Summary
100% of all REPORTED Findings have been addressed
- 1Not Applicable
- 3Risk Accepted
- 3Solved
- 7All Findings
- Critical2
- 2Solved
- High1
- 1N/A
- Medium2
- 2Risk A.
- Low1
- 1Risk A.
- Informational1
- 1Solved
Introduction#
Ripple engaged Halborn to conduct a security assessment on XRP Ledger (XRPL) feature amendments beginning on February 17, 2025 and ending on March 13, 2025, focusing on PR #5224
The feature introduces a Single Asset Tokenized Vault, a new on-chain primitive that allows for aggregating assets (XRP, IOU, or MPT) from one or more depositors and represents ownership through MPToken shares. The vault serves as a foundational building block for diverse purposes such as lending markets, aggregators, yield-bearing tokens, and asset management by decoupling the liquidity provision functionality from specific protocol logic. The implementation includes core functionality for vault creation, deposits, withdrawals, and clawback operations, with support for both public and private vaults through permissioned domains.
Assessment Summary#
The team at Halborn assigned a full-time security engineer to assess the security of the node. The security engineer is a blockchain and smart-contract security expert in advanced penetration testing, smart-contract hacking, and deep knowledge of multiple blockchain protocols.
The scope of this audit encompasses:
Single Asset Vault Ledger Entry Implementation
Core Vault Transaction Types (Create, Set, Delete, Deposit, Withdraw, Clawback)
Share Token Management and Access Controls
Asset Handling and Transfer Mechanisms
Vault State Management and Accounting
Test Approach and Methodology#
Halborn performed a combination of manual review of the code and automated security testing to balance efficiency, timeliness, practicality, and accuracy in regard to the scope of the Batch Transaction feature security assessment. The following phases and tools were used:
Research into the architecture and mechanics of the Single Asset Vault through review of the specification, including asset management, share tokenization, and vault ownership models.
Manual code review and walkthrough to identify potential vulnerabilities in vault operations, share calculations, and asset transfers.
Security control testing for vault access restrictions, private vault permissions, and non-transferable share enforcement.
Documentation analysis covering vault creation parameters, transaction flows, and security considerations.
Edge case testing for asset freezes, transfer fees, and maximum vault capacity limits.
Functional testing of transaction processing flows and error handling mechanisms.
Review of error handling and recovery mechanisms.
Risk Methodology#
4.1 EXPLOITABILITY
Attack Origin (AO):
Attack Cost (AC):
Attack Complexity (AX):
Metrics:
| EXPLOITABILITY METRIC () | METRIC VALUE | NUMERICAL VALUE |
|---|---|---|
| Attack Origin (AO) | Arbitrary (AO:A) | 1 |
| Specific (AO:S) | 0.2 | |
| Attack Cost (AC) | Low (AC:L) | 1 |
| Medium (AC:M) | 0.67 | |
| High (AC:H) | 0.33 | |
| Attack Complexity (AX) | Low (AX:L) | 1 |
| Medium (AX:M) | 0.67 | |
| High (AX:H) | 0.33 |
4.2 IMPACT
Confidentiality (C):
Integrity (I):
Availability (A):
Deposit (D):
Yield (Y):
Metrics:
| IMPACT METRIC () | METRIC VALUE | NUMERICAL VALUE |
|---|---|---|
| Confidentiality (C) | None (C:N) | 0 |
| Low (C:L) | 0.25 | |
| Medium (C:M) | 0.5 | |
| High (C:H) | 0.75 | |
| Critical (C:C) | 1 | |
| Integrity (I) | None (I:N) | 0 |
| Low (I:L) | 0.25 | |
| Medium (I:M) | 0.5 | |
| High (I:H) | 0.75 | |
| Critical (I:C) | 1 | |
| Availability (A) | None (A:N) | 0 |
| Low (A:L) | 0.25 | |
| Medium (A:M) | 0.5 | |
| High (A:H) | 0.75 | |
| Critical (A:C) | 1 | |
| Deposit (D) | None (D:N) | 0 |
| Low (D:L) | 0.25 | |
| Medium (D:M) | 0.5 | |
| High (D:H) | 0.75 | |
| Critical (D:C) | 1 | |
| Yield (Y) | None (Y:N) | 0 |
| Low (Y:L) | 0.25 | |
| Medium (Y:M) | 0.5 | |
| High (Y:H) | 0.75 | |
| Critical (Y:C) | 1 |
4.3 SEVERITY COEFFICIENT
Reversibility (R):
Scope (S):
Metrics:
| SEVERITY COEFFICIENT () | COEFFICIENT VALUE | NUMERICAL VALUE |
|---|---|---|
| Reversibility () | None (R:N) | 1 |
| Partial (R:P) | 0.5 | |
| Full (R:F) | 0.25 | |
| Scope () | Changed (S:C) | 1.25 |
| Unchanged (S:U) | 1 |
| Critical | High | Medium | Low | Informational |
| 9 - 10 | 7 - 8.9 | 4.5 - 6.9 | 2 - 4.4 | 0 - 1.9 |
Scope#
Assessment Summary & Findings Overview#
# | Title | Severity | Score | Status |
|---|---|---|---|---|
| Insufficient Amount Validation in Vault Operations | Critical | 10.0 | Solved03/12/2025 | |
| Vault Fails to Account for IOU Transfer Fees Leading to Negative User Balances | Critical | 10.0 | Solved04/01/2025 | |
| Unsafe Arithmetic Operations in Vault Asset Management | High | 7.5 | Not Applicable04/01/2025 | |
| Missing Validation Allows Creation of Private Vaults for XRP Native Asset | Medium | 5.0 | Risk Accepted04/01/2025 | |
| Missing Validation Allows Setting of Contradictory Vault Flags | Medium | 5.0 | Risk Accepted04/01/2025 | |
| Missing Non-Transferable Share Validation in Vault Withdrawals | Low | 2.5 | Risk Accepted04/01/2025 | |
| Avoid Unnecessary Processing Overhead via Early Authorization Check | Informational | 0.0 | Solved04/01/2025 |
Findings & Tech Details#
Description
Proof of Concept
Recommendation
Description
Proof of Concept
Recommendation
Description
Recommendation
Remediation Comment
Description
Proof of Concept
Recommendation
Remediation Comment
Description
Proof of Concept
Recommendation
Remediation Comment
Description
Recommendation
Remediation Comment
Description
Recommendation
Disclaimer#
Halborn strongly recommends conducting a follow-up assessment of the project either within six months or immediately following any material changes to the codebase, whichever comes first. This approach is crucial for maintaining the projectโs integrity and addressing potential vulnerabilities introduced by code modifications.
