threat model

SECURITY

What is enforced by the program, what is enforced by economics, and the gaps we know are still open. A security page that lists no weaknesses is marketing.

Enforced on chain

  • ✓No instruction moves vault SOL to an arbitrary address. Not a check that could be written wrong — the function does not exist.
  • ✓Trades route only into whitelisted AMM programs, and output must land in vault-owned accounts, asserted on post-balances.
  • ✓No trading into a venue the leader controls — the destination pool is checked against their identity and transfer-linked wallets.
  • ✓Withdrawals require the depositor's own signature and pay only to the wallet in their position record.
  • ✓Settlement is permissionless. A leader cannot withhold it to trap capital.
  • ✓Adding a trader is timelocked 24h; revoking is instant. Asymmetric in favour of safety.
  • ✓Profit share and access mode freeze at first deposit. The deal cannot change under you.
The timelock is the control that does the most work. It converts every key-compromise scenario — including the leader's cold identity key — from an instant drain into a visible 24-hour warning during which depositors can leave.

Known gaps

RiskStatusWhat limits it
A leader losing your money by trading badlynot mitigated Nothing. Buying a token that goes to zero passes every rail. This is the risk you are taking.
Smart contract failureaudit-dependent The real tail risk. Code is audited before it holds third-party capital; an audit reduces but never removes it.
Leader front-running their own vault from an unlinked walletpartially open Not preventable outright. Detectable across many trades: a wallet that keeps preceding a leader's entries shows up statistically.
Losing deliberately into an unrelated accomplice's tokenpartially open Liquidity, age and holder floors bound the damage per trade. Repetition is visible in the same way.
Exit visibilityunfixable A draining token account is public on a transparent chain. Mitigated by batching, private bundles and not publishing live holdings.
Survivorship marketing across identitiespartially open One identity aggregates all its vaults including dead ones. Multiple identities remain possible; the luck test devalues the prize.

The claim we actually make

A leader cannot take your money, and cannot trade it into a venue they control. They can lose it.

That sentence is narrow on purpose and every clause is checkable. Anything broader — "your funds are safe", "non-custodial means protected" — would not be true, and the first blown-up vault would expose it.