Threat model (summary)
This page summarises the threat model. The full version, written for auditors, is
docs/THREAT_MODEL.md in the repository; the evidence is in docs/research/*.md and
contracts/PORTING.md.
Assets to protect
- Beneficiary funds in the
FeeVault. - Beneficiary identity and wallet (privacy).
- The fee flow: 75% to the beneficiary, 25% to the protocol, F within [1%, 5%].
- Trading integrity: the locked liquidity and the fixed supply.
Adversaries
| Adversary | Goal | What stops it |
|---|---|---|
| Sniper bots | Buy most of the supply in the first blocks | Optional descending fee, Fair preset, atomic dev buy, private submission |
| Pool griefer | Pre-create or pre-initialize the launch pool at a hostile price | Only the hook (called by the factory) can initialize zk-pad pools |
| JIT liquidity provider | Add liquidity around large trades to capture the fee | Only the locker can add liquidity |
| Sandwich attacker | Sandwich the locker's fee-conversion swap | Fees are collected on every swap, so only one swap's worth is exposed, and a conversion never runs at a price pushed against it earlier in the same block (it is deferred to a later block). Consolidation uses a signed minOut or oracle bounds |
| Fee-dodging seller | Pay less protocol or beneficiary fee by overshooting into a thin band with flash-borrowed tokens, then buying back | Sells pay the protocol fee at the execution value; only 75% of the part above the post-swap value is rebated to the positions, and the locker tops the protocol up to 25% of what the later conversion realizes. A sell that ends with no in-range liquidity keeps the whole fee for the protocol |
| Malicious creator | Take the beneficiary's money after launch | Cannot redirect the id. Can claim until the beneficiary rotates the stealth key they generated; rotating also discards any shield templates registered with the old key. Creator rights are limited to its own launch's credit (a pro-rata share that shrinks with every owner withdrawal), oracle-bounded, at least 1 USDT per swap, and shield only to the beneficiary's own templates. |
| Griefing creator | Make the beneficiary's full-balance claim or consolidation revert by consolidating first | Full-balance claims (amount = 2^256 − 1) and quoted full-balance consolidations (2^255 | quoted) are resolved at execution with the signed rate; each creator swap must be worth at least minCreatorShield (1 USDT) of the attacker's own launch credit |
| Malicious relayer | Steal or redirect a claim | Every field of the claim, including the destination hash and fee, is signed. A relayer can only refuse to submit; use another relayer or submit yourself. |
| Malicious minority of attestors | Bind an escrow to their own key | Requires k distinct attestor signatures over one shared deadline |
| k colluding attestors | Bind an escrow to their own key | Timelock, single-attestor veto, guardian veto, contest flow. Not fully prevented in phase 0. |
| Attestor key thief (or any one attestor) | Decrypt hints | Hints are padded to a fixed length and reveal identities, not funds. Not threshold-protected: hints are encrypted with threshold 1, so each recipient attestor, or a thief of its hint key, reads the platform and user id of every hint addressed to it |
| Dictionary attacker | Find which account an escrow is for | A fresh random 32-byte nonce in every commitment, known only to the creator and the hint's readers (the attestor salt is in the hint and is not what hides the account) |
| Chain analyst | Link a beneficiary to a real-world identity | Stealth keys, relayers, USDT consolidation, Railgun; limited by BSC's anonymity set and by coin metadata |
| Network observer or RPC provider | Link an IP to a beneficiary | Fetch-everything APIs, nothing account-specific in URLs, no per-id RPC reads (nonces from the relayer index, unit-price oracle quotes, an event-sourced attestor index), no per-user logs, private metrics, Tor/OHTTP-friendly endpoints. The user should use Tor. |
| Relayer spammer | Starve a beneficiary's gasless claims by exhausting its per-id rate limit | The per-id limit is charged only after a successful simulation, i.e. for requests carrying valid signatures |
| Protocol admin | Take funds or change coins | No admin function moves beneficiary balances or changes existing coins. Caveats: the FeeVault owner controls the attestor set and guardian, so a compromised owner could bind social escrows to its own key after the public timelock; and the owner configures the creator path's price bound (feeds, executors, registry), so a malicious owner with a colluding creator could drain launch-credited balances through a bad feed or executor. The owner is currently a single EOA with no timelock in front of it. See trust assumptions. |
Out of scope or accepted
-
Fee-conversion swaps have no minimum output (Clanker parity). Only the previous swaps' token-side fees are exposed, never at a price pushed down earlier in the same block. A launch can opt out with
FeeIn.Both(orToken), but then the beneficiary is credited in the launched token, which relayers cannot price and consolidation cannot route: that balance needs a self-funded claim from a wallet holding BNB. The launch wizard and the SDK make the creator acknowledge this (allowSelfFundedTokenFees). -
Partial fills under a trader's own price limit can over-pay the protocol share on exact-in buys (Clanker parity); the trader never pays more than
amountIn. Sells cannot over-charge: the excess over the post-swap value is rebated 75% to the positions. -
Creator-triggered consolidation can lose up to
maxDeviationBpsagainst Chainlink per swap if sandwiched, capped bymaxSwapSize; there is no cooldown. -
A validator holding a manipulated price across a block boundary to meet a deferred conversion. It pays F on both legs and is open to every other trader in between.
-
Issuer freezes of a quote token or of USDT.
-
PancakeSwap Infinity governance pausing the vault or raising its protocol fee (max 0.4%).
-
Railgun governance pausing, upgrading, blocklisting or changing the shield fee.
-
A compromised beneficiary device. Whoever has the stealth key can claim.
-
Coin metadata that reveals the beneficiary.
-
Platform account takeover for social escrows, beyond what the timelock and contest flow catch.
Fixed in review rounds and no longer accepted: the exact-out-sell partial-fill over-charge; sells valued at a seller-chosen post-swap price; buys measured on the pool's net input instead of the trader's gross input; fee-free exits through the conversion swap; creators reaching balances their launch did not credit; and creator front-runs breaking full-balance owner signatures.
See external dependencies for the details.