Audit Open Original ↗
Gensyn Automated Settlement and Permit
Type
Security review
Client
Gensyn
Date
2026-07
Domain
Blockchain
Effort
1.2 wks
Section
Ethereum/EVM
Trail of Bits's security review of Gensyn (2026) identified 6 issues: 1 high, 1 medium, and 4 low.
Findings · 6
- 1 Blacklisted market creator address permanently locks market funds High
- 2 Oracle relayer can settle or fail markets without a preceding resolution request Medium
- 3 Permissionless market creators can send untrusted metadata references to the Truebit backend Low
- 4 In-flight markets are stranded when the gateway oracle relayer is unset or rotated mid-flight Low
- 5 Malicious WatchTower can orphan an in-flight market by returning a duplicate execution ID Low
- 6 Front-running the permit in buyExactOutWithPermit causes the bundled buy to revert Low
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related