Audit Reports
Security is a top priority for the COTI network. Below you’ll find a list of independent security audits conducted on different components of the COTI ecosystem. Each report outlines the scope, focus areas, and includes a link to the full audit documentation.
These audits play a critical role in ensuring that the COTI protocol remains secure, reliable, and ready for real-world adoption.
You can find all published audit reports here:
PoD Inbox and Privacy Portal hardening (internal review)
In addition to the external reports above, the PoD Inbox (coti-pod-inbox-contracts) and PoD Privacy Portal stack received an internal security review with follow-up fixes. Integrators should treat the following as current behavior (also reflected in the PoD / Avalanche books):
Capped returndata
Execution failures store at most 256 bytes of returndata. getOutboxError returns (code, data) with those raw bytes for client-side decoding.
retryFailedRequest
Permissionless while error code is 1. Encode failure on retry reverts and preserves code 1 (does not flip to encode-failed).
One-way errorSelector
sendOneWayMessage rejects non-zero errorSelector—use two-way for error callbacks.
executed / response events
Mean the return leg was ingested, not that the app callback committed.
Fee gas price
On-chain budgets use bounded reference gas price (setGasPriceBounds), not unbounded tip manipulation.
Oracle cache
refreshCache() refreshes both inbox legs; configure with setInboxTokens (Uniswap oracles set legs from pairs at construction).
Portal deposits
Prefer refundFailedDeposit only after SystemFailed. Stuck Pending may be retryable execution failure or miner lag—diagnose before refunding. Keep deposits off until mother registration confirms.
See Async private operations, How do PoA fees work?, and Privacy Portal troubleshooting.
Last updated
Was this helpful?