Skip to content
Cosmopediaby Unity Nodes
Documentationinformalsystems/auditsinformalsystems/audits › InjectiveView on informalsystems/audits ↗

Audit Dashboard

Audit Dashboard

Target Summary

  • Name: Injective Protocol
  • Version: 4dac628eb1d08f4d66685e9f228f6ff53e9197c9 through baa69e1c366e9dc8727c7385fa120c08162b08e0
  • Type: Implementation and preliminary documentation
  • Platform: Golang

Engagement Summary

  • Dates: May 11 through June 14, 2021 (kick-off meeting May 7)
  • Method: Whitebox, model-based testing, symbolic model checking
  • Employees Engaged: 2
  • Time Spent: 21 person days

Fundings Summary by Severity and Difficulty

SeverityDifficulty#Finding
HighLow1IF-INJECTIVE-10
HighHigh2IF-INJECTIVE-11, IF-INJECTIVE-12
MediumMedium2IF-INJECTIVE-07, IF-INJECTIVE-08
LowLow7IF-INJECTIVE-02, IF-INJECTIVE-03, IF-INJECTIVE-01, IF-INJECTIVE-04, IF-INJECTIVE-05, IF-INJECTIVE-06, IF-INJECTIVE-09
Total12

Category Breakdown

Finding Type#
Distributed System Reliability and Fault Tolerance3
Protocol, Economics & Implementation3
Implementation & Testing6
Total12

Severity Categories

SeverityDescription
InformationalThe issue does not pose an immediate risk (it is subjective in nature); they are typically suggestions around best practices or readability
LowThe issue is objective in nature, but the security risk is relatively small or does not represent security vulnerability
MediumThe issue is a security vulnerability that may not be directly exploitable or may require certain complex conditions in order to be exploited
HighThe issue is exploitable security vulnerability

Difficulty Categories

DifficultyDescription
LowCan be attacked by a user without special permission
MediumCan be exploited without special permission with in-depth knowledge and control of the security architecture
HighNeeds a collection of privileged users with in-depth knowledge and control of the security architecture