Audit Open Original ↗
Offchain Labs Stylus SDK
Type
Security review
Client
Offchain Labs
Date
2026-04
Domain
Blockchain
Effort
9 wks
Section
Offchain Labs
Trail of Bits's security review of Offchain Labs (Apr 2026) identified 30 issues: 1 high, 3 medium, 15 low, and 11 informational.
Findings · 30
- 1 Reliance on vulnerable brotli2 package Informational
- 2 When a contract is being verified, its build script runs as root High
- 3 Contract build scripts have network access in Docker container Informational
- 4 verify_create_deployment always returns Ok(()) Low
- 5 run_in_docker_container does not propagate exit codes Low
- 6 Manual termination does not kill child process during contract deployment Informational
- 7 Deploy and Verify commands do not respect user options when run in a reproducible way Low
- 8 Deploy command does not call the constructor of a contract with no arguments Medium
- 9 Verify command does not check that the initData calls the constructor Medium
- 10 Verify command does not check that the transaction succeeded Medium
- 11 No minimal version is enforced for --cargo-stylus-version Informational
- 12 Parameterized traits with associated types are unsupported Informational
- 13 Unused CLI parameter --project for trace subcommand Informational
- 14 Malicious code execution during ABI export through malicious build.rs Low
- 15 cargo-stylus generates incomplete ABI Low
- 16 Inconsistent use of unsafe in stylus-sdk/src/storage/vec.rs Informational
- 17 console! macro panics when stylus-test feature is enabled Low
- 18 PhantomData causes a division by zero when used with StorageArray and StorageVec Low
- 19 StylusDeployer’s deploy function does not include msg.sender or initValue when computing the salt for create2 Low
- 20 cargo stylus replay is unusable when the contract uses the console! macro Low
- 21 Incorrect data location for constructor’s arguments Informational
- 22 Parsing of public function does not get fallback function’s argument Informational
- 23 Complex structs cannot be used inside function parameters due to string length constraints Informational
- 24 Solidity named mapping breaks the parsing of sol_storage! macro Low
- 25 sol_interface! does not allow the interface defined to be used as key in a storage mapping Low
- 26 sol_interface! macro does not support Solidity function overloading Low
- 27 AbiType macro allows struct to have Solidity primitive type name Low
- 28 underscore_if_sol function contains multiple issues Low
- 29 Selector override macro allows a function to have the same selector as the constructor Low
- 30 Purity::infer allows to non-Self reference type Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related
- 2026-08 Offchain Labs Arbitrum Chains Genesis File Generator Audit
- 2026-08 Offchain Labs Tip Collection Toggler Audit
- 2026-08 Offchain Labs Yield-Bearing Bridge Audit
- 2026-07 Offchain Labs 3.2.0 Upgrade Action Contract Audit
- 2026-07 Offchain Labs Sequencer Feed Ticketing Audit
- 2026-07 Offchain Labs Arbitrum ArbOS 60/61 Audit