All articles
· 6 min read· Frax

Security is our product

How Frax secures frxUSD: continuous audits, AI-assisted monitoring, hardware-enforced operations, and a 5/5 DVN crosschain setup, over 5 years without incident.

Security is our product, shown with the Frax logo set into a metallic shield

For a stablecoin issuer, security is the product itself. At Frax, that means continuous audits rather than one-time reviews, AI-assisted monitoring between them, hardware-enforced operational security, and a crosschain architecture we configure ourselves — a discipline that has kept a flawless security record across 5+ years and billions of dollars in assets.

At Frax, we are building the future of the digital dollar with frxUSD, a fully collateralized and redeemable stablecoin. But the most important challenge is not distribution or incentives. The real challenge is trust.

How do you build a form of digital money that users are comfortable holding for years? How do institutions gain confidence deploying large amounts of capital into a stablecoin system? How do you earn credibility in an industry where exploits and operational failures have destroyed billions of dollars?

Every architectural decision, operational process, and infrastructure choice ultimately feeds back into a single question: can users trust us with their capital?

Extensive auditing and continuous AI security monitoring

Security reviews cannot be treated as a one-time event for systems responsible for securing billions of dollars. At Frax, audits are part of an ongoing engineering discipline rather than a checkbox before deployment.

Over the years, Frax has worked extensively with leading security firms to review core contracts, governance systems, bridge infrastructure, and protocol upgrades. These reviews are designed to identify edge cases and unintended interactions between systems where vulnerabilities often emerge.

Alongside traditional audits, we continuously invest in AI-assisted code analysis and internal security monitoring. Modern crypto systems are too large and interconnected for purely manual review processes alone. AI systems can continuously analyze code, flag dangerous permission structures, detect anomalous behavior patterns, and identify deviations from expected logic in real time.

Human auditors remain essential, but AI-assisted monitoring provides persistent scrutiny between formal reviews. As more advanced models emerge and new attack vectors evolve, our security systems evolve with them.

Frax also provides one of the largest bug bounty programs in the industry for exploits where user or protocol-controlled funds are at risk. Security researchers play a critical role in strengthening crypto infrastructure, and meaningful incentives help ensure vulnerabilities are identified responsibly before they can ever impact users.

Security beyond smart contracts

The attack surface for a modern protocol extends far beyond smart contracts to domains, deployment pipelines, infrastructure providers, governance systems, signing devices, and internal operational procedures.

Many of the industry's largest failures were not caused by flaws in smart contracts themselves, but by compromised operational security, poor key management, centralized infrastructure, or manipulated frontends. Users do not care where a failure originates. If funds are lost, trust disappears immediately.

That is why Frax approaches security as a layered system rather than relying on any single defense mechanism. Alongside extensive audits and decentralized infrastructure, we maintain strict internal operational security standards across infrastructure access, deployment procedures, and production systems:

  • Hardware-backed signing. All multisig signers at Frax use hardware wallets, and all pushes to our codebase require authenticated hardware security keys as an additional safeguard against unauthorized access.
  • Segmented environments. Sensitive environments are segmented, permissions are tightly controlled, and operational responsibilities are distributed to reduce concentrated points of failure.
  • Domain and frontend protection. Frax uses MarkMonitor for domain protection, because compromised DNS or frontend infrastructure can redirect users to malicious interfaces capable of draining wallets. These risks are often overlooked across crypto despite being one of the most common operational attack vectors.

Good security is rarely visible to users. The goal is not to create the appearance of safety, but to systematically reduce risk across every layer of the system before problems ever emerge.

Crosschain infrastructure

Crosschain interoperability is one of the largest security risks in crypto. From the beginning, Frax approached interoperability from first principles, with the goal being native issuance of assets on every chain, secured by us.

Before adopting external interoperability infrastructure, we built our own internal bridging solution, Fraxferry, entirely in-house. The goal was to maintain complete control over our security. Fraxferry was intentionally slow by design, using long settlement windows and strict validation processes to maximize safety when moving value across chains.

As the market evolved, users increasingly demanded near-instant transfers. We would not move away from our own infrastructure unless we could preserve the same security philosophy and control over the system itself. That is what attracted us to LayerZero. LayerZero's modular design gave us complete control to define our security model rather than inherit a fixed one. At Frax, we use internally maintained libraries, run our own internal Frax DVN, maintain control over verification rules, and require unanimous external DVN consensus for value transfers. No external entity, including LayerZero itself, can unilaterally upgrade or control our system configuration.

Modular systems are only as secure as the way they are configured. From day one of the frxUSD mint-burn mesh rollout, Frax deployed with a conservative 3/3 DVN setup. We have since upgraded that architecture to an even more resilient 5/5 configuration across a diverse set of operators, to continue leading with best-in-class standards for security. We are in the process of adding circuit-breakers as well. If there's a way for us to bring greater security to our users, we do not hesitate to take action.

As of today, Frax assets worth over $500M span 20+ blockchains with LayerZero, having securely moved hundreds of millions across tens of thousands of messages and growing. Users can move frxUSD across those chains from the swap and bridge interface on frax.com.

Trust is earned through consistency

In crypto, trust is earned over years and extremely easy to lose. Users remember exploits. Institutions remember operational failures. Markets remember shortcuts.

Long-term credibility comes from consistency. It comes from careful engineering, conservative assumptions, redundant safeguards, disciplined operational processes, and a willingness to prioritize resilience over short-term acceleration. This culture has allowed Frax to maintain a flawless security track record over 5 years while managing billions of dollars in assets across multiple market cycles.

It is also what makes the rest of the system possible. Protocols integrate frxUSD because the underlying infrastructure has held up: Aave as the first major lending market to adopt frxUSD ReserveLink, and Curve and 25+ partners using frxUSD as a PegKeeper. Reserves backing frxUSD are published on the Frax transparency dashboard.

As stablecoins continue to permeate global financial infrastructure, security standards will only become more demanding. The systems that endure long term will not necessarily be the fastest moving or highest yielding. They will be the systems users trust to reliably secure capital over years and eventually decades.

That is the standard we are building toward with frxUSD. Because when we build the future of money, security isn't just a feature, security is our product.

Explore