Skip to content
Mainnet Live. All executions, addresses and hashes are live.
WORMHOOK
skeletonv0.1 · skeleton docs

Security

What is real today, what the design will enforce, and the threats it has to survive.

What's real today

AreaState
Contracts / programsNot written for production. Interfaces in docs are conceptual.
AuditNot started. Planned before any mainnet deployment.
Admin keysNot created. Governance model in CORE_TECH_PLAN.md.
DataSimulated.

Trust assumptions (design)

  1. Wormhole guardians. A VAA is accepted if 13 of 19 guardians signed it. WORMHOOK inherits that assumption; it adds no additional verifier in v1.
  2. Executors are untrusted for correctness. They can delay or decline, not forge or replay. See Executor model.
  3. Adapters and hooks are trusted only by the apps that call them. WORMHOOK does not review third-party hook logic. The registry shows audit status honestly.
  4. Admins can pause the router and gateway and manage the registry. During a pilot they may also upgrade contracts. This is a real trust assumption and is labelled as one.

Planned protections

ThreatMitigation
Forged callerRouter only posts for registered apps; gateway checks the router emitter.
Forged hook / unknown hookGateway only dispatches registry entries (WH-303).
Replay / duplicate deliveryCall ID consumed before execution (WH-302).
Stale messageExpiry in the call; gateway refuses late calls (WH-201).
OverspendmaxSpend checked against hook and app caps at the gateway and in adapters (WH-306).
Malicious adapterGas limit per hook, try/catch isolation, no gateway re-entrancy, per-hook pause.
EVM re-entrancynonReentrant gateway, checks-effects-interactions.
Compromised adminTimelock + multisig planned; pause separated from upgrade authority.
Relay delay / censorshipExpiry bounds the damage; permissionless redelivery planned.
Duplicate receiptRouter records exactly one receipt per pending call ID.
Partial executionFirst-class partial status; adapters report what succeeded.
Failed return pathReceipts can be redelivered; the hook never re-runs.
Finality mismatchFinalized consistency on the outbound leg; return-leg setting chosen per destination.

The full threat model, with test plans for each item, is in CORE_TECH_PLAN.md §Security.

Reporting

There's no production deployment to report against yet. Design feedback is welcome now, while it's cheap to change.