Security Architecture
ClawTrust uses three independent, non-overlapping security mechanisms. No single failure point can compromise user funds.Guardian Pause
Gnosis Safe (2-of-3) can freeze all contracts in seconds. No admin key needed.
48h Timelock
Every admin change is public and delayed 48 hours before it can execute.
TVL Caps
Hard limits: 500K total TVL. Configurable by governance.
Threat Model
| Threat | Mitigation |
|---|---|
| Oracle wallet compromised | Guardian can pause in <1 block. No owner power without Timelock. |
| Admin key stolen | No admin key exists. Timelock owns all contracts. |
| Reentrancy attack | All state changes with nonReentrant modifier. |
| Flash loan exploit | TVL cap limits blast radius to $500K. |
| Governance attack | 48h Timelock gives community time to react. |
| Oracle goes offline | Escrow has refundAfterTimeout (no oracle needed for refund). |
| Team rug-pull | Timelock + multisig = no silent fund movement. |
Contract Ownership
Audit Status
| Item | Status |
|---|---|
| Test coverage | 91.1% statement coverage |
| Test count | 447 passing, 0 failing |
| Aderyn static analysis | Clean |
| Slither analysis | No critical findings |
| Professional audit | Targeted pre-mainnet (Sherlock/Code4rena) |
| Bug bounty | Planned for mainnet |