Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[L1] Kaia | Finschia | May2024

Date:

Aug 8, 2024

Table of Content

→Introduction
→Audit Summary
→System Overview
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Kaia team for the collaborative engagement that enabled the execution of this Blockchain Protocol Security Assessment.

Upon the merger of the Klaytn and Finschia chains, a seamless transition of assets from the Finschia chain to the Kaia chain will be facilitated. This process will culminate in the establishment of Kaia as a universally accessible blockchain platform. Designed to democratize and simplify blockchain technology, Kaia is grounded in the core principles of Community, Sustainability, and Simplicity.

Document

NameBlockchain Protocol Review and Security Analysis Report for Kaia
Audited ByTanuj Soni
Approved ByNino Lipartiia
Websitehttps://www.finschia.io/→
Changelog08/08/2024 - Report split; Final Finschia Report
PlatformFinschia
LanguageGolang
TagsLayer 1
Methodologyhttps://hackenio.cc/blockchain_methodology→

Review Scope

Repositoryhttps://github.com/Finschia/finschia-sdk/tree/release/v0.49.x→
Commitde3499fcba851480548a567007f6ceb6b7af7b91

Audit Summary

4Total Findings
4Resolved
0Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • The existing Finschia SDK documentation has been sufficient for building the simulation app and testing the modules.

  • Additional detailed documentation for the x/fswap and x/fbridge modules would be beneficial.

Code quality

  • x/fswap and x/fbridge Inherit Finschia SDK code quality, with added features adhering to the same high standards.

  • x/fswap and x/fbridge adhere to the highest best practices of Go programming, ensuring robust and efficient code.

  • Test coverage was significantly enhanced during the audit process.

Architecture quality

  • Finschia SDK is built on the well-established Cosmos SDK, providing a solid technical base.

  • In x/fbridge, user roles (Guardians, Operators, etc.) are available with clearly defined permissions, enhancing security and accountability.

  • Changes to the x/fbridge module are made through a transparent proposal and voting process, ensuring consensus and preventing arbitrary decisions.

System Overview

The Finschia-Kaia bridge system is designed to facilitate seamless cross-chain asset transfers and decentralized token swaps. This audit report provides a comprehensive analysis of the Finschia SDK. The custom modules within the Finschia SDK include:

  • x/fswap: This module is tasked with enabling decentralized token swaps within the Finschia ecosystem.

  • x/fbridge: This module is engineered to facilitate secure cross-chain asset transfers between the Finschia and Kaia networks.

Findings

F-2024-4900Critical Vulnerabilities in External Go Dependencies
Status
fixed
Severity

Critical
F-2024-4899Critical Vulnerabilities in Go Standard Library
Status
fixed
Severity

Critical
F-2024-4904Low Test Coverage in x/fbridge and x/fswap
Status
fixed
Severity

Observation
F-2024-4902Style Guide violations
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2024-4900Critical Vulnerabilities in External Go Dependencies
fixed

Critical
F-2024-4899Critical Vulnerabilities in Go Standard Library
fixed

Critical
F-2024-4904Low Test Coverage in x/fbridge and x/fswap
fixed

Observation
F-2024-4902Style Guide violations
fixed

Observation
1-4 of 4 findings

Findings like these can secure your blockchain.

Appendix 1. Severity Definitions

Severity

Description

Critical
Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.

High
High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.

Medium
Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.

Low
Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.
  • Severity

    Critical

    Description

    Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.

    Severity

    High

    Description

    High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.

    Severity

    Medium

    Description

    Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.

    Severity

    Low

    Description

    Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.

Appendix 2. Scope

The scope of the project includes the following components from the provided repository:

Scope Details

Repositoryhttps://github.com/Finschia/finschia-sdk/tree/release/v0.49.x→
Commitde3499fcba851480548a567007f6ceb6b7af7b91

Components in Scope

Finschia SDK modules:

  • native module

  • x/fswap

  • x/fbridge

  • proto/lbm/fswap/v1

  • proto/lbm/fbridge/v1

Disclaimer