Trail of Bits

Offchain Labs Arbitrum ArbOS 50 and 51 (Fusaka)

Type

Security review

Client

Offchain Labs

Date

2025-12

Domain

Blockchain

Effort

Section

Offchain Labs

Trail of Bits's security review of Offchain Labs (Dec 2025) identified 6 issues: 1 medium, 1 low, and 4 informational.

Findings · 6

  1. 1 Outdated block gas limit used inside the block in which the ArbOS upgrade is executed Low
  2. 2 Lack of checks when setting the block gas limit Informational
  3. 3 Possible underflow inside the gas charging hook Medium
  4. 4 GetScheduledTx out-of-bounds check ignores the case in which txId equals len(s.txs) Informational
  5. 5 Call to batch.Write in headerchain does not have error checking Informational
  6. 6 ARB_GAS_INFO variable is unused Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related