Contract security
What the programs guarantee
InferMesh runs on three Anchor programs. This page lists their addresses, the invariants they enforce on every transaction, the admin powers that exist, and how the off-chain services are secured.
Programs
Live mint addresses and balances are on the Explorer.
Invariants enforced on-chain
Credit registry
- Full backing. Purchases at par and redemptions move USDC and credit liabilities one-for-one. Publishing a distribution or withdrawing reserve surplus fails with
InsufficientBackingif the USDC reserve would no longer cover every outstanding credit. - Cumulative claims. Each published epoch commits a merkle root of cumulative entitlements; a wallet can never claim more than its proven cumulative total, and total claims can never exceed total distributed.
- Mint safety. $CREDIT must use 6 decimals, have no freeze authority, start with zero supply and have the registry PDA as its only mint authority.
- Bounded fees. The market protocol fee is capped at 10% and the referral commission at 20% in the program itself.
- Buyer protection. A listing fill fails if the price exceeds the buyer's maximum.
- Agent limits. Session keys can only move vault USDC into their agent's balance, within the per-top-up maximum, daily cap and expiry the owner set; the owner can revoke them instantly.
Fee router and staking
- Fee splits must sum to exactly 10,000 basis points.
- The token mint's withdraw-withheld authority must be the fee router's PDA, so harvested fees can only flow through the router.
- Stake earns nothing until it has been held for the pool's minimum hold period (24 hours); time-weighted stake-seconds are accumulated on-chain and replayed exactly off-chain.
- Staking and unstaking refund the token's transfer fee in the same instruction, so moving in and out of the pool is fee-neutral.
Admin powers
- Only the program upgrade authority can initialize each program, preventing front-run initialization with hostile parameters.
- Admins can pause new stakes, pause the registry and keeper withdrawals, and adjust fees within the hard caps above. Admin transfers are two-step (propose, then accept).
- The programs are upgradeable. Treat the upgrade authority as a trusted party until it is moved to a multisig or made immutable.
Off-chain security
- API keys are 256-bit random secrets stored only as HMAC-SHA256 hashes with a per-key salt and a server-side pepper; they are shown once.
- Requests are authorized against per-key scopes, spend caps and rate limits atomically in the database; repeated failed authentications block the source IP.
- Sign-in uses single-use, expiring Sign-In-With-Solana messages; sessions are HttpOnly, SameSite cookies.
- Agent session keys are encrypted at rest with AES-256-GCM.
- The gateway records token counts, latency and status for billing — never prompts or completions.
Reporting a vulnerability
Please report suspected vulnerabilities privately by direct message to our official X account. Do not open public posts with exploit details.