Audit Open Original ↗
The Quantum Resistant Ledger go-qrllib Library
Type
Security review
Client
The Quantum Resistant Ledger (QRL)
Date
2026-07
Domain
Blockchain
Effort
3.2 wks
Section
Other/Multi-Chain
Trail of Bits's security review of The Quantum Resistant Ledger (QRL) (Jul 2026) identified 15 issues: 1 high, 4 low, and 10 informational.
Findings · 15
- 1 XMSS implementation is not fully compliant with RFC 8391 Low
- 2 XMSS InitializeTree accepts invalid typed Height values above MaxHeight Low
- 3 Modern wallet signatures do not bind descriptor metadata Informational
- 4 Wallet allows SPHINCS+ as valid signature scheme Informational
- 5 prf function hardcodes input length without validating the actual input length Informational
- 6 ML-DSA implementation uses deterministic signing Informational
- 7 SHAKE_128 is a non-compliant FIPS parameter with reduced quantum security Informational
- 8 Exported XMSSWallet API drops security-critical documentation Informational
- 9 C-to-Go translation can silently change semantics due to operator precedence differences Informational
- 10 ML-DSA secret-memory cleanup is inconsistent across functions Informational
- 11 ML-DSA Open and Verify panic on a nil public key Low
- 12 ML-DSA Seal naming implies confidentiality for a signature-only operation Informational
- 13 Invalid XMSS hash function values produce degenerate interchangeable keys and signatures High
- 14 ML-DSA Open API collapses distinct failure modes into a nil result Informational
- 15 Unpinned external GitHub CI/CD action versions Low
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related