Quantstamp has performed an audit and a penetration test of Sequence's Identity Instrument. The Sequence Identity Instrument is a Go-based authentication and identity management system that provides enclave-based authentication using multiple methods, including OIDC, OAuth 2.0, and email OTP. The system uses AWS Nitro Enclaves for cryptographic operations and implements Shamir's Secret Sharing for key management across trusted third parties (TTPs). During the audit, a range of issues have been identified, mainly revolving around the penetration testing side of the engagement. However, a few issues in the design and authentication implementation have also been identified. We recommend that all the issues identified in the report be addressed. The test suite is quite limited and should be improved. **Fix review 1 (November 12th, 2025)** <br> Many issues remain unresolved and must be promptly addressed. Non-fixed issues center on insecure JWT handling, missing schema/input restrictions, and weak validation on several endpoints. Some replay-attack risks and incomplete error handling remain. A few infrastructure and key-rotation items are only partially mitigated. Latest commit hash: 129bdf2975ddb7834a212ecd48c2df93a259cb33 **Fix review 2 (December 1st, 2025)** <br> Most of the outstanding issues of the first fix-review phase have been addressed. A small subset was classified as acknowledged, indicating that while the behavior exists, it does not present a material security or functional risk in the current context. No issues remain unresolved. Tests have also improved in comparison to the initial audit. The mean statement coverage is presently at 71%. The project’s test coverage shows strong emphasis on security-critical components—such as encryption, OTP flows, OIDC validation, and telemetry—which consistently achieve high coverage and indicate solid engineering practices. However, important modules, including AuthCode and ID-Token handlers, metadata validation, and parts of the RPC layer, exhibit only partial coverage, leaving error paths and boundary conditions insufficiently tested. Some operational packages, particularly CLI entrypoints and configuration loading, have no coverage at all, increasing the risk of deployment-time issues. Overall, while the core authentication and cryptographic layers are well tested, the project would benefit from broader coverage of negative cases, RPC edge behavior, and initialization logic.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | 20 | 1 | - | - | 21 |
Acknowledged | - | - | - | - | 0 |
Fixed | 2 | 14 | 9 | - | 25 |
| Total | 22 | 15 | 9 | 0 | 46 |
| # | File Name |
|---|---|
| 1 | Scope not recorded here: see the report |