Security and audits
Every TokenLabs contract that holds user funds has been audited by an independent firm. Here are the reports, the official addresses and how to report a problem.
Independent audits
MoveBit
- Scope
- vIOTA liquid staking contracts (Move, IOTA Rebased)
- Result
- 0 critical and 0 major findings
AuditOne
- Scope
- Token and vesting contracts (Solidity, IOTA EVM)
- Result
- 25 findings: all 8 high, 5 medium and 7 low resolved
SolidProof
- Scope
- Token factory and ERC-20 token (Solidity, IOTA EVM)
- Result
- 0 critical, 0 high; 1 medium fixed
An audit reduces risk but does not remove it. Always check that you are on tokenlabs.network before signing a transaction.
Your funds stay yours
With native staking you delegate from your own wallet: TokenLabs never takes custody of your IOTA and you can withdraw whenever you want. With liquid staking you receive vIOTA in your wallet, which you can redeem for IOTA.
Stake IOTA with TokenLabsOfficial addresses
Report a vulnerability
If you find a security problem, email us before making it public so we can fix it. Include the steps to reproduce it.
admin@tokenlabs.network