Tokenised bond platform on the European Blockchain Services Infrastructure (EBSI): an ERC-6909 bond registry and token, a custody-backed marketplace with a policy-driven wallet, and a Kernel-based ERC-7579 account-abstraction layer.
WebAuthn.verifySignature returns the raw P256 result when the attacker-controlled responseTypeLocation is uint256 max, skipping the userOpHash challenge check, so a captured passkey assertion can authorise any userOp and drain the account.
In WeightedValidator.validateUserOp the last signature does not revert on failure, yet _checkSigVote credits the chosen guardian's weight before the check, so an attacker can poison votes of guardians who never signed and reach the threshold.
_validateInterestActivationWindow enforces only the upper bound of the post-expiry window and never requires block.timestamp >= saleEnd, so interests can be activated into deals while the sale is still running.
BondRegistry._validateBurnAuthorization checks only the BURNER role, while forced transfers also require an enabled EntityRegistry account, so disabling an entity does not stop a BURNER holder from executing privileged burns.
On seller acceptance, resolveCounterOffer calls the liveness-only _validateEntityWalletEnabled instead of the full type check, so a buyer whose entity type was removed from the allowlist can still complete a trade.
Get a free 30-minute security assessment. We’ll review your codebase scope and flag the top 3 risk areas.
No commitment required · Typical audits start within 1–2 weeks