹

  • April 2024: FusionLock Smart Contract Security Review. Report