marmot

Marmot docs

20 pages, from the idea to the error codes

Concepts

Vault and roles

Who can do what, and, more importantly, what nobody can do.

The vault

One vault is one contract, deployed for one owner. It holds ETH and any ERC-20 or NFT sent to it. The factory that deploys it has no power over it afterwards: no fee, no owner, no registry you must use.

Owner

A single address. It can be a normal account, or a smart account (a Safe, an ERC-4337 account): the vault only checks that msg.sender is the owner, so any contract that can call it can be one. The owner can announce things and cancel their own announcements. They cannot execute early, cannot veto, and cannot change anything instantly.

Guardian

One of three kinds, decided at creation and changeable only by an announcement:

KindHow it refusesGas for the guardian
Passkey (P-256)Signs with Face ID / fingerprint / PIN. Anyone submits the signature (vetoWithSig).None
Wallet (EOA)Calls veto directly, or signs an EIP-712 message anyone can submit.Only if it calls directly
Contract (ERC-1271)A Safe or smart account that validates a signature. Handled by the same vetoWithSig.None

The guardian has exactly two powers: refuse one announcement, refuse everything pending (panic). Look at the contract: no function lets the guardian send, approve, call, change the owner or change a setting.

Anyone

Two public actions: execute(id) once an announcement is ripe, and submitting a guardian signature. Because both are open, nothing depends on a particular server or relayer. If one stops, you submit it yourself.

Who can do what

ActionOwnerGuardianAnyone
Deposityesyesyes
Announce (send, call, setting)yesnono
Cancel an announcementyes (any pending)nono
Refuse an announcementnoyesonly by carrying the guardian's signature
Kill everything pending (panic)noyesonly by carrying the guardian's signature
Execute a ripe announcementyesyesyes
Change delay, guardian or owner instantlynonono

What nobody can do

  • Skip the wait. There is no emergency path, no admin override.
  • Move funds by whistling. A veto and a panic only change the status of announcements.
  • Upgrade the contract, pause it or take a fee.
  • Target the vault itself with a queueCall: the owner cannot make the vault call its own functions.