Sixty findings, none critical, in Miden
An OpenZeppelin review of the Miden contract library reports no critical or high issues and eleven medium ones, most of them about authorisation.
3 minSmart Contract Audits
OpenZeppelin has published its review of the Miden smart contract library, written in Rust and MASM and audited between 18 May and 30 June 2026. The headline count is sixty issues, of which fifty were resolved and four partially resolved.
- Critical — none raised.
- High — none raised.
- Medium — 11 raised, 7 resolved and 2 partially resolved.
- Low — 17 raised, 14 resolved and 2 partially resolved.
- Notes and additional information — 32 raised, 29 resolved.
No critical or high findings in a library of this size is the result the client wanted, and it is worth stating plainly. What is more informative is the shape of what was found: the medium band is dominated by authorisation and access control rather than arithmetic or memory safety.
Among them are transfer policies registered as reserved that can never be activated, ownership transfers and role assignments permanently restricted to version-one account identifiers, and authority-gated setters that turn out to be permissionless in one pairing of components. Another finding reports that account authentication does not bound the transaction fee that gets deducted, and one describes repeated unauthorised consumption of input notes draining an account through fees alone.
Two findings concern what a signature actually commits to — a signed transaction summary that binds neither expiration nor reference block, and foreign procedure invocation reading state from a prover-chosen reference block rather than the current one. Those are the class of issue that looks academic in a report and becomes an incident when someone builds a bridge on top.
Zero client-reported issues were logged, meaning the findings came from the review rather than from problems already known to the team.
Retold from OpenZeppelin. This is a summary in our own words; follow the link for the original reporting.