Review · Flare C-Chain · 1 October 2026, 17:20 London

myXRP Flare Bridge Security Review Report

This letter is paper against live bytecode. The desk read the Flare bridge the way a stranger would: lock official FXRP, hold a receipt named myXRP, burn that receipt, and walk the public desk at myxrp.fi. The question was whether the machine can mint a silent balance, retarget the FXRP pipe, or let an admin pull cash the receipt still claims. After the review, the answer is no.

myXRP at this address is a sealed 1:1 receipt. It is not native XRP, not a rebasing share, and not affiliated with Ripple. name() is myXRP. There is no operator key on the contract. Residual risk is that withdraw can pay only the FXRP the contract still holds — not an open finding.

Scope

Out of scope: cabinet snapshot credits, holder key custody, FAssets agent economics. Those do not change the 1:1 math this letter signs. Constructor arguments are (fxrp, maxAssets) only.

How the paper reads the machine

Balances are stored. There is no index. Deposit pulls FXRP and mints the same amount, or reverts CapExceeded when the mint would pass maxAssets. Withdraw burns the same amount and pushes FXRP, or reverts InsufficientLiquidity when the contract’s FXRP balance is short. It does not write a bad balance. A failed outbound transfer reverts TransferFailed and the burn rolls back.

The lock this paper signs is maxAssets(), 10,000,000.000000 FXRP, read on 1 October 2026, 17:20 London. It is the constructor argument of this deployment.

There is no owner, no admin sweep, no accrual, no supply setter, and no pause. There is no proxy, no delegatecall, no selfdestruct, no leftover initialize, no tx.origin auth, no fee-on-transfer, and no second minter. deposit and withdraw are nonReentrant.

The only outbound path pays one FXRP per one myXRP burned. If the contract’s FXRP balance is short, withdraw reverts before the burn is kept.

Public desk

The desk walked myxrp.fi as a stranger: connect, read the panel, open explorer-verify, fetch token.json. The UI binds this bridge. The official name is on the page. The room line is room(), in myXRP, on this contract.

Weaknesses

Total findings 2 · informational 2 · critical / high / medium / low 0. Both notes are closed. Nothing in this letter requires a code change before use.

RH-N1 · no upgrade slot on this runtime

Severity: Informational · Status: Closed · Path: runtime dispatch

The paper looked for a proxy, delegatecall, initialize, and selfdestruct. None are in this runtime. The source file was published on the Flare explorer at 23:11 London on 30 September 2026, and that file is what a reader diffs. No patch.

RH-N2 · a failed push does not keep the burn

Severity: Informational · Status: Closed · Path: MyXRPBridge.withdraw

withdraw checks the FXRP balance, burns, then transfers. TransferFailed reverts the transaction, so the receipt is not burned on a failed push. No patch. The order is the control.

Verdict

The review is closed. This letter reads the bytecode of 17:20 London on 1 October 2026. The source file on the Flare explorer was published at 23:11 London on 30 September 2026. Write [email protected] if you need a copy of this letter on paper.

← Back to Audit