Security & Threat Architecture
Security is not an afterthought. In an autonomous economy where machines move value, cryptographic constraints must be rigorous and verifiable.
Apraxus is currently in active prototype development (Phase 02). Formal third-party security audits will be commissioned and published prior to public testnet and mainnet genesis (Phase 08). We do not claim completed audits before verified completion.
Agent Key Compromise
If an agent's sub-key is leaked or hallucinated into prompt logs, attacker damage is mathematically bounded by the remaining time-window spend budget and allowlist destinations.
Replay & Double-Spend
Every signed transaction payload includes deterministic nonce tracking and chain ID validation enforced directly at the Rust transaction verification pipeline.
Responsible Vulnerability Disclosure
If you discover a security vulnerability in any Apraxus core repository or prototype, please disclose it responsibly to security@apraxus.io. We prioritize rapid patch review and triage.