Soroban Contract State Management
ID: fe83f7df-dfad-5160-8355-6dda9a568f5d
STIX ID: report--fe83f7df-dfad-5160-8355-6dda9a568f5d
Feed Name: CertiK Blog
This CertiK research analyzes Soroban (Stellar) smart contract storage and demonstrates three primary security risks: storing critical data in Temporary storage (leading to permanent data loss), relying on ledger TTL expiry as a security boundary (allowing anyone to extend TTL and keep stale nonces/signatures valid), and contract storage bloat attacks that exhaust per-entry limits and cause DoS. The report includes PoC contracts and commands, root-cause analysis, and practical mitigation guidance (use persistent/instance storage, enforce in-contract expirations, shard state across keys, and adopt proactive TTL-extension strategies).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
