Reth

June 2026

NFT Bounty assessed Reth as an Ethereum execution client, focusing on transaction decoding, state-transition correctness, trie and state-provider behavior, and malformed input handling. The case study shows the kind of protocol audit work needed where implementation divergence can become consensus risk.

Engagement snapshot

NFT Bounty assessed Reth across transaction decoding, state-transition correctness, and protocol boundary behavior. The review produced a broad findings set, among them high/severe items and extensive lower-severity hardening opportunities consistent with client maturity work. The report tightens client safety through stricter validation, deterministic behavior, and shrunk divergence risk under malformed or adversarial inputs.

By the numbers

Total findings

51

High + high-severity findings

10

Scope we covered

  • Transaction and payload processing

    RLP decoding and execution-path correctness under malformed and edge-case inputs.

  • State and trie operations

    State-provider and trie/log behavior affecting consensus-relevant correctness.

  • Protocol conformance

    Execution semantics and assumptions across high-severity client pathways.

Related services

Looking for a security audit?

Book a scoping talk