Introduction
We express our gratitude to the IOPn team for the collaborative engagement that enabled the execution of this Blockchain Protocol Security Assessment.
OPN Chain is an EVM-compatible Layer 1 blockchain built on the Cosmos SDK. It combines EVM compatibility with Cosmos interoperability, enabling seamless deployment of Ethereum smart contracts while leveraging IBC for cross-chain communication. The network implements early support for Ethereum's Pectra upgrade, specifically EIP-7702 for smart account delegation. OPN Chain focuses on scaling the DeFi ecosystem through high-performance EVM execution and advanced cross-chain capabilities, with a token mapping system that automatically converts assets between native Cosmos tokens and EVM-compatible contracts.
Document | |
|---|---|
| Name | Blockchain Protocol Review and Security Analysis Report for OPN Chain |
| Audited By | Tanuj Soni |
| Approved By | Nino Lipartiia |
| Website | https://iopn.io→ |
| Changelog | 18/11/2025 - Preliminary Report |
| Changelog | 04/12/2025 - Final Report |
| Changelog | 05/01/2026 - Final report updated to reflect the latest repository versions |
| Platform | OPN Chain |
| Language | Golang |
| Tags | Cosmos SDK, EVM-compatible, IBC, EIP-7702, Cross-chain DeFi |
| Methodology | https://docs.hacken.io/methodologies/blockchain-protocols→ |
Document
- Name
- Blockchain Protocol Review and Security Analysis Report for OPN Chain
- Audited By
- Tanuj Soni
- Approved By
- Nino Lipartiia
- Website
- https://iopn.io→
- Changelog
- 18/11/2025 - Preliminary Report
- Changelog
- 04/12/2025 - Final Report
- Changelog
- 05/01/2026 - Final report updated to reflect the latest repository versions
- Platform
- OPN Chain
- Language
- Golang
- Tags
- Cosmos SDK, EVM-compatible, IBC, EIP-7702, Cross-chain DeFi
Review Scope | |
|---|---|
| Repository 1: Ethermint | https://github.com/OPNCHAIN/Ethermint→ |
| Commit | 4698179e0a4f4bd701a3f08cf6227f3b3858e614 |
| Remediation Commit | 2fefad457a98672cfdf6b6809f163a07580e6f57 |
| Repository 2: OPNchain | https://github.com/OPNCHAIN→ |
| Commit | 2471aa09cf5daaa4077f854056312d5484a047c5 |
| Remediation Commit | c1fcadf0f7887cfffc6d1f58b55cef2f81931ff8 |
Review Scope
- Repository 1: Ethermint
- https://github.com/OPNCHAIN/Ethermint→
- Commit
- 4698179e0a4f4bd701a3f08cf6227f3b3858e614
- Remediation Commit
- 2fefad457a98672cfdf6b6809f163a07580e6f57
- Repository 2: OPNchain
- https://github.com/OPNCHAIN→
- Commit
- 2471aa09cf5daaa4077f854056312d5484a047c5
- Remediation Commit
- c1fcadf0f7887cfffc6d1f58b55cef2f81931ff8
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
Documentation Quality
Provides OPN Chain specific documentation covering the IOPn module, token mapping, and precompile contracts; however, some README files are outdated relative to the current implementation.
Presents technical specifications for selected OPN Chain subsystems, offering insights into architecture and workflows, though coverage and consistency vary across custom modules.
Follows a logical structure with component-level explanations in README files, but lacks comprehensive high-level architectural overview documentation.
Aligned with the current codebase version for OPN Chain specific components, yet includes limited inline documentation across custom modules.
Features readable documentation for precompiles and EVM handlers, though offering more practical examples and edge case scenarios would further improve clarity.
Code Quality
Effectively reuses forked Ethermint and Cronos codebases, with custom modifications for Pectra upgrade support, precompile implementations, and token mapping functionality, though some opportunities exist to reduce duplication and improve error handling.
Employs well-structured modular design. The IOPn module (
x/iopn) is organized into clear subcomponents (keeper, precompiles, evmhandlers, middleware), offering immediate familiarity for developers familiar with Cosmos SDK patterns.Demonstrates consistent naming conventions and structured organization of IOPn-specific components, though a few minor naming inconsistencies remain in custom handlers.
The code is generally readable and idiomatic Go, with well-defined domain models, though validation logic in custom handlers and error handling in precompile execution paths need improvement.
Inline documentation is limited but partially offset by clear, self-documenting code structure in IOPn-specific components.
Unit tests are present for IOPn module components, though coverage is limited, particularly for edge cases in precompile operations and negative scenarios in EVM event processing.
