Email the maintainers or open a private security advisory on the repo. Do not file a public issue for an exploitable vulnerability.
The relayer is a trusted federated component in the current design. Its
signing key can call corridor_registry.post_root for the corridors it is
configured for.
- Relayer key compromise — attacker posts an arbitrary root, admitting
invalid credentials or censoring valid ones for that corridor. Keep
RELAYER_SIGNER_SECRETin a secret store, scope the key to nothing else; corridor operators canset_pausedinstantly. - Relayer posts a stale/wrong root (bug) —
epochis strictly monotonic on-chain (a lower epoch is rejected). Run--once+ verify externally before automating. The real fix is multi-relayer quorum — #2. - Indexer lies about the Midnight state — wrong root. Read from an indexer you trust; quorum across independent indexers (M5).
- Alert webhook leaks corridor ids — low; corridor ids are public.
The end state removes the relayer's trust: quorum → fraud-proof window →
Midnight↔Stellar light client. See corridor/ARCHITECTURE.md §6.
- Commit
RELAYER_SIGNER_SECRETor anyS…key. - Point the relayer at an untrusted indexer URL.