Security audit 2026-09-23: ADR 0003 payment-scan analysis - #11
Draft
RunTimeAdmin wants to merge 3 commits into
Draft
RunTimeAdmin wants to merge 3 commits into
RunTimeAdmin wants to merge 3 commits into
Conversation
Comprehensive security review covering: - Contracts (staking, identity, reputation, oracle bond) - Oracle operators (payment-scan ADR 0003 analysis) - SDK/SigvaraGate nonce handling - Deployment/ops configuration Key findings: - CONDITIONAL GO for enabling paymentScan on testnet - GO for further product work - 2 High severity items (mainnet blockers, testnet acceptable) - 5 Medium severity items (testnet acceptable) - Regression check against 17 Sep review shows most gaps closed No critical blockers for testnet operations. Co-authored-by: David Cooper <david@runtimeadmin.com>
SEC-01 reported the ADR 0003 scanner as unmerged. It was not. oracle/payment-scan.js landed in 68a871d, two commits before the pin this audit used, so the finding was written against code that had already been superseded. The error inverted the finding rather than merely dating it. SEC-01 listed risks to watch for when the scanner was eventually built. One of them, checkpoint advance past unprocessed events, was present in merged code: a credit whose block timestamp could not be read was left uncredited while the checkpoint advanced past it anyway, and the scan only moves forward, so that payment would never have been looked at again. Fixed in c98e462 by checkpointAfter. So the auditor's list was good enough to find a live defect, and the wording buried that as hypothetical future risk. Recorded plainly rather than quietly corrected. Each predicted risk is now checked against the real code and marked addressed, partly addressed or fixed, with the remaining gap named: there is still no canary to tell a filter that matches nothing from a genuinely quiet range. Nothing else is altered. SEC-02 through SEC-06 were verified against the live deployment and stand as written, and the Go / Conditional Go verdict is unchanged. Claims added here were checked against main: 24 scanner tests, checkpointAfter with five, recipient batching at 50, confirmations floor of 6, scan disabled by default. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
- Add file:line locations to SEC-01 risk table - Add success:null/hasOutcome, self-payment, and named refusals to risk table - Update SEC-04: document split confirmation defaults between /attest and scan - Update SEC-10: mark evidence gap as CLOSED by ADR 0003 - Add Implementation Location table with file:line references - Add Test Coverage section documenting payment-scan.test.js - Update Risks table with current status - Mark verified items in ADR 0003 recommendations - Update operational checklist with verified items and metrics to monitor Co-authored-by: David Cooper <david@runtimeadmin.com>
cursor
Bot
force-pushed
the
cursor/security-audit-2026-09-23-cd7b
branch
from
September 23, 2026 04:11
05befd0 to
1857e60
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Comprehensive security audit of the Sigvara protocol, corrected against commit
c98e462(current HEAD of main after the checkpoint fix), covering:Correction Note
SEC-01 as originally written was factually wrong: it reported the ADR 0003 pull scanner as unmerged. It was not —
oracle/payment-scan.jslanded in68a871d, before this audit was published. One of the predicted risks (checkpoint advance past unprocessed events) was present in the merged code and is fixed inc98e462.Key Findings
Go/No-Go Recommendations
Finding Summary
SEC-01: Payment-Scan Implementation Analysis
The audit now includes detailed analysis of the implemented payment-scan with file:line citations:
payment-scan.js:47-55usedPaymentTxspayment-scan.js:179,index.js:315success: null/hasOutcomepayment-scan.js:193-195,payments.js:269-270MIN_SCAN_CONFIRMATIONS=6floorpayment-scan.js:57-83c98e462payment-scan.js:215-232payment-scan.js:183-186payment-scan.js:175-186High-Severity Items (Mainnet Blockers)
SplitAuthority.s.solexists but not runGaps Closed
Files Changed
docs/SECURITY_AUDIT_2026-09-23.md— Full audit report with severity-ordered findings, updated with real code analysis