marmot

Marmot docs

20 pages, from the idea to the error codes

Trust

Security model

What an attacker can and cannot do, and what we assume.

The goal

A stolen owner key must not be enough to take your funds, as long as the guardian notices in time. Everything else follows from that.

Properties the contract enforces

  1. No money leaves the vault except through execute on an announcement that waited at least delay seconds.
  2. The wait of an announcement is fixed when it is announced. Changing the delay later does not shorten announcements already made.
  3. Settings changes (delay, guardian, owner) are announcements, with the same wait and the same veto.
  4. The guardian can only change the status of announcements. No guardian function transfers value or changes a setting.
  5. An announcement runs at most once, and only inside its window (ripe to ripe + 14 days).
  6. Owner rotation and panic kill every announcement made before them (epochs).
  7. A guardian signature binds chain, vault, announcement id and epoch. It cannot be replayed elsewhere, or after an epoch change.
  8. No admin, no upgrade, no pause, no fee.

Each one has a test: see Verification.

What you must trust

AssumptionIf it fails
The guardian looks, in timeThe wait is only a delay: a thief's announcement ripens and runs
The chain executes the P-256 precompile at 0x100 correctlyPasskey vetoes could be wrongly accepted or rejected
The guardian's device and biometric are not both compromisedA thief could freeze the vault by vetoing everything (never take funds)
The sequencer's clock is roughly honestWaits of minutes could shift by seconds
The code is correctSee limits: not audited

Token behaviour

The vault never calls a token on its own: it only runs what the owner announced, by a plain call. Fee-on-transfer, rebasing and blocklisting tokens therefore behave as they do for any account. An approve hands real power to its spender once it runs, so approvals deserve a close look at announcement time.

Reentrancy and failure

execute sets the status to Executed before the external call and holds a lock during it. If the call fails the whole transaction reverts, so the announcement stays pending and can be retried or cancelled. One failing announcement never blocks another.

What it does not protect against

  • The owner approving, for months, something that the guardian also approves.
  • A guardian who is asleep or who always says yes.
  • Loss of the owner key: nothing can recover it.
  • Bugs in tokens or contracts the owner chooses to interact with.