Matomo

Smart contract security audit for Allbridge Classic | Cossack Labs
Case studies
Smart contract security audit for Allbridge Classic

Smart contract security audit for Allbridge Classic

AUG–SEPT 2022 Finance Smart contracts
Smart contract security audit for Allbridge Classic

Allbridge's Tezos Project audit results

In the public report, we summarised the security assessment of Allbridge's Tezos Project: the process, a list of findings, theoretical and practical concerns. We would like to note the efforts that the Allbridge team has put into the security & reliability of smart contracts code and their infrastructure. The team has implemented not only 'band-aid' fixes but refactored and improved significant pieces of code based on our recommendations.

Read executive summary

Overview

Industry

  • FSA / Fintech
  • DeFi

Technology stack

  • Smart contracts
  • Tezos Network
  • JavaScript, Python, LIGO

Regulations

  • Typical fintech security requirements

Challenges

[01]

LIGO language barriers

Tezos has its own smart contract language, which has a number of benefits. However, as a relatively new and evolving language, tooling requires additional work from the auditors.

[02]

Smart contract specific attacks

Smart contracts occupy a separate niche in the software world and have their unique attack vectors: gas exhaustion, reentrancy, front-running attacks, signature replay, malicious miners, etc. Developers should understand all these attacks to build suitable defence mechanisms.

[03]

Gas consumption issues

The Tezos blockchain uses gas as a unit of computation to limit the execution time of smart contracts, prevent infinite loops, and keep miners from abusing their computing power. The irrational usage of gas—unnecessary code pieces, uncontrollable growth of data, or calls to malicious contracts—can lead to blocking the entire contracts or user funds.

[04]

Smart contracts are more than just a code

Smart contracts require a proper surrounding infrastructure and processes: testing, deploying, updating, migrating, monitoring, and stopping in an emergency. All these procedures don't magically appear; they should be created and—preferably—automated. Often, smart contract security depends on the developer's operational security habits and how they handle sensitive admin keys and other assets.

[05]

Dependency management and vulnerability monitoring

Heavily relying on external dependencies is a common practice in modern software development. Selecting secure and reliable libraries, on-time monitoring and updating should be a part of any development process, not just for smart contracts.

[06]

Smart contracts infrastructure

Tezos Project contains a set of smart contracts that communicate with each other. Third parties can use some of the contracts from outside the Tezos Project. Thus, all entrypoints should be secured with proper input validation, covering all possible edge cases.

Technology requirements

Technology requirements

Immutable smart contracts

Once deployed, smart contracts can not be changed or replaced easily. Developers should design the update mechanisms, like migrating the whole contract to a new version or switching its individual parts. However, it creates a trade-off between the maintainability and security of smart contracts.

A bridge works across several blockchains

A bridge provides a mechanism for different incompatible blockchain networks to interoperate. Ensuring that these components work as intended, even in unusual circumstances, is crucial to protecting users' funds and the bridge itself against abuse and misuse.

Support of token standards

The Tezos network relies on two standards for implementing tokens in smart contracts: FA1.2 and FA2. As the Tezos Project uses its own tokens, they must be compatible with standards for easy integration with other tools in the Tezos ecosystem.

Our approach

Keen understanding of blockchain threats

Cossack Labs has been working with mature blockchain research organisations for years, dealing with cryptographic cores, wallets, smart contracts, nodes, etc. By researching vulnerabilities and fixes, monitoring ecosystems, and analysing different blockchains, we keep up-to-date with blockchain threats, security controls and mitigations.

Pragmatic security, proven methods

We apply “traditional” software security practices to novel contexts to fully comprehend threat vectors. Our team borrows verification standards from the world of distributed apps, financial security standards from banking, and development maturity guidelines from NIST. It allows benefiting from years of experience in software security.

Comprehensive security review and analysis

We go beyond code and also review use cases, tests, deployment pipelines, key management processes, user experience, integration with backends, supply chain issues, maintenance, etc. Our engineers suggest security improvements for better future reliability and development of the project. Why fix bugs if you can just prevent them?
Our approach

Solution

We started the audit by analysing, threat modelling, and assessing the risks associated with smart contracts and off-chain entities:

Keeping the bridge context in mind, we reviewed its design and use cases:

We conducted a security audit of smart contracts core and transactions:

Besides all the above, we provided recommendations for security improvements aligned with the “defence in depth” approach:

Results and outcomes

Tezos Foundation and Allbridge hold a comprehensive review of Tezos smart contracts as a part of the Tezos Project project. In this audit, we focused on consistency, security, and defence in depth providing recommendations on numerous fixes and improvements.

We verified existing security controls and suggested new ones, boosting Allbridge's and users' confidence in the bridge's correctness. Several improvements were made to the Tezos part of the bridge, including routines for changing sensitive parameters, more consistent functionality, compliance with FA2 and TZIP-016 standards, additional test paths, more efficient storage, and many more.


Up next

Got a challenge that's still standing?

Let’s start a conversation.

Start a conversation

Get whitepaper

Apply for the position

Our team will review your resume and provide feedback
within 5 business days

Thank you!
We’ve received your request and will respond soon.
Your resume has been sent!
Our team will review your resume and provide feedback
within 5 business days