Repository navigation
Expand file tree
/
Copy pathwallet-security.json
More file actions
235 lines (235 loc) · 9.91 KB
/
Copy pathwallet-security.json
File metadata and controls
235 lines (235 loc) · 9.91 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
{
"nodes": [
{
"id": "asset-seed-secrets",
"type": "asset",
"title": "Seed phrase and recovery secrets",
"summary": "The mnemonic or recovery material that reconstructs signing keys. Anyone who sees it can take the wallet.",
"domains": ["devices-identity", "people"],
"status": "proposed",
"tags": ["seed-phrase", "recovery", "keys"],
"roles": ["multisig-signer"],
"lifecycle": ["normal-operations", "incident-response"],
"framework": "wallet-security"
},
{
"id": "component-hardware-wallet",
"type": "component",
"title": "Hardware wallet",
"summary": "A dedicated signing device that keeps keys offline and shows destination and amount on its own screen.",
"domains": ["devices-identity", "governance-treasury"],
"status": "proposed",
"tags": ["hardware-wallet", "cold-wallet"],
"roles": ["multisig-signer"],
"lifecycle": ["normal-operations"],
"framework": "wallet-security"
},
{
"id": "component-software-wallet",
"type": "component",
"title": "Software wallet",
"summary": "A hot wallet on a phone or browser that signs from an internet-connected device. Convenience with a larger remote attack surface.",
"domains": ["devices-identity", "onchain-systems"],
"status": "proposed",
"tags": ["software-wallet", "hot-wallet"],
"roles": ["multisig-signer"],
"lifecycle": ["normal-operations"],
"framework": "wallet-security"
},
{
"id": "component-seed-backup",
"type": "component",
"title": "Seed backup",
"summary": "Offline copies of the seed phrase: paper, metal, or split shares. Physical access here is wallet takeover.",
"domains": ["devices-identity", "people"],
"status": "proposed",
"tags": ["seed-phrase", "backup"],
"roles": ["multisig-signer"],
"lifecycle": ["normal-operations", "recovery"],
"framework": "wallet-security"
},
{
"id": "surface-transaction-signing",
"type": "attack-surface",
"title": "Transaction signing",
"summary": "The moment a wallet approves calldata. A hostile UI or unread payload turns a good key into an authorized drain.",
"domains": ["devices-identity", "onchain-systems"],
"status": "proposed",
"tags": ["signing", "calldata"],
"roles": ["multisig-signer"],
"lifecycle": ["normal-operations"],
"framework": "wallet-security"
},
{
"id": "surface-seed-custody",
"type": "attack-surface",
"title": "Seed custody",
"summary": "How the seed is written, stored, split, and retrieved. Digital copies and casual physical access both count as exposure.",
"domains": ["devices-identity", "people"],
"status": "proposed",
"tags": ["seed-phrase", "custody"],
"roles": ["multisig-signer"],
"lifecycle": ["normal-operations", "recovery"],
"framework": "wallet-security"
},
{
"id": "surface-token-approvals",
"type": "attack-surface",
"title": "Token approvals",
"summary": "ERC-20 approve and permit grants that let a spender move tokens later. Unlimited allowance outlives the original swap.",
"domains": ["onchain-systems"],
"status": "proposed",
"tags": ["approvals", "permit", "erc20"],
"roles": ["engineer-developer", "multisig-signer"],
"lifecycle": ["normal-operations"],
"framework": "wallet-security"
},
{
"id": "threat-blind-signing",
"type": "threat",
"title": "Blind signing",
"summary": "The signer approves attacker-controlled calldata because a website, chat, or wallet UI was trusted instead of the raw transaction.",
"domains": ["devices-identity", "onchain-systems"],
"status": "proposed",
"tags": ["signing", "phishing", "calldata"],
"severity": "critical",
"severityBasis": "Default triage is critical because a valid signature spends funds without stealing the key. Impact scales with what the wallet can move.",
"framework": "wallet-security"
},
{
"id": "threat-seed-phrase-compromise",
"type": "threat",
"title": "Seed phrase compromise",
"summary": "The seed is photographed, typed into a connected device, stored in cloud notes, or read by someone with physical access.",
"domains": ["devices-identity", "people"],
"status": "proposed",
"tags": ["seed-phrase", "theft"],
"severity": "critical",
"severityBasis": "Default triage is critical because the seed reconstructs every derived key. Treat any suspected exposure as full compromise.",
"framework": "wallet-security"
},
{
"id": "threat-unlimited-token-approval",
"type": "threat",
"title": "Unlimited token approval",
