Security

Built to reduce risk

DeFi always carries risk. Rujira is built to reduce avoidable risk with transparent systems, safer infrastructure, self-custody, and clear information, so you understand what protects you and what still needs your attention.

Rujira interface security illustration.

Protections

What helps protect you

Rujira is designed with several layers of protection. These protections do not remove all risk, but they help reduce common failure points across cross-chain DeFi, pricing, custody, and system control.

  1. Enshrined Oracles

    Built to reduce oracle risk

    Price manipulation is a common risk in DeFi. Rujira uses THORChain and Enshrined Oracle design, which combines prices from multiple independent sources rather than relying on a single feed.

    Outliers are filtered out before prices are reported, helping protect against inaccurate data. If one source goes offline, fails, or reports an abnormal price, the network can continue using data from the remaining sources.

    Embedding oracle prices directly into chain consensus helps reduce front-running from bots watching mempool activity or pending oracle updates.

    Read the oracle architecture
  2. Secured Assets

    Backed by real native assets

    Secured Assets are backed 1:1 by real native assets held in THORChain's decentralized vault network. These vaults are managed by a rotating set of decentralized node operators, helping protect the assets that back the system.

    They make cross-chain access possible without relying on third-party bridges or traditional wrapped assets custodied by centralized intermediaries, while maintaining verifiable backing to the underlying native asset.

    Explore Secured Assets
  3. Time lock

    Time to respond before funds move

    Every outbound transaction on THORChain includes a delay before assets leave the network. The size of the transaction determines how long that delay is, with larger transactions waiting longer than smaller ones.

    This gives the network and node operators time to detect unusual activity and respond if needed before funds are released.

  4. CONTRACT SAFETY

    Designed to avoid common smart contract risks

    Rujira contracts run on CosmWasm, a framework designed to reduce several risks often seen in Solidity-based systems. Its execution model helps prevent reentrancy, avoids risky delegate call patterns, and supports safer contract upgrades.

    No smart contract platform is risk-free, but CosmWasm gives Rujira a stronger foundation for building reliable DeFi products.

Security works best in layers

Layered security illustration showing multiple connected networks protected by a lock.

Continuous Security

Protection doesn't stop at the infrastructure

Strong infrastructure is only one part of security. Rujira also invests in audits, open-source development, bug bounties, security partners, and continuous review to help identify issues before they become problems.

  1. TRANSPARENCY

    Open source and community reviewed

    Rujira's code is publicly available for anyone to inspect, test, and verify. We also work with bug bounty partners to reward security researchers who responsibly identify and report vulnerabilities.

    More eyes on the code helps strengthen the platform and improve security for everyone.

    View Source Code & Bug Bounties
  2. NETWORK OVERSIGHT

    Node operators can step in when needed

    THORChain's decentralized node operators continuously monitor network activity and have access to multiple safeguards designed to respond to abnormal conditions. If suspicious behavior is detected, they can use network controls to pause affected products, contracts, or other parts of the system while the issue is investigated.

    This provides a decentralized response mechanism without relying on a single administrator or centralized operator.

  3. Self-custody

    You control your assets

    Rujira is built around self-custody. You connect your wallet, sign your own transactions, and interact directly with the protocol instead of handing custody to a centralized platform. This gives you control, but it also means your decisions matter.

  4. Continuous review

    Security review doesn't stop at launch

    Security threats continue to evolve after deployment. Rujira uses automated analysis tools and AI-assisted review systems to help identify suspicious patterns, monitor code changes, and support ongoing security assessments.

    These systems do not replace auditors, bug bounty programs, or security researchers. They provide an additional layer of continuous review, helping human experts investigate potential issues faster and more effectively.

Understanding Risk

No system is risk-free

Rujira is designed with security, transparency, and resilience in mind, but no DeFi protocol can eliminate risk entirely. Software can contain unknown issues, external networks can experience disruptions, and some events remain outside of our control.

We believe it's important to be upfront about these risks so you can make informed decisions and use the platform with confidence.

Smart contract risk

Audits reduce risk, but they do not eliminate it. Smart contracts can contain unknown bugs or edge cases. Rujira works to reduce this risk, but code risk exists in every DeFi protocol.

Chain halting

THORChain has halted before and may halt again. This can temporarily pause transactions, withdrawals, or cross-chain movement. Halts can be disruptive, but they can also protect users during abnormal conditions.

Risks beyond our control

Rujira connects many blockchain networks into a single experience. If one of those networks experiences technical issues, congestion, or downtime, deposits and withdrawals for assets on that chain may be delayed or temporarily unavailable.

These events are outside Rujira's control and can occur even when the rest of the system is functioning normally.

Self-custody comes with responsibility

One of the benefits of Rujira is that you stay in control of your assets. There is no intermediary between you and your funds, but that also means there is no central authority that can reverse transactions or recover assets on your behalf.

Funds sent to the wrong address, misunderstood product mechanics, malicious websites, fake support accounts, or unintended transaction approvals can all result in losses that cannot be undone.

Stay Safe

Simple ways to protect your assets

Rujira is designed to reduce risk, but your decisions matter too. These simple habits can help protect your assets, avoid common mistakes, and make your experience smoother.

1

Choose the right wallet

Not all wallets offer the same level of protection. Hardware wallets keep your private keys offline, while solutions like Vultisig provide stronger self-custody through multi-device security.

Whichever wallet you choose, make sure you control the recovery phrase or vault shares yourself. Anyone with access to them can access your funds.

Get Vultisig
2

Always verify the address

Check the first and last characters of every address before sending. Clipboard malware, phishing websites, and fake addresses are real risks.

For larger transfers, taking a few extra seconds to verify details can prevent costly mistakes.

3

Try with a small amount first

If you're moving a significant amount of funds or using a new wallet, chain, or product, consider testing with a small transaction first.

It may cost a little extra in fees and take a few more minutes, but it can help confirm everything is working as expected before committing larger amounts.

4

Understand before you commit funds

Different products come with different mechanics and risks. Before committing funds, take time to understand how liquidations work, the impact of slippage, the different order types on RUJI Trade, and the risks involved when lending or providing liquidity.

There is no support team that can reverse transactions, so understanding how a product works before using it is an important part of self-custody.

Read the Docs

FAQ

Common security questions

Learn how Rujira protects your assets, where risks exist, and what you can do to use the platform safely and confidently.

Keep learning

Understand the system before you deposit

Security is easier to understand when you can see how the pieces fit together. These pages explain Rujira's oracle design, asset model, architecture, getting started steps, and support resources.

Start with Support if you want guidance before using a product.

Explore Support