Skip to main content

Threat model (summary)

This page summarises the threat model. The full version, written for auditors, is docs/THREAT_MODEL.md in the repository; the evidence is in docs/research/*.md and contracts/PORTING.md.

Assets to protect​

  1. Beneficiary funds in the FeeVault.
  2. Beneficiary identity and wallet (privacy).
  3. The fee flow: 75% to the beneficiary, 25% to the protocol, F within [1%, 5%].
  4. Trading integrity: the locked liquidity and the fixed supply.

Adversaries​

AdversaryGoalWhat stops it
Sniper botsBuy most of the supply in the first blocksOptional descending fee, Fair preset, atomic dev buy, private submission
Pool grieferPre-create or pre-initialize the launch pool at a hostile priceOnly the hook (called by the factory) can initialize zk-pad pools
JIT liquidity providerAdd liquidity around large trades to capture the feeOnly the locker can add liquidity
Sandwich attackerSandwich the locker's fee-conversion swapFees are collected on every swap, so only one swap's worth is exposed, and a conversion never runs at a price pushed against it earlier in the same block (it is deferred to a later block). Consolidation uses a signed minOut or oracle bounds
Fee-dodging sellerPay less protocol or beneficiary fee by overshooting into a thin band with flash-borrowed tokens, then buying backSells pay the protocol fee at the execution value; only 75% of the part above the post-swap value is rebated to the positions, and the locker tops the protocol up to 25% of what the later conversion realizes. A sell that ends with no in-range liquidity keeps the whole fee for the protocol
Malicious creatorTake the beneficiary's money after launchCannot redirect the id. Can claim until the beneficiary rotates the stealth key they generated; rotating also discards any shield templates registered with the old key. Creator rights are limited to its own launch's credit (a pro-rata share that shrinks with every owner withdrawal), oracle-bounded, at least 1 USDT per swap, and shield only to the beneficiary's own templates.
Griefing creatorMake the beneficiary's full-balance claim or consolidation revert by consolidating firstFull-balance claims (amount = 2^256 − 1) and quoted full-balance consolidations (2^255 | quoted) are resolved at execution with the signed rate; each creator swap must be worth at least minCreatorShield (1 USDT) of the attacker's own launch credit
Malicious relayerSteal or redirect a claimEvery field of the claim, including the destination hash and fee, is signed. A relayer can only refuse to submit; use another relayer or submit yourself.
Malicious minority of attestorsBind an escrow to their own keyRequires k distinct attestor signatures over one shared deadline
k colluding attestorsBind an escrow to their own keyTimelock, single-attestor veto, guardian veto, contest flow. Not fully prevented in phase 0.
Attestor key thief (or any one attestor)Decrypt hintsHints are padded to a fixed length and reveal identities, not funds. Not threshold-protected: hints are encrypted with threshold 1, so each recipient attestor, or a thief of its hint key, reads the platform and user id of every hint addressed to it
Dictionary attackerFind which account an escrow is forA fresh random 32-byte nonce in every commitment, known only to the creator and the hint's readers (the attestor salt is in the hint and is not what hides the account)
Chain analystLink a beneficiary to a real-world identityStealth keys, relayers, USDT consolidation, Railgun; limited by BSC's anonymity set and by coin metadata
Network observer or RPC providerLink an IP to a beneficiaryFetch-everything APIs, nothing account-specific in URLs, no per-id RPC reads (nonces from the relayer index, unit-price oracle quotes, an event-sourced attestor index), no per-user logs, private metrics, Tor/OHTTP-friendly endpoints. The user should use Tor.
Relayer spammerStarve a beneficiary's gasless claims by exhausting its per-id rate limitThe per-id limit is charged only after a successful simulation, i.e. for requests carrying valid signatures
Protocol adminTake funds or change coinsNo admin function moves beneficiary balances or changes existing coins. Caveats: the FeeVault owner controls the attestor set and guardian, so a compromised owner could bind social escrows to its own key after the public timelock; and the owner configures the creator path's price bound (feeds, executors, registry), so a malicious owner with a colluding creator could drain launch-credited balances through a bad feed or executor. The owner is currently a single EOA with no timelock in front of it. See trust assumptions.

Out of scope or accepted​

  • Fee-conversion swaps have no minimum output (Clanker parity). Only the previous swaps' token-side fees are exposed, never at a price pushed down earlier in the same block. A launch can opt out with FeeIn.Both (or Token), but then the beneficiary is credited in the launched token, which relayers cannot price and consolidation cannot route: that balance needs a self-funded claim from a wallet holding BNB. The launch wizard and the SDK make the creator acknowledge this (allowSelfFundedTokenFees).

  • Partial fills under a trader's own price limit can over-pay the protocol share on exact-in buys (Clanker parity); the trader never pays more than amountIn. Sells cannot over-charge: the excess over the post-swap value is rebated 75% to the positions.

  • Creator-triggered consolidation can lose up to maxDeviationBps against Chainlink per swap if sandwiched, capped by maxSwapSize; there is no cooldown.

  • A validator holding a manipulated price across a block boundary to meet a deferred conversion. It pays F on both legs and is open to every other trader in between.

  • Issuer freezes of a quote token or of USDT.

  • PancakeSwap Infinity governance pausing the vault or raising its protocol fee (max 0.4%).

  • Railgun governance pausing, upgrading, blocklisting or changing the shield fee.

  • A compromised beneficiary device. Whoever has the stealth key can claim.

  • Coin metadata that reveals the beneficiary.

  • Platform account takeover for social escrows, beyond what the timelock and contest flow catch.

Fixed in review rounds and no longer accepted: the exact-out-sell partial-fill over-charge; sells valued at a seller-chosen post-swap price; buys measured on the pool's net input instead of the trader's gross input; fee-free exits through the conversion swap; creators reaching balances their launch did not credit; and creator front-runs breaking full-balance owner signatures.

See external dependencies for the details.