Trust
Limits and risks
Read this before putting real money in.
Status
The contract is not audited and not deployed. The website demo runs on a pretend ledger inside your browser.
What Marmot is not
- Not a recovery tool. It does not restore a lost owner key. It limits what a stolen one can do.
- Not magic. It needs a guardian who looks. The wait buys time; you still have to spend it well.
- Not private. Announcements are public by design. That is how the guardian sees them.
- Not a token. $MARMOT is a separate community coin. The contracts never use it.
Design limits
- Friction. Every withdrawal waits. Keep working money in a normal wallet and savings in the vault.
- The freeze. A compromised guardian can refuse everything forever. See Threat scenarios.
- Single guardian. One guardian at a time. Use an ERC-1271 contract for several signers.
- Single owner. Likewise: use a smart account for shared ownership.
- Not a wallet delegation. We did not build this on EIP-7702: a key holder can always replace a delegation, so the wait could be bypassed. The vault is a separate contract on purpose.
Passkey limits
- A passkey is tied to the website domain. Pick the domain before creating it, and keep it.
- Sync is the provider's job (iCloud, Google). Check your passkey syncs.
- Browser and OS support differs. Test the whistle once (the Guardian page has a test button) before depositing.
Technical limits
- Time is
block.timestampin seconds, set by the sequencer. - The browser simulator runs ETH sends and ERC-20 transfers only.
- The web lookout depends on a reachable RPC. You can change it in the page.
- Gas figures are estimates from
eth_gasPriceand exclude any data-availability fee.
Before using real funds
- Get the contract audited.
- Deploy, then run the real-chain checks against the deployed address.
- Create a vault with a short wait and a small amount. Announce, whistle, execute. Time how long the alert takes.
- Only then raise the amount and the wait.