Introduction
We express our gratitude to the Kaia team for the collaborative engagement that enabled the execution of this Blockchain Protocol Security Assessment.
Upon the merger of the Klaytn and Finschia chains, a seamless transition of assets from the Finschia chain to the Kaia chain will be facilitated. This process will culminate in the establishment of Kaia as a universally accessible blockchain platform. Designed to democratize and simplify blockchain technology, Kaia is grounded in the core principles of Community, Sustainability, and Simplicity.
Document | |
|---|---|
| Name | Blockchain Protocol Review and Security Analysis Report for Kaia |
| Audited By | Tanuj Soni |
| Approved By | Nino Lipartiia |
| Website | https://www.finschia.io/→ |
| Changelog | 08/08/2024 - Report split; Final Finschia Report |
| Platform | Finschia |
| Language | Golang |
| Tags | Layer 1 |
| Methodology | https://hackenio.cc/blockchain_methodology→ |
Document
- Name
- Blockchain Protocol Review and Security Analysis Report for Kaia
- Audited By
- Tanuj Soni
- Approved By
- Nino Lipartiia
- Website
- https://www.finschia.io/→
- Changelog
- 08/08/2024 - Report split; Final Finschia Report
- Platform
- Finschia
- Language
- Golang
- Tags
- Layer 1
- Methodology
- https://hackenio.cc/blockchain_methodology→
Review Scope | |
|---|---|
| Repository | https://github.com/Finschia/finschia-sdk/tree/release/v0.49.x→ |
| Commit | de3499fcba851480548a567007f6ceb6b7af7b91 |
Review Scope
- Commit
- de3499fcba851480548a567007f6ceb6b7af7b91
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
Documentation quality
The existing Finschia SDK documentation has been sufficient for building the simulation app and testing the modules.
Additional detailed documentation for the x/fswap and x/fbridge modules would be beneficial.
Code quality
x/fswap and x/fbridge Inherit Finschia SDK code quality, with added features adhering to the same high standards.
x/fswap and x/fbridge adhere to the highest best practices of Go programming, ensuring robust and efficient code.
Test coverage was significantly enhanced during the audit process.
Architecture quality
Finschia SDK is built on the well-established Cosmos SDK, providing a solid technical base.
In x/fbridge, user roles (Guardians, Operators, etc.) are available with clearly defined permissions, enhancing security and accountability.
Changes to the x/fbridge module are made through a transparent proposal and voting process, ensuring consensus and preventing arbitrary decisions.
System Overview
The Finschia-Kaia bridge system is designed to facilitate seamless cross-chain asset transfers and decentralized token swaps. This audit report provides a comprehensive analysis of the Finschia SDK. The custom modules within the Finschia SDK include:
x/fswap: This module is tasked with enabling decentralized token swaps within the Finschia ecosystem.
x/fbridge: This module is engineered to facilitate secure cross-chain asset transfers between the Finschia and Kaia networks.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2024-4900 | Critical Vulnerabilities in External Go Dependencies | fixed | Critical | |
| F-2024-4899 | Critical Vulnerabilities in Go Standard Library | fixed | Critical | |
| F-2024-4904 | Low Test Coverage in x/fbridge and x/fswap | fixed | Observation | |
| F-2024-4902 | Style Guide violations | fixed | Observation |
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required. |
High | High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category. |
Medium | Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively. |
Low | Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system. |
Severity
- Critical
Description
- Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.
Severity
- High
Description
- High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.
Severity
- Medium
Description
- Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.
Severity
- Low
Description
- Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.
Appendix 2. Scope
The scope of the project includes the following components from the provided repository:
Scope Details | |
|---|---|
| Repository | https://github.com/Finschia/finschia-sdk/tree/release/v0.49.x→ |
| Commit | de3499fcba851480548a567007f6ceb6b7af7b91 |
Scope Details
- Commit
- de3499fcba851480548a567007f6ceb6b7af7b91
Components in Scope
Finschia SDK modules:
native module
x/fswap
x/fbridge
proto/lbm/fswap/v1
proto/lbm/fbridge/v1