# \#security

**URL:** https://forum.dfinity.org/tag/security/35.md

[Latest](https://forum.dfinity.org/latest.md) · [Categories](https://forum.dfinity.org/categories.md) · [Tags](https://forum.dfinity.org/tags.md)

---

## [Inter-canister messages and inspect\_message, cycles burn with no way to reject?](https://forum.dfinity.org/t/inter-canister-messages-and-inspect-message-cycles-burn-with-no-way-to-reject/66149)

<div class="topic-metadata">

**Author:** [@da5id](https://forum.dfinity.org/u/da5id)\
**Replies:** 7\
**Last updated:** [April 2, 2026, 8:30am UTC](https://forum.dfinity.org/t/inter-canister-messages-and-inspect-message-cycles-burn-with-no-way-to-reject/66149 "2026-04-02T08:30:49Z")

</div>

I’m trying to understand if this is really true. According to some previous conversations I have seen on the forums, and The Internet Computer Interface Specification | Internet Computer it seems clear that : The canis…

---

## [Canfuzz: Introducing the Canister Fuzzing Framework](https://forum.dfinity.org/t/canfuzz-introducing-the-canister-fuzzing-framework/60755)

<div class="topic-metadata">

**Author:** [@vsekar](https://forum.dfinity.org/u/vsekar)\
**Replies:** 9\
**Last updated:** [March 17, 2026, 8:07am UTC](https://forum.dfinity.org/t/canfuzz-introducing-the-canister-fuzzing-framework/60755 "2026-03-17T08:07:59Z")

</div>

We are excited to introduce canister\_fuzzing(crate: canfuzz), a new open-source automated testing framework designed to help finding vulnerabilities in your canisters. Motivation: Why Fuzzing? Fuzzing is a dynamic softw…

---

## [Security Advisory: Sign-In with Ethereum/Bitcoin/Solana (SIW E/B/S) prone to Phishing](https://forum.dfinity.org/t/security-advisory-sign-in-with-ethereum-bitcoin-solana-siw-e-b-s-prone-to-phishing/64050)

<div class="topic-metadata">

**Author:** [@vsekar](https://forum.dfinity.org/u/vsekar)\
**Replies:** 5\
**Last updated:** [February 11, 2026, 10:02pm UTC](https://forum.dfinity.org/t/security-advisory-sign-in-with-ethereum-bitcoin-solana-siw-e-b-s-prone-to-phishing/64050 "2026-02-11T22:02:38Z")

</div>

:warning: Important Disclaimer / Confidentiality The advisory was responsibly disclosed to all known users of SIW\* on July 1st, 2025. It is now made available for everyone since the embargo period of 90 days has ended. …

---

## [Orbit Security Assessment by Trail of Bits](https://forum.dfinity.org/t/orbit-security-assessment-by-trail-of-bits/62700)

<div class="topic-metadata">

**Author:** [@robin-kunzler](https://forum.dfinity.org/u/robin-kunzler)\
**Replies:** 3\
**Last updated:** [January 21, 2026, 7:18am UTC](https://forum.dfinity.org/t/orbit-security-assessment-by-trail-of-bits/62700 "2026-01-21T07:18:07Z")

</div>

Summary Orbit - a top Internet Computer based multi-approver governance platform for multichain assets - was recently assessed by Trail of Bits, a leading technical security auditor operating as a center of excellence fo…

---

## [OISY Security Assessment by Trail of Bits](https://forum.dfinity.org/t/oisy-security-assessment-by-trail-of-bits/61125)

<div class="topic-metadata">

**Author:** [@robin-kunzler](https://forum.dfinity.org/u/robin-kunzler)\
**Replies:** 1\
**Last updated:** [December 8, 2025, 3:26pm UTC](https://forum.dfinity.org/t/oisy-security-assessment-by-trail-of-bits/61125 "2025-12-08T15:26:23Z")

</div>

Summary A top Internet Computer based digital asset wallet - OISY - was recently assessed by Trail of Bits, a leading technical security auditor operating as a center of excellence for blockchain security. OISY is the wo…

---

## [VetKeys Cryptography Review by NCC Group](https://forum.dfinity.org/t/vetkeys-cryptography-review-by-ncc-group/58961)

