| Safe Haskell | Safe-Inferred |
|---|---|
| Language | Haskell2010 |
Convex.ThreatModel.TokenForgery
Contents
Description
Threat model for detecting Token Forgery vulnerabilities.
A Token Forgery Attack exploits minting policies that are too permissive. If a minting policy allows tokens to be minted under weak conditions (e.g., just requiring any signature), an attacker can mint unauthorized tokens.
Vulnerability Pattern ==
A vulnerable minting policy might only check:
MintValidation -> {
// VULNERABLE: Anyone who signs can mint!
list.length(self.extra_signatories) > 0
}
This is trivially satisfied by ANY signed transaction, allowing anyone to forge tokens that should be restricted.
Consequences ==
- Validation token bypass: If a validator requires a "validation token" to prove authorization, attackers can mint their own tokens.
- Asset theft: Forged tokens can be used to satisfy validator checks, potentially draining funds.
- Protocol manipulation: In DeFi protocols, forged governance or utility tokens can manipulate voting, rewards, or access control.
Mitigation ==
A secure minting policy should:
- Require specific authorized signers (not just "any signature")
- Check that minting is authorized by a governance mechanism
- Verify minting is part of a valid protocol operation
- Use one-shot minting for unique tokens (NFTs, thread tokens)
tokenForgeryAttack tests if additional tokens can be minted using a minting
policy the transaction under test already exercises, reusing the same
redeemer. If the transaction still validates with the extra minted tokens,
that minting policy is too permissive. Use tokenForgeryAttackWith to test a
specific policy instead (e.g. one the transaction doesn't otherwise use).
Synopsis
- tokenForgeryAttack :: ThreatModel ()
- tokenForgeryAttackWith :: IsPlutusScriptInEra lang => ScriptData -> PlutusScript lang -> AssetName -> ThreatModel ()
Threat models
tokenForgeryAttack :: ThreatModel () Source #
Check for Token Forgery vulnerabilities against a minting policy the transaction under test already exercises.
For every Plutus minting policy the transaction mints a positive quantity under, resolved from its own witness set or a reference-script UTxO, this picks one such policy/asset pair and attempts to mint one additional unit of that asset under the same policy with the same redeemer the transaction already used. If the modified transaction still validates, the minting policy accepted more than it authorized.
Skips (via threatPrecondition) transactions that don't mint under any resolvable
Plutus policy. Use tokenForgeryAttackWith to test a specific policy instead,
e.g. one unrelated to anything the transaction does.
tokenForgeryAttackWith Source #
Arguments
| :: IsPlutusScriptInEra lang | |
| => ScriptData | Redeemer for the minting policy |
| -> PlutusScript lang | The minting policy to test |
| -> AssetName | The asset name to mint |
| -> ThreatModel () |
Check for Token Forgery vulnerabilities with a specific minting policy and redeemer, regardless of whether the transaction under test already uses it.
-- Test with MintValidation redeemer (Constr 0 []) tokenForgeryAttackWith (ScriptDataConstructor 0 []) mintingPolicy assetName -- Test with custom redeemer tokenForgeryAttackWith myRedeemer mintingPolicy assetName