> ## Documentation Index
> Fetch the complete documentation index at: https://www.zkcompression.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> Overview to Light Protocol's bug bounty program, third party security audits, and formal verification of circuits.

### Bug Bounty

Light Protocol is hosting a [bug bounty program](https://immunefi.com/bug-bounty/light-protocol/information/).

### Security Audits

The Light protocol on-chain programs were audited by independent security firms Certora, OtterSec, Accretion, HashCloak, Neodyme, and Zellic.

| Firm          | Scope                                | Date          | Report                                                                                                                                      |
| :------------ | :----------------------------------- | :------------ | :------------------------------------------------------------------------------------------------------------------------------------------ |
| **Certora**   | Light Token                          | December '25  | [View](https://github.com/Lightprotocol/light-protocol/blob/main/audits/certora_2025-12_light-token.pdf)                                    |
| **OtterSec**  | CPI Context Refactor                 | December '25  | [View](https://github.com/Lightprotocol/light-protocol/blob/main/audits/ottersec_2025-12_cpi-context-refactor.pdf)                          |
| **Accretion** | ZK Compression v2                    | June '25      | [View](https://github.com/Lightprotocol/light-protocol/blob/main/audits/accretion_2025-06_zkcompression-v2.pdf)                             |
| **OtterSec**  | Batched Merkle Trees                 | June '25      | [View](https://github.com/Lightprotocol/light-protocol/blob/main/audits/ottersec_2025-06_batched-merkle-trees.pdf)                          |
| **HashCloak** | Compressed Token & ZK Compression v2 | March '25     | [View](https://github.com/Lightprotocol/light-protocol/blob/main/audits/hashcloak_2025-03_compressed-token-update-and-zkcompression-v2.pdf) |
| **OtterSec**  | Zerocopy                             | March '25     | [View](https://github.com/Lightprotocol/light-protocol/blob/main/audits/ottersec_2025-03_zerocopy.pdf)                                      |
| **Accretion** | Compressed Token Program Update      | January '25   | [View](https://github.com/Lightprotocol/light-protocol/blob/main/audits/accretion_2025-01_compressed-token-program-update.pdf)              |
| **Zellic**    | ZK Compression v1                    | September '24 | [View](https://github.com/Lightprotocol/light-protocol/blob/main/audits/zellic_2024-09_zkcompression-v1.pdf)                                |
| **Neodyme**   | ZK Compression v1                    | August '24    | [View](https://github.com/Lightprotocol/light-protocol/blob/main/audits/neodyme_2024-08_zkcompression-v1.pdf)                               |
| **OtterSec**  | ZK Compression v1                    | August '24    | [View](https://github.com/Lightprotocol/light-protocol/blob/main/audits/ottersec_2024-08_zkcompression-v1.pdf)                              |

### Groth16 Circuit Security

The ZK Compression circuit was formally verified by Reilabs. See the report [here](https://github.com/Lightprotocol/light-protocol/blob/main/audits/reilabs_2024-08_circuits_formal_verification_report.pdf).

Information about the Trusted Setup Ceremony for the groth16 circuits is [here](https://github.com/Lightprotocol/gnark-mt-setup/blob/main/README.md).

<Info>
  **For additional information on Light Protocol's security policy, read** [**here**](https://github.com/Lightprotocol/light-protocol/blob/main/SECURITY.md)**.**
</Info>