<div class="topic-metadata">

**Author:** [@robin-kunzler](https://forum.dfinity.org/u/robin-kunzler)\
**Replies:** 0\
**Last updated:** [October 14, 2025, 1:12pm UTC](https://forum.dfinity.org/t/vetkeys-cryptography-review-by-ncc-group/58961 "2025-10-14T13:12:38Z")

</div>

Summary A top Internet Computer feature - verifiably encrypted threshold key derivation (vetKeys) - was recently assessed by Cryptography Services at NCC Group, a leading technical security auditor for cryptography and b…

---

## [Critical Vulnerability in Sign-In With Bitcoin (SIWB) used to Attack Odin.fun - Learnings and Discussion](https://forum.dfinity.org/t/critical-vulnerability-in-sign-in-with-bitcoin-siwb-used-to-attack-odin-fun-learnings-and-discussion/44721)

<div class="topic-metadata">

**Author:** [@robin-kunzler](https://forum.dfinity.org/u/robin-kunzler)\
**Replies:** 6\
**Last updated:** [August 14, 2025, 8:18am UTC](https://forum.dfinity.org/t/critical-vulnerability-in-sign-in-with-bitcoin-siwb-used-to-attack-odin-fun-learnings-and-discussion/44721 "2025-08-14T08:18:00Z")

</div>

Hi, On Monday April 14, DFINITY’s security team was involved to investigate the Odin.fun security incident where user funds were stolen (Odin’s postmortem tweet). We identified a critical vulnerability in the sign-in wi…

---

## [Endpoints for Cycle Drains Attacks - Log Visibility and Guarded Endpoints](https://forum.dfinity.org/t/endpoints-for-cycle-drains-attacks-log-visibility-and-guarded-endpoints/51721)

<div class="topic-metadata">

**Author:** [@Lorimer](https://forum.dfinity.org/u/Lorimer)\
**Replies:** 2\
**Last updated:** [June 27, 2025, 9:18pm UTC](https://forum.dfinity.org/t/endpoints-for-cycle-drains-attacks-log-visibility-and-guarded-endpoints/51721 "2025-06-27T21:18:56Z")

</div>

Is there any information available regarding cycle usage for operations such as: dfx canister logs {canister} assuming public log visibility dfx canister call {canister} {guarded\_query\_endpoint} assuming the query meth…

---

## [Critical Security Bug: Authentication Bypass in SIWB](https://forum.dfinity.org/t/critical-security-bug-authentication-bypass-in-siwb/43927)

<div class="topic-metadata">

**Author:** [@vsekar](https://forum.dfinity.org/u/vsekar)\
**Replies:** 2\
**Last updated:** [April 24, 2025, 11:24am UTC](https://forum.dfinity.org/t/critical-security-bug-authentication-bypass-in-siwb/43927 "2025-04-24T11:24:37Z")

</div>

Dear all, We have recently discovered an authentication bypass vulnerability in ic\_siwb\_provider canister that allows an attacker to take full control of any Internet Computer (IC) account principal created using the SI…

---

## [Unmaintained IC Agents Containing Vulnerabilities](https://forum.dfinity.org/t/unmaintained-ic-agents-containing-vulnerabilities/41589)

<div class="topic-metadata">

**Author:** [@eduard-galindo](https://forum.dfinity.org/u/eduard-galindo)\
**Replies:** 2\
**Last updated:** [April 22, 2025, 2:12pm UTC](https://forum.dfinity.org/t/unmaintained-ic-agents-containing-vulnerabilities/41589 "2025-04-22T14:12:59Z")

</div>

Hello community, We noticed some security vulnerabilities in IC agents last year and promptly reported them. Note that we did not systematically review these agents. Unfortunately, some of the reported issues have not b…

---

## [ISO 27001 certification](https://forum.dfinity.org/t/iso-27001-certification/43500)

<div class="topic-metadata">

**Author:** [@jakepeg](https://forum.dfinity.org/u/jakepeg)\
**Replies:** 2\
**Last updated:** [April 7, 2025, 10:25am UTC](https://forum.dfinity.org/t/iso-27001-certification/43500 "2025-04-07T10:25:55Z")

