EIP-712 domain separator missing chainId
Balancer (v2 + v3)'s assessment for RD-F-020 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Balancer v2 operates on multiple chains with the same vanity Vault address (0xBA1222...); EIP-712 domain separators include chainId to prevent cross-chain replay. This is standard v2 design. No published finding of missing chainId in EIP-712 domain separator. ToB 2022 Batch Relayer audit covers signature contexts — no chainId issue at high severity found.
Sources #
- AuditTrail of Bits 2022-05-27: Batch Relayer audithttps://github.com/balancer/balancer-v2-monorepo/blob/master/audits/trail-of-bits/2022-05-27.pdfretrieved 2026-05-05
- v2 multi-chain deployment with same vanity addresshttps://github.com/balancer/balancer-deployments/blob/master/v2/tasks/20210418-vault/output/mainnet.jsonretrieved 2026-05-05
Methodology #
Determine whether the EIP-712 domain separator struct omits the `chainId` field, allowing cross-chain replay.
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol balancer factor RD-F-020 score green collected_at 2026-05-05 12:41:36