01 Smart Contract Audit
The VORA token contract has been reviewed by EVM Smart Audit. The report returned a risk score of 4 out of 100 — low risk, with no critical, high or medium findings. The full report is public and can be read in its entirety at the link below.
| Severity | Findings | Status |
|---|---|---|
| Critical | 0 | None found |
| High | 0 | None found |
| Medium | 0 | None found |
| Low | 1 | Missing zero-address check in constructor |
| Informational | 5 | Code-quality notes, no security impact |
| Gas optimisation | 8 | Efficiency suggestions, no security impact |
Standards coverage from the same report: OWASP Smart Contract Top 10 — 8 of 10 categories clear (SC04 Input Validation and SC08 Integer Overflow & Underflow flagged), and SWC Registry — 10 of 12 clear (SWC-101 Integer Overflow and SWC-103 Floating Pragma flagged).
| Audited artefact | Detail |
|---|---|
| Contract | 0xa4B392e307C014ec842E520fc70233028cDd4A22 |
| Network | BNB Chain |
| Token | VORA (VRA), ERC-20 |
| Compiler | solc v0.8.28+commit.7893614a |
| Codebase | 631 lines · 3 contracts · 30 functions · 6 state variables · 0 external calls |
| Attack surface | 9 external · 11 public · 10 internal · 0 payable · 15 view/pure |
Read the full EVM Smart Audit report →
Scope and limits. This report covers the VORA token contract only — it does not cover the presale, vault or any bridge component. In the auditor's own words, automated and AI-assisted analysis reduces but does not eliminate risk; the report is not a guarantee of security, and a manual review by qualified auditors is recommended before mainnet deployment. Read the full report and make your own assessment before contributing.
02 Contract Security Features
The VORA smart contracts implement industry-standard protections:
Reentrancy Guard
All state-changing functions are protected against reentrancy attacks using the Checks-Effects-Interactions pattern.
24-Hour Timelock
Any admin action on the protocol is delayed by 24 hours, giving the community time to review and react.
Guardian System
An emergency guardian can pause the contract instantly if an exploit is detected, limiting damage.
Open Source
Contract source code is verified on Etherscan and BscScan, so anyone can review and confirm it on-chain.
03 Treasury & Multisig
Presale contributions and the VORA treasury are protected by a Gnosis Safe multisig wallet. No single person can move funds.
- 5-of-8 signature policy: any transfer requires approval from at least 5 of 8 signers.
- Separated roles: signers include core team, advisors, and independent community members.
- Liquidity lock: 100% of DEX liquidity is locked for 24 months via Team Finance.
- Transparent reporting: treasury addresses and movements are published monthly.
All contributions go on-chain to a publicly verifiable contract address. Always confirm the address on our official channels before contributing.
04 Responsible Disclosure
If you find a vulnerability in the VORA contracts or this website, we want to hear about it. There is no paid bug bounty programme at this stage — we will not claim one until it is actually funded and live. What we do commit to is a clear disclosure process:
- Report privately first. Email us before disclosing anything publicly or on social media.
- Include a proof of concept. Steps to reproduce, affected contract address, and expected versus actual behaviour.
- Acknowledgement within 72 hours, and a status update at least every 7 days until the issue is closed.
- Public credit for the reporter once a fix is deployed, if you want it.
Send reports to security@vorachain.com. Do not test against mainnet in a way that puts other users' funds at risk.
05 AI Risk Engine
VORA integrates a real-time AI risk engine that monitors on-chain activity to detect suspicious patterns:
- Rug detection: flags contracts showing rug-pull behaviour before users interact with them.
- MEV protection: presale contributions are routed to minimize front-running and sandwich attacks.
- Anomaly alerts: unusual wallet activity triggers automatic review and optional pausing.
06 Wallet Safety Tips
Protect yourself. Always follow these best practices:
- Never share your seed phrase. No one from VORA will ever ask for it.
- Store your seed phrase offline on paper — never in a cloud service or a screenshot.
- Use a hardware wallet (Ledger, Trezor) for large contributions.
- Double-check the destination contract address before confirming any transaction.
- Beware of fake "support" agents on Telegram or Discord — official accounts are pinned on our website.
Scammers create fake websites that look exactly like VORA. Always reach the presale through the official link and verify the URL before connecting your wallet.
07 Anti-Scam Policy
VORA will never:
- Send you a direct message first on Telegram, Discord, or X.
- Ask you to send tokens to "verify" or "activate" your wallet.
- Offer guaranteed returns, airdrops, or bonuses outside the official platform.
- Request your private key, seed phrase, or password.
If you encounter a suspicious message or a site impersonating VORA, report it immediately.
08 Report a Vulnerability or Scam
Security is a shared responsibility. If you find a vulnerability, encounter a scam, or have a security concern, contact us right away:
- Security email: security@vorachain.com
- Audit report: EVM Smart Audit — VORA
- Scam report: Contact form — pick “Security report”
- PGP key: available on request for sensitive disclosures
We acknowledge every security report within 48 hours and coordinate the fix directly with the reporter.
Security you can verify
Audited, multisig-protected, and bug-bounty backed. Join the presale with confidence.
Buy VORA Now