Architecture Quality
In-chain performance & scalability. All OPN Chain logic runs directly on the existing Cosmos SDK framework, benefiting from Cosmos’s low-latency, high-throughput consensus without introducing additional inter-module overhead.
Clear separation of concerns. State management (via keeper), business logic (in precompiles and EVM handlers), and integration (via middleware) are neatly layered, making each component easier to reason about and test.
Strong EVM-Cosmos integration. Custom precompile contracts allow smart contracts to interact with IBC operations, native token management, and interchain accounts, maintaining separation between EVM and Cosmos execution while enabling seamless asset movement.
Implements early support for Ethereum's Pectra upgrade (EIP-7702) with custom transaction processing that validates authorization lists and applies delegations during state transition, though this introduces additional complexity and testing requirements.
The token mapping system provides bidirectional conversion between native Cosmos tokens and EVM contract addresses, enabling automatic wrapping and unwrapping of assets while maintaining token identity and supply consistency.
Limited observability & metrics. There's no built-in telemetry for critical flows (e.g., precompile execution rates, token mapping operations, IBC packet processing), so external instrumentation is needed to monitor performance and anomalies.
System Overview
OPN Chain is an EVM-compatible Layer 1 blockchain built on the Cosmos SDK. It combines EVM compatibility with Cosmos interoperability, supporting the Pectra upgrade (EIP-7702) for smart account delegation. The implementation uses two coordinated forks: a modified Ethermint for EVM execution and a Cronos-based chain for Cosmos integration. The implementation is organized into several Go modules that form the full node software. The primary components are:
IOPn Module The IOPn module (
x/iopn) provides custom business logic for token management and cross-chain operations. It maintains token mappings between native Cosmos tokens and EVM contract addresses, enabling automatic wrapping and unwrapping of assets. The module processes EVM events for cross-chain transfers, automatically deploys minimal CRC20 contracts for incoming IBC tokens, and manages the lifecycle of token mappings through governance or authorized transactions. It integrates with the bank module for native token operations and with IBC modules for cross-chain communication, ensuring seamless asset movement between Cosmos and EVM environments.EVM Event Handlers The system processes EVM events emitted by smart contracts to trigger cross-chain operations. When contracts emit specific events (such as __IopnSendToIbc), the IOPn module's event handlers intercept these events during transaction execution and convert them into Cosmos messages. The handlers validate that emitting contracts are registered in the token mapping system, extract transfer parameters from event data, and route transactions to appropriate IBC channels or native bank transfers. This mechanism enables smart contracts to initiate cross-chain transfers without direct access to Cosmos modules, maintaining separation between EVM and Cosmos execution contexts.
Precompile Contracts OPN Chain provides native precompile contracts that enable smart contracts to interact with Cosmos functionality. The Bank precompile allows contracts to mint, burn, and transfer native tokens directly from EVM code, with token denominations derived from the calling contract's address to maintain token isolation. The Relayer precompile enables contracts to perform IBC operations, including client creation, channel management, and packet handling, allowing EVM contracts to act as IBC relayers. The ICA (Inter-Chain Accounts) precompile enables contracts to register and control inter-chain accounts for cross-chain operations. These precompiles are accessible at fixed addresses and provide a bridge between EVM execution and Cosmos-native features, enabling complex cross-chain DeFi applications.
Token Mapping System The system maintains bidirectional mappings between native Cosmos tokens and EVM contract addresses, supporting automatic conversion of IBC-transferred tokens into CRC20 contracts. When tokens arrive via IBC channels, the system automatically deploys or maps them to EVM-compatible contracts, allowing seamless integration with existing Web3 tooling. The mapping system supports both auto-deployed minimal contracts and external contract registrations, with governance controls for mapping management. This architecture enables assets to flow between Cosmos chains and the EVM environment without manual intervention, maintaining token identity and supply consistency across both execution contexts.
Pectra Upgrade Integration OPN Chain implements early support for Ethereum's Pectra upgrade, specifically EIP-7702 for smart account delegation. The system processes transaction type 0x04, which includes authorization lists that delegate account code execution to smart contracts. The state transition function applies these delegations before EVM execution, enabling accounts to temporarily execute as smart contracts without permanent code deployment. The transaction processing pipeline validates authorization lists in the ante handler, preserves authorization data through message conversion, and applies delegations during state transition. This feature supports advanced account abstraction patterns and batch transaction capabilities, allowing users to leverage smart account functionality while maintaining compatibility with standard Ethereum tooling.
