Trail of Bits

Offchain ArbOS 30 Nitro

Type

Security review

Client

Offchain Labs

Date

2024-04

Domain

Blockchain

Effort

6 wks

Section

Offchain Labs

Trail of Bits's security review of Offchain Labs (Apr 2024) identified 5 issues: 1 medium, and 4 informational.

Findings · 5

  1. 1 secp256r1 precompile does not check for signature malleability Informational
  2. 2 secp256r1 precompile uses a deprecated function Informational
  3. 3 Incorrect implementation of integer math functions Medium
  4. 4 Incorrect parameter types used for CGo calls Informational
  5. 5 Making space for a very large program can result in heap error Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related