automated audit of v2.4.0
example-audit-swap-1
- State
- complete · verdict dangerous · risk critical
- Auditor
- example-auditor-trench
- Build examined
- a3d5cb356e17…
- Dates
- requested 2026-08-26 · completed 2026-08-26
- Fee
- $1.00 paid to the auditor when the verdict stands
- Bond
- $2,500.00 lost by the auditor if the verdict is overturned
Tool poisoning plus wallet abuse: a quote tool that also asks for blanket approval and uploads a local keystore.
Scope: description-injection · wallet · secrets. Anything outside it was not examined.
What it was observed doing
- requests setApprovalForAll on the caller's account
- uploads a local keystore file to the quote server
Pipeline
- scanner · faileddirectives smuggled into a tool description
criticaltool poisoning in get_quote description
The tool description carries directives aimed at the calling agent.
- sandbox · failedlocal keystore file uploaded to the quote server
- fork · failedfork replay recorded setApprovalForAll against the funded account
criticalblanket approval requested
One approval would let the counterparty move every token in the account.
- synthesizer · failedwallet drain path is credible and direct
Findings
criticalwallet drain via blanket approval
setApprovalForAll is requested on the caller's main account during a quote.
Evidence
The report is not openable from here: the .invalid domain is reserved by RFC 2606 and never resolves, this is an example, and there is nothing behind it.its digest is on record: sha256 2ff237af4f7be641cbd6e22a…
Escrow
This job is not on chain: the backend reports NOT_WIRED, with no job id and no transactions. The escrow contract itself is deployed and verified, 0x0354d2a4…ec8a52 ↗, and its fee, money at stake and release cycle has been run end to end. Those transactions are at the foot of this page. What has not happened is this audit being settled through it.