Menu

Participate
Security

How FVC Is Secured

How the FVC smart contracts are built, tested and controlled. Everything on this page can be checked on-chain.

Last updated 4 October 2026 · FVC Asset Group Ltd

Smart Contracts

FVC runs on Ethereum mainnet. The contracts are not upgradeable: fixing a contract means deploying a replacement and migrating, not changing code in place.

Treasury and Admin Controls

  • The treasury is a Safe multisig. Today it requires 2 of 4 signers; it moves to 3 of 5 before TGE.
  • The Safe holds the token's admin and minting roles and owns the sale contract. No single person can mint tokens or change sale settings.
  • A timelock on admin and treasury actions will be in place before TGE, so changes are announced on-chain before they take effect.
  • Total supply is capped at 1,000,000,000 FVC in the token contract. Nobody can mint above the cap.

Independent Audit

An independent security audit of the FVC smart contracts by Hashlock is in progress. The final report will be published here when it is complete.

Testing

  • 297 automated unit and integration tests run on every change.
  • Stateful invariant fuzzing with Foundry checks that key rules always hold, for example that nobody can claim more than they were allocated or claim before their cliff ends, across hundreds of random sequences of transactions.
  • Mutation testing confirms the tests catch deliberately broken code.
  • Static analysis with Slither before every deployment.

What You Are Trusting

We would rather you know this up front:

  • The Safe signers can change the sale price, accepted tokens and individual investor terms, and can make off-chain (OTC) allocations.
  • ETH pricing uses the Chainlink ETH/USD feed. If the feed is stale, the contract falls back to a rate set by the Safe.
  • Governance is off-chain today. On-chain voting is planned as the ecosystem develops.
  • The current Vesting contract cannot be changed. Claiming vested tokens works as designed; a second version with improved admin accounting is planned before the first cliff unlocks in March 2027.

Report a Vulnerability

Email security@fvcdigital.com with enough detail to reproduce the issue. Please do not post anything that could put funds at risk publicly. We aim to reply within 48 hours. A formal bug bounty is not open yet.

Want to dig deeper?

The whitepaper covers the contract architecture, tokenomics and vesting in full.

Read the whitepaper Contact the FVC team