Matomo

Crypto wallet security assessment for Temple Wallet | Cossack Labs
Case studies
Crypto wallet security assessment for Temple Wallet

Crypto wallet security assessment for Temple Wallet

SEP 2021 - MAY 2022 Finance Digital wallet
Crypto wallet security assessment for Temple Wallet

Overview

Industry

  • FSA / Fintech
  • Blockchain
  • Cryptocurrency

Technology stack

  • React Native (iOS, Android)
  • Web extension (Chrome, Firefox)
  • LPoS

Regulations

  • Typical fintech security requirements
  • Encryption Export Regulations

Challenges

[01]

User's private keys protection against leakage and abuse

Secure storage of an account's private keys is crucial for non-custodial cryptocurrency wallets because their leakage equals losing the funds. Building intuitive security-focused design and transparent apps' business logic should prevent users from accidentally exposing private keys or signing fraudulent transactions.

[02]

Encryption scheme should be consistent across all supported platforms

Account synchronisation means that users can easily open their account from the mobile app to the web app, and back. The sync process occurs by transferring the account's seed—encrypting the data in one wallet and decrypting it in another one. Thus, each supported platform should use the same crypto primitives. Cryptographic libraries available natively (on iOS, Android, and the Web) are frequently out of sync, forcing to use a third-party crypto primitives source.

[03]

Binding encryption with user authentication

Crypto wallets often use in-app passwords to derive a cryptographic key for encrypting wallet’s private data. Thus, they make users fully responsible for passwords security. This approach should be implemented with caution, using a reliable password-based key derivation function and informing users that losing their passwords may result in the inability to restore their data.

[04]

Secure communication with DApps

Apps are third-party apps that communicate with the wallet and allow users to perform more actions with their funds and NFTs. Communication with DApps should be protected: authenticated, validated, and sanitised to avoid issuing unintended transactions.

[05]

Dependency management

Modern software development brings the common practice of heavily relying on many external dependencies, including cryptographic and security libraries. It raises the question of selecting reliable and secure third-party libraries (especially for the React Native ecosystem) and regularly updating them as a part of Secure SDLC.

[06]

Secure local storage is complicated on each platform

Each platform has its own approach to storing sensitive data securely, which requires a thorough understanding of each platform’s internals. For example, iOS provides Keychain to store any sensitive data; however there's no similar secure storage for Android or web extension, so developers must implement data at rest encryption on their own.

[07]

Web apps risks

Web extensions operate in a risky environment. Their security relies on the browser's and the user's machine's security. Wallets can be targeted through a browser via installed malicious extensions or browser exploits that provide access to the extension memory sandbox. So, proper application security and data protection measures should mitigate these risks.

Technology requirements

Technology requirements

Encrypt data at rest

Non-custodial wallets store private keys and mnemonic phrases locally on the client side. They require an advanced level of protection and encryption for data at rest.

Multi-platform solution

The Temple Wallet operates on three platforms (iOS, Android, and Web browsers). A deep dive into threat analysis for each supported platform revealed the need for platform-specific security controls that provide a comparable level of security.

Financial app security built into UX

Users expect security by default from the apps handling their financial data. Apps should inform users about their limitations, provide security warnings and educational tips, and give hints on how to use the app securely.

Our approach

Understanding blockchain and non-custodial wallet security threats

Cryptocurrency wallets could be viewed as a young generation of financial apps with a similar security baseline but blockchain-specific threats. Threats include user deanonymysation, potential attacks on blockchain nodes, secure client-side storage of sensitive data for non-custodial wallets, and many others. Understanding specific threats of the financial apps and applying the cryptocurrency context enables us to prioritise security mitigations.

Building mobile/web platform-specific security controls

Cryptocurrency wallets can work on any platform: Temple Wallet runs on iOS, Android, and as a web extension in different browsers. It means that the app should be designed with risks, threats, and limitations of each platform in mind. Storing wallet seed and user private keys securely on mobile and web requires different approaches. Execution environment trust is often disputed: should applications actively resist running on compromised platforms, or is this the user's responsibility?

Integrating reliable cryptographic tools

Development teams frequently face challenges in using proper cryptographic primitives for the correct purpose, dealing with cryptographic libraries API, befriending libraries across multiple platforms, etc. We audited the Temple Wallet cryptographic code, communicated issues we found, suggested and implemented an improved cryptographic core, and ensured its maintainability for future cross-platform releases.
Our approach

Solution

We started crypto wallet security audit with risk assessment and threat modelling for the Temple Wallet apps and backend ecosystem:

Temple Wallet web extension, iOS and Android mobile apps underwent a deep cryptography audit.

Besides the cryptographic enhancements, we also provided dozens of application security improvements aligned with the “defense in depth” approach:

We analyzed the development process and made recommendations for improvements, ranging from further automation in the CI/CD pipeline to formalizing a security roadmap:

Additional relevant materials

Results and outcomes

The Tezos Foundation and Madfish Solutions received an in-depth security review of Temple Wallet apps, including not only a list of found security issues—but also suggestions for improving application logic from a security perspective.

The security, general stability, and maintainability of the Temple Wallet ecosystem were improved. Applications were enriched with numerous updates in security, cryptography usage and design, platform-specific controls, defenses against reverse engineering and tampering, and other enhancements.


Up next

Got a challenge that's still standing?

Let’s start a conversation.

Start a conversation

Get whitepaper

Apply for the position

Our team will review your resume and provide feedback
within 5 business days

Thank you!
We’ve received your request and will respond soon.
Your resume has been sent!
Our team will review your resume and provide feedback
within 5 business days