Audit Portal

// report details

Trustless Work

smart-escrow-platform

1

Scheduled

2

In Progress

Completed

// Executive Summary

Trustless Work engaged Runtime Verification, Inc. to audit its smart contracts between August 5th and September 12th, 2025. The audit assessed security, correctness, and potential vulnerabilities, providing recommendations to enhance reliability.

Trustless Work enables trustless payments via smart contract escrows, securing funds until clients approve milestones. Stablecoins like USDC are commonly used, but any token can serve as the escrow’s trustline. Escrows act as vaults controlled by smart contract logic and user roles with defined responsibilities.

The audit involved comprehensive manual code review and formal verification, including invariant analysis and testing across state transitions. A limited three week review of the TypeScript backend identified recurring architectural and security issues, suggesting potential additional vulnerabilities.

Findings ranged from critical to informative, with recommendations to address all issues, perform further internal review, and conduct a follow-up audit of the backend and remediated components before securing significant value.

// Metadata

Date Completed2025-09-12
Type of EngagementCode Review Audit
Codebase LinkGitHub

// Findings Summary

Critical/High
19
Medium
4
Low/Informative
29

// Reports

Trustless Work.pdf
download PDF