DAML
security audits

Your protocol’s security is our responsibility. We take each and every audit very personally, and we make sure no issues are left behind.

What Are We Looking For

Those are some of the vulnerabilities we focus on. Our goal is to provide complete protocol security.

Flexible Controller Privilege Escalation

A controller read from a choice argument lets anyone pass any party and exercise sensitive choices, escalating privilege without authorization.

Divulgence Privacy Leak

Non-stakeholder parties become informees in transaction trees and gain visibility into private contracts through ledger projections they were never meant to see.

Contract Key Maintainer Misconfiguration

Maintainers not properly derived from the key expression or not signatories break uniqueness guarantees and key-lookup authorization.

Non-Consuming Choice Abuse

A choice missing the consuming keyword can be exercised repeatedly on the same contract, minting unlimited assets or duplicating claims.

Missing Precondition Guards

Templates without ensure clauses and choices without assert statements allow creation or exercise with economically invalid, exploit-enabling values.

Unilateral Archival Attack (Weak Signatory)

When only one party signs a contract, that party can unilaterally archive it and destroy the other parties' rights without their consent.

Ready to Secure Your Codebase?

Get in touch and we’ll respond within 6 hours with price and timeline estimate.