> For the complete documentation index, see [llms.txt](https://docs.noon.capital/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.noon.capital/5.-the-security-framework/smart-contract-security-and-audits.md).

# Smart Contract Security & Audits

Are Noon's smart contracts secure? Code-level verification, continuous auditing, and hardcoded programmatic guardrails.

## <mark style="color:$success;background-color:$success;">**Prevent**</mark>

At <mark style="color:purple;">**Noon**</mark>, smart contract security is not a one-time pre-launch checkbox—it is a continuous, multi-layered discipline.

Smart contracts execute autonomously on public ledgers to handle minting, redemption, staking, yield routing, and rebalancing for <mark style="color:violet;">**$USN**</mark> and <mark style="color:violet;">**$sUSN**</mark>. To guarantee complete system integrity, <mark style="color:purple;">**Noon**</mark> enforces security across two distinct code-level vectors: Rigorous Third-Party Code Auditing and Hardcoded On-Chain Protection Rules.

<figure><img src="https://3816918787-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FL26rQzcNmiUZrCXkxkjS%2Fuploads%2FEgXUkVXIqsn54eE2dsQH%2FContractSecurity.png?alt=media&amp;token=d50d4e66-d3bb-4976-97ca-0514e3d5a6b9" alt=""><figcaption></figcaption></figure>

## <mark style="color:$primary;">1. Smart Contract Auditing Standards</mark>

No smart contract code reaches mainnet or secondary blockchain deployments without undergoing comprehensive, remediated third-party security audits.

#### Our Code Audit Policy

* **Pre-Deployment Execution:** Every core contract deployment must complete a full third-party audit before accepting user deposits.
* **Continuous Upgrade Trigger:** Every protocol upgrade, logic modification, adapter addition, or cross-chain expansion automatically triggers a fresh, independent security review prior to mainnet execution.
* **Multi-Firm Diversity:** We engage multiple leading auditing firms—including Quantstamp, Halborn, Hashlock, MoveBit, and Sherlock—to eliminate single-auditor blind spots and achieve multi-lens code verification.

### Comprehensive Audit History

The cards below catalogs every smart contract audit executed across Noon’s protocol architecture:

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><strong>Sept 2024</strong></td><td>Auditor: Quantstamp</td><td>Audit Report: <a href="https://drive.google.com/file/d/1JVaUhXwhfB6eesWPNhSfHG3mJ7g_JpYL/view?usp=drive_link"><strong>Link</strong></a></td><td><a href="https://3816918787-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FL26rQzcNmiUZrCXkxkjS%2Fuploads%2Fz9aIpRRxcsfylqUzSnJF%2FQuantstamp.jpeg?alt=media&amp;token=8dcc6beb-3aa4-407f-b223-df68dd89d08c">Quantstamp.jpeg</a></td></tr><tr><td><strong>Dec 2024</strong></td><td>Auditor: Halborn</td><td>Audit Report: <a href="https://drive.google.com/file/d/1vWysiNkjxRrhP9xJ4HywuDXsDWNj7X7r/view?usp=drive_link"><strong>Link</strong></a></td><td><a href="https://3816918787-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FL26rQzcNmiUZrCXkxkjS%2Fuploads%2FmZHeewvqiQeysJWkK7sZ%2FHalborn.jpeg?alt=media&amp;token=b4638166-b808-4e9f-983e-e6c8defe83f3">Halborn.jpeg</a></td></tr><tr><td><strong>March 2025</strong></td><td>Auditor: Halborn</td><td>Audit Report: <a href="https://www.halborn.com/audits/noon-capital-stablecoin/staking-vault-c3c4ef"><strong>Link</strong></a></td><td><a href="https://3816918787-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FL26rQzcNmiUZrCXkxkjS%2Fuploads%2FmZHeewvqiQeysJWkK7sZ%2FHalborn.jpeg?alt=media&amp;token=b4638166-b808-4e9f-983e-e6c8defe83f3">Halborn.jpeg</a></td></tr></tbody></table>

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td><strong>June 2025</strong></td><td>Auditor: Hashlock</td><td>Audit Report: <a href="https://hashlock.com/audits/noon-capital"><strong>Link</strong></a></td><td><a href="https://3816918787-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FL26rQzcNmiUZrCXkxkjS%2Fuploads%2FBMMnjeFy38aQtE0M2G6s%2Fphoto_2025-07-10%2015.23.04.jpeg?alt=media&amp;token=8ea29d72-7ddf-4255-b97f-410cabc02f18">photo_2025-07-10 15.23.04.jpeg</a></td></tr><tr><td><strong>November 2025</strong></td><td>Auditor: Hashlock</td><td>Audit Report: <a href="https://hashlock.com/audits/noon-capital"><strong>Link</strong></a></td><td><a href="https://3816918787-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FL26rQzcNmiUZrCXkxkjS%2Fuploads%2FiQOpvBayvH7ukI1jWaxc%2Fhashlocknoon.avif?alt=media&amp;token=a6fc39d3-6511-42c8-b350-baef9b2d9d30">hashlocknoon.avif</a></td></tr><tr><td><strong>March 2026</strong></td><td>Auditor: Hashlock</td><td>Audit report: <a href="https://hashlock.com/audits/noon-capital"><strong>Link</strong></a></td><td><a href="https://3816918787-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FL26rQzcNmiUZrCXkxkjS%2Fuploads%2FiQOpvBayvH7ukI1jWaxc%2Fhashlocknoon.avif?alt=media&amp;token=a6fc39d3-6511-42c8-b350-baef9b2d9d30">hashlocknoon.avif</a></td></tr><tr><td><strong>June 2026</strong> (SUI only)</td><td>Auditor: MoveBit</td><td>Audit Report: <a href="https://www.movebit.xyz/reports/sUSN-Audit-Report.pdf"><strong>Link</strong></a><br></td><td><a href="https://3816918787-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FL26rQzcNmiUZrCXkxkjS%2Fuploads%2FcnHg4NIgrRTxaoyhtUjO%2FMovebit.avif?alt=media&amp;token=94b3e151-cb3f-46fd-af09-7bd8218bfdfc">Movebit.avif</a></td></tr><tr><td><strong>June 2026</strong></td><td>Auditor: Sherlock</td><td>Audit report: <a href="https://github.com/sherlock-protocol/sherlock-reports/blob/main/audits/2026.07.21%20-%20Final%20-%20Noon%20Capital%20Collaborative%20Audit%20Report%201784634533.pdf"><strong>Link</strong></a></td><td><a href="https://3816918787-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FL26rQzcNmiUZrCXkxkjS%2Fuploads%2FnHETUlSPSo24oaZb08ws%2F699fb20f8210155e1a154ca1_brandkit_bp-suggested-6.webp?alt=media&amp;token=a089830a-7d35-4446-83aa-46efba2f0a1e">699fb20f8210155e1a154ca1_brandkit_bp-suggested-6.webp</a></td></tr></tbody></table>

## <mark style="color:$primary;">2. On-Chain Code Protection & Programmatic Guardrails</mark>

Auditing code is only effective when paired with defensive, hardcoded execution rules. <mark style="color:purple;">**Noon**</mark> enforces strict programmatic guardrails directly within its smart contract architecture:

* **Separated Role Permissions:** Administrative functions—such as Admin, Staking, Rebase, and Blacklist—are isolated into distinct, role-gated smart contracts. No single admin key or role can cross boundaries to access or sweep user funds.
* **48-Hour Public Timelocks:** All non-emergency contract updates are subjected to a mandatory 48-hour on-chain timelock. This public delay allows stakers, integrators, and security researchers to inspect queued contract changes on-chain—and exit positions if they disagree—before code executes.
* **Granular Emergency Circuit Breakers:** Pause controls allow authorized security roles to halt minting, redemptions, staking vaults, or $USN transfers in an emergency. Crucially, pause mechanisms cannot transfer, divert, or reallocate user capital; they serve purely as a fast, low-risk containment measure.
* **Contract-Level Safety Rules:** Direct minting and redemptions enforce per-block and per-day volume caps, utilize nonce checks to prevent replay attacks, and anchor valuations to redundant price oracles that automatically reject stale or out-of-band market feeds.

## <mark style="color:$primary;">Verification & Bug Reporting</mark>

#### Canonical Address Verification

To protect against phishing attacks and spoofed contracts, always verify smart contract addresses against our official directory before interacting:

* [Contract Addresses & Oracles](/6.-resources/contract-addresses-and-oracles.md)

#### Whitehat Security & Vulnerability Reporting

If you discover a potential vulnerability or security flaw in Noon’s smart contracts, please report it immediately through our structured triage framework:

* [Thorough Incident Response Framework](/5.-the-security-framework/thorough-incident-response-framework.md)
