> For the complete documentation index, see [llms.txt](https://gotts.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://gotts.gitbook.io/docs/gotts-vaults/vault/19-threat-model.md).

# Threat Model

> **Part of**: [Vault PRD](/docs/gotts-vaults/vault.md) | **Last Updated**: 2026-02-16

***

## Overview

This document provides a structured threat model for Gotts Vaults. It defