Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[SCA] Shuttle Labs | Rust | Jan2025

Date:

Jan 27, 2025

Table of Content

→Introduction
→Audit Summary
→System Overview
→Potential Risks
→Findings
→Appendix 1. Definitions
→Appendix 2. Scope
→Appendix 3. Additional Valuables
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Shuttle Labs team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.

The Shuttle Labs is a groundbreaking solution, synthesizing advanced cross-chain liquidity management and order execution methodologies into a seamless, high-performance cross-chain asset transfer system.

Document

NameSmart Contract Code Review and Security Analysis Report for Shuttle Labs
Audited ByPrzemyslaw Swiatowiec
Approved ByGrzegorz Trawinski
Websitebridgesmarter.com→
Changelog16/01/2025 - Preliminary Report, 27/01/2025 - Final Report
PlatformSolana
LanguageRust
TagsLiquidity, Orders, Bridge
Methodologyhttps://hackenio.cc/sc_methodology→
  • Document

    Name
    Smart Contract Code Review and Security Analysis Report for Shuttle Labs
    Audited By
    Przemyslaw Swiatowiec
    Approved By
    Grzegorz Trawinski
    Changelog
    16/01/2025 - Preliminary Report, 27/01/2025 - Final Report
    Platform
    Solana
    Language
    Rust
    Tags
    Liquidity, Orders, Bridge

Review Scope

Repositoryhttps://github.com/Shuttle-Labs/genius-contracts-solana→
Commit1ca628357d27f652d6e16e00cda53e36697b1a07

Audit Summary

7Total Findings
5Resolved
2Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • Functional requirements are provided.

  • Technical description is provided.

Code quality

  • The development environment is configured.

Test coverage

Several tests are provided including both success and negative test cases. Due to the limitation of tools in the Solana ecosystem, the test coverage could not be calculated.

System Overview

The Shittle Labs is a cross-chain asset transfer and liquidity management system designed to facilitate seamless token swaps and asset movement between multiple blockchain networks. Users can deposit tokens into a vault to create orders for cross-chain execution. Orchestrators, operated by the protocol, are responsible for processing these orders and ensuring the accurate transfer of assets to the target chain.

Key components of the system include:

  1. Global State: Maintains critical configuration and operational parameters, such as admin keys, fee settings, and system status (e.g., frozen or active).

  2. Orchestrators: Specialized accounts that handle order execution and liquidity management on the protocol's behalf. Orchestrators process orders, claim fees, and manage bridge liquidity.

  3. Vault: The central repository for user deposits and liquidity management. It securely holds assets until orders are processed or withdrawn.

  4. Fee Management: Enforces a minimum fee structure for cross-chain transactions, ensuring orchestrators are compensated for their work. This includes dynamic fee adjustments to adapt to varying gas costs across chains.

  5. Order Lifecycle: Supports order creation and order fill.

Privileged roles

Admin

  • Responsible for initializing the protocol, managing orchestrators, updating global parameters, and nominating new admins.

Orchestrators

  • Execute cross-chain orders, claim processing fees, and manage bridge liquidity.

  • Operated by the protocol and must remain authorized to function.

Freeze/Thaw Authorities

  • Control the operational state of the protocol by freezing or thawing the global state to manage sensitive operations.

Users

  • Create and manage orders by depositing tokens into the vault for cross-chain execution.

Potential Risks

Off-Chain Orchestrator Vulnerability - Many processes are handled off-chain, making orchestrators a potential weak point. Malicious actors could target orchestrators to disrupt protocol operations.

Centralization Risk - Since orchestrators are operated by a single company, there is a risk of centralization, which may reduce the protocol's trustworthiness and resilience to failure or malicious behavior.

Lack of Documentation on Key Processes - Processes such as swapping all tokens back and forth to USDC are not well-documented. This lack of clarity can lead to misunderstandings, improper implementation, or unintentional errors by orchestrators and developers.

Findings

F-2025-8250Fee Amount Not Validated, Allowing Users to Create Orders with Insufficient Fee
Status
fixed
Severity

Critical
F-2025-8249Missing Minimum Order Amount Validation Can Lead to System Inefficiency and Off-Chain DoS Risks
Status
fixed
Severity

Medium
F-2025-8187Lack of Order Cancellation Mechanism Forces Protocol to Cover Processing Costs for Mismanaged Fees
Status
fixed
Severity

Low
F-2025-8183Orchestrator Accounts Are Not Closed Upon Removal, Leading to Wasted Rent
Status
accepted
Severity

Observation
F-2025-8181Use Anchor Events Instead of msg! for Structured Logging
Status
accepted
Severity

