Cryptography / Smart Contract Security2024 / Completed / Open Source

Auth-Governed Secure Vault

Off-Chain EIP-712 ECDSA Authorized Vault Protocol

Source code
01 / Context

The engineering problem.

Smart contract vaults relying solely on msg.sender or simple access modifiers are vulnerable to compromised private keys, phishing transactions, and reentrancy loops.

Overview

A cryptographic custody vault requiring cryptographic authorizations signed by a designated security signer before executing capital disbursements. Ideal for high-value operations requiring off-chain compliance or multi-party approvals.

Signature Standard
EIP-712
Replay Security
100% Nonce Verified
Test Suite
Foundry Invariant
SolidityFoundryDockerECDSAEIP-712 Signatures
02 / System design

EIP-712 Typed Signature Verification & Nonce Accounting

Validates structured off-chain permits against an immutable domain separator before updating internal accounting.

Architecture / Cryptography / Smart Contract Security
Auth-Governed Secure Vault: select an annotation below to inspect the architecture.STATE / AUTHORIZATION01 / VAULT02 / SIGNATURE03 / NONCE
[01]

SecureVault.sol: Holds ETH reserves and executes payouts only upon valid signature submission.

03 / Adversarial defense

Technical challenges & mitigations.

Signature Malleability in ecrecover

Utilized OpenZeppelin ECDSA library to strictly reject signatures with non-standard s-values (preventing s-malleability exploits).

Cross-Contract Reentrancy Safeguards

Maintained strict CEI ordering and nullified user allowances prior to invoking low-level .call{value: amount} transfers.

04 / Implementation

Key features.

  • 01EIP-712 structured data hashing for transparent wallet signing
  • 02Replay protection through per-account nonce increments and expiration timestamps
  • 03Zero external dependency execution paths for emergency withdrawals
  • 04Formal invariant test suite authored in Foundry
Next study / 01

Omnichain Asset Bridge