1/4
@nullreturn_io completed a security audit of @launchnodes Canton KMS Driver.
The reviewed component connects a Canton participant node with Azure Key Vault, and GCP KMS, supporting signing, encryption, and key wrap/unwrap operations without private key export.
1/4
@nullreturn_io completed a security audit of @launchnodes Canton KMS Driver.
The reviewed component connects a Canton participant node with Azure Key Vault, and GCP KMS, supporting signing, encryption, and key wrap/unwrap operations without private key export.
4/4
For @CantonNetwork infrastructure, security is not only about the code path.
It is also about how keys are managed, how failures are handled, and how the component behaves under real production constraints.
NullReturn recently completed a private security review of a Canton KMS driver integration.
The report remains confidential and the client is undisclosed, but the work reflects where we are expanding: high-assurance infra, cryptographic boundaries, and key management systems.
This type of review goes beyond standard smart contract auditing.
It includes signing flows, KMS integration, API behavior, failure handling, deployment assumptions, and the trust boundary between protocol infrastructure and cloud key management.
We help teams secure systems where correctness and trust boundaries matter.
Working on Canton, KMS integrations, protocols, smart contracts, or applied cryptography?
We’re open to a conversation.
Using a crypto library does not automatically make a system cryptographically correct.
Most crypto bugs happen in the integration layer: what gets signed, how keys rotate, how signatures are encoded, and how KMS behavior maps to production.
Full post on LinkedIn⬇️:
NullReturn × 2xSwap Audit
1/4
Audit Release
The @nullreturn_io team has completed a full smart contract security audit for @2xswap — a liquidation-free 2x leveraged swap protocol built on Ethereum.
3/4
Why this matters
Protocols with leverage and pooled liquidity face unique attack surfaces:
• First-depositor & rounding attacks
• Oracle manipulation scenarios
• Pool insolvency under extreme conditions
• Gov & fee control risks
Audit outcome
📊 47 total findings
✅ 100% of Critical & High issues resolved
Thanks to the 2xSwap team for strong collaboration and a security-first approach.
📄 Read the full report: 👉 @2xswap
2xSwap has been independently audited by Null Return @nullreturn_io. 35+ security fixes applied. Every critical and high severity finding resolved before mainnet launch.
What this means for you:
• Your deposits are protected by battle-tested OpenZeppelin standards
• Price feeds are validated through Chainlink with built-in staleness checks
• The protocol can automatically pause itself if it detects abnormal conditions
• No admin keys exist. No one — including us — can touch your funds.
The contracts are fully immutable, open-source, and verified on Etherscan.
2xswap.gitbook.io/2xswap-doc…
At DZap, security is not an add-on. It is built into the core
Our smart contracts are audited by @BlockSecTeam, @nullreturn_io & @0xCommitAudits, helping ensure every swap and bridge interaction is reliable, safe, & seamless across chains.
Try it now at DZap.io
DeFi hacks have changed a lot in the last five years.
If you’re building today, you need to understand how attacks work now, and where they actually show up in code and tooling.
We’re hosting a livestream on modern DeFi attacks, including CPIMP attacks and GlassWorm.
More details and registration below 👇