Docs
Threat Model
Threats, impact and mitigations across clients, backend and supply chain.
Threats & mitigations
- Seed phrase theft — on-device generation, encrypted vault, reveal behind PIN, screenshot/app-switcher protection (NATIVE).
- Private key theft — keys in Secure Enclave/Keystore-wrapped vault; minimal time in memory.
- Malicious apps — OS sandbox, no exported components, integrity checks (NATIVE).
- Clipboard hijacking — remember copied value, warn on change, never auto-replace.
- Address poisoning — whole-address similarity vs history/address book, warning before send.
- Phishing — domain intelligence, dApp connection screen shows exact origin.
- Wallet drainers — simulation, unlimited-approval and Permit warnings.
- Malicious dApps — explicit per-session permissions, decoded signing.
- Fake tokens / spam NFTs — verified-token lists, spam flags, hide/report.
- RPC manipulation — multi-provider, chain ID check, simulation cross-check.
- Transaction substitution — show what is signed, sign the exact reviewed payload.
- Supply-chain attacks — lockfiles, dependency scanning, signed builds, SBOM.
- Malicious dependencies — minimal deps, audited crypto libs only.
- Deep-link attacks — strict parser, https-only dApp links, confirmation required.
- Man-in-the-middle — TLS everywhere, certificate pinning on mobile.
- Rooted/jailbroken devices — risk detection and warning (NATIVE).
- Extension attacks — MV3, minimal permissions, isolated vault, origin checks.
- XSS — React escaping, no untrusted HTML, strict CSP.
- CSRF — token-based auth, SameSite cookies, no cookie auth on mutation APIs.
- CSP failures — CSP reporting, nonce-based scripts.
- Server credential leaks — secret manager, rotation, no secrets in code.
- Insider threats — no backend path to keys; admin RBAC and audit logs.
- Logging leaks — redaction middleware blocks seed, key, PIN, keystore fields.
Items marked NATIVE must be implemented as audited native code (Swift, Kotlin, Rust or C++), not in the web app.

