Security auditing for the TON Foundation: A Collaborative Approach to Secure Ecosystem Development
SmartState is delighted to have collaborated with the TON Foundation, working together to optimize functional components of the TON protocol and successfully resolving unique security goals for the TON ecosystem projects. Our joint efforts have led to the development of an effective security audit methodology tailored specifically to address specific challenges facing the TON blockchain.
Unique Methodology for the TON protocol
As a one-of-a-kind protocol, TON requires innovative solutions that cater to its distinct security needs. SmartState’s comprehensive auditing approach for each crypto project on the TON protocol includes (but not limited to):
- Best code practices
- FA2 compliance (if applicable)
- Logical bugs and code logic issues
- Error handling issues
- Cryptographic errors
- Protocol and header parsing errors
- 8. Private data leaks
- Unchecked call return method
- Code with no effects
- Unused vars
- Use of deprecated functions
- Authorization issues
- Reentrancy
- Arithmetic overflows/underflows
- Hidden malicious code
- External contract referencing
- Short address/parameter attack
- Uninitialized storage pointers
- Floating points and precision
- Message rebounce
- The order of data import
- Consider the case where a message fails
- Cost refund
- Cell data and storage params
- Security of concurrent message calls and locks
- Access control is enforced properly
- Asynchronous messages do not create race condition
- Address formats handled correctly
- Gas accounting is correct
- Bounced messages are handled correctly
- The funds are reserved correctly
- Function specifiers are correct
- Logic is implemented properly
Collaborative Approach: Security benefits
We are delighted to join the TON ecosystem, and we are committed to ensuring the security of projects and developers alike. In an ever-evolving blockchain landscape where innovation often comes with new security challenges, SmartState’s goal is to create conditions that empower every project and developer to feel confident in protecting their work and data. Partnering with the TON Foundation not only reinforces SmartState’s commitment to the highest safety standards, but also provides an opportunity to make a meaningful contribution to the TON ecosystem.
We operate following recognized international standards such as ISO/IEC 27001 and NIST ones, which ensures strict control over all processes. SmartState’s methodology includes continuous audits, risk assessments and the implementation of innovative solutions tailored to the unique features of the TON blockchain platform. Our approach goes beyond meeting the highest security standards - we are constantly and proactively looking for new ways to improve security and to protect the entire ecosystem from current and future threats.
For developers, this means being assured that their projects can grow and develop in a secure environment which enables them to focus on innovation, knowing that their infrastructure and data are robustly protected.
Our shared goal is to create a trusted environment where every participant can safely develop and implement their solutions. We aim to build a future where security and innovation walk side by side, ensuring sustainable growth for all ecosystem participants.
Conclusion
Our collaboration with the TON Foundation marks an important milestone in our mission to safeguard the blockchain ecosystem community and raise the overall security level of the industry. By working together, we are committed to delivering cutting-edge auditing services that cater specifically to the unique needs of TON projects. Join us in this journey as we strive to create a secure and innovative environment for all participants in the TON ecosystem.