Skip to main content

cNEAR

Type

Security review

Client

cAssets Management Ltd

Date

2026-08

Domain

Blockchain

Effort

1.2 wks

Section

Other/Multi-Chain

Trail of Bits's security review of cAssets Management Ltd (Aug 2026) identified 14 issues: 2 high, 1 medium, 4 low, and 7 informational.

Findings · 14

  1. 1 Locked dependencies contain known security vulnerabilities Informational
  2. 2 Deployment retains access keys that bypass contract-governed administration Informational
  3. 3 Default deployment creates only one-billionth of one cNEAR Informational
  4. 4 Account-existence checks treat RPC errors as existing accounts Low
  5. 5 Deployment omits controller registration required for cNEAR upgrades Low
  6. 6 Ownership verification failures do not fail deployment Low
  7. 7 Controller-mediated upgrades deploy malformed contract code High
  8. 8 Unpinned controller source can change privileged deployment code Informational
  9. 9 owner_get can disagree with effective ownership Informational
  10. 10 Freeze-list growth uses contract-funded storage contrary to documentation Informational
  11. 11 Pause, freeze, and price changes do not emit dedicated events Low
  12. 12 Force transfers bypass the pause and freeze controls without documentation Informational
  13. 13 Ownership transfer retains the previous owner’s administrative permissions High
  14. 14 Frozen or paused accounts can burn their balance via storage_unregister, defeating owner recovery Medium

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related