All Reports
Tokenised Bond Platform

Tokenised Bond Platform

2026-06-30
Download PDF
Critical0
High2
Medium14
Low40
Info15

About the Protocol

Tokenised bond platform on the European Blockchain Services Infrastructure (EBSI): an ERC-6909 bond registry and token, a custody-backed marketplace with a policy-driven wallet, and a Kernel-based ERC-7579 account-abstraction layer.

Findings (71)

H-01HighFixed

WebAuthn dummy-signature path bypasses challenge binding, enabling passkey assertion replay

WebAuthn.verifySignature returns the raw P256 result when the attacker-controlled responseTypeLocation is uint256 max, skipping the userOpHash challenge check, so a captured passkey assertion can authorise any userOp and drain the account.

H-02HighFixed

The WeightedValidator’s validateUserOp(...) votes can be inflated

In WeightedValidator.validateUserOp the last signature does not revert on failure, yet _checkSigVote credits the chosen guardian's weight before the check, so an attacker can poison votes of guardians who never signed and reach the threshold.

M-01MediumFixed

Missing lower bound in _validateInterestActivationWindow allows interests to be activated before saleEnd

_validateInterestActivationWindow enforces only the upper bound of the post-expiry window and never requires block.timestamp >= saleEnd, so interests can be activated into deals while the sale is still running.

M-02MediumFixed

BURNER caller lacks the EntityRegistry-enabled check that FORCE_TRANSFER enforces

BondRegistry._validateBurnAuthorization checks only the BURNER role, while forced transfers also require an enabled EntityRegistry account, so disabling an entity does not stop a BURNER holder from executing privileged burns.

M-03MediumFixed

resolveCounterOffer(...) checks buyer liveness but not entity-type allowlist membership on acceptance

On seller acceptance, resolveCounterOffer calls the liveness-only _validateEntityWalletEnabled instead of the full type check, so a buyer whose entity type was removed from the allowlist can still complete a trade.

Start here

Ready to secure your project?

Get a free 30-minute security assessment. We’ll review your codebase scope and flag the top 3 risk areas.

No commitment required · Typical audits start within 1–2 weeks