Summary
100% of all REPORTED Findings have been addressed
- 0Risk Accepted
- 1Acknowledged
- 2Solved
- 3All Findings
- Critical0
- High0
- Medium1
- 1Solved
- Low1
- 1Solved
- Informational1
- 1Ack.
Introduction#
HSuite engaged Halborn to conduct a web application review on their DEX application. The security assessment was scoped to application provided to Halborn to conduct the assessment.
This report contains a detailed list of findings, highlighting the severity and impact of each one and certain proposed resolutions.
Assessment Summary#
Halborn performed a security assessment of the client’s application to evaluate the overall robustness of its core functionality and identify potential risks that could impact reliability, integrity, and user trust. The review focused on key areas of the platform, including critical backend API behavior and components related to pool operations within the DEX.
Overall, the assessment identified opportunities to strengthen how the system handles edge cases and unexpected user behavior. In particular, the review highlighted scenarios where normal user actions could lead to unintended outcomes, such as the ability to influence pool balances outside of the expected configuration, as well as cases where invalid inputs caused the application to return internal server errors. While some of these issues were not directly exploitable on their own, addressing them will improve platform stability and reduce the risk of future abuse.
It is recommended to prioritize improvements in validation, safeguards around pool operations, and general resilience controls. Implementing these measures will enhance the consistency of the platform, reduce operational risk, and provide a more reliable experience for end users.
Scope#
https://testnet.silksuite.app/
https://testnet-sn1.hbarsuite.network
https://testnet-sn2.hbarsuite.network
https://testnet-sn3.hbarsuite.network
https://testnet-sn4.hbarsuite.network
Risk Methodology#
- 5 - Almost certain an incident will occur.
- 4 - High probability of an incident occurring.
- 3 - Potential of a security incident in the long term.
- 2 - Low probability of an incident occurring.
- 1 - Very unlikely issue will cause an incident.
- 5 - May cause devastating and unrecoverable impact or loss.
- 4 - May cause a significant level of impact or loss.
- 3 - May cause a partial impact or loss to many.
- 2 - May cause temporary impact or loss.
- 1 - May cause minimal or un-noticeable impact.
- 10 - CRITICAL
- 9 - 8 - HIGH
- 7 - 6 - MEDIUM
- 5 - 4 - LOW
- 3 - 1 - VERY LOW AND INFORMATIONAL
Scope#
Assessment Summary & Findings Overview#
Findings & Tech Details#
Description
Proof of Concept
Recommendation
Remediation Comment
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Remediation Comment
Disclaimer#
Halborn strongly recommends conducting a follow-up assessment of the project either within six months or immediately following any material changes to the codebase, whichever comes first. This approach is crucial for maintaining the project’s integrity and addressing potential vulnerabilities introduced by code modifications.
