Skip to content
AAAhtisham Ashraf
000

Project 05

Blockchain Platform Security Audit

Application, P2P & Infrastructure Assessment

Context
FundFantasy
Period
2017 — 2018
Categories
Application Security · Security Audit · Blockchain

Overview

A full security audit of a blockchain-based platform, covering the web application, the peer-to-peer communication layer, the codebase and the supporting infrastructure. The engagement produced findings and remediation guidance across all four areas.

Challenge

Blockchain platforms attract attention to their cryptographic design while the practical risk usually sits elsewhere — in the web application, the surrounding services and the infrastructure that hosts them. The audit had to cover the full surface rather than the interesting part of it, and produce findings the engineering team could act on in priority order.

Role

Security auditor — application assessment, code review, peer-to-peer layer analysis and infrastructure hardening guidance.

Architecture

  1. 01

    Web Application

    Assessment of the application surface, authentication and authorisation behaviour.

  2. 02

    Peer-to-Peer Layer

    Analysis of the communication layer and its trust assumptions.

  3. 03

    Codebase

    Secure code review across the application for insecure patterns and design weaknesses.

  4. 04

    Infrastructure

    Review of hosting configuration and encrypted communications, with hardening guidance.

Conceptual only. No real topology, configuration or internal architecture is described.

Solution

  • Structured audit across application, protocol, code and infrastructure layers.
  • Findings prioritised by severity with remediation guidance.
  • Infrastructure hardening and encrypted communication recommendations.

Security

  • This entry describes the engagement only. No vulnerability details, reproduction steps, payloads or exploit information are published.

Outcome

  • More than 40 critical vulnerabilities identified during the engagement.
  • Remediation guidance delivered across application, protocol and infrastructure layers.

40+

Critical vulnerabilities identified

Lessons

  • The novel technology is rarely where the platform breaks — the ordinary web surface around it usually is.
  • A finding is only useful if the team can act on it; severity without remediation guidance is noise.