Market Cap: $2.1532T -0.32%
Volume(24h): $35.0938B -46.31%
  • Market Cap: $2.1532T -0.32%
  • Volume(24h): $35.0938B -46.31%
  • Fear & Greed Index:
  • Market Cap: $2.1532T -0.32%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

Cryptocurrency News Articles

Disclosing the Neo X Bridge Audit Report by Secure3

Aug 13, 2024 at 11:53 am

Neo has released the results of an audit contest conducted by Secure3, a platform that collaborates with security experts to identify and mitigate threats to Web3 protocols.

Disclosing the Neo X Bridge Audit Report by Secure3

Web3 protocol security platform Secure3 has completed an audit of the Neo Native Bridge, which was developed by Bane Labs to facilitate asset transfers between Neo N3 and Neo X. The audit aimed to ensure the integrity and security of the bridge, which is crucial for safeguarding user funds and maintaining the integrity of the Neo ecosystem.

The Neo Native Bridge comprises two primary components: a bridge smart contract deployed on Neo X and a relayer code that facilitates communication between Neo N3 and Neo X. The audit focused on both these aspects to identify and mitigate any potential vulnerabilities or risks.

? Bridge contract audit

The audit of the Neo X Bridge Contract identified several issues, including a medium-severity concern related to token registration and deregistration. This issue could potentially allow replay attacks on the bridge, posing a significant risk to the security of asset transfers.

The audit team highlighted this issue and worked closely with the Neo team to resolve it promptly. The system was modified to disallow the deregistration of token bridges, effectively mitigating the identified risk and ensuring the integrity of the Neo Native Bridge.

Furthermore, the audit uncovered several low-severity concerns, which were either acknowledged for future resolution or fixed by adopting more secure alternatives. These included:

The use of safeTransferFrom instead of transferFrom, which could lead to unexpected behavior with certain tokens due to non-standard ERC20 implementations. This was addressed by using OpenZeppelin’s SafeERC20 library.

The use of the ecrecover function, which limited validators to externally owned accounts and made the system vulnerable to signature malleability, potentially enabling forgery or replay attacks. These issues were either acknowledged for future resolution or fixed by switching to more secure alternatives like OpenZeppelin’s ECDSA.recover function.

Minor informational issues, such as code style inconsistencies and unused errors, were also identified and addressed where necessary.

? Bridge relayer audit

The audit of the Neo X Bridge Relayer also revealed several low-severity issues, which were promptly addressed or acknowledged for future improvements. These included:

The relayer’s program continued to run indefinitely in the event of a non-connection-related error, potentially leading to resource exhaustion. This was resolved by ensuring the program exits appropriately in such scenarios.

The potential for a denial of service attack due to the lack of a timeout in the signature processing function, which was fixed by implementing a timeout mechanism.

The system did not verify the uniqueness of signatures, which could allow possible bypasses. This issue was acknowledged and will be addressed in future updates.

The hardcoded threshold for the number of signatures required for relayer operations, which limited the flexibility of the system. This was acknowledged, and a more dynamic approach will be implemented in future releases.

Other informational issues, such as improper handling of decrypted accounts, insecure password storage, and the risk of race conditions due to the use of goroutines in loops, were also noted. While most of these issues were promptly addressed, some were acknowledged and earmarked for future improvements.

The full reports can be found in the announcement linked below: https://medium.com/neo-smart-economy/disclosing-the-neo-x-audit-report-by-secure3-1b7eae9dc47b

Original source:neonewstoday

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Aug 02, 2026