Observation
F-2025-8186Incorrect Length Validation in AddGlobalStateAuthority Allows Adding One Extra Authority
Status
fixed
Severity

Observation
F-2025-8182Missing Event Emission for Critical Actions
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2025-8250Fee Amount Not Validated, Allowing Users to Create Orders with Insufficient Fee
fixed

Critical
F-2025-8249Missing Minimum Order Amount Validation Can Lead to System Inefficiency and Off-Chain DoS Risks
fixed

Medium
F-2025-8187Lack of Order Cancellation Mechanism Forces Protocol to Cover Processing Costs for Mismanaged Fees
fixed

Low
F-2025-8183Orchestrator Accounts Are Not Closed Upon Removal, Leading to Wasted Rent
accepted

Observation
F-2025-8181Use Anchor Events Instead of msg! for Structured Logging
accepted

Observation
F-2025-8186Incorrect Length Validation in AddGlobalStateAuthority Allows Adding One Extra Authority
fixed

Observation
F-2025-8182Missing Event Emission for Critical Actions
fixed

Observation
1-7 of 7 findings

Identify vulnerabilities in your smart contracts.

Appendix 1. Definitions

Severities

When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.

Reference on how risk scoring is done is available through the repository in our Github organization:

Severity

Description

Critical
Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

High
High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

Medium
Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

Low
Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution.
  • Severity

    Critical

    Description

    Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

    Severity

    High

    Description

    High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

    Severity

    Medium

    Description

    Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

    Severity

    Low

    Description

    Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution.

Potential Risks

The "Potential Risks" section identifies issues that are not direct security vulnerabilities but could still affect the project’s performance, reliability, or user trust. These risks arise from design choices, architectural decisions, or operational practices that, while not immediately exploitable, may lead to problems under certain conditions. Additionally, potential risks can impact the quality of the audit itself, as they may involve external factors or components beyond the scope of the audit, leading to incomplete assessments or oversight of key areas. This section aims to provide a broader perspective on factors that could affect the project's long-term security, functionality, and the comprehensiveness of the audit findings.

Appendix 2. Scope

The scope of the project includes the following smart contracts from the provided repository:

Scope Details

Repositoryhttps://github.com/Shuttle-Labs/genius-contracts-solana→
Commit1ca628357d27f652d6e16e00cda53e36697b1a07
WhitepaperProvided as files.
RequirementsProvided as files.
Technical RequirementsProvided as files.

Assets in Scope

programs
genius
src
constant.rs - programs › genius › src › constant.rs
error.rs - programs › genius › src › error.rs
instructions
accept_authority.rs - programs › genius › src › instructions › accept_authority.rs
add_global_state_authority.rs - programs › genius › src › instructions › add_global_state_authority.rs
add_orchestrator.rs - programs › genius › src › instructions › add_orchestrator.rs
borrow.rs - programs › genius › src › instructions › borrow.rs
claim_fees.rs - programs › genius › src › instructions › claim_fees.rs
create_order.rs - programs › genius › src › instructions › create_order.rs
fill_order.rs - programs › genius › src › instructions › fill_order.rs
freeze_thaw_global_state.rs - programs › genius › src › instructions › freeze_thaw_global_state.rs
initialize.rs - programs › genius › src › instructions › initialize.rs
mod.rs - programs › genius › src › instructions › mod.rs
nominate_authority.rs - programs › genius › src › instructions › nominate_authority.rs
remove_bridge_liquidity.rs - programs › genius › src › instructions › remove_bridge_liquidity.rs
remove_global_state_authority.rs - programs › genius › src › instructions › remove_global_state_authority.rs
remove_orchestrator.rs - programs › genius › src › instructions › remove_orchestrator.rs
repay.rs - programs › genius › src › instructions › repay.rs
set_traget_chain_min_fee.rs - programs › genius › src › instructions › set_traget_chain_min_fee.rs

Appendix 3. Additional Valuables

Additional Recommendations

The smart contracts in the scope of this audit could benefit from the introduction of automatic emergency actions for critical activities, such as unauthorized operations like ownership changes or proxy upgrades, as well as unexpected fund manipulations, including large withdrawals or minting events. Adding such mechanisms would enable the protocol to react automatically to unusual activity, ensuring that the contract remains secure and functions as intended.

To improve functionality, these emergency actions could be designed to trigger under specific conditions, such as:

  • Detecting changes to ownership or critical permissions.

  • Monitoring large or unexpected transactions and minting events.

  • Pausing operations when irregularities are identified.

These enhancements would provide an added layer of security, making the contract more robust and better equipped to handle unexpected situations while maintaining smooth operations.

Disclaimer