Summary
100% of all REPORTED Findings have been addressed
- 2Future Release
- 2Not Applicable
- 4Risk Accepted
- 18Solved
- 26All Findings
- Critical0
- High7
- 1Risk A.
- 6Solved
- Medium8
- 6Solved
- 1N/A
- 1Risk A.
- Low6
- 1Risk A.
- 1N/A
- 4Solved
- Informational5
- 2Solved
- 2F. Release
- 1Risk A.
Summary#
Introduction#
Crossmint engaged Halborn to perform a security assessment of the Signer-Frames, Crossmint-SDK, Crossbit-main, and TEE-ts repositories. The assessment scope included these repositories, although only specific paths within some were included. Halborn was granted access to the source code to conduct security testing using automated tools and manual techniques to identify, detect, and validate potential vulnerabilities within the application.
Assessment Summary#
The Halborn team was provided a timeline for the engagement and assigned a dedicated full-time security engineer to evaluate the security of the scoped assets. This engineer is a penetration testing expert with advanced expertise in web, mobile, reconnaissance, discovery, and infrastructure penetration testing.
The security assessment uncovered multiple vulnerabilities across the repositories, varying in severity. It is strongly recommended to remediate these issues promptly to mitigate unnecessary risks.
Seven (7) high-impact issues were identified during the assessment:
Host MitM and Insecure Default
targetOrigin. The application accepts messages from any origin, allowing a man-in-the-middle attacker to inject or steal cross-origin data and compromise user sessions.Environment Parameter Tampering via URL Override. An attacker can override configuration parameters through query strings, causing the backend to operate in an unintended environment and exposing sensitive functionality.
Lack of Content Security Policy and Frame-Ancestor Protection. The absence of a Content Security Policy (CSP) and clickjacking protections permits hostile iframes and arbitrary script execution, potentially leading to malware injection and data theft.
Potential Arbitrary JavaScript Injection. Unescaped user input is reflected into HTML, enabling execution of attacker-supplied JavaScript and full compromise of the victim’s browser session.
Potential Authentication Bypass with
ACCESS_SECRETUnset. When the shared secret is missing, the server skips verification, allowing an unauthenticated caller to impersonate any user.Log Injection and Use of
X-Forwarded-For. User-controlled strings are logged without sanitization, enabling attackers to forge IP addresses, insert fake entries, and mislead incident responders.Excessive Exposure of Key Shares. Key fragments are exposed in the browser memory allowing a potential attacker that has compromised the computer to extract them.
Nine (9) medium-impact issues were identified during the assessment:
Insecure Storage of Cryptographic Keys in
localStorage. Persisting keys client-side exposes them to theft via cross-site scripting (XSS) or physical device access, undermining encryption guarantees.Hard-coded and Weak Secret. The use of a static, low-entropy secret enables attackers to brute-force credentials offline within minutes.
Potential XSS and Reverse-Tabnabbing. Unsanitized URL parameters and unguarded
target="_blank"links allow script injection and phishing attacks through malicious tabs.IDOR in Public Key Derivation. Predictable identifiers permit one tenant to request another tenant’s key material, resulting in horizontal privilege escalation.
Lack of Rate Limiting. Unlimited authentication attempts and API requests facilitate credential-stuffing attacks and resource exhaustion.
Attestation Response Replay Attack. Previously captured attestation tokens can be replayed to gain illegitimate trust and bypass integrity checks.
Potential Timing Attack on Shared-Secret Comparison. Measurable processing time differences reveal partial key bytes, enabling gradual recovery of the secret.
Lack of Message Origin Validation. The application processes
postMessageevents without verifying the sender’s domain, allowing cross-site request forgery of privileged actions.Master Keys Not Explicitly Removed from Memory. Keys remain in RAM after use, so memory dumps or crash reports could expose them to attackers.
Five (5) low-impact issues were identified during the assessment:
Excessive Data Shared in Attestation. The attestation payload includes unnecessary user attributes, increasing privacy risks if intercepted.
Missing
event.sourceValidation Allows Same-Origin Message Spoofing. Attackers executing code within the same domain can forge trusted messages and manipulate application state.Weak Randomness. Non-cryptographic random generators produce predictable tokens, reducing the effort required for brute-force attacks.
Excessive Error Information Exposed to Caller. Detailed stack traces and configuration values leak internal implementation details that could aid attackers.
Sensitive Data Logged to Console. Debug logging outputs secrets to browser consoles and monitoring tools, risking inadvertent disclosure.
Five (5) informational findings were identified during the assessment:
Denial of Service (DoS) via Uncontrolled Memory Allocation. Very large input sizes can cause high memory consumption, potentially crashing the service under stress conditions.
Documentation Issues. Incomplete or outdated security documentation may lead to insecure operational practices.
Potential Production DoS Bug. Concurrency flaws could allow a high-rate attacker to exhaust worker threads and degrade availability.
Over-Privileged
ACCESS_SECRET. The shared secret grants broader access than necessary, increasing the blast radius if leaked.Deterministic Generation of Master Keys (Risk Accepted). Reproducible key generation facilitates development but may weaken uniqueness across deployments; this risk has been formally accepted by stakeholders.
