Hey everyone. I’m considering a ZCG application to do an independent security and architecture review of red·bridge (the Zcash-Avalanche bridge), focused on the current design docs: guardian-controlled custody via FROST threshold signatures, RBR staking for validator participation, and the ZEC.rbr wrapped-asset contract. A few things I’d like to nail down before I write the full application:
Is an independent review at this stage, architecture is public, contracts aren’t written yet, something the red·bridge team or this community would actually find valuable? I’d rather find out now than assume.
red·bridge’s earlier updates mention a threat-model review by Least Authority, but that was scoped to the ZavaX Oracle component specifically, back in Dec 2024. Does that also cover the current v1.1.0 architecture doc, or would a review of the full bridge design be new ground?
The newly approved grant (issue #335, $477,658) covers launch deliverables, revenue operations, legal/Swiss Verein setup, go-to-market, and WebZjs/Snap maintenance. I don’t see a security review line item in that scope. Is one already planned separately, through ZCG or the Avalanche Foundation side?
@mrkit2u if you’re around: is there someone on the red·bridge side I should talk to directly before I submit, so the application reflects an actual conversation instead of a guess?
@ZcashGrants which category fits best for review work like this? I don’t see a dedicated Security category in the application dropdown, Research & Development looked closest, curious if that’s right or if Offensive Security (issue #340) landed somewhere else.
Appreciate any pointers. Also happy to hear if the scope should be narrower, just the custody/guardian design, or wider, including the WebZjs/Snap fork too.
Regarding the category: Infrastructure is a fine choice if you apply immediately. We’ll get a security category added shortly so look for that if you wait a few days to apply.
Following up on the red·bridge review question above, I know this is a busy week with Ironwood. One narrow question to make it easy: is an independent design/threat-model review of the current bridge architecture something the team would want before contracts are written, or is that already covered by your existing process? A one-line yes/no is all I need to decide whether to write the full application. Thanks. @mrkit2u
Hi and apologies for the slow reply to this thread; I’ve been away from the forum for two weeks.
red·bridge has already received significant grant money allocations from Avalanche Foundation to partially fund audits from highly regarded auditing firms, and we have been planning on requesting any additional funds needed to pay auditors ourselves from ZCG when the time comes.
Our roadmap includes two audits for the bridging feature, one from ZCGs Security Lead, Least Authority, and one from another well-regarded team. It also includes creation and review of a threat model for the bridging feature.
We plan on launching the L1 with just the oracle feature prior to these audits since the oracle use case is lower risk. However, the later audits will also include the oracle feature.
red·bridge is a community project, and as such, we welcome community members’ interest and contributions. What we are explicitlynotlooking for at this time are AI-generated security and architecture reviews, as we are capable of performing these ourselves. Just this past week, we have had a bad experience with an “auditor” which I’m 99% sure was entirely AI that wasted a few days of our team’s time, exaggerating issues, proposing unworkable solutions, etc.
We recognize the emerging role of AI in helping accelerate and enhance the work of highly-trained humans; however, in the hands of a human without expertise, AI can produce audit work-product that appears to be confident, correct, and even concerning to the average person, yet, in fact, is not correct.
Thanks Kit, that’s exactly the clarity I was after, and no worries on timing. Sounds like audits and the threat model are well in hand between Least Authority, the second firm, and your own team, so there’s no gap here for me to fill. That’s the answer I wanted before writing anything, so I’ll leave the security review side to your planned process.
And understood on the AI point. That’s a fair line to draw, and sorry you lost time to it. For what it’s worth I do manual audit work - soloking - Sherlock , but you don’t need to take that on faith and you don’t need another reviewer, so I’ll leave it there. Wishing the L1 launch and the Ironwood week go smoothly. I’ll be following red·bridge’s progress.