SECURITY · AUDITED

Two audits.Zero critical.

Coinsult and Certik reviewed every line of contract before it touched mainnet. Our team is KYC-verified by AssureDeFi. All reports are public.

2
Independent Audits
0
Critical Findings
KYC
Team Verified
100%
Public Reports
The Auditors

Names you can google in five minutes.

Independent security reviews and identity verification you can check yourself.

AUDIT · 2024

Coinsult

PASSED
Smart contract security audit
AUDIT · 2024

Certik

PASSED
Full project security assessment
KYC · 2024

AssureDeFi

VERIFIED
Team identity verification (KYC)
Public Reports

Full transparency. Verify yourself.

All audit reports and KYC verification are publicly available. Don't trust, verify.

ZERO CRITICAL

No critical vulnerabilities were found in any audit. Full reports are available for public review.

The Pact

Find a bug. Take the bounty.

Five severity tiers. Real payouts. Same day response, even if it lands at 2am.

CRITICAL
+ 3 City credits

Loss of funds. Treasury drain. Total chain halt.

HIGH
+ 1× Tier 3 & 1× Tier 2 credit

Sig replay. Re-entrancy. Bridge race.

MEDIUM
+ 1× Tier 3 credit

DoS. Oracle staleness. Reward rounding.

LOW

Gas griefing. UI spoofing. Event omission.

INFORMATIVE
SWAG

Style. Docs. Best-practice nudges.

FOUND SOMETHING?

Send us the details and a proof-of-concept. We reply within the hour, even at 2am.

HALL OF FAME

No submissions yet. Be the first to find a vulnerability and earn a bounty.

The Protocol

How to tell us you found something.

01

Find

0

A bug in contract, bridge, or wallet flow. Reproducible in a test.

02

Email

T+1h

security@earthmeta.ai · PGP signed if possible. We confirm within the hour.

03

Triage

T+24h

Severity assigned. Bounty quoted. Patch branch opened.

04

Patch

T+7d

Code merged. Re-audited if severity >= medium.

05

Ship

T+9d

Time-locked upgrade. Disclosure goes public. Bounty pays out.

For Users

Your half of the floor.

Security is a shared job. We lock down the protocol; these six habits lock down your side. Give them two minutes.

EarthMeta reminder: admin will never DM you first
01

Verify the URL

The only real site is earthmeta.ai: nothing else. We never use Punycode look-alikes or “.io / .app” clones. Bookmark it and open EarthMeta only from that bookmark.

02

Read every prompt

Every wallet prompt shows the exact spend and the exact target. If a MetaMask prompt asks for more than you expect, decline it; you can always try again.

03

Backup your passkey

Keep two devices with two passkeys. We can never recover your keys; only your wallet provider can, so set up your backup before you ever need it.

04

Use a hardware key

For any wallet holding more than 5,000 EMT, use a Ledger or Trezor. Your keys stay offline, out of reach of malware.

05

Revoke approvals

Every quarter, run a /revoke audit. The fewer contracts that can move your funds, the smaller your attack surface.

06

Beware DMs

We will never DM you first.Anyone offering “support”, giveaways or “validation” in your DMs is a scammer; ignore and block.

The slightest doubt? Just ask us. The chat box in the corner is on every page of the site; if a link, a prompt or a message feels off, check with us before you sign anything.

security@earthmeta.ai · 24/7

Find it.
Take the bounty.

Help us keep EarthMeta safe. Every valid submission gets a response within the hour.

Newsletter

Stay in the loop.

Get the news before everyone else: every big launch, drop and promotion, straight to your inbox. No tracking pixels. Unsubscribe in one click.

No tracking pixels. Unsubscribe in one click.