Cube3

Multi-Chain
Audited on 2023/10/20
No open critical findings

Summary

Cube3 contracted the services of Resonance to conduct a comprehensive security audit of their smart contracts between May 8, 2023 and May 19, 2023. The primary objective of the assessment was to identify any potential security vulnerabilities and ensure the correct functioning of smart contract operations.The Cube3 Protocol is a security tool that implements RASP (Runtime Application Self-Protection) functionality for on-chain traffic. Web3 applications and smart contracts are protected from malicious activities through monitoring and filtering of incoming traffic, acting to some extent as a Web3 Application Firewall.The system can be deployed on multiple Ethereum-based chains and is best used with Cube3’s Risk API. It essentially comprises 4 important components, the customer’s integration registered to be protected by Cube3, the router used to forward protected traffic, the modules that different security functionality, and the on-chain registry which interfaces with Cube3’s Key Management System. The components are expected to be protected with required access control mechanisms and to communicate securely between themselves.As a general workflow, traffic sent to a customer’s registered application or smart contract is forwarded by the router to the specified module. This is accomplished with the usage of a secure payload retrieved off-chain, and then exchanged throughout the components of the system. At the end, verified payloads are eventually capable of validating or invalidating on-chain activities of customers users.


Issues (8)

Low
Medium
High
Critical
Total
Not fixed
1---1
Acknowledged
----0
Fixed
421-7
Total52108


Contracts (13)