Blog

MetaMask Extension – Seed Phrase Implementation

Our team performed a security audit of the MetaMask extension’s seed phrase implementation. In particular, the focus of our investigation was a potential error in the seed phrase implementation, in response to MetaMask user claims that the same seed phrase can generate different account lists. According to the MetaMask team,

Read More »

Endaoment – v2 Smart Contracts

Endaoment has requested that Least Authority perform a security audit of their v2 Smart Contracts. Our final audit report was completed on July 20th, 2022. To read the full report, including our findings, click here: Report

Read More »

DeGate – Smart Contracts

The DeGate Order Book system is an ERC-20 token exchange platform, which forks from Loopring V3 that uses ZK Rollups to significantly increase transaction throughput and reduce transaction costs. For this audit, we reviewed audit the smart contracts component of the DeGate system. Our final audit report was completed on

Read More »

Manifest V2 to V3: Challenges and Security Considerations.

We want to alert the community that Manifest V2 extensions that are not already available in the Chrome Web Store will have to be reimplemented in the Manifest V3 extension platform in order to be published.  As of January 2022, the Chrome Web Store stopped accepting new Manifest V2 extensions

Read More »

Umee – Peggo Orchestrator

Umee has requested that Least Authority perform a security audit of the Peggo Orchestrator. To read the full report, including our findings, click here: Report

Read More »

Matrix – vodozemac

Matrix has requested that Least Authority perform a security audit of vodozemac, the Rust implementation of the libolm cryptographic library. libolm implements the Olm and Megolm ratchets, and is originally written in C/C++.

Read More »
Archives