Security
An honest accounting of Veto's security posture. We list what's strong, what's still maturing, and how to report a bug.
The on-chain enforcement - a VetoGuard installed as the guard on your self-custodial Safe smart account - is currently unaudited. We're scoping an external audit. Until then, the CLI gates mainnet deploys behind a typed-phrase acknowledgment ("i understand unaudited"). Don't put more on the contract than you can afford to lose.
/.well-known/jwks.json. Anyone can verify a Veto decision happened - Veto doesn't need to be online.(chain, contract, jti, exp, recipient, amount, token) via EIP-712 on EVM and a domain-separated hash on Solana. A mandate signed for one vault cannot be replayed against another.jti; a second use of the same jti reverts. No replay.Replay across vaults · replay of the same mandate · mutated mandate fields · spend over the cap · spend after expiry · wrong recipient · wrong token mint · OFAC-sanctioned addresses · canonical merchant typosquats
External audit · SPL token-2022 extensions · multi-key Veto signer · MEV / front-running on Solana (partial: jti single-use + exp window) · novel attack patterns we haven't seen yet
If you think you've found a security issue:
SECURITY: and a clear write-up.