Skip to content
This repository was archived by the owner on Sep 10, 2026. It is now read-only.

Security: Sconce-Labs/corridor-relayer

Security

SECURITY.md

Security

Reporting

Email the maintainers or open a private security advisory on the repo. Do not file a public issue for an exploitable vulnerability.

Threat model (relayer-specific)

The relayer is a trusted federated component in the current design. Its signing key can call corridor_registry.post_root for the corridors it is configured for.

  • Relayer key compromise — attacker posts an arbitrary root, admitting invalid credentials or censoring valid ones for that corridor. Keep RELAYER_SIGNER_SECRET in a secret store, scope the key to nothing else; corridor operators can set_paused instantly.
  • Relayer posts a stale/wrong root (bug) — epoch is strictly monotonic on-chain (a lower epoch is rejected). Run --once + verify externally before automating. The real fix is multi-relayer quorum — #2.
  • Indexer lies about the Midnight state — wrong root. Read from an indexer you trust; quorum across independent indexers (M5).
  • Alert webhook leaks corridor ids — low; corridor ids are public.

The end state removes the relayer's trust: quorum → fraud-proof window → Midnight↔Stellar light client. See corridor/ARCHITECTURE.md §6.

Never

  • Commit RELAYER_SIGNER_SECRET or any S… key.
  • Point the relayer at an untrusted indexer URL.

There aren't any published security advisories