Dual-Fork Architecture OPN Chain maintains separate forks of Ethermint and Cronos to achieve full control over both the EVM execution layer and Cosmos integration. The Ethermint fork includes custom transaction type handling for EIP-7702, modified state transition logic for the authorization application, and enhanced RPC compatibility. The Cronos-based fork includes the IOPn module, precompile implementations, and custom hooks that bridge EVM and Cosmos operations. This dual-fork approach enables rapid innovation and customization while maintaining compatibility with both Ethereum and Cosmos ecosystems, allowing OPN Chain to implement cutting-edge features ahead of upstream releases.
Together, these components form the OPN Chain protocol, combining EVM transaction processing, Cosmos ecosystem integration, and advanced protocol features within a modular architecture designed for DeFi scalability and cross-chain interoperability.
Risks
The codebase uses custom forks and multiple dependency layers that require manual synchronization with upstream repositories. Version mismatches between submodules and main dependencies may expose the system to known vulnerabilities that have been addressed in upstream releases, requiring continuous monitoring and systematic update processes.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2025-1379 | Missing SetCodeAuthorizations in AsMessage | fixed | High | |
| F-2025-1401 | Missing EIP-7702 Authorization Application in State Transition | fixed | High | |
| F-2025-1393 | Missing Upstream Changes of Cronos | fixed | High | |
| F-2025-1403 | Missing Caller Authentication in Custom Handlers | fixed | High | |
| F-2025-1401 | Incorrect Caller Address Handling in Precompiles | fixed | Medium | |
| F-2025-1380 | Missing Validation for SetCodeAuthorizations | fixed | Medium | |
| F-2025-1408 | Missing EIP-7702's TransactionType Implementation | fixed | Medium | |
| F-2025-1386 | Missing Upstream changes of Ethermint | fixed | Low | |
| F-2025-1379 | Dependency Fork Change - Supply Chain Risk | fixed | Low | |
| F-2025-1408 | Missing Validation in ParseDenomTrace | fixed | Low |
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required. |
High | High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category. |
Medium | Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively. |
Low | Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system. |
Severity
- Critical
Description
- Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.
Severity
- High
Description
- High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.
Severity
- Medium
Description
- Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.
Severity
- Low
Description
- Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.
Appendix 2. Scope
The scope of the project includes the following components from the provided repository:
Scope Details | |
|---|---|
| Repository 1: Ethermint | https://github.com/OPNCHAIN/Ethermint→ |
| Commit | 4698179e0a4f4bd701a3f08cf6227f3b3858e614 |
| Remediation Commit | 2fefad457a98672cfdf6b6809f163a07580e6f57 |
| Repository 2: OPNChain | https://github.com/OPNCHAIN→ |
| Commit | 2471aa09cf5daaa4077f854056312d5484a047c5 |
| Remediation Commit | c1fcadf0f7887cfffc6d1f58b55cef2f81931ff8 |
Scope Details
- Repository 1: Ethermint
- https://github.com/OPNCHAIN/Ethermint→
- Commit
- 4698179e0a4f4bd701a3f08cf6227f3b3858e614
- Remediation Commit
- 2fefad457a98672cfdf6b6809f163a07580e6f57
- Repository 2: OPNChain
- https://github.com/OPNCHAIN→
- Commit
- 2471aa09cf5daaa4077f854056312d5484a047c5
- Remediation Commit
- c1fcadf0f7887cfffc6d1f58b55cef2f81931ff8
Components in Scope
OPNchain → - Protocol changes introduced since forking from Cronos v1.4.7 →.
Ethermint → - Protocol changes implemented since forking Ethermint → at commit 730da6a6d4e06dfb09f1d5b14978033ee8394d25.
Note : We audited iopn-admin/Ethermint (testing: 0e8841c, remediation: 42d52f3) and iopn-admin/opn_chain (testing: 516df57, remediation: a1b4bf0). The updated repositories OPNChain/Ethermint (testing: 4698179, remediation: 2fefad4) and OPNChain/OPNChain (testing: 2471aa0, remediation: c1fcadf) have corresponding testing and remediation commits with equivalent code.
Appendix 3. Additional Valuables
Frameworks and Methodologies
This security assessment was conducted in alignment with recognised penetration testing standards, methodologies and guidelines, including the NIST SP 800-115 – Technical Guide to Information Security Testing and Assessment →, and the Penetration Testing Execution Standard (PTES) →, These assets provide a structured foundation for planning, executing, and documenting technical evaluations such as vulnerability assessments, exploitation activities, and security code reviews. Hacken’s internal penetration testing methodology extends these principles to Web2 and Web3 environments to ensure consistency, repeatability, and verifiable outcomes.