Overview
IBC has undergone multiple independent security audits by blockchain security firms. The audits cover the protocol itself and its implementations in Go, Solidity, and Rust, along with the application modules and light clients built on top of them. Each report is an independent assessment of code quality, potential vulnerabilities, and architectural design. Reports are published in the repository they apply to: cosmos/ibc-go for the Go implementation, and cosmos/ibc-contracts for the Solidity and Solana implementations.Protocol
IBC v2
- Auditor: Sherlock
- Audit period: February to March 2025
- Report date: April 2025
- Pages: 74
- Audited commit:
79218a531e769bb5c29022d50ef017bd81e4bd9b - Final commit:
d316a8b6c3716bad1bc2b1e8a3f573a7144dfc2d
IBC v2 Protocol Audit Report
Complete security assessment of the IBC v2 protocol implementation (74 pages)
Go implementation
Audits of ibc-go, the Go implementation of IBC used by Cosmos SDK chains.ICS-20 Token Transfer v2
- Auditor: Atredis Partners
- Report date: September 2024
- Pages: 41
ICS-20 v2 Audit Report
Security assessment of ICS-20 v2 token transfer features (41 pages)
Channel Upgrades
- Auditor: Atredis Partners
- Testing period: January to February 2024
- Report date: March 2024
- Pages: 38
Channel Upgrades Audit Report
Assessment of IBC channel upgrade functionality (38 pages)
08-wasm Light Client
Two reviews are available for the WASM light client.Halborn security audit
- Auditor: Halborn
- Engagement period: February 2023
- Pages: 55
WASM Client Halborn Audit
Halborn security assessment of the WASM light client (55 pages)
Ethan Frey review
- Reviewer: Ethan Frey
- Type: Technical review
WASM Client Technical Review
Technical review of the WASM client implementation
Interchain Accounts (ICS-27)
- Auditor: Trail of Bits
- Report date: December 2021
- Pages: 42
Interchain Accounts Audit
Trail of Bits assessment of Interchain Accounts (42 pages)
Solidity and Ethereum light client
Audits of the Solidity contracts and the Ethereum light client in ibc-contracts.Solidity contracts and Ethereum light client
- Auditor: Zellic
- Review period: March 2025
- Report date: March 25, 2025
- Pages: 37
- Audited commit:
6bb8fcf6af5094487c85f12d9398c8401fd4a1b7
cw-ics08-wasm-eth CosmWasm client, and the SP1 programs. The engagement also reviewed the EurekaHandler contract in skip-mev/skip-go-evm-contracts.
Solidity and Ethereum Light Client Audit
Zellic assessment of the Solidity contracts and Ethereum light client (37 pages)
Solana implementation
Audits of the Solana programs in ibc-contracts.Solana programs
- Auditor: Zenith
- Audit period: February to March 2026
- Report date: April 2026
- Pages: 62
- Audited commit:
5560586d241a7e33f2359bdd0bed4403cee34ce5 - Mitigation review commit:
3b594aab7d17dcf5f1afe088a5ae8d95de695d7d
Solana Programs Audit
Zenith assessment of the IBC Solana programs (62 pages)
Key security areas
These audits collectively cover:Protocol security
- Core IBC protocol mechanics
- Handshake protocols and state machines
- Timeout and error handling
- Proof verification systems
Feature security
- Token transfer mechanisms, both lock-and-mint and mint-and-burn
- General message passing and cross-chain contract execution
- Cross-chain account control
- Light client implementations, including consensus, attestation, and ZK clients
- Channel upgrade procedures
Implementation security
- Memory safety and resource management
- Cryptographic operations
- State consistency guarantees
- Access control and permissions
Recommendations for developers
When building with IBC:- Review the audit reports that cover the features you are implementing
- Adopt the security practices the audits recommend
- Include security testing based on audit findings
- Monitor security advisories and updates for the implementation you depend on
- Follow responsible disclosure practices when reporting vulnerabilities
Continuous security
IBC maintainers sustain an ongoing commitment to security through:- Regular audits of new features and major releases
- Rapid response to security disclosures
- Transparent communication via security advisories
- Active collaboration with security researchers
- Continuous improvement based on audit findings