Introduction
We express our gratitude to the Kaia team for the collaborative engagement that enabled the execution of this Finschia-Kaia bridge components Assessment.
Upon the merger of the Klaytn and Finschia chains, a seamless transition of assets from the Finschia chain to the Kaia chain will be facilitated. This process will culminate in the establishment of Kaia as a universally accessible blockchain platform. Designed to democratize and simplify blockchain technology, Kaia is grounded in the core principles of Community, Sustainability, and Simplicity.
Document | |
|---|---|
| Name | Blockchain Protocol Code Review and Security Analysis Report for Kaia |
| Audited By | Tanuj Soni |
| Approved By | Nino Lipartiia |
| Website | https://klaytn.foundation/say-hello-to-kaia/→ |
| Changelog | 17/06/2024 - Preliminary Report |
| Changelog | 04/07/2024 - Final Report |
| Changelog | 08/08/2024 - Report split; Final Kaiarelayer Report |
| Platform | Kaia |
| Language | Typescript |
| Tags | Layer 1, Relayer |
| Methodology | Blockchain Protocol and Security Analysis Methodology→ |
Document
- Name
- Blockchain Protocol Code Review and Security Analysis Report for Kaia
- Audited By
- Tanuj Soni
- Approved By
- Nino Lipartiia
- Changelog
- 17/06/2024 - Preliminary Report
- Changelog
- 04/07/2024 - Final Report
- Changelog
- 08/08/2024 - Report split; Final Kaiarelayer Report
- Platform
- Kaia
- Language
- Typescript
- Tags
- Layer 1, Relayer
Review Scope | |
|---|---|
| Repository | https://github.com/klaytn/kaiarelayer→ |
| Commit | 9540009e82c02a7bb34cabe840e3213ac396ce54 |
Review Scope
- Repository
- https://github.com/klaytn/kaiarelayer→
- Commit
- 9540009e82c02a7bb34cabe840e3213ac396ce54
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
Documentation quality
The Kaiarelayer README explains how to run the relayer in different modes, it also explains how to configure the relayer with instructions to run the test transaction on simulated x/fswap and x/bridge
Kairelayer communicates with kaiabridge contracts, and the repository of kaiabridge contains README that explains the roles of Guardian, Operator, Judge, and Bridge contract.
A single comprehensive document listing all components in one place would be useful to the community and the relayer operator.
A security guideline for relayers would be helpful to operators in ensuring security.
Code quality
Kaiarelayer code conforms to Typescript programming, ensuring robust and efficient code.
Unit test coverage on Kaiarelayer needs to be improved.
Architecture quality
The architecture provides sufficient segregation of responsibilities, and the relayer codebase can run in different modes, further isolating the functionalities.
It features an innovative architectural design that separates components for different purposes, including the segregated functionalities for Guardian, Operator, Judge, and Bridge.
The bridge components allow m-of-n confirmations to be enforced before the funds are unlocked into destination chains.
During the audit, the relayer's private key management was significantly enhanced, mitigating the risk of exposure during runtime.
System Overview
The Finschia-Kaia bridge system enables seamless cross-chain asset transfers and decentralized token swaps. This audit report focuses on the Kaiarelayer application, which facilitates the transfer of assets between disparate blockchains (KAIA and FNSA). The application interacts with source blockchain nodes to retrieve data related to bridge events, which is then used to sign transactions that unlock funds on the destination chain. Multiple relayers are deployed to implement a multi-signature approach, ensuring that funds on the destination chain are unlocked only when a defined threshold of m\-of-n operators confirms the transaction.
Risks
The current system architecture, characterized by each Relayer instance's reliance on a single blockchain node, presents a potential single point of failure. The absence of multi-source verification introduces a degree of centralization, which could potentially affect the system's overall resilience and availability.
The Kaia team has stated their intention to implement node diversity, whereby each Relayer would refer to a different endpoint to fetch on-chain data. The endpoints are operated by different entities, possibly outside Kaia Foundation, to distribute the integrity and availability risks. The endpoints may include third-party RPC providers, public endpoints, and internal resources.
Furthermore, the Kaia team has indicated the existence of additional mitigation measures, such as a monitoring system with fraud detection rules that can detect and possibly halt malicious bridge events. In tandem with the timelock feature, a 24/7 response team can detect, if not prevent, unintended token transfers.
The effectiveness of these mitigation mechanisms is contingent upon the responsiveness of human monitoring and the efficacy of the implemented detection capabilities. Verifying these additional measures was also outside the scope of this audit. It is important to note that neither of these measures can be considered foolproof.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2024-3607 | Implicit Trust in External URLs & Missing MITM Protection | fixed | High | |
| F-2024-3892 | Security Risks in Relayer Application Key Management and Architecture | fixed | Medium | |
| F-2024-3849 | Lack of Password Complexity Enforcement | fixed | Medium | |
| F-2024-3889 | Missing Secret Masking Mechanism in Logger and Third-Party Exposure | fixed | Low | |
| F-2024-3887 | Risks from Relayers Depending on a Single Node | accepted | Low | |
| F-2024-3881 | Insecure Dockerfiles and Excessive Attack Surface | fixed | Low | |
| F-2024-3615 | Dependencies Not Hard Pinned | fixed | Low | |
| F-2024-3947 | Linting Errors & Missing Style Guide | fixed | Observation | |
| F-2024-3886 | Missing Unit Test for Complex Relayer Logic | accepted | Observation |
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required. |
High | High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category. |
Medium | Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively. |
Low | Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system. |
Severity
- Critical
Description
- Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.
Severity
- High
Description
- High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.
Severity
- Medium
Description
- Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.
Severity
- Low
Description
- Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.
Appendix 2. Scope
The scope of the project includes the following components from the provided repository:
Scope Details | |
|---|---|
| Repository | https://github.com/klaytn/kaiarelayer→ |
| Commit | 9540009e82c02a7bb34cabe840e3213ac396ce54 |
Scope Details
- Repository
- https://github.com/klaytn/kaiarelayer→
- Commit
- 9540009e82c02a7bb34cabe840e3213ac396ce54
Components in Scope
Full codebase of the Relayer.