Skip to content

Threat-model inherited ZFi behavior and resolve audit findings #44

Description

@stxphxn

Summary

Perform an explicit security review of inherited ZFi assumptions before treating the fork as production-ready.

Scope

  • Review total-balance refunds, permissionless sweep, generic execute, trusted targets, lazy approvals, callbacks, and transient accounting.
  • Map each Cantina/Zellic finding to current code.
  • Classify as fixed, removed, redesigned, accepted with controls, or not applicable.
  • Add regression tests for every retained risk.
  • Document the router’s custody and adversarial transaction model.

Acceptance criteria

  • Every inherited finding has a disposition and owner.
  • High-impact behavior is enforced by code, not only operational assumptions.
  • Accepted risks include concrete monitoring and limits.
  • Regression tests reproduce the original failure class.
  • Threat model is reviewed before external audit.

Dependencies

Ethereum compatibility baseline.
Setwise execution paths.

Difficulty

Expert — requires adversarial understanding of a large, highly optimized router.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: contractsSolidity contracts and interfacesarea: securitySecurity design, review, and remediationdifficulty: expertSecurity-critical or highly specialized workdocumentationImprovements or additions to documentationenhancementNew feature or requestphase: rolloutTestnet, security, and production rolloutpriority: p0Release blocker or critical path

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions