Trust
Security model
Who can do what, and what each attacker cannot.
Powers
| Who | Can | Cannot |
|---|---|---|
| Anyone | Submit a valid type-4 transaction and pay for it. | Change a target, an amount or a recipient. |
| Sponsor | Choose when to fire, pay the gas. | Make a wallet do anything it did not sign. |
| Coordinator | Call execute on wallets that carry the trusted marker. | Hold funds, change rules, or call a wallet that is not delegated to the trusted code. |
| Arm owner | Everything its wallet can do. | Spend another arm's funds. |
Design choices that matter
- The wallet signs the exact calls. The digest covers every call, a nonce and a deadline.
- Bound to wallet and chain. The EIP-712 domain includes the wallet address and chain id, so a signature cannot be moved to another wallet or chain.
- Nonce in a private slot. The slot is namespaced, so another delegation cannot corrupt it, and a replay is refused.
- Trusted marker check. A plain wallet cannot pass as a success, because the coordinator compares the wallet's code with the expected marker.
- Atomic option. You choose all-or-nothing.
- No admin, no upgrade, no fee. There is no key that can change the rules.
What you still trust
- The chain's EIP-7702 implementation.
- The target contracts you call, such as a curve.
- This code, which has not been audited by an outside firm.
- Your own handling of the arm keys.