Audit Open Original ↗
Orga and Merk
Type
Security review
Client
Turbofish
Date
2024-11
Domain
Blockchain
Effort
10 wks
Section
Tendermint/Cosmos
Trail of Bits's security review of Turbofish (Nov 2024) identified 7 issues: 1 high, 1 medium, and 5 low.
Findings · 7
- 1 Slashing of re-delegated stake is computed incorrectly Medium
- 2 Malicious state sync peer can cause syncing nodes to crash Low
- 3 Interrupted snapshots can lead to inconsistent state Low
- 4 Malicious state sync peer can cause a stack overflow in Merk Low
- 5 Merk trunk splitting can lead to panics on degenerate trees Low
- 6 Stored IBC consensus states cannot be pruned Low
- 7 Merk proofs can be forged to claim arbitrary key/value inclusions High
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related