Audit Open Original ↗
Lit Protocol Cait-Sith
Type
Security review
Client
Lit Protocol
Date
2024-06
Domain
Crypto
Effort
10 wks
Section
Cryptography Reviews
Trail of Bits's security review of Lit Protocol (Jun 2024) identified 12 issues: 3 high, 3 medium, and 6 informational.
Findings · 12
- 1 Correlated-OT-Extension does not properly use session ID in PRG High
- 2 Timing di erences in hash_to_scalar implementation may disclose information to the sender in Random-OT-Extension Medium
- 3 Insu cient warnings or safeguards against reusing presignatures and triples High
- 4 Cait-Sith does not time out if progress is not made Informational
- 5 Sensitive data is not zeroized upon completion of subprotocols Medium
- 6 Protocol implementation tells the user to wait after completion Informational
- 7 Iterated extended oblivious transfer is not secure against a malicious receiver High
- 8 Caller responsibilities around aborts are unclear Medium
- 9 Di erent participants in triple generation and triple setup causes deadlock Informational
- 10 Requirements on thresholds are unclear and inconsistently verified in the implementation Informational
- 11 The receiver in Batch-Random-OT does not check that Y is nonzero Informational
- 12 Cait-Sith is implemented with outdated dependencies Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related