In February 2021, Incognito engaged Coinspect to perform a source code review of the smart contracts that comprise the Incognito-Ethereum bridge.

The main contracts are:

  • Vault: responsible for deposits and withdrawals; it holds assets (Ether or ERC20 tokens) and emits events that the Incognito Chain interprets as minting instructions; and when presented with a burn proof created over at the Incognito Chain, it releases the assets back to the user.

Continue reading Coinspect’s Incognito Smart Contract Audit report to learn more about how the bridge works and the details of the security issues identified.


In March 2021, Liquity engaged Coinspect to perform its second third-party source code review of the smart contracts that comprise the Liquity Protocol.

Coinspect identified a high risk issue, a missing requirement in a function that allowed attackers to force the system to enter Recovery Mode in order to liquidate troves. This finding was promptly fixed by Liquity’s team during the assessment and the resulting code was verified by Coinspect.

Coinspect also identified two medium risks issues, one shows how attackers could leverage flash loans to inflate system fees, the other calls attention to how after the introduction of batch…


In August 2020, Aragon engaged Coinspect to perform a series of third-party source code reviews of the smart contracts that comprise their Protocol.

Following are descriptions of the scope for several of those reviews:

  1. The ANTv2 contract is a new lightweight token intended to replace ANT. In…


In September 2020, SpaceChain engaged Coinspect to perform a security audit of the following SpaceChain Token V2 contract deployed to mainnet on September 19th, 2020:

https://etherscan.io/address/0x86ed939b500e121c0c5f493f399084db596dad20

The objective of the audit was to evaluate the security of the smart contract source code, deployment, and user tokens migration procedures. During the assessment, Coinspect identified the following issues:


Executive Summary

In February 2020, Horizen engaged Coinspect to audit the security of its blockchain platform. In particular this first engagement focused on reviewing Horizen platform additions to the Zcash protocol implementation including its core consensus rules, network protocols and privacy features. Also, Coinspect verified Horizen has properly fixed every known vulnerability inherited from the Zcash codebase.

During this engagement, Coinspect consultants used a hands-on approach to evaluate the platform security, which included:

  • Rapid prototyping of potential attacks and proof of concept development.

The…


Starting in September 2020, Bloq requested Coinspect to review selected parts of Vesper Pool’s source code while the contracts were being developed. Coinspect auditors spent 5 weeks during a period of 5 months.

Coinspect published 5 smart contract audit reports detailing the tasks performed. Each report focused on an individual new feature and/or set of modifications performed to previously reviewed code, specifically selected by the development team. Hence, the reviews do not represent a complete audit of the final project code and does not include the interactions with external components such as third party DeFi systems which were not in scope as per the client’s request.

Continue reading Vesper Pools Smart Contract Audit

Contact us to request a Smart Contract Audit


Executive Summary

In October 2020, Sovryn engaged Coinspect to perform a source code review of their new decentralized Bitcoin trading and lending platform. The objective of the audit was to evaluate the security of their smart contracts.

The code reviewed was found to be clear, well written, and properly documented. The modifications performed to the forked projects did not introduce any vulnerabilities. However, Coinspect observed the oracle integration implementation weakens the system security and could be abused by attackers to manipulate the price feeds.

Moreover, the protocol is dependent on third party oracle providers, whose security should be evaluated and taken into…


Executive Summary

In January 2021, Sovryn engaged Coinspect to perform a source code review of their new governance, staking and fee sharing contracts. The objective of the audit was to evaluate the security of the smart contracts implementing these features.

The code reviewed was found to be clear, well written, and properly documented. No high risk vulnerabilities were discovered during this audit.

Even though the new features give the protocol users more participation, it is worth noting, by design, centralized roles are still able to control governance decisions, at least until governance abdicates their proposal veto right.

The following issues were identified…


Executive Summary

Between September and October 2018, IOVLabs engaged Coinspect to perform source code reviews of the RIF Token smart contracts. The objective of the audits was to evaluate the security of the smart contracts. During the assessments, Coinspect identified seven security issues. The high risk issues identified compromised the integrity of the token. External attackers could have abused RIF-002 to steal tokens belonging to shareholders, and initial contributors could have exploited RIF-004 to obtain bonus amounts higher than expected. Coinspect verified that all the identified security issues were correctly fixed in the revision `rc3` (git: 6194d7edca0abbcb5275350da7b225edd18b7573) of RIF Token contracts.

Introduction

The…


Executive Summary

In August 2020, Aragon engaged Coinspect to perform a source code review of the new Staking app 0.3.0. The objective of the audit was to evaluate the security of the smart contracts.

The assessment was conducted on the Staking and StakingFactory contracts from the Git repository at https://github.com/aragon/staking as of commit c7537c4519930ca254f693ff4e65117619b08f23 tag audit of September 10th.

The code was found to be clear, well written, well commented, and very well tested.

The following issues were identified during the assessment:

Coinspect Security

Security for a Decentralized World

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store