Security
What is verified, and what is still a plan.
369X is launching on testnet first, so the controls below are intended designs until audited code is live. Real funds go into the protocol only after an independent audit finishes with no open critical issues. Until contract addresses appear on this site, treat any address claiming to be a 369X contract as fake.
Evidence and status
Control by control
Independent audit
A full third-party audit and re-audit, with zero open critical issues, before any real funds. Mainnet also requires a test suite across the whole lifecycle (create, buy, sell, fees, resolution, dispute, void, refund, claim, re-entrancy) and fuzz testing.
Planned for mainnetBug bounty
A programme paying up to $250,000 for critical findings, launching with mainnet. The intended platform is Immunefi; no programme is active and no partnership should be assumed.
Planned for mainnetNon-custodial design
Intended so that no operator, admin or DAO can move user funds, change finalised outcomes or confiscate positions.
Intended designEmergency pause
A 2-of-3 multisig can pause trading. The pause expires on its own after 7 days, and claims, refunds and disputes are designed never to pause.
Intended designGovernance timelock
Every parameter change waits 48 hours and must stay within hard-coded bounds, such as a platform fee of 0–5%.
Intended designAnti-manipulation
A 1-hour trading cut-off, a 30-minute TWAP for liquidations, bonded disputes and wash-trade filters (wallets placing more than 50 bets in 24 hours, or trading less than 10 seconds apart, are flagged).
Intended designImmutable core
No proxy and no admin upgrade key on core contracts. Upgrades deploy new contracts; old markets resolve under old rules.
Intended designLP Vault limits
Leverage borrowing capped at 20% of the vault; a 10%-per-day loss trigger restricts new activity. Neither caps losses during sudden gaps.
Intended designWhat non-custodial does and doesn’t mean
It means no company holds your funds or keys. It doesn’t mean funds never enter contracts: every trade does. It doesn’t mean nobody has any powers: the multisig can pause trading. And it doesn’t remove protocol risk: a bug in a contract can still lock or lose funds, even after an audit.
About the Security & Insurance Reserve
5% of the token supply sits in a bucket named Security & Insurance Reserve, locked and releasable only by governance. The name describes an allocation. It isn’t evidence of a third-party insurance policy, and it doesn’t guarantee that anyone will be reimbursed after a loss.
Oracle, network and front-end risks
- Oracle: a wrong outcome can finalise if nobody disputes it within 48 hours.
- Network: RPC outages and congestion can delay transactions; MEV bots can reorder them.
- Front end: phishing copies of the app can ask you to sign a malicious approval.
- Stablecoin: payouts are in a USD stablecoin whose peg 369X doesn’t control.
Official links
Official links
- Website369x.online
- App369x.win (opens in a new tab)Testnet
- X@x369official (opens in a new tab)
- Telegramt.me/x369official (opens in a new tab)
Bookmark these. 369X will never DM you first or ask for your seed phrase.
Verify before you sign
- Type the address of this site yourself. Don’t follow links from direct messages or ads.
- Compare every character of a contract address with the one on this site. Until addresses appear here, treat any address claiming to be a 369X contract as fake.
- Read what a wallet asks you to approve. Unlimited token approvals deserve extra caution.
- Nobody from 369X will ever ask for your seed phrase or private key.
Reporting a vulnerability
Found a vulnerability? Report it privately to the team via our official Telegram (opens in a new tab). Never post it publicly.
The bug-bounty programme is planned for mainnet. Planned for mainnet