Built to protect your assets.
MetaWorm is built for real-world value, which means security is foundational — not an afterthought. Here is how we protect the protocol and your assets.
Contracts under audit
27 UUPS-upgradeable contracts are undergoing external security audit. No completed third-party report has been published yet — this is a Sepolia testnet deployment.
Self-custody
Privy embedded wallets are key-shard, exportable, and recoverable. You always own your assets.
Upgrade governance
Contracts are upgradeable (UUPS). Upgrade authority is being migrated to timelocked, MAAT-governed control — until that migration completes, treat this as an admin-controlled testnet deployment.
Responsible disclosure
Found a vulnerability? We want to hear from you.
Report security issues privately to security@metaworm.io. Please do not disclose publicly until we have confirmed and patched the issue.
We aim to acknowledge reports within 48 hours and provide a remediation timeline within five business days. Eligible reports qualify for our testnet bug-bounty program.