Beneficiary account:
3zkooCHZAiukUCPp1dXwTRkRwyfzcyzFFZ1tptXwZShnFoPx
Budget request for the proposal:
1 PHA = 0.1009 USD according to EMA7 of 11th Jul,2025 by CoinMarketCap
This proposal seeks funding from the Phala Treasury to cover the costs associated with a professional third-party security audit of the Dstack framework—Phala Cloud’s core confidential computing infrastructure built atop Intel TDX.
The audit was conducted by zkSecurity, a respected firm with deep expertise in zero-knowledge and trusted execution environment security.
Dstack is Phala Cloud’s next-generation confidential computing stack, built to support containerized applications running inside Intel TDX-based Confidential Virtual Machines (CVMs). It is the foundation for decentralized confidential computing workloads, supporting remote attestation (RA-TLS), full disk encryption, dynamic application deployment, and secure key provisioning via dstack-KMS.
Due to its foundational role in Phala Cloud, securing Dstack is a high-priority task for the long-term reliability and trust of the entire network.
The audit covered two main codebases:
Key audited components include:
The audit was performed in two stages:
The auditors identified and categorized 14 findings, including:
All high and medium severity issues were acknowledged and addressed promptly. Fixes include:
Security is the foundation of trust. This audit ensures that Dstack, the backbone of Phala Cloud, is built with verifiable integrity, hardened interfaces, and transparency. We believe this proposal is essential to fulfill Phala’s commitment to safe, open, and reliable confidential computing.
We kindly request the Council and community to support this treasury request.
This proposal asks for money from the Phala Treasury to pay for a security check of the Dstack framework, which is a very important part of Phala Cloud. Dstack helps keep computer programs and data secret and safe. A company called zkSecurity did the security check and found some problems, but they were fixed quickly. This makes Phala Cloud more secure and trustworthy. The proposal includes a full report of the security check, the fixes made, and other important information. The people who made this proposal want the Phala Council and community to support it.