Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[dApp] Runes Dex | dapp | Jan2025

Date:

Mar 22, 2025

Table of Content

→Introduction
→Audit Summary
→System Overview
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Runes Dex team for the collaborative engagement that enabled the execution of this dApp Security Assessment.

RunesDEX is a decentralized Automated Market Maker (AMM) operating on the Bitcoin blockchain, specifically designed for trading Runes, Ordinals, and BRC-20 tokens.

Document

NamedApp Code Review and Security Analysis Report for Runes Dex
Audited ByStephen Ajayi
Approved ByStephen Ajayi
Websitehttps://www.runesdex.com→
Changelog21/02/2025 - Preliminary Report
Changelog26/03/2025 - Final Report
PlatformRunes, Ordinals, BRC-20
LanguageRust, JavaScript, TypeScript, Docker, HTML
TagsDEX, Frontend, Backend
Methodologyhttps://hackenio.cc/dApp_methodology→
  • Document

    Name
    dApp Code Review and Security Analysis Report for Runes Dex
    Audited By
    Stephen Ajayi
    Approved By
    Stephen Ajayi
    Changelog
    21/02/2025 - Preliminary Report
    Changelog
    26/03/2025 - Final Report
    Platform
    Runes, Ordinals, BRC-20
    Language
    Rust, JavaScript, TypeScript, Docker, HTML
    Tags
    DEX, Frontend, Backend

Review Scope

Backend Repositoryhttps://github.com/hknio/runes-dex-backend-657c0c971750bd499c50d,→
Backend Commit268e0d244c5d1ced9ef447e50c84d903d1342d83
Frontend Repositoryhttps://github.com/hknio/runes-dex-frontend-9ff88dbe436ed9b609ff→
Frontend Commitf8e8ccaf3fc839227cd975628b8e3c04d9e7c630

Audit Summary

18Total Findings
12Resolved
5Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • The project includes essential documentation including key files like README.md, API documentation (/docs/Rest-API.md, Swagger YAML), environment setup (docker-compose.yaml, .env), and a CHANGELOG.md for tracking updates. This provides a solid foundation for onboarding and maintenance.

  • API documentation exists (/docs/Rest-API.md and Swagger YAML files), which is good for backend integrations.

  • CI/CD and environment setup details are provided in docker-compose.yaml and .env files.

  • The presence of CHANGELOG.md ensures proper tracking of updates and changes.

Code quality

  • The codebase demonstrates good structure and modern development practices:

  • Consistent modular architecture across frontend (React + TypeScript) and backend.

  • Clean, well-organized code with removed TODOs and commented-out sections.

  • Readable function implementations with meaningful naming and separation of concerns.

  • Proper use of constants and well-structured imports for maintainability.

System Overview

RunesDEX is a decentralized Automated Market Maker (AMM) operating on the Bitcoin blockchain, specifically designed for trading Runes, Ordinals, and BRC-20 tokens. Unlike traditional exchanges that utilize order books, RunesDEX enables users to trade directly against liquidity pools, ensuring a decentralized and permissionless trading experience.

Project Overview RunesDEX

RunesDEX is a decentralized Automated Market Maker (AMM) built on the Bitcoin blockchain, allowing seamless swaps of Runes, Ordinals, and BRC-20 tokens. This project consists of both backend and frontend components.

Backend Overview

The backend is responsible for handling transaction processing, liquidity pool management, and API interactions. It includes the following directories:

  • /src – Contains the core application logic, including API endpoints, services, and database models.

  • /docs – Holds technical documentation, API specifications, and architectural design details.

  • /config – Includes configuration files for different environments, such as database connections, authentication settings, and API integrations.

  • /scripts – Contains utility scripts for deployment, testing, and system automation.

  • /.github/workflows – Defines CI/CD pipelines for automated testing and deployment.

The backend is designed to ensure secure and efficient trading operations using a RESTful API, WebSockets, and database interactions.

Frontend Overview

The frontend is a React-based web application providing a user-friendly interface for interacting with RunesDEX. It includes:

  • /src – Contains the main React components, pages, and utility functions that power the application.

  • /public – Holds static assets such as images, icons, and metadata files.

  • /styles – Includes global and component-specific styles for UI customization.

  • /config – Stores frontend configurations related to API endpoints and environment variables.

  • /constants – Defines reusable constants such as validation patterns, pagination settings, and notification messages.

The frontend integrates with the backend, ensuring real-time updates, wallet interactions, and smooth trading experiences.

Findings

F-2025-8912Insecure Message Signing Mechanism
Status
fixed
Severity

High
F-2025-8913Insecure Input Handling in SearchInput Component
Status
fixed
Severity

Medium
F-2025-8845Possible Uncontrolled Resource Consumption (Memory Leak)
Status
fixed
Severity

Medium
F-2025-8651Insecure Cross-Origin Resource Sharing (CORS) Configuration
Status
accepted
Severity

Medium
F-2025-8644Insecure Key Decryption in Memory
Status
accepted
Severity

Medium
F-2025-8467Unencrypted Storage of Private Keys in LegacyKeyPool
Status
fixed
Severity

Medium
F-2025-8451Unbounded Pagination in get_utxo - Backend
Status
fixed
Severity

Medium
F-2025-8364Lack of Pagination Boundaries in UTXO Fetching - Backend
Status
accepted
Severity

Low
F-2025-8508Pagination Issues in mod.rs - Backend
Status
fixed
Severity

Low
F-2025-8888DOM-based Identifier Manipulation
Status
fixed
Severity

Low
Code
―
Title
Status
Severity
F-2025-8912Insecure Message Signing Mechanism
fixed

High
F-2025-8913Insecure Input Handling in SearchInput Component
fixed

Medium
F-2025-8845Possible Uncontrolled Resource Consumption (Memory Leak)
fixed

Medium
F-2025-8651Insecure Cross-Origin Resource Sharing (CORS) Configuration
accepted

Medium
F-2025-8644Insecure Key Decryption in Memory
accepted

Medium
F-2025-8467Unencrypted Storage of Private Keys in LegacyKeyPool
fixed

Medium
F-2025-8451Unbounded Pagination in get_utxo - Backend
fixed

Medium
F-2025-8364Lack of Pagination Boundaries in UTXO Fetching - Backend
accepted

Low
F-2025-8508Pagination Issues in mod.rs - Backend
fixed

Low
F-2025-8888DOM-based Identifier Manipulation
fixed

Low
1-10 of 18 findings

Protect your dApp with insights like these.

Appendix 1. Severity Definitions

Severity

Description

Critical
These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

High
These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

Medium
These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

Low
These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
  • Severity

    Critical

    Description

    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    Severity

    High

    Description

    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Severity

    Medium

    Description

    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Severity

    Low

    Description

    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

Appendix 2. Scope

The scope of the project includes the following repository:

Scope Details

Backend Repositoryhttps://github.com/BoostyLabs/runes-dex-backend→
Backend Commit268e0d244c5d1ced9ef447e50c84d903d1342d83
Frontend Repositoryhttps://github.com/BoostyLabs/runes-dex-frontend→
Frontend Commitf8e8ccaf3fc839227cd975628b8e3c04d9e7c630

Assets in Scope

RundeDex Backend - RundeDex Backend
RunesDex Frontend - RunesDex Frontend

Disclaimer