Blog

Trust Machines – Multisafe

Trust Machines have requested that Least Authority perform a security audit of the Multisafe, a shared multi-signature crypto wallet for managing Stacks (STX) and Bitcoin (BTC). To read the full report including our findings, click here: Report

Read More »

Human-centered design at Least Authority

Human-centered design is one of the key approaches Least Authority adopts alongside security- and privacy-by-design. Our human-centered design process involves building an understanding of user needs and experiences, while using those learnings to shape design and development goals and iterations. The case studies below provide examples of this approach. The

Read More »

Dark Crystal social backup using Magic Wormhole

The following document is an extract from Magic Crystal, which describes how to leverage social secret sharing with Dark Crystal using Magic Wormhole for identity-less transport without using any Public Key Infrastructure. The document also includes a protocol design for developers wanting to integrate this feature into their application. It

Read More »

Blox Staking – Wallet 2nd Review

Least Authority performed research, investigation, and review of the Blox Staking Wallet followed by issue reporting, along with mitigation and remediation instructions as outlined in this report. For this review, the scope of the audit was limited to the staking features of the Blox wallet implemented since our last review.

Read More »

MetaMask Extension – Seed Phrase Implementation

Our team performed a security audit of the MetaMask extension’s seed phrase implementation. In particular, the focus of our investigation was a potential error in the seed phrase implementation, in response to MetaMask user claims that the same seed phrase can generate different account lists. According to the MetaMask team,

Read More »

Endaoment – v2 Smart Contracts

Endaoment has requested that Least Authority perform a security audit of their v2 Smart Contracts. Our final audit report was completed on July 20th, 2022. To read the full report, including our findings, click here: Report

Read More »
Archives