Polkadot Security Reviews for Substrate, Parachains, XCM, and Bridges

Taran.Space has delivered 8 Polkadot ecosystem projects across Substrate and Polkadot SDK runtimes, parachain infrastructure, XCM configuration, pallet logic, light-client bridges, and developer tooling. The work spans DeFi pallets, identity primitives, cross-chain verification, Polkadot-Ethereum bridge security, and custom tooling for Polkadot and Substrate networks.

Polkadot
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
4000+
of something
2023-2025
Security Audit
In partnership with Oak

Snowbridge is a trustless bridge between Polkadot and Ethereum, using light-client verification instead of a trusted multisig or external validator set. Working as part of Oak Security’s team, we reviewed multiple releases, focusing on the boundaries between consensus assumptions, bridge logic, and Solidity/EVM execution.

Review scope included proof validation, replay resistance, finalized-state assumptions, and contract-side logic for accepting or rejecting cross-chain updates. The work combined cryptographic protocol review with production cross-chain infrastructure security.

Cross-Chain
Polkadot
EVM
Cryptography
Cross-Chain
Polkadot
EVM
Solidity
Rust
Cryptography
All reports
In partnership with Oak
4000+
of something
February 2025
Security Audit
In partnership with Oak

Hydration is a Polkadot DeFi protocol built around shared liquidity infrastructure. In the Oak Security engagement, we reviewed Hydration’s peg-drift stableswap and oracle components, focusing on AMM invariant safety, oracle integrity, and privileged-control risks.

The review covered Substrate-based DeFi logic where pricing, liquidity movement, and administrative controls interact. Scope included stableswap behavior, oracle-dependent assumptions, edge cases around peg drift, and failure modes that could affect liquidity accounting or market correctness.

Polkadot
DEX
Rust
Polkadot
Rust
DEX
DeFi
View Report
In partnership with Oak
4000+
of something
April, November-December 2024
Security Audit
In partnership with Oak Security

Mythical Games builds blockchain infrastructure for games, digital assets, and player-owned economies. Our Oak Security work covered Mythical’s Polkadot parachain runtime, XCM configuration, and Ethereum-account handling primitives.

The review focused on runtime and transaction-safety risks, including cross-chain configuration assumptions, account-handling behavior, and protocol logic that affects how assets and transactions move through a Substrate-based gaming chain.

Polkadot
Rust
Polkadot
Rust
Cross-Chain
Private engagement
In partnership with Oak Security
4000+
of something
February 2025
Security Audit
In partnership with Oak

KILT is a Polkadot ecosystem protocol for decentralized identity, credentials, and self-sovereign data. For the Oak Security audit, we reviewed KILT’s Substrate bonding-curve pallet, focusing on runtime logic and the correctness of the economic primitive behind the module.

The review covered accounting behavior, edge cases in bonding-curve operations, runtime-level safety, and failure modes that could lead to incorrect balances, exploitable state transitions, or operational lock-up risk.

Polkadot
Rust
Polkadot
Rust
View Report
In partnership with Oak
4000+
of something
June 2023
Security Audit
In partnership with Oak

Centauri connected the Cosmos and Polkadot ecosystems through IBC-style light-client bridging. Our Oak Security work covered Centauri’s verification logic, relayer assumptions, trust boundaries, and the security model behind moving messages and assets between Cosmos chains and DotSama networks.

A later review covered fixes for the Grandpa CosmWasm Light Client, extending the work into proof verification and finality-related bridge logic. The engagement focused on cross-chain correctness, light-client assumptions, and the failure modes that can appear when two different interoperability ecosystems meet.

Cross-Chain
Polkadot
Cosmos
Cross-Chain
Polkadot
Cosmos
Rust
Private engagement
In partnership with Oak
4000+
of something
January-February 2024
Security Audit
In partnership with Oak Security

Bifrost Finance is a Polkadot DeFi protocol focused on liquid staking and liquidity infrastructure. The Oak Security audit included our review of Bifrost’s Substrate lend-market, leverage-staking, and prices pallets.

The work covered leveraged-staking logic, pricing and oracle integration points, economic validation paths, and risks that could lead to fund loss, manipulation, denial of service, or incorrect protocol accounting.

Polkadot
DeFi
Rust
Polkadot
DeFi
Rust
View Report
In partnership with Oak Security
4000+
of something
October 2022
Protocol Design

Synternet, formerly Syntropy, builds infrastructure for real-time multichain data, decentralized data marketplaces, and access to indexed blockchain information. Its ecosystem centers on data-layer infrastructure for applications that need live cross-chain signals, monitoring, and execution-ready data.

Taran Space worked with the team on decentralized infrastructure research and prototyping, including designs built with Polkadot SDK, Polygon Edge, and ChainBridge. The engagement focused on protocol architecture, interoperability, and the reliability of systems that coordinate data and execution across decentralized networks.

EVM
Polkadot
Cross-Chain
Solidity
Polkadot
EVM
Cross-Chain
Rust
Private engagement
4000+
of something
2019-2020
Tooling

Polkadot CLI was a custom developer-tooling project for Parity Technologies, built to make interaction with the Polkadot mainnet and custom Substrate networks faster and more practical for engineering workflows. The toolset supported DevOps-style usage, network interaction, testing, and rapid prototyping around Polkadot infrastructure.

The work covered Rust-based command-line tooling for Substrate environments, including support for EVM-compatible workflows on custom networks. It combined protocol familiarity with practical developer experience, turning low-level chain operations into repeatable tools for day-to-day engineering.

Polkadot
Rust
EVM
Polkadot
Rust
EVM
View Source
No items found.

Contact

Whether you're gearing up for a thorough audit or are still in the planning stages of your project, we encourage you to get in touch. Our expertise extends to architecture and security consulting, catering to a diverse range of needs. Rest assured, all inquiries are attentively processed during business hours. You can expect a response within an hour; however, we appreciate your patience if it occasionally takes a few days.

Thank you for your inquiry! We've received your message and will respond soon.
Oops! Something went wrong while submitting the form.