Skip to main content

Offchain Labs Stylus SDK

Type

Security review

Client

Offchain Labs

Date

2026-04

Domain

Blockchain

Effort

9 wks

Section

Offchain Labs

Trail of Bits's security review of Offchain Labs (Apr 2026) identified 30 issues: 1 high, 3 medium, 15 low, and 11 informational.

Findings · 30

  1. 1 Reliance on vulnerable brotli2 package Informational
  2. 2 When a contract is being verified, its build script runs as root High
  3. 3 Contract build scripts have network access in Docker container Informational
  4. 4 verify_create_deployment always returns Ok(()) Low
  5. 5 run_in_docker_container does not propagate exit codes Low
  6. 6 Manual termination does not kill child process during contract deployment Informational
  7. 7 Deploy and Verify commands do not respect user options when run in a reproducible way Low
  8. 8 Deploy command does not call the constructor of a contract with no arguments Medium
  9. 9 Verify command does not check that the initData calls the constructor Medium
  10. 10 Verify command does not check that the transaction succeeded Medium
  11. 11 No minimal version is enforced for --cargo-stylus-version Informational
  12. 12 Parameterized traits with associated types are unsupported Informational
  13. 13 Unused CLI parameter --project for trace subcommand Informational
  14. 14 Malicious code execution during ABI export through malicious build.rs Low
  15. 15 cargo-stylus generates incomplete ABI Low
  16. 16 Inconsistent use of unsafe in stylus-sdk/src/storage/vec.rs Informational
  17. 17 console! macro panics when stylus-test feature is enabled Low
  18. 18 PhantomData causes a division by zero when used with StorageArray and StorageVec Low
  19. 19 StylusDeployer’s deploy function does not include msg.sender or initValue when computing the salt for create2 Low
  20. 20 cargo stylus replay is unusable when the contract uses the console! macro Low
  21. 21 Incorrect data location for constructor’s arguments Informational
  22. 22 Parsing of public function does not get fallback function’s argument Informational
  23. 23 Complex structs cannot be used inside function parameters due to string length constraints Informational
  24. 24 Solidity named mapping breaks the parsing of sol_storage! macro Low
  25. 25 sol_interface! does not allow the interface defined to be used as key in a storage mapping Low
  26. 26 sol_interface! macro does not support Solidity function overloading Low
  27. 27 AbiType macro allows struct to have Solidity primitive type name Low
  28. 28 underscore_if_sol function contains multiple issues Low
  29. 29 Selector override macro allows a function to have the same selector as the constructor Low
  30. 30 Purity::infer allows to non-Self reference type Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related