teleo-codex/decisions/internet-finance/umbra-fund-security-audits.md
m3taversal 018ee566e2 rio: standardize all 10 ownership coin entities with portfolio dashboard schema
- What: Rewrote all 10 ownership coin entity files (mtnCapital, OmniPair, Umbra,
  Avici, Loyal, ZKFG, Paystream/PAYS, Solomon/SOLO, Ranger, P2P.me) with
  standardized frontmatter schema for dashboard consumption. Deduplicated
  9 redundant files (Ranger had 4, P2P had 4, Umbra had 2, OmniPair had 2).
  Updated all wiki links across decisions/, sectors/, and entities/ to point
  to canonical files.
- Why: m3ta requested portfolio dashboard. Entity stubs had near-zero structured
  data. Dashboard rendering requires standardized schema with raise amounts,
  token addresses, traction metrics, and chain data.
- Gaps flagged: Token addresses for 5 coins, treasury multisig addresses for all 10,
  LP pool addresses, mtnCapital raise details. Phase 2 cron script will auto-fill
  on-chain numerics.

Pentagon-Agent: Rio <244BA05F-3AA3-4079-8C59-6D68A77C76FE>
2026-04-17 13:23:42 +01:00

3.9 KiB

type entity_type name domain status parent_entity platform proposer proposal_url proposal_date resolution_date category summary tracked_by created source_archive
decision decision_market Umbra: UMBRA-001 — Fund Security Audits internet-finance passed umbra-privacy-protocol futardio Umbra team https://www.metadao.fi/projects/umbra/proposal/71nYHjLpgY7evn9G4UaGCBd6cYHpGWzrzd3ESs2KUduG 2025-11-12 2025-11-15 operations Fund Umbra security audits before mainnet launch rio 2026-03-24 inbox/archive/2025-11-12-futardio-proposal-umbra-001-fund-umbra-security-audits.md

Umbra: UMBRA-001 — Fund Security Audits

Summary

Umbra allocated treasury funds for security audits before mainnet launch, following the same pre-launch audit pattern as Omnipair (OMFG-002).

Market Data

  • Outcome: Passed
  • Duration: 2025-11-12 to ~2025-11-15

Significance

Second FaaS-launched project (after Omnipair) using futarchy to approve pre-launch security audits, establishing this as a standard governance pattern.

Relationship to KB

Full Proposal Text

Source: futard.io, tabled 2025-11-12

Proposer: Kru Requested: 105,000 USDC Recipient: Kru (for audit coordination) Purpose: Security audits for Umbra before mainnet

Summary

We are in the final stages of Umbra going live on mainnet alongside Arcium and we've spent the last month evaluating different audit partners. So far the best partner for us seems to be Halborn. This proposal looks to initiate a spend of $105,000 USDC for the same.

About Halborn

  • Founded: 2019

  • Focus: Cybersecurity and auditing firm

  • Value Secured: Over $1 trillion in digital assets

  • Clients: 600+ across exchanges, custody infrastructure, and blockchains

  • Solana Ecosystem Security Work: Conducted audits for Solana Foundation, Solana Labs, and Anza.

  • Reviewed 150K+ lines of code across SPL programs and Layer-1 components.

Goal

  • Halborn will secure and verify both ZK circuits and Anchor program before Arcium mainnet launch.

Challenges and scope as highlighted by Halborn

Challenges

  • Two codebases nearing completion, with ZK circuits ready for audit and Solana programmes following within weeks.

  • No prior external audit of Umbra's cryptographic logic - high need for independent ZK + Rust review.

  • Tight launch window (~30 days) creates risk without parallel audit execution and structured issue tracking.

  • Complex dependencies on Arcium's evolving MPC infra make code freeze and scoping fluid.

  • Global, remote team (India + Spain) requires timezone-aligned engineering collaboration and rapid feedback loops

  • Scope Includes

    • Software, System & Process design advisory
    • Technical & Security Overview
    • Penetration Testing & Source Code Security Assessment
    • Mobile Application Security Assessment
    • Red Team Exersice ( OpSec )
    • Cloud Security Assessment

You can read more about the payment terms and scope of work here: (Halborn Retainer Doc).

Execution and Timeline

  • Total: $105,000
  • Disbursement:
    • Upfront: $35,000
    • The remaining balance of $70,000 shall be paid upon the earlier of:
      • (a) Approval of the payment and release of funds allocated to Umbra
      • (b) Delivery of the draft report by Halborn to Client.
  • Timeline: 35 Days
  • Note: To ensure we can meet our launch timelines Kru will be making an upfront payment of $35000 to help us proceed with the engagement with Halborn without any delays

Raw Data

  • Proposal account: 71nYHjLpgY7evn9G4UaGCBd6cYHpGWzrzd3ESs2KUduG
  • Proposal number: 1
  • DAO account: BLkBSE96kQys7SrMioKxeMiVbeo4Ckk2Y4n1JphKxYnv
  • Proposer: BF8hxzzR4KuVxfsyAUFyy26E6y2GhsSZgBoUQrygwof1
  • Autocrat version: 0.6