Pilot
All systems live
Security

Security is our top priority.
Audited by top companies.

Six independent audits. Zero critical vulnerabilities. $1M bug bounty. Every layer of Pilot is built to protect your assets.

Independent audits
6
Bug bounty max
$1M
Critical findings
0
Non-custodial
100%
Architecture

Defense in depth.

Non-custodial by design
Private keys are generated and stored locally on your device. Pilot's servers never see, store, or have access to your keys. Even if our infrastructure were compromised, your funds remain safe.
Transaction simulation
Every transaction is simulated in a sandboxed environment before you sign. Malicious contract interactions, phishing attempts, and abnormal token approvals are flagged and blocked automatically.
Real-time threat detection
Pilot's security engine continuously monitors for known exploit patterns, contract vulnerabilities, and suspicious address activity. Threats are neutralized before they reach your wallet.
Open source contracts
All core smart contracts are publicly deployed and verified on-chain. Anyone can inspect, audit, or fork the code. Transparency is a security feature, not a liability.
Hardware wallet native
Ledger and Trezor work natively — desktop via USB, mobile via Bluetooth. The most sensitive operations never touch software-only signing. Hardware security modules protect institutional deployments.
Multi-sig governance
Protocol upgrades require multi-signature approval from a geographically distributed set of keyholders. No single point of failure. Emergency pause mechanisms are built into every critical contract.
Audit Reports

Fully audited. Fully public.

FirmDateScopeFindingsStatus
ToB
Trail of Bits
Mar 2026Core Contracts v20 Critical, 2 LowResolved
O
OpenZeppelin
Jan 2026Bridge & Router0 Critical, 1 MedResolved
C
Consensys
Nov 2025Perpetuals Engine0 Critical, 3 LowResolved
Q
Quantstamp
Sep 2025Yield Vault Contracts0 Critical, 0 MedClean
SP
Sigma Prime
Jul 2025Oracle Integration0 Critical, 1 LowResolved
M
MixBytes
May 2025Token & Governance0 Critical, 0 MedClean
Timeline

Security milestones.

Q1 2025
Initial security architecture designed with zero-trust principles
Q2 2025
First two audits completed — MixBytes and Sigma Prime
Q3 2025
Bug bounty program launched with $500K max payout
Q4 2025
Consensys and Quantstamp audits completed
Q1 2026
OpenZeppelin audit; bug bounty raised to $1M
Q2 2026
Trail of Bits v2 audit; zero critical findings across all 6 audits
$1,000,000

Bug Bounty Program

Found a vulnerability? We pay up to $1M for critical findings. Responsible disclosure is rewarded — not prosecuted.