Audit Open Original ↗
Mina Decentralized Treasury
Type
Security review
Client
Mina Foundation
Date
2026-06
Domain
Blockchain
Effort
4.6 wks
Section
Other/Multi-Chain
Trail of Bits's security review of Mina Foundation (Jun 2026) identified 9 issues: 2 high, 1 medium, 2 low, and 4 informational.
Findings · 9
- 1 Unpausing a proposal resets its status to UNKNOWN, discarding approval or rejection outcomes Informational
- 2 Custom multisignature implementation baked into application code Informational
- 3 Incomplete action state check allows a malicious prover to manipulate proposal outcomes High
- 4 All-abstain voting permanently blocks proposal tally Low
- 5 No minimum proposal amount allows bond-free proposal spam Low
- 6 Signatures are not bound to a specific deployment, enabling cross-deployment replay Medium
- 7 Multisignature circuit does not enforce participant key uniqueness Informational
- 8 Unchecked actionStateHistoryTarget enables selective vote-tally exclusion High
- 9 Incomplete error handling in deserialization methods Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related