Trail of Bits

Polygon Labs Iden3 Circuits

Type

Security review

Client

Polygon Labs

Date

2024-05

Domain

AppSec

Effort

2 wks

Section

Technology Product Reviews

Trail of Bits's security review of Polygon Labs (May 2024) identified 7 issues: 1 high, 5 informational, and 1 undetermined.

Findings · 7

  1. 1 Unsafe use of Num2Bits in multiple circuits High
  2. 2 EdDSA R value is not constrained to be on-curve Undetermined
  3. 3 Lack of domain separation in hash functions Informational
  4. 4 SpongeHash is not a sponge hash Informational
  5. 5 Ambiguous padding in SpongeHash Informational
  6. 6 Signature challenge does not bind claim or query Informational
  7. 7 Linked queries can prove expired or revoked claims Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related