Skip to content

mainnet gate: external security audit of the three verifiers #4

Description

@dendisuhubdy

Both internal review passes (2026-09-17, docs/audit/2026-09-17-predeploy-audit.md and the second pass whose follow-ups landed in e44b7b6) found no critical or high finding — but they are internal, from the same tooling that wrote the code. Before any endpoint holds real value:

  • External audit of evm/src/ (all three endpoints share RandBridgeBase + lib/Attestation.sol + lib/SafeTransfer.sol)
  • External audit of solana/programs/rand-bridge/
  • External audit of the fullnode bridge (bridge-codec, randprotocol-core::bridge, randprotocol-core::ledger::bridge_notes) — coordinate with the fullnode repo
  • Sign-off on operational values: six guardian keys on distinct operators and hardware, admin multisig, pauser, per-token release caps (including whether Tron USDC is enabled at all — Circle discontinued it), relayer-fee policy (fee is record-only on the lock leg, paid only on release)
  • A bridged Rand chain cut (genesis bridge section naming the six guardians and the four emitters) — enabling the bridge on a running chain is impossible; it is a hard fork

Depends on the testnet round trips and the guardian/relayer daemons.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions