Reth
June 2026
NFT Bounty assessed Reth as an Ethereum execution client, focusing on transaction decoding, state-transition correctness, trie and state-provider behavior, and malformed input handling. The case study shows the kind of protocol audit work needed where implementation divergence can become consensus risk.
Engagement snapshot
NFT Bounty assessed Reth across transaction decoding, state-transition correctness, and protocol boundary behavior. The review produced a broad findings set, among them high/severe items and extensive lower-severity hardening opportunities consistent with client maturity work. The report tightens client safety through stricter validation, deterministic behavior, and shrunk divergence risk under malformed or adversarial inputs.
By the numbers
Total findings
51
High + high-severity findings
10
Scope we covered
-
Transaction and payload processing
RLP decoding and execution-path correctness under malformed and edge-case inputs.
-
State and trie operations
State-provider and trie/log behavior affecting consensus-relevant correctness.
-
Protocol conformance
Execution semantics and assumptions across high-severity client pathways.
Related services
Looking for a security audit?
Book a scoping talk