DAML
security audits
Your protocol’s security is our responsibility. We take each and every audit very personally, and we make sure no issues are left behind.
What Are We Looking For
Those are some of the vulnerabilities we focus on. Our goal is to provide complete protocol security.
Flexible Controller Privilege Escalation
A controller read from a choice argument lets anyone pass any party and exercise sensitive choices, escalating privilege without authorization.
Divulgence Privacy Leak
Non-stakeholder parties become informees in transaction trees and gain visibility into private contracts through ledger projections they were never meant to see.
Contract Key Maintainer Misconfiguration
Maintainers not properly derived from the key expression or not signatories break uniqueness guarantees and key-lookup authorization.
Non-Consuming Choice Abuse
A choice missing the consuming keyword can be exercised repeatedly on the same contract, minting unlimited assets or duplicating claims.
Missing Precondition Guards
Templates without ensure clauses and choices without assert statements allow creation or exercise with economically invalid, exploit-enabling values.
Unilateral Archival Attack (Weak Signatory)
When only one party signs a contract, that party can unilaterally archive it and destroy the other parties' rights without their consent.
Ready to Secure Your Codebase?
Get in touch and we’ll respond within 6 hours with price and timeline estimate.