LIGO language barriers
Tezos has its own smart contract language, which has a number of benefits. However, as a relatively new and evolving language, tooling requires additional work from the auditors.

In the public report, we summarised the security assessment of Allbridge's Tezos Project: the process, a list of findings, theoretical and practical concerns. We would like to note the efforts that the Allbridge team has put into the security & reliability of smart contracts code and their infrastructure. The team has implemented not only 'band-aid' fixes but refactored and improved significant pieces of code based on our recommendations.
Read executive summaryAllbridge Classic is a cross-chain bridge that enables users to transfer their assets between the Tezos network and other supported blockchains (Ethereum, BNB Chain, Solana, and more). The Tezos part of the cross-chain bridge (named Tezos Project) was developed as part of a collaboration between Allbridge and MadFish Solutions teams, containing smart contacts and off-chain infrastructure.
Tezos Foundation requested a security audit of the Tezos Project from Cossack Labs. Our security engineers went through the usual audit labour: reviewed and analysed smart contracts core, tests, deployment pipelines, development processes, and surrounding infrastructure. Having validated fixes for soundness, we can now mention this project.
Tezos has its own smart contract language, which has a number of benefits. However, as a relatively new and evolving language, tooling requires additional work from the auditors.
Smart contracts occupy a separate niche in the software world and have their unique attack vectors: gas exhaustion, reentrancy, front-running attacks, signature replay, malicious miners, etc. Developers should understand all these attacks to build suitable defence mechanisms.
The Tezos blockchain uses gas as a unit of computation to limit the execution time of smart contracts, prevent infinite loops, and keep miners from abusing their computing power. The irrational usage of gas—unnecessary code pieces, uncontrollable growth of data, or calls to malicious contracts—can lead to blocking the entire contracts or user funds.
Smart contracts require a proper surrounding infrastructure and processes: testing, deploying, updating, migrating, monitoring, and stopping in an emergency. All these procedures don't magically appear; they should be created and—preferably—automated. Often, smart contract security depends on the developer's operational security habits and how they handle sensitive admin keys and other assets.
Heavily relying on external dependencies is a common practice in modern software development. Selecting secure and reliable libraries, on-time monitoring and updating should be a part of any development process, not just for smart contracts.
Tezos Project contains a set of smart contracts that communicate with each other. Third parties can use some of the contracts from outside the Tezos Project. Thus, all entrypoints should be secured with proper input validation, covering all possible edge cases.



Tezos Foundation and Allbridge hold a comprehensive review of Tezos smart contracts as a part of the Tezos Project project. In this audit, we focused on consistency, security, and defence in depth providing recommendations on numerous fixes and improvements.
We verified existing security controls and suggested new ones, boosting Allbridge's and users' confidence in the bridge's correctness. Several improvements were made to the Tezos part of the bridge, including routines for changing sensitive parameters, more consistent functionality, compliance with FA2 and TZIP-016 standards, additional test paths, more efficient storage, and many more.
Let’s start a conversation.
Get whitepaper
Apply for the position
Our team will review your resume and provide feedback
within 5 business days