Jaxx Liberty

Audited code, published results

Open-source code lets anyone read the implementation. Independent audits bring professional scrutiny. Published results let everyone see what was found and how it was fixed.

Why audits matter

Open-source code is a necessary condition for trust, but it is not sufficient on its own. The codebase of a modern cryptocurrency wallet is complex enough that subtle vulnerabilities can exist in plain sight for years without being discovered by casual review. Professional security auditors bring specialized expertise, systematic methodology, and adversarial thinking that goes beyond what community review alone can provide.

Jaxx Liberty treats audits as an ongoing process, not a one-time checkbox. Each major release undergoes independent review, and the full reports are published so that users and researchers can evaluate the findings and the remediation for themselves.

Audit scope

Security audits of Jaxx Liberty cover the most critical components of the application:

Key management

Entropy generation, BIP-39 mnemonic creation, BIP-44 key derivation, key storage, and encryption. The foundation of wallet security.

Transaction signing

The full transaction lifecycle: construction, validation, signing, and broadcast for every supported blockchain.

Cryptographic implementations

Elliptic curve operations, hashing functions, encryption routines, and random number generation.

Network communication

API endpoints, data serialization, TLS configuration, and defense against man-in-the-middle attacks.

Bug bounty program

Jaxx Liberty maintains a responsible disclosure program that rewards security researchers who identify and report vulnerabilities. The bug bounty program is open to anyone and covers all components of the wallet application, including the mobile apps, desktop apps, browser extension, and supporting infrastructure.

Rewards are determined by the severity and impact of the reported vulnerability:

  • Critical — vulnerabilities that could lead to loss of funds, private key extraction, or remote code execution.
  • High — vulnerabilities that could lead to significant security degradation, such as bypassing authentication or encryption weaknesses.
  • Medium — vulnerabilities with limited impact, such as information disclosure or denial-of-service conditions.
  • Low — minor issues with minimal security impact.

To report a vulnerability, send a detailed description to the security contact listed in the repository's SECURITY.md file. Please include steps to reproduce the issue and any relevant proof-of-concept code.

Vulnerability disclosure policy

Jaxx Liberty follows a coordinated disclosure process. When a vulnerability is reported, the security team acknowledges receipt within 48 hours, triages the issue within one week, and works with the reporter to understand the full scope and impact.

Critical and high-severity vulnerabilities are patched as quickly as possible, typically within days. The fix is verified by the reporter and independently reviewed before release. Once the patch is deployed and users have had time to update, the vulnerability details are published along with the fix and any relevant context.

This approach balances transparency with responsible handling: users are protected first, and the full disclosure follows.

Penetration testing

In addition to code-level audits, Jaxx Liberty undergoes regular penetration testing that evaluates the application from an attacker's perspective. Penetration testers attempt to compromise the wallet through every available attack surface, including the application UI, network interfaces, local storage, inter-process communication, and device-level attack vectors.

Penetration testing complements code audits by identifying vulnerabilities that may not be apparent from source code review alone, such as timing attacks, side-channel leaks, and race conditions that only manifest at runtime.

Continuous security

Audits and penetration tests are snapshots in time. Jaxx Liberty's security model is designed so that every component is continuously verifiable. The open-source code is always available for review. The reproducible builds can be verified at any time. The hardware signing architecture ensures that keys are always protected by a physical boundary.

Security is not a destination — it is an ongoing practice. Jaxx Liberty is committed to continuous improvement through regular audits, an active bug bounty, and an architecture that makes verification easy.

Security you can verify

Open source, reproducible builds, independent audits, and hardware signing. Every claim is verifiable.

Open Wallet