Test Approach and Methodology#
Halborn employed both whitebox and blackbox methodologies according to the scope, combining manual and automated security testing to balance efficiency, timeliness, practicality, and accuracy. Manual testing is essential to uncover flaws in logic, processes, and implementation, while automated techniques enhance coverage and quickly identify infrastructure vulnerabilities. The assessment methodology included, but was not limited to, the following phases and tools:
Mapping Content and Functionality of APIs and SDKs
Application Logic Flaws
Access Handling
Authentication and Authorization Flaws
Rate Limiting Tests
Input Handling
Source Code Review
Fuzzing of All Input Parameters
Logic Errors
Out of Scope#
In the
Signer-Framesrepository, all contents except/testand/src/libare in scope.In the
Crossmint-SDKrepository, all contents exceptpackages/client/rn-windowandpackages/client/windoware in scope.In the
Crossbit-mainrepository, only the contents oflibraries/products/wallets/ncsandapps/crossmint-nextjs/src/api/wallets/ncs.controller.tsare in scope.
Risk Methodology#
- 5 - Almost certain an incident will occur.
- 4 - High probability of an incident occurring.
- 3 - Potential of a security incident in the long term.
- 2 - Low probability of an incident occurring.
- 1 - Very unlikely issue will cause an incident.
- 5 - May cause devastating and unrecoverable impact or loss.
- 4 - May cause a significant level of impact or loss.
- 3 - May cause a partial impact or loss to many.
- 2 - May cause temporary impact or loss.
- 1 - May cause minimal or un-noticeable impact.
- 10 - CRITICAL
- 9 - 8 - HIGH
- 7 - 6 - MEDIUM
- 5 - 4 - LOW
- 3 - 1 - VERY LOW AND INFORMATIONAL
Scope#
Assessment Summary & Findings Overview#
Impact x Likelihood
HAL-01
HAL-02
HAL-03
HAL-04
HAL-05
HAL-06
HAL-07
HAL-08
HAL-09
HAL-10
HAL-11
HAL-12
HAL-13
HAL-14
HAL-15
HAL-16
HAL-17
HAL-18
HAL-19
HAL-20
HAL-21
HAL-22
HAL-23
HAL-24
HAL-25
HAL-26
# | Title | Severity | Score | Status |
|---|---|---|---|---|
| Host MitM and Insecure Default Target Origin | High | 8.1 | Risk Accepted07/10/2025 | |
| Environment Parameter Tampering via URL Override | High | 8.1 | Solved07/01/2025 | |
| Lack of Content Security Policy and Frame Ancestor Protection | High | 8.0 | Solved07/14/2025 | |
| Potential Arbitrary JavaScript Injection | High | 7.4 | Solved07/11/2025 | |
| Potential Authentication Bypass with ACCESS_SECRET Unset | High | 7.4 | Solved07/10/2025 | |
| Log Injection & use of x-forwarded-for | High | 7.2 | Solved07/11/2025 | |
| Excessive Exposure of Key Shares | High | 7.1 | Solved07/10/2025 | |
| Insecure storage of cryptographic keys in localStorage | Medium | 6.8 | Solved07/10/2025 | |
| Hardcoded and Weak Secret | Medium | 6.8 | Solved07/15/2025 | |
| Potential XSS & Potential Reverse-Tabnabbing | Medium | 6.3 | Solved07/11/2025 | |
| IDOR in Public Key Derivation | Medium | 5.3 | Not Applicable07/11/2025 | |
| Lack of Rate Limiting | Medium | 5.3 | Solved07/14/2025 | |
| Attestation Response Replay Attack | Medium | 5.3 | Solved07/18/2025 | |
| Potential Timing-Attack on Shared Secret Comparison | Medium | 4.8 | Solved07/09/2025 | |
| Lack of Message Origin Validation | Medium | 4.2 | Risk Accepted07/11/2025 | |
| Master Keys Not Explicitly Removed from Memory | Low | 3.7 | Risk Accepted07/14/2025 | |
| Too Much Data Shared in Attestation | Low | 3.7 | Not Applicable07/11/2025 | |
| Missing event.source Validation Allows Same-Origin Message Spoofing | Low | 3.6 | Solved07/11/2025 | |
| Weak Randomness | Low | 3.6 | Solved07/15/2025 | |
| Excessive Error Information Exposed to Caller | Low | 3.5 | Solved07/11/2025 | |
| Sensitive Data Logged to Console | Low | 3.5 | Solved07/15/2025 | |
| DoS via Uncontrolled Memory Allocation | Informational | 1×1 | Solved07/16/2025 | |
| Other Documentation Issues | Informational | 1×1 | Solved07/18/2025 | |
| Potential Production DoS Bug | Informational | 1×1 | Future Release07/15/2025 | |
| Too Privileged ACCESS_SECRET | Informational | 1×1 | Future Release07/15/2025 | |
| Deterministic generation of Master Keys | Informational | 1×1 | Risk Accepted06/24/2025 |
Findings & Tech Details#
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Remediation Comment
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Remediation Comment
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Remediation Comment
Description
Proof of Concept
Recommendation
Remediation Comment
Description
Proof of Concept
Recommendation
Remediation Comment
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Description
Recommendation
Remediation Comment
Description
Proof of Concept
Recommendation
Remediation Comment
Description
Recommendation
Remediation Comment
Description
Proof of Concept
Recommendation
Remediation Comment
Disclaimer#
Halborn strongly recommends conducting a follow-up assessment of the project either within six months or immediately following any material changes to the codebase, whichever comes first. This approach is crucial for maintaining the project’s integrity and addressing potential vulnerabilities introduced by code modifications.