</div>

I’m looking into getting ISO 27001 certification for an ICP dapp. Has anyone been down this route? I can’t find anything about ISO 27001 in the docs so assume ICP isn’t certified, but interested to know if it is complia…

---

## [Critical Security Risk: Preventing Unauthorized User Registrations](https://forum.dfinity.org/t/critical-security-risk-preventing-unauthorized-user-registrations/41580)

<div class="topic-metadata">

**Author:** [@jyotirmaygithub](https://forum.dfinity.org/u/jyotirmaygithub)\
**Replies:** 1\
**Last updated:** [February 25, 2025, 5:42am UTC](https://forum.dfinity.org/t/critical-security-risk-preventing-unauthorized-user-registrations/41580 "2025-02-25T05:42:58Z")

</div>

My user registration function allows users to register by retrieving their principal ID. While it blocks anonymous principals, it does not verify whether a principal is genuinely issued by ICP Identity, NFID, or a valid …

---

## [Community Conversations | Security Best Practices](https://forum.dfinity.org/t/community-conversations-security-best-practices/16563)

<div class="topic-metadata">

**Author:** [@robin-kunzler](https://forum.dfinity.org/u/robin-kunzler)\
**Replies:** 6\
**Last updated:** [January 11, 2025, 10:16am UTC](https://forum.dfinity.org/t/community-conversations-security-best-practices/16563 "2025-01-11T10:16:41Z")

</div>

Learn how to develop secure dApps on the Internet Computer! Join our community conversation this Wednesday, November 16th at 7:30 AM PT / 4:30 PM CET. We’ll dive into two aspects of security: storing confidential data b…

---

## [New security best practice on integrating II for mobile apps](https://forum.dfinity.org/t/new-security-best-practice-on-integrating-ii-for-mobile-apps/39157)

<div class="topic-metadata">

**Author:** [@roel-storms](https://forum.dfinity.org/u/roel-storms)\
**Replies:** 8\
**Last updated:** [January 6, 2025, 12:24pm UTC](https://forum.dfinity.org/t/new-security-best-practice-on-integrating-ii-for-mobile-apps/39157 "2025-01-06T12:24:03Z")

</div>

Hi everyone, We published a new security best practice that explains the caveats when integrating II on mobile applications. A short presentation which is part of the November global R&D covers this best practice as wel…

---

## [Security Bug - Memory leak when calling a canister method via \`ic\_cdk::call\`](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782)

<div class="topic-metadata">

**Author:** [@vsekar](https://forum.dfinity.org/u/vsekar)\
**Replies:** 10\
**Last updated:** [September 27, 2024, 5:44pm UTC](https://forum.dfinity.org/t/security-bug-memory-leak-when-calling-a-canister-method-via-ic-cdk-call/34782 "2024-09-27T17:44:36Z")

</div>

Dear all, We recently discovered a memory leak in the ic\_cdk::call\* implementation in @dfinity/cdk-rs. Canisters built in Rust with ic\_cdk and ic\_cdk\_timers are affected. If these canisters call a canister method, use ti…

---

## [Is there a possibility that ii might be exposed to risks associated with the M-series in macOS](https://forum.dfinity.org/t/is-there-a-possibility-that-ii-might-be-exposed-to-risks-associated-with-the-m-series-in-macos/29007)

<div class="topic-metadata">

**Author:** [@Luffy](https://forum.dfinity.org/u/Luffy)\
**Replies:** 0\
**Last updated:** [March 27, 2024, 11:54pm UTC](https://forum.dfinity.org/t/is-there-a-possibility-that-ii-might-be-exposed-to-risks-associated-with-the-m-series-in-macos/29007 "2024-03-27T23:54:26Z")

</div>

According to my understanding, many ICP holders and developers indeed use macOS. The risk seems significant, and I’m unsure whether our II would be exposed to this risk during its usage. I would appreciate it if mor…

---

## [Agent-js: Insecure Key Generation in \`Ed25519KeyIdentity.generate\`](https://forum.dfinity.org/t/agent-js-insecure-key-generation-in-ed25519keyidentity-generate/27732)

