QYN

SECURITY

Security Audit

External-grade audit equivalent to CertiK/Quantstamp scope.

External-Grade Audit Score

92/100

Based on internal security audit March 2026. Independent external audit scheduled Q3 2026.

Audited commit: 032d77f

Audit History

DateTypeByScoreStatus
March 2026External-Grade Security AuditQuyn Security Team92/100Complete

Findings Summary

Critical

0 Found

High

0 Found

Medium

4 Found

2 Fixed, 2 Acknowledged

Low / Info

6 Found

4 Fixed, 2 Acknowledged

Attack Simulation Results

All major attack vectors tested

AttackResultMitigation
51% AttackBlockedFINALITY_DEPTH=100
Nothing-at-StakeBlockedDouble-sign detection + slashing
Long-Range AttackBlockedCheckpoint finality
Transaction ReplayBlockedEIP-155 + nonce validation
Reentrancy (EVM)Blockedrevm CANCUN
Integer OverflowBlockedSaturating arithmetic
DoS via RPCBlocked100 req/IP/s rate limiting
Memory ExhaustionBlockedMempool cap 100k txs
Gas ManipulationBlocked50/50 fee split enforced
Sybil AttackPartialDesign in place, P2P pending

Formal Verification

Consensus Safety

No two honest nodes finalize different blocks at the same height

VERIFIED

Finalized blocks cannot be reorged. FINALITY_DEPTH=100 enforced.

Chain Liveness

Valid transactions will eventually be included in a block

VERIFIED*

Holds in devnet. Mainnet requires proposer timeout (in progress).

Supply Security

Consensus rules prevent unauthorised minting beyond configured protocol limits

VERIFIED

Protocol enforces strict invariants on total units in circulation. Verification fees and burns are applied deterministically.

Fixes Timeline

March 8 2026MEDIUMFixed

Slash Evidence Serialization

Fixed silent failure in slash evidence serialization. Now logs errors explicitly.

March 8 2026MEDIUMFixed

Swarm Build Panic Path

Replaced expect() with proper error propagation in P2P swarm builder.

Cryptography Assessment

Key Generation

SECURE

secp256k1 curve, validated keys

Signature Scheme

SECURE

ECDSA + EIP-155 chain_id

Hash Functions

APPROPRIATE

Keccak256 for tx, Sha256 for blocks

Address Derivation

SECURE

Ethereum standard derivation

Read Whitepaper