> For the complete documentation index, see [llms.txt](https://docs.extrafi.io/extrafi-xlend/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.extrafi.io/extrafi-xlend/security/audits-and-security.md).

# Audits & Security

### **1. Audits** <a href="#id-1.-audits" id="id-1.-audits"></a>

* Audit report from Sherlock ([Source](https://sherlock-files.ams3.digitaloceanspaces.com/reports/extra-finance-audit-report-1734534935.pdf))

{% file src="/files/oBLFiTLMKQrtuTJ3kM5I" %}

* Audit report from PeckShield ([Source](https://github.com/peckshield/publications/blob/master/audit_reports/PeckShield-Audit-Report-ExtraFi-v1.0.pdf))

{% file src="/files/xmlerAwHUrfSBwLGDiCR" %}

* XLend liquidity protocol is a fork of Aave V3. Check Aave's audit reports [here](https://github.com/aave/aave-v3-core/tree/master/audits).

### **2. Bug Bounty**

XLend bug bounty is live on Immunefi:

{% embed url="<https://immunefi.com/bug-bounty/extrafinance/information/>" %}

### **3. Proactive Monitoring**

*(The partnership has not yet been renewed in 2025, still in review)*

We have partnered with [Hexagate](https://www.hexagate.com/) to protect the protocol from cyber exploits, hacks, governance, and financial risks.

### 4. Rainy-Day Fund

Approximately **$1,000,000 USDC** has been accumulated to the Rainy-Day Fund to safeguard the protocol against unexpected incidents and protect the lending pool from insolvency.

For more details and to track the current balance of the Rainy-Day Fund, visit: <https://debank.com/profile/0xC918a60e4D40d15959A85fa8b35f6dB96907BabF>

### **5. Oracle Safety**

Please check our Oracle selection & usage here:  [Price Feed](/extrafi-xlend/borrow-lend/price-feed.md)
