Highlights
Race Condition: 4 prior fixes. Scrutinize any change in this area.
lib/swap/SwapManager.ts: most-fixed (2 issues). Treat as high-risk during review.
7 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Authentication Bypass: The rescue endpoint lacked signature verification, allowing unauthorized swap restoration. The fix added signature verification with a timestamp window, but similar endpoints may still lack such checks.
Auth Bypass: Multiple gRPC methods were callable without authentication, exposing privileged operations. JWT authentication was added, but other RPC surfaces (e.g., REST, CLI) may still lack equivalent protection.
Auth Bypass: Commitment claims could be made by unauthorized parties because the claim address was not validated against the signer. The fix adds that check, but similar signature validation may be missing in other claim paths.