background
logo

Security Audit Report for KEYRING's multisig-wallet-contracts

DESCRIPCIÓN

The target of this audit is the code repository of multisig-wallet-contracts of KEYRING. This project implements a permissionless multisig wallet system. A factory deploys deterministic minimal-proxy wallets for users and stores each wallet’s signer set and approval threshold. Wallets can receive native tokens, ERC20, ERC721, and ERC1155 assets, and allow withdrawals only after validating threshold EIP-712 signatures from approved signers. Each withdrawal type uses an independent nonce and deadline for replay protection, while recipients are restricted to wallet signers. The factory also emits standardized withdrawal events for created wallets.

Please refer to the report for the detailed audit scope.

Our audit methodology employs automated vulnerability scans, manual verification, and business logic analysis to uncover potential security issues coupled with gas and code quality optimization recommendations.

In summary, we did not find any critical issues within the audited codebase. However, we have identified some non-critical issues that should be addressed. Additionally, we have put forth recommendations that should be taken into consideration. It is important to note that the scope of our audit was strictly limited to the specific code versions mentioned in the report. Any updates made subsequent to our review would require a re-evaluation.

HALLAZGOS CLAVE

En total encontramos 1 posibles incidencias en el smart contract. Añadimos además 3 recomendaciones y 0 notas, como se detalla a continuación:

Riesgo alto: 0
Riesgo medio: 0
Riesgo bajo: 1
Recomendación: 3
Nota: 0
ID Severity Description Status
1 Low Lack of EOA signer validation in function createMultisigWallet() Fixed
2 - Add zero address validation in function constructor() Fixed
3 - Enforce a dynamic minimum signature threshold Fixed
4 - Emit only verified signatures in withdrawal events Fixed

Encontrarás más detalles en el informe de auditoría.

Da el primer paso hacia un futuro seguro

¡Contacta ahora con los servicios expertos de auditoría de código de BlockSec y refuerza la seguridad de tu protocolo antes de lanzarlo!