Summary
Orbit - a top Internet Computer based multi-approver governance platform for multichain assets - was recently assessed by Trail of Bits, a leading technical security auditor operating as a center of excellence for blockchain security. To learn more about Orbit, see the Medium post and Orbit on GitHub.
The new report can be found here, along with a list of all previous third-party audits.
The finding breakdown is as follows:
-
High - 2 issues found
-
Medium - 2 issue found
-
Low - 5 issues found
-
Informational - 13 issues found
-
Undetermined - 1 issue found
Many issues have been addressed and went through a fix review. 1 high and 2 medium were resolved, 1 high was partially resolved. See the fix review results in Appendix E of the report.
Weβd like to thank the Trail of Bits team for their excellent contributions, the audit and security-related recommendations, and the effective collaboration.
Discussion Leads
Happy to discuss and answer any questions you may have. The people at DFINITY who were most involved and can be tagged for questions are @robin-kunzler (Security) and @aterga (Orbit).
Previous Forum Discussions about Security Assessments
-
βOISY Security Assessmentβ by Trail of Bits
-
βVetKeys Cryptography Review by NCC Groupβ by NCC
-
βckBTC and Service Nervous System (SNS) Third-Party Security Assessmentsβ by Trail of Bits
-
βThreshold ECDSA Integration and Bitcoin Canisters - Security Reviewβ by Trail of Bits
-
βCanister Sandboxingβ by Trail of Bits
-
βThreshold ECDSA Cryptography Reviewβ by NCC Group
-
βInternet Computer Consensus: Security Assessmentβ by Trail of Bits
-
βIC Assessmentβ by Trail of Bits