Skip to content
Back to Blog
Ecosystem

RSK Security Audit Results

Read Time: 1 mins
RSK Security Audit Results

As part of our commitment to create the most secure platform, we have conducted two independent external security audits. These have been held by recognized security audit teams: Trail of Bits, and Patrick McCorry and Andrew Miller. Each team was focused on auditing the areas of the code where we believe they could contribute most with their expertise.

Today we are making the final reports available to the public, summarizing the findings and actions RSK team has taken in response. Links to these reports can be found in sections below.

Also, we’d like to remind the community that our vulnerabilities bounty program has already started. The bounty program rewards researchers for reporting not yet identified platform vulnerabilities,

Find below complete security audit reports:

Trail of Bits

Scope of work: smart contract issues related to the virtual machine, virtual machine compatibility with other Ethereum VM implementations, correctness of the Trie data structure, and correctness of the precompiled contracts for the two-way peg.

Link to report: https://github.com/trailofbits/publications/blob/master/reviews/RSKj.pdf

Patrick McCorry and Andrew Miller

Scope of work: first version of the REMASC and Bridge native smart contracts.

Link to report: http://www0.cs.ucl.ac.uk/staff/P.McCorry/rskaudit_ginger_120717.pdf

What’s next

In RSK we believe in defense in depth: that’s why won’t stop at security audits, and we’ll keep thinking how to improve security and adding more security layers in the future.

We are undergoing a third external security audit of the current Bridge contract, while a fourth audit is already planned for the first quarter of 2018. Conducting periodic external security reviews is highly valuable for the development team and the community to continuously validate and improve RSK’s secure development procedures.

We thank security experts Josselin Feist, Evan Sultanik, Patrick McCorry and Andrew Miller for their professional work during the conducted audits.

 

Recommended articles

Rootstock Integrates USDT0 to Unlock BTCFi at Scale

Rootstock Integrates USDT0 to Unlock BTCFi at Scale

Rootstock, the most secure Bitcoin DeFi (BTCFi) layer, is now home to USDT0, the omnichain deployment of Tether’s USDT.  This integration connects the world’s most trusted stablecoin with Bitcoin’s most secure BTCFi layer, offering a unified and composable dollar asset for Rootstock’s fast-growing DeFi ecosystem. Why This Matters With LayerZero connectivity previously live on Rootstock, […]

Ecosystem
Rootstock 2025 Roadmap: Scaling BTCFi with Trust-Minimized Bridges and Yield Infrastructure

Rootstock 2025 Roadmap: Scaling BTCFi with Trust-Minimized Bridges and Yield Infrastructure

2025 is a transformational year for Rootstock. With major protocol upgrades, powerful new integrations, and a focus on institutional-grade security and composable DeFi infrastructure, Rootstock is becoming not only the most secure but also the most composable Bitcoin Layer 2.  From faster transactions and liquid staking to trust-minimized bridging and DeFi vaults, Rootstock is building […]

Ecosystem
Golden Sats Challenge: User Guide to the New Campaign on Rootstock

Golden Sats Challenge: User Guide to the New Campaign on Rootstock

5 Lil Pudgies up for grabs and a $500k+ of incentives to earn! The Rootstock community is excited to introduce the new campaign: The Golden Sats Challenge, and this is your chance to win a Lil Pudgy while earning some decent APR at the same time.  Complete onchain tasks such as bridging through Stargate and […]

Users