<div class="topic-metadata">

**Author:** [@vsekar](https://forum.dfinity.org/u/vsekar)\
**Replies:** 1\
**Last updated:** [February 22, 2024, 1:48pm UTC](https://forum.dfinity.org/t/agent-js-insecure-key-generation-in-ed25519keyidentity-generate/27732 "2024-02-22T13:48:19Z")

</div>

Dear all, Recently, the DFINITY security team received a disclosure of a critical bug affecting the agent-js repository, in particular @dfinity/identity and @dfinity/auth-client. The library offers a function to genera…

---

## [Long range security of chain-key ECDSA signatures](https://forum.dfinity.org/t/long-range-security-of-chain-key-ecdsa-signatures/27103)

<div class="topic-metadata">

**Author:** [@wanderingbort](https://forum.dfinity.org/u/wanderingbort)\
**Replies:** 2\
**Last updated:** [February 1, 2024, 6:17pm UTC](https://forum.dfinity.org/t/long-range-security-of-chain-key-ecdsa-signatures/27103 "2024-02-01T18:17:52Z")

</div>

The papers cover signature generation quite extensively however, the re-sharing protocol (X-NET or otherwise) have a comparatively light analysis. Has there been extensive analysis that shows re-sharing does not degrade…

---

## [Security Advisory - Candid Upgrade Required](https://forum.dfinity.org/t/security-advisory-candid-upgrade-required/25341)

<div class="topic-metadata">

**Author:** [@rsundar01](https://forum.dfinity.org/u/rsundar01)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 1:58am UTC](https://forum.dfinity.org/t/security-advisory-candid-upgrade-required/25341 "2023-12-08T01:58:03Z")

</div>

Dear All, Recently, the DFINITY security team uncovered a denial of service (DoS) vulnerability in the Candid library, which when exploited can degrade canister’s performance. We urge everyone who is currently on versio…

---

## [ckBTC and Service Nervous System (SNS) Third-Party Security Assessments by Trail of Bits](https://forum.dfinity.org/t/ckbtc-and-service-nervous-system-sns-third-party-security-assessments-by-trail-of-bits/24380)

<div class="topic-metadata">

**Author:** [@robin-kunzler](https://forum.dfinity.org/u/robin-kunzler)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 8:19am UTC](https://forum.dfinity.org/t/ckbtc-and-service-nervous-system-sns-third-party-security-assessments-by-trail-of-bits/24380 "2023-11-03T08:19:38Z")

</div>

Summary Two top Internet Computer features – SNS DAOs and Chain-key Bitcoin (ckBTC) – were recently assessed by Trail of Bits, a leading technical security auditor operating as a center of excellence for blockchain secur…

---

## [Context around the security patch proposal 125000 for the ckBTC Ledger](https://forum.dfinity.org/t/context-around-the-security-patch-proposal-125000-for-the-ckbtc-ledger/23549)

<div class="topic-metadata">

**Author:** [@maciejdfinity1](https://forum.dfinity.org/u/maciejdfinity1)\
**Replies:** 7\
**Last updated:** [October 7, 2023, 12:32pm UTC](https://forum.dfinity.org/t/context-around-the-security-patch-proposal-125000-for-the-ckbtc-ledger/23549 "2023-10-07T12:32:46Z")

</div>

Dear IC Community, We would like to give some context around the security patch proposal 125000 to upgrade the ckBTC Ledger. On Friday 2023-10-06 afternoon DFINITY found a security bug in the ckBTC Ledger and immediate…

---

## [Context around the security patch proposal 123012 for the ICP Ledger](https://forum.dfinity.org/t/context-around-the-security-patch-proposal-123012-for-the-icp-ledger/20847)

<div class="topic-metadata">

**Author:** [@mariop](https://forum.dfinity.org/u/mariop)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 4:27pm UTC](https://forum.dfinity.org/t/context-around-the-security-patch-proposal-123012-for-the-icp-ledger/20847 "2023-06-20T16:27:11Z")

</div>

Dear IC Community, I would like to give some context around the security patch proposal 123012 to upgrade the ICP Ledger. On Friday 2023-06-16 afternoon DFINITY found a security bug in the ICP Ledger and immediately st…
