ton-bug-triage
Audited by Socket on Mar 18, 2026
1 alert found:
SecurityThis document is an explicit developer blueprint for injecting protocol-level mutations (withholding, malformed packets, reordering, delays, invalid artifacts) in validator/node code, gated by environment variables and with provisions for self-immunity. While legitimate for controlled testing or chaos experiments, the guidance enables high-impact sabotage if applied in production or by an attacker who can set environment variables or modify code. The file is dangerous as a recipe for supply-chain or insider attacks against consensus networks and should be treated with caution; if present in a codebase it requires strict controls (access, review, CI safeguards, and runtime env var protections) and should not be shipped to production environments without removal or additional hardening.