"summary": "A spender keeps uint256 allowance or a permit grant after the intended swap. A later exploit or hostile spender drains the wallet.",
"domains": ["onchain-systems"],
"status": "proposed",
"tags": ["approvals", "permit"],
"severity": "high",
"severityBasis": "Default triage is high because the drain does not need the key, but it is limited to the approved token and spender. Treat as critical when the spender is unaudited or the allowance is protocol-wide.",
"framework": "wallet-security"
},
{
"id": "control-cold-wallet-separation",
"type": "control",
"title": "Cold and hot wallet separation",
"summary": "Keep high-value keys on offline or hardware signers. Use a hot wallet only for amounts you can afford to lose.",
"domains": ["devices-identity", "governance-treasury"],
"status": "proposed",
"tags": ["cold-wallet", "isolation"],
"controlClass": "preventive",
"assessmentEligible": true,
"roles": ["multisig-signer"],
"lifecycle": ["normal-operations"],
"framework": "wallet-security"
},
{
"id": "control-offline-seed-custody",
"type": "control",
"title": "Offline seed custody",
"summary": "Keep the seed offline, preferably durable and split. Treat any screen, photo, or cloud copy as compromise and rotate.",
"domains": ["devices-identity", "people"],
"status": "proposed",
"tags": ["seed-phrase", "offline"],
"controlClass": "preventive",
"assessmentEligible": true,
"roles": ["multisig-signer"],
"lifecycle": ["normal-operations", "recovery"],
"framework": "wallet-security"
},
{
"id": "control-simulate-before-sign",
"type": "control",
"title": "Simulate and decode before signing",
"summary": "Independently simulate the transaction and read destination, asset, and calldata on a trusted display. Do not sign because a website said it was safe.",
"domains": ["devices-identity", "onchain-systems"],
"status": "proposed",
"tags": ["simulation", "verification"],
"controlClass": "preventive",
"assessmentEligible": true,
"roles": ["multisig-signer"],
"lifecycle": ["normal-operations"],
"framework": "wallet-security"
},
{
"id": "control-limited-token-approvals",
"type": "control",
"title": "Limited token approvals",
"summary": "Approve only the amount needed for this transaction. Revoke leftover allowances. Avoid permit and infinite approve by default.",
"domains": ["onchain-systems"],
"status": "proposed",
"tags": ["approvals", "allowance"],
"controlClass": "preventive",
"assessmentEligible": true,
"roles": ["engineer-developer", "multisig-signer"],
"lifecycle": ["normal-operations"],
"framework": "wallet-security"
},
{
"id": "guidance-wallet-security",
"type": "guidance",
"title": "Wallet Security",
"summary": "Custody models, hot versus cold tradeoffs, signing verification, seed custody, and safer contract interaction.",
"domains": ["devices-identity", "onchain-systems"],
"status": "proposed",
"tags": ["wallet"],
"href": "/wallet-security/overview",
"framework": "wallet-security"
},
{
"id": "guidance-cold-vs-hot",
"type": "guidance",
"title": "Cold vs hot wallets",
"summary": "Match fund tier to connectivity. Cold and hardware signers cut remote theft; hot wallets stay for operational amounts.",
"domains": ["devices-identity"],
"status": "proposed",
"tags": ["cold-wallet", "hot-wallet"],
"href": "/wallet-security/cold-vs-hot-wallet",
"framework": "wallet-security"
},
{
"id": "guidance-seed-phrase-management",
"type": "guidance",
"title": "Seed phrase management",
"summary": "Offline backup, metal and split-share options, and the rule that suspected exposure means rotate immediately.",
"domains": ["devices-identity", "people"],
"status": "proposed",
"tags": ["seed-phrase"],
"href": "/wallet-security/seed-phrase-management",
"framework": "wallet-security"
},
{
"id": "guidance-signing-verification",
"type": "guidance",
"title": "Signing and verification",
"summary": "Never sign blindly. Prefer the hardware screen and independently verified calldata over any web UI claim.",
"domains": ["devices-identity", "onchain-systems"],
"status": "proposed",
"tags": ["signing", "verification"],
"href": "/wallet-security/signing-and-verification/signing-verification",
"framework": "wallet-security"
},
{
"id": "guidance-smart-contract-interaction",
"type": "guidance",
"title": "Smart contract interaction security",
"summary": "Verify the contract, simulate, and limit approvals before interacting. Most losses here are interaction mistakes, not stolen keys.",
"domains": ["onchain-systems"],
"status": "proposed",
"tags": ["approvals", "simulation"],
"href": "/wallet-security/smart-contract-interaction-security",
"framework": "wallet-security"
}
]
}