MM0
Launch
DOCS / THREAT-MODEL

MM0 Threat Model

Version: 0.1 (Stage 0) · Method: assets → trust boundaries → threats → controls → residual risk.

1. Assets

  1. Maker capital (vault balances and venue positions)
  2. Executor authority (the only key that can act on the vault)
  3. Mandate integrity (limits that can't be silently changed)
  4. Ledger integrity (the public record)
  5. Accounting correctness (NAV, P&L, fees, used for any fee charged)

2. Trust boundaries

 untrusted ─────────────────────────────────────────────────────────── trusted
 social / metadata │ AI supervisor output │ RPC data │ strategy intents │ risk engine │ vault program
 (never ingested)  │ (schema-validated)   │ (cross-checked) │ (risk-checked) │ (pure fn)   │ (onchain rules)
  • Model output is untrusted input. It is parsed by validateSupervisorOutput (strict keys, enums, bounds). Free text is display-only.
  • Strategy intents are untrusted until evaluateIntent passes. Malformed input fails closed (a regression test exists for a null intent).
  • Built transactions are untrusted until verifyTransaction and re-simulation pass. That includes those from our own adapter.

3. Threats and controls

# Threat Control(s) Test / status
T1 Vault exploit: logic bug drains vault Vault program allows only the approved instruction set for the executor PDA. No transfer instruction exists for the executor. Vault invariant reconciliation every tick → HALT. vault-tamper stress; Stage 4 audit
T2 Executor compromise: attacker controls the executor key The executor key has narrowly scoped authority: add/remove/claim/swap on approved pools, proceeds to vault accounts only (enforced onchain, not just offchain). It can't change its own permissions or approve programs. spec; onchain enforcement Stage 4
T3 AI compromise / prompt injection Supervisor ingests only a numeric context schema (no tweets, Discord, Telegram, websites, token metadata). Output is schema-validated and bounded. It can't produce intents. Changes are timelocked, and risk-increasing ones are replay-gated. supervisor output is untrusted test
T4 Oracle manipulation Independent reference (not the execution pool). Freshness and deviation checks. Deviation > limit → circuit break and withdraw. Ranges must sit within maxRangeDistance of the reference. oracle-divergence stress
T5 Pool manipulation (push the pool price, then trigger MM0 to re-range at a bad price) Same as T4, plus re-ranges use the reference price, not spot. Swaps must clear vs reference. The DISLOCATED regime blocks new deployment. risk engine I10/I17/I20
T6 Malicious RPC / stale data Multi-RPC quorum (Stage 3). Slot/age checks. Oracle age → no new risk. Re-simulation at send time. rpc-outage stress
T7 Transaction substitution (adapter or middleware alters a tx) verifyTransaction: programs, instruction ↔ leg mapping, mints, authority, every source/destination, amounts, slippage. Re-simulation must match the approved outcome. compromised adapter redirecting proceeds test
T8 Venue exploit Reserve integrity monitor (actual reserves / accounted liabilities). < 0.999 → VENUE_SECURITY_INCIDENT → withdraw what remains, manual reset. pool-exploit stress
T9 Sandwich / MEV on MM0 swaps Swaps are rare and bounded (≤ action size, impact ≤ 0.8·limit), with tight minAmountOut (0.3%) and a reference-price check. Stage 4: private/bundled submission. I16/I17
T10 Private-key compromise (admin) The admin can pause only. There is no drain / transfer path (emergencyControls.canTransferCapital: false). Recovery is designed separately, behind governance + timelock. spec
T11 Admin compromise: mandate swap The mandate is immutable per version. Its hash is on the ledger and on every receipt. A new version requires governance + timelock + republication. mandate hash tests
T12 Strategy exploit (adversary games deterministic behavior, e.g. baiting re-ranges) Cooldowns, re-range caps, grace periods, edge buffers, regime hysteresis, reference-based placement. Markout monitoring detects being picked off. Stage 2 adversarial sims
T13 Token authority change (freeze, mint, extension added) Preflight blocks freeze authority and hostile Token-2022 extensions (TransferHook, PermanentDelegate, TransferFee, Pausable, …). Continuous diff → UNSUPPORTED_TOKEN_CHANGE → withdraw, manual reset. freeze-authority, mint-authority-change stress
T14 Accounting error Identity check every tick (residual ≤ 1e-6 NAV, else HALT). Unitized NAV. Independent recomputation from the ledger (Stage 3). accounting identity test
T15 Integer / math errors, overflow Onchain: checked math, fixed-point, rounding toward the vault, property tests against the float model. Stage 4
T16 Position NFT / account theft Position accounts owned by the vault PDA. Verifier requires the vault authority as sole authority on every instruction. I24
T17 Dependency compromise (SDK, npm) Pinned and audited venue SDKs. Instruction builders independently re-verified by our verifier. Minimal deps (Stage 1 has zero runtime dependencies). process
T18 Wash-trading / self-trade by the system itself SELF_TRADE invariant: no swap while MM0 liquidity is in the venue. No multi-wallet coordination exists. Objective excludes volume. I18 test
T19 Ledger rewrite Hash chain + periodic onchain anchoring of the head. ledger tamper test
T20 Fee-model gaming (operator inflates "performance") Performance defined net of inventory, costs, and flows vs HODL, with a high-water mark. Gross fees are never called profit. Accounting spec

4. Abuse cases the protocol refuses by design

Volume generation, price support, pumps, holder/transaction-count inflation, spoofing, layering, and front-running or sandwiching users. Any implementation proposal that relies on one of these is rejected. The objective function and fee model give no reward for any of them.

5. Residual risks (accepted, disclosed)

  • LP convexity losses in gaps (bounded only by deployment caps).
  • Venue smart-contract risk (bounded by exposure caps and monitoring, not eliminated).
  • Oracle availability for long-tail tokens (bootstrap mode is explicitly lower-confidence).
  • Onchain enforcement of executor scope doesn't exist until Stage 4. Stage 1–3 enforcement is offchain only, so no real capital is held before Stage 5.