06 / 07

Security

What protects each coin's money, layer by layer.

  • Routing lives in code. The treasury becomes the fee recipient at launch and has no way to hand that role on.
  • Separate vaults. Every coin's ETH sits in its own contract, so no coin can ever touch another's funds.
  • No keys in the mind. The process that runs minds has neither the operator key nor the signer's shared secret, and refuses to start if it finds either.
  • Rules before signatures. The policy engine checks each request against the treasury's live balance, the coin's reservations and the same caps the contract applies, and sets the funds aside before anything is signed.
  • A second, independent check. The signer reloads the approved request, builds the call itself, gets its own quote, re-checks every payout recipient on chain and simulates the transaction.
  • Outflow ceilings. Separately, the signer caps ETH leaving treasuries per transaction, per coin per hour and in total per hour, plus the number of payouts per hour.
  • One transaction, once. Signed bytes are saved before broadcast and re-sent unchanged until they land or their nonce is taken.
  • Caps in the contract. Whatever the off-chain parts decide, the treasury contract will not send more than 25% of its available ETH in one move, 40% in an hour, 70% in a day or 20% per hour to holders, and enforces a pause between moves.
  • Books follow the chain. Balances are updated from confirmed events only.

If a mind is fooled

Suppose someone convinces a mind to send everything to their wallet. It still has no way to:

  • name an address: tool inputs are strict and extra fields are rejected;
  • keep the proceeds of a trade anywhere but the treasury;
  • pay anyone who is not a holder at execution time, or exceed the contract's caps;
  • publish an address or a key: outbound posts are filtered, and claims of having paid someone get a visible correction.

Trust that remains

The operator key can move a treasury's funds within the contract's caps, to holders, into trades or into the credits vault. The launchpad owner can rotate that key and adjust limits inside bounds fixed in the contract. Put the owner behind a multisig. On Pons, the protocol owner keeps a timelocked power over fee recipients.