Trust
Security model
What an attacker can and cannot do, and what we assume.
The goal
A stolen owner key must not be enough to take your funds, as long as the guardian notices in time. Everything else follows from that.
Properties the contract enforces
- No money leaves the vault except through
executeon an announcement that waited at leastdelayseconds. - The wait of an announcement is fixed when it is announced. Changing the delay later does not shorten announcements already made.
- Settings changes (delay, guardian, owner) are announcements, with the same wait and the same veto.
- The guardian can only change the status of announcements. No guardian function transfers value or changes a setting.
- An announcement runs at most once, and only inside its window (ripe to ripe + 14 days).
- Owner rotation and panic kill every announcement made before them (epochs).
- A guardian signature binds chain, vault, announcement id and epoch. It cannot be replayed elsewhere, or after an epoch change.
- No admin, no upgrade, no pause, no fee.
Each one has a test: see Verification.
What you must trust
| Assumption | If it fails |
|---|---|
| The guardian looks, in time | The wait is only a delay: a thief's announcement ripens and runs |
The chain executes the P-256 precompile at 0x100 correctly | Passkey vetoes could be wrongly accepted or rejected |
| The guardian's device and biometric are not both compromised | A thief could freeze the vault by vetoing everything (never take funds) |
| The sequencer's clock is roughly honest | Waits of minutes could shift by seconds |
| The code is correct | See limits: not audited |
Token behaviour
The vault never calls a token on its own: it only runs what the owner announced, by a plain call. Fee-on-transfer, rebasing and blocklisting tokens therefore behave as they do for any account. An approve hands real power to its spender once it runs, so approvals deserve a close look at announcement time.
Reentrancy and failure
execute sets the status to Executed before the external call and holds a lock during it. If the call fails the whole transaction reverts, so the announcement stays pending and can be retried or cancelled. One failing announcement never blocks another.
What it does not protect against
- The owner approving, for months, something that the guardian also approves.
- A guardian who is asleep or who always says yes.
- Loss of the owner key: nothing can recover it.
- Bugs in tokens or contracts the owner chooses to interact with.