Security

Reporting a vulnerability

How to tell us about a security problem in Levy, what is in scope, and what we commit to in return.

Status. Levy runs on Arc testnet and has not been audited yet. No real money flows through it, and its contracts never hold funds at rest. Reports now still matter: everything found before mainnet gets fixed before mainnet.

How to report

Email hello@getlevy.xyz with "Security" in the subject. Please include:

Please keep it private until it is fixed or we have agreed a date to publish together. This address is also listed in our security.txt.

Scope

Out of scope: Arc itself, USDC, Permit2 and wallets (please report those to their owners), denial of service and load testing, social engineering, and scanner output or missing headers without a demonstrated impact.

Rules for testing

What we commit to

Levy does not run a paid bug bounty yet.

Levy © 2026 · hello@getlevy.xyz