Quantstamp Audits Ampleforth, a Digital-Asset-Protocol for Smart Commodity-Money

Share this article:

Quantstamp engineers recently completed an audit of Ampleforth, a digital-asset-protocol for smart commodity-money and the first IEO on Tokinex (Ethfinex/Bitfinex IEO platform). 

Founded with a mission to create fair, politically independent money, the Ampleforth protocol receives exchange-rate information from trusted oracles, and propagates that to holders of its units (Amples) by proportionally increasing or decreasing the number of tokens each individual holds. Quantstamp will serve as a trusted data feed provider for Ampleforth’s price oracle.

“Being audited by Quanstamp was important to us,” said Ampleforth CTO Brandon Iles. “They hold their clients and themselves to the highest security standards. We know that identifying any risks and vulnerabilities is critical to mitigating the risk of any future hacks.”

Commodity-monies such as gold and silver are naturally fair and independent; however, they are inadequate substitute for central-bank-money as they cannot respond efficiently to fluctuations in demand. To tackle this challenge, Ampleforth’s protocol allows its units (Amples) to avoid the deflationary problems of fixed-supply commodities without requiring a central authority. As the price of Amples fluctuates, the number of Amples a trader holds adjusts to meet the price target, stabilizing the asset.

Quantstamp’s objective was to evaluate the repository for security-related issues, code quality, and adherence to specification and best practices. The audit was conducted by three experienced security engineers from Quantstamp’s auditing team and involved architecture review, unit testing, functional testing, computer-aided verification and manual review. In the end, there were no significant security vulnerabilities found during the audit. The full report is publicly available.

Following the launch of Security Network V2, Ampleforth will be running a Quantstamp node, helping contribute to the reliability and decentralization of the network.


Back
Quantstamp Announcements

July Security Beat: Keys Over Code (Again?)

Crypto lost more than $240 million across 29 incidents in July 2026, up roughly 216% from June's $75.87M, even as the number of attacks fell from 40 to 29. For the second month running, the damage didn't come from clever contract exploits. The same failure class ran through Web2, from a $12.3M rail-industry ransom to a 1TB bank breach that started with one employee's email. Here's the month in security 👇

Read more
Quantstamp Announcements

June Security Beat: Keys Over Code

$75.32M was lost across 32 crypto incidents in June, up from May's $59.52M. No coordinated campaign carried the month, but one targeted operation did. A targeted social-engineering attack against Humanity Protocol reached the keys behind the $H token and drained $32M, roughly 42% of every dollar lost in June. Quantstamp led the independent investigation and traced the tooling to a phishing campaign previously seen targeting macOS users. Offchain, a fresh npm supply chain wave hit Red Hat's packages on the first day of the month, and a PeopleSoft zero-day was exploited for two weeks before Oracle said a word. Here's the month in security 👇

Read more
Quantstamp Announcements

May 2026 Security Beat

$59.52M was lost across 29 crypto incidents, down sharply from April's ~$635M. No single hack carried the month. The bigger story happened off-chain, where a self-propagating npm worm called Mini Shai-Hulud kept resurfacing in new waves through the month, ultimately spanning more than 1,000 malicious package versions across the npm ecosystem.

Read more