Introduction
We express our gratitude to the Runes Dex team for the collaborative engagement that enabled the execution of this dApp Security Assessment.
RunesDEX is a decentralized Automated Market Maker (AMM) operating on the Bitcoin blockchain, specifically designed for trading Runes, Ordinals, and BRC-20 tokens.
Document | |
|---|---|
| Name | dApp Code Review and Security Analysis Report for Runes Dex |
| Audited By | Stephen Ajayi |
| Approved By | Stephen Ajayi |
| Website | https://www.runesdex.com→ |
| Changelog | 21/02/2025 - Preliminary Report |
| Changelog | 26/03/2025 - Final Report |
| Platform | Runes, Ordinals, BRC-20 |
| Language | Rust, JavaScript, TypeScript, Docker, HTML |
| Tags | DEX, Frontend, Backend |
| Methodology | https://hackenio.cc/dApp_methodology→ |
Document
- Name
- dApp Code Review and Security Analysis Report for Runes Dex
- Audited By
- Stephen Ajayi
- Approved By
- Stephen Ajayi
- Website
- https://www.runesdex.com→
- Changelog
- 21/02/2025 - Preliminary Report
- Changelog
- 26/03/2025 - Final Report
- Platform
- Runes, Ordinals, BRC-20
- Language
- Rust, JavaScript, TypeScript, Docker, HTML
- Tags
- DEX, Frontend, Backend
- Methodology
- https://hackenio.cc/dApp_methodology→
Review Scope | |
|---|---|
| Backend Repository | https://github.com/hknio/runes-dex-backend-657c0c971750bd499c50d,→ |
| Backend Commit | 268e0d244c5d1ced9ef447e50c84d903d1342d83 |
| Frontend Repository | https://github.com/hknio/runes-dex-frontend-9ff88dbe436ed9b609ff→ |
| Frontend Commit | f8e8ccaf3fc839227cd975628b8e3c04d9e7c630 |
Review Scope
- Backend Repository
- https://github.com/hknio/runes-dex-backend-657c0c971750bd499c50d,→
- Backend Commit
- 268e0d244c5d1ced9ef447e50c84d903d1342d83
- Frontend Repository
- https://github.com/hknio/runes-dex-frontend-9ff88dbe436ed9b609ff→
- Frontend Commit
- f8e8ccaf3fc839227cd975628b8e3c04d9e7c630
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
Documentation quality
The project includes essential documentation including key files like
README.md, API documentation (/docs/Rest-API.md, Swagger YAML), environment setup (docker-compose.yaml,.env), and aCHANGELOG.mdfor tracking updates. This provides a solid foundation for onboarding and maintenance.API documentation exists (
/docs/Rest-API.mdand Swagger YAML files), which is good for backend integrations.CI/CD and environment setup details are provided in
docker-compose.yamland.envfiles.The presence of
CHANGELOG.mdensures proper tracking of updates and changes.
Code quality
The codebase demonstrates good structure and modern development practices:
Consistent modular architecture across frontend (React + TypeScript) and backend.
Clean, well-organized code with removed TODOs and commented-out sections.
Readable function implementations with meaningful naming and separation of concerns.
Proper use of constants and well-structured imports for maintainability.
System Overview
RunesDEX is a decentralized Automated Market Maker (AMM) operating on the Bitcoin blockchain, specifically designed for trading Runes, Ordinals, and BRC-20 tokens. Unlike traditional exchanges that utilize order books, RunesDEX enables users to trade directly against liquidity pools, ensuring a decentralized and permissionless trading experience.
Project Overview RunesDEX
RunesDEX is a decentralized Automated Market Maker (AMM) built on the Bitcoin blockchain, allowing seamless swaps of Runes, Ordinals, and BRC-20 tokens. This project consists of both backend and frontend components.
Backend Overview
The backend is responsible for handling transaction processing, liquidity pool management, and API interactions. It includes the following directories:
/src– Contains the core application logic, including API endpoints, services, and database models./docs– Holds technical documentation, API specifications, and architectural design details./config– Includes configuration files for different environments, such as database connections, authentication settings, and API integrations./scripts– Contains utility scripts for deployment, testing, and system automation./.github/workflows– Defines CI/CD pipelines for automated testing and deployment.
The backend is designed to ensure secure and efficient trading operations using a RESTful API, WebSockets, and database interactions.
Frontend Overview
The frontend is a React-based web application providing a user-friendly interface for interacting with RunesDEX. It includes:
/src– Contains the main React components, pages, and utility functions that power the application./public– Holds static assets such as images, icons, and metadata files./styles– Includes global and component-specific styles for UI customization./config– Stores frontend configurations related to API endpoints and environment variables./constants– Defines reusable constants such as validation patterns, pagination settings, and notification messages.
The frontend integrates with the backend, ensuring real-time updates, wallet interactions, and smooth trading experiences.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2025-8912 | Insecure Message Signing Mechanism | fixed | High | |
| F-2025-8913 | Insecure Input Handling in SearchInput Component | fixed | Medium | |
| F-2025-8845 | Possible Uncontrolled Resource Consumption (Memory Leak) | fixed | Medium | |
| F-2025-8651 | Insecure Cross-Origin Resource Sharing (CORS) Configuration | accepted | Medium | |
| F-2025-8644 | Insecure Key Decryption in Memory | accepted | Medium | |
| F-2025-8467 | Unencrypted Storage of Private Keys in LegacyKeyPool | fixed | Medium | |
| F-2025-8451 | Unbounded Pagination in get_utxo - Backend | fixed | Medium | |
| F-2025-8364 | Lack of Pagination Boundaries in UTXO Fetching - Backend | accepted | Low | |
| F-2025-8508 | Pagination Issues in mod.rs - Backend | fixed | Low | |
| F-2025-8888 | DOM-based Identifier Manipulation | fixed | Low |
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm. |
High | These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach. |
Medium | These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention. |
Low | These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation. |
Severity
- Critical
Description
- These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.
Severity
- High
Description
- These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.
Severity
- Medium
Description
- These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.
Severity
- Low
Description
- These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
Appendix 2. Scope
The scope of the project includes the following repository:
Scope Details | |
|---|---|
| Backend Repository | https://github.com/BoostyLabs/runes-dex-backend→ |
| Backend Commit | 268e0d244c5d1ced9ef447e50c84d903d1342d83 |
| Frontend Repository | https://github.com/BoostyLabs/runes-dex-frontend→ |
| Frontend Commit | f8e8ccaf3fc839227cd975628b8e3c04d9e7c630 |
Scope Details
- Backend Repository
- https://github.com/BoostyLabs/runes-dex-backend→
- Backend Commit
- 268e0d244c5d1ced9ef447e50c84d903d1342d83
- Frontend Repository
- https://github.com/BoostyLabs/runes-dex-frontend→
- Frontend Commit
- f8e8ccaf3fc839227cd975628b8e3c04d9e7c630