Skip to content

fix(security): remove hardcoded third-party RPC API keys from public endpoints - #1

Open
mozluk wants to merge 1 commit into
QuipNetwork:mainfrom
mozluk:mozluk-patch-1
Open

mozluk wants to merge 1 commit into
QuipNetwork:mainfrom
mozluk:mozluk-patch-1

Conversation

@mozluk

@mozluk mozluk commented Oct 4, 2026

Copy link
Copy Markdown

Summary of Changes

Addresses audit finding HIGH-2 (CWE-798: Use of Hard-coded Credentials) by removing third-party RPC endpoints carrying embedded private API keys in constants/extraRpcs.js:

  1. Eliminated Key-Bearing Endpoints:

    • Ethereum (Chain 1): Removed rpcfast.com and chain49.com endpoints containing hardcoded credentials.
    • BNB Smart Chain (Chain 56): Removed rpcfast.com endpoint containing hardcoded credentials.
    • Polygon (Chain 137): Removed rpcfast.com endpoint containing hardcoded credentials.
    • Velas (Chain 106): Removed rpcfast.com endpoint containing hardcoded credentials.
  2. Security & Reliability Justification:

    • Private credentials shipped in public frontend bundles risk unauthorized quota consumption and service disruption.
    • Ample zero-auth public RPC alternatives remain available in the catalogue for all affected chains.

Follow-Up Recommendations

  • Revoke and rotate the exposed rpcfast and chain49 keys with the upstream providers.
  • Implement pre-commit hooks (e.g. gitleaks or git-secrets) to prevent future key commits.

…endpoints

### Summary of Changes
Addresses audit finding **HIGH-2 (CWE-798: Use of Hard-coded Credentials)** by removing third-party RPC endpoints carrying embedded private API keys in `constants/extraRpcs.js`:

1. **Eliminated Key-Bearing Endpoints:**
   - **Ethereum (Chain 1):** Removed `rpcfast.com` and `chain49.com` endpoints containing hardcoded credentials.
   - **BNB Smart Chain (Chain 56):** Removed `rpcfast.com` endpoint containing hardcoded credentials.
   - **Polygon (Chain 137):** Removed `rpcfast.com` endpoint containing hardcoded credentials.
   - **Velas (Chain 106):** Removed `rpcfast.com` endpoint containing hardcoded credentials.

2. **Security & Reliability Justification:**
   - Private credentials shipped in public frontend bundles risk unauthorized quota consumption and service disruption.
   - Ample zero-auth public RPC alternatives remain available in the catalogue for all affected chains.

---

### Follow-Up Recommendations
- Revoke and rotate the exposed `rpcfast` and `chain49` keys with the upstream providers.
- Implement pre-commit hooks (e.g. `gitleaks` or `git-secrets`) to prevent future key commits.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant