Credshieds has extensive experience researching the security of public blockchains such as Bitcoins, Ethereum, Cosmos, and others and has a deep understanding of the security of crucial modules like P2P communication, node security, RPC calls, cryptography, consensus mechanisms, and asset transactions.
Our process flow is smooth and simple.
Schedule
A Meeting
Scope Assessment
And Timeline
Payment
for Services
Security
Audit
Draft
Report
Retesting
Final
Audit Report
| S.NO | Audit Category | Audit Category Checklist |
|---|---|---|
| 1 | Node Security | |
| Data and State Storage | ||
| Blockchain Database Security | ||
| Database State Integrity Check | ||
| 2 | Node Operation | |
| Default Configuration Security | ||
| Default Configuration Optimization Node Upgrade And Rollback Mechanism | ||
| 3 | Node Communication | |
| External RPC Implementation Logic | ||
| External RPC Function Security | ||
| Node P2P Protocol Implementation Logic | ||
| Node P2P Protocol Security Serialization/Deserialization | ||
| Invalid/Malicious Node Management Mechanism Communication Encryption/Decryption | ||
| Eclipse Attack Protection | ||
| Fingerprint Attack Protection | ||
| 4 | Consensus | |
| Consensus Algorithm Scalability | ||
| Consensus Algorithm Implementation Logic | ||
| Consensus Algorithm Security | ||
| 5 | Transaction Model | |
| Transaction Privacy Security | ||
| Transaction Fee Mechanism Security Transaction Congestion Attack Protection | ||
| 6 | VM | |
| VM Implementation Logic | ||
| VM Implementation Security | ||
| VM Sandbox Escape | ||
| VM Stack/Heap Overflow | ||
| Contract Privilege Control | ||
| Predefined Function Security | ||
| 7 | Account Model | |
| Status Storage Algorithm Adjustability | ||
| Status Storage Algorithm Security | ||
| Double Spending Protection | ||
| 8 | Incentive Model | |
| Mining Algorithm Security | ||
| Mining Algorithm ASIC Resistance | ||
| Tokenization Reward Mechanism |
Get exclusive updates on the latest security threats, innovative solutions, and industry news. Connect with fellow security enthusiasts, developers, and businesses building a secure Web3 future.