Security Overview
GIGA’s security model has two layers: proven, heavily audited code for the pools that hold user liquidity, and GIGA’s own incentive system on top of it, which never touches user funds and has been independently audited by Cantina.
Pools: battle-tested designs
Swapping and providing liquidity run entirely on established AMM designs:
- Classic pools are a fork of Uniswap v2.
- Concentrated liquidity pools are built on PancakeSwap v3, a fork of Uniswap v3.
These are among the most forked, reviewed, and battle-tested contracts in DeFi. They have secured billions in liquidity across many chains over several years, backed by extensive independent audits and years of adversarial testing in production.
The pool contracts are immutable. Once deployed they cannot be upgraded, paused, or altered by anyone, including the GIGA team. See Governance & Access Control for what this covers.
The incentive system
GIGA’s differentiator is new code written specifically for GIGA: revenue-driven emissions rebalanced hourly, veGIGA, gauges, and the GIGA Machine. It has been live since GIGA Genesis. Its authority is limited to protocol-level functions, such as steering emissions and routing fees, and never extends to user funds in the pools.
Audits
The custom code introduced at GIGA Genesis has been independently audited by Cantina. The review was a Cantina Managed engagement led by Valerian Callens, Lead Security Researcher, and ran from 15 to 22 August 2026 against commit 6d36108 of the contracts repository. The final report was published on 3 September 2026.
Scope
The review covered the incentive system in full: the controller, the GIGA token, the vault, the emission center, the fee center and fee receivers, the fee policy library, and the storage libraries behind the upgradeable contracts.
Cantina also performed a differential review of every contract GIGA adapted from an existing design, comparing GIGA’s Classic MasterChef against the Trader Joe MasterChefJoeV2, and GIGA’s CL MasterChef, liquidity-mining pool, and position manager against their PancakeSwap v3 counterparts. This checked the changes GIGA made to those battle-tested contracts against the originals.
Results
No critical, high, or medium severity issues were found.
| Severity | Found | Status |
|---|---|---|
| Critical | 0 | |
| High | 0 | |
| Medium | 0 | |
| Low | 4 | Acknowledged |
| Informational | 2 | Acknowledged |
The four low-risk findings are edge cases in operator-only fee collection and vault compounding that do not put user funds at risk. Two of them are scheduled for the next protocol upgrade. Each finding and the team’s response are documented in the report.
From the Cantina team statement: “No significant security issues were identified within the scope of the assessment.” The team also noted that Trantor “demonstrated strong security awareness and proactively identified and addressed numerous edge cases” during the engagement.
Resources
- Governance & Access Control explains what can be changed and what is not.
- Contracts lists every deployed address, verified on-chain.
- Cantina security review is the full audit report for the incentive system.