Skip to main content
Skip to main content
Polkadot logo

The Polkadot Claims Audit

Web3 Foundation engaged Chain Security for an audit of the Polkadot Claims smart contract. The audit found 0 Critical, 0 High, 2 Medium and 9 Low level issues, all of which have been resolved in the latest commits to the code.

By PolkadotAugust 7, 2019

Web3 Foundation engaged Chain Security for an audit of the Polkadot Claims smart contract. The audit found 0 Critical, 0 High, 2 Medium and 9 Low level issues, all of which have been resolved in the latest commits to the code.

The Polkadot Claims contract is an Ethereum smart contract that allows holders of the DOT allocation indicator token to claim their balances of DOTs to a Polkadot public key ahead of Polkadot genesis.

In order to launch Polkadot in a transparent and decentralized way, an Ethereum smart contract was required to hold data necessary to the genesis of Polkadot including the Polkadot public key to associate to a specific allocation, the index of the public key, and the vested status of the allocation.

Submission of this data to the Ethereum blockchain enables the community to generate and verify the genesis chain specification themselves in an independent manner. It is an integral piece to the launch of Polkadot in a transparent way.

For this reason, the security of the contract was of the utmost importance, especially regarding the certain immutability of the state of the contract after claiming actions have taken place.

To guarantee that the Claims contract is secure and functionally correct, ChainSecurity formally verified the contract's code with respect to its intended specification. In more detail, ChainSecurity formalized 12 critical functional requirements and verified them using their state-of-the-art tool for formal verification. Examples of the properties that were verified include the immutability of the state after the initialization, access-control requirements, and safety of the contract set-up period.

In addition to the formal verification, the full audit report details each of the issues that were found in the categories of Security Issues, Trust Issues, and Design Issues. It also describes the fixes that were applied to each and reasoning of the Web3 Foundation.

You can find the full audit report here.

From the blog

What Does Web3 Music Success Actually Look Like?

The Decentralized Mic brought together builders and investors actively shaping the future of Web3 music to discuss what's working, what's broken, and where the industry is headed next.

How the Polkadot community enabled our multi-chain breakthrough

From treasury proposal to multi-chain reality: How Polkadot's governance and community support enabled Bifrost's breakthrough in bringing liquid staking across major DeFi networks.

Building to stay, not just for hype

How Peer3’s journey from the Polkadot Blockchain Academy shaped its vision for the future.

DeFi Builders Program: Scaling the future of DeFi on Polkadot

The DeFi Builders Program on Polkadot helps developers tackle the biggest challenges in DeFi, including liquidity, security, and adoption. It combines funding, technical support, and scalable infrastructure to launch stronger, safer applications.

How to stake DOT on Polkadot (without breaking a sweat)

A step-by-step guide to staking DOT on Polkadot. Learn how to stake from your wallet or with the Polkadot Staking Dashboard—and start earning rewards securely.

Your HOA sucks. Maybe it needs a DAO.

Endless meetings. Hidden decisions. Petty drama. What if your HOA (or PTA, or book club) ran onchain instead? DAOs bring transparency, accountability, and real participation to everyday groups.

6 takeaways from Gavin Wood’s Web3 Summit 2025 keynote

From JAM to proof of personhood to Web3 outposts, Gavin Wood’s keynote offers a clear vision for the future of Polkadot—and Web3 more broadly.

DePIN 101: How Polkadot powers the future of decentralized infrastructure

Discover the basics of DePIN, real-world use cases, and why Polkadot’s ecosystem is leading the way in decentralized infrastructure.

DeFAI: Could AI agents be the missing piece for DeFi adoption?

AI agents could make DeFi feel intuitive instead of overwhelming. Built on Polkadot, DeFAI aims to simplify participation and expand access for all users.

Web3 promised a music industry revolution—it hasn't delivered (yet)

Web3 promised to revolutionize music. So far, it hasn’t. This blog breaks down why most projects fall short, and what it’ll take to build tools that actually work.

Inside JAM: Daniel Cukier on implementing Polkadot’s next big upgrade

As a core implementer of the JAM upgrade, Daniel Cukier brings both technical expertise and artistic sensibility to Polkadot’s next chapter. In an interview with Abigail Carlson, he shares how JAM is reshaping blockchain infrastructure, and why appealing to developers might be the key to adoption.

Stablecoins: The $30 trillion market building tomorrow’s financial rails

Stablecoins are moving more money than Visa and Mastercard, but still make up just 1 percent of the global monetary supply. Here’s what needs to change.