docs(security): document and test threat model for Freighter and Ledger flows (#841) - #1101
Merged
Manuelshub merged 1 commit intoSep 28, 2026
Conversation
…er flows Document comprehensive threat models and attack matrices for Freighter browser extension and Ledger hardware wallet flows covering wallet spoofing, phishing, and malicious dApp scenarios. Implement defensive public key and BIP-44 derivation path validations, expand E2E wallet fixtures with deterministic threat simulation hooks, and add unit and integration test suites for primary, boundary, and failure paths.
|
@CathyZaks Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
|
@CathyZaks is attempting to deploy a commit to the nanle-code's projects Team on Vercel. A member of the Team first needs to authorize it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Header
security docs and e2e wallet fixturesfix/issue-841-threat-model-freighter-ledgerProblem
The dashboard previously lacked formal threat model matrices and end-to-end fixture coverage for browser extension (
Freighter) and hardware wallet (Ledger) flows. Crucial attack vectors—such as wallet provider spoofing, DOM API tampering, derivation path manipulation, deceptive phishing memos/origins, and cross-network signature replays—were not documented or systematically guarded against across input sanitization, unsupported runtime detection, and failure recovery.Solution
Freighter Threat Model MatrixandLedger Hardware Wallet Threat Model MatrixinSECURITY.mdcovering wallet spoofing, phishing, malicious dApps, and failure states.docs/security/wallet-threat-model.mddetailing trust boundaries, invalid input handling, unsupported browser behavior (WebUSB/WebHID in Chromium vs Firefox/Safari), and failure recovery.src/lib/wallet/freighter.tsto defensively validate provider public keys viaStrKey.isValidEd25519PublicKeyand reject empty or invalid XDR inputs.src/lib/wallet/ledger.tsto enforce BIP-44 Stellar derivation paths (^44'/148'/\d+'?$) and validate public keys returned by devices.validateWalletPublicKey,validateDerivationPath, andevaluateWalletThreatModelinsrc/lib/wallet/security.ts.tests/e2e/fixtures/freighter-mock.jswith simulation hooks for wallet spoofing (simulateSpoofedPublicKey), network mismatches (simulateNetworkMismatch), hostile DOM providers (simulateHostileProvider), and unsupported environments (simulateUnsupportedEnvironment).tests/e2e/fixtures/ledger-mock.jssupporting WebUSB device simulation, PIN locks (0x6b0c), app-closed state (0x6d00), user rejection (0x6985), and firmware vulnerability checks.tests/unit/lib/wallet/walletSecurityThreatModel.test.tscovering primary, boundary, and failure cases for all threat vectors.tests/unit/lib/wallet/freighter.test.jsandsrc/lib/wallet/__tests__/ledger.test.ts.tests/e2e/freighter.spec.js.Changes
SECURITY.md: Added Freighter and Ledger threat model matrices and referenced detailed architecture docs.docs/security/wallet-threat-model.md: Detailed threat model documentation, attack matrices, runtime compatibility, failure paths, and developer integration guidance.src/lib/wallet/freighter.ts: Validates public keys against StrKey specifications and sanitizes XDR input parameters.src/lib/wallet/ledger.ts: Enforces BIP-44 Stellar specification on derivation paths and validates returned device public keys.src/lib/wallet/security.ts: ImplementedvalidateWalletPublicKey,validateDerivationPath, andevaluateWalletThreatModel.tests/e2e/fixtures/freighter-mock.js: Added threat simulation controls for spoofed keys, hostile providers, network mismatches, and environment degradation.tests/e2e/fixtures/ledger-mock.js: Created mock fixture for browser-level Ledger hardware wallet testing.tests/e2e/freighter.spec.js: Added E2E tests for wallet spoofing rejection, network mismatch boundary case, and unsupported environment handling.tests/unit/lib/wallet/freighter.test.js: Added unit tests for connection, signing, spoofed public key rejection, user rejection, and locked state.src/lib/wallet/__tests__/ledger.test.ts: Added tests for high BIP-44 account index boundaries, derivation path manipulation, device lock (0x6b0c), app closed (0x6d00), and rejection (0x6985).tests/unit/lib/wallet/walletSecurityThreatModel.test.ts: Added unit test suite verifying primary, boundary, and failure cases across spoofing, phishing, and replay vectors.Testing
npx vitest run tests/unit/lib/wallet/freighter.test.js src/lib/wallet/__tests__/ledger.test.ts tests/unit/lib/wallet/walletSecurityThreatModel.test.ts44'/148'/255', network normalization, account change events).npx eslintpassed on all touched files with 0 errors and 0 warnings.npx prettier --checkpassed on all touched files.Unrelated Findings for Follow-up
e9c77037) introduced syntax errors insrc/components/dashboard/Contracts.tsxandsrc/lib/tests/contractInvoker.test.ts.ee0d2f3aintroduced duplicate exports ofLogLevelinsrc/utils/logger.ts.9a32317b) upgraded@stellar/stellar-sdkto^17.1.0inpackage.jsonwithout updatingpnpm-lock.yaml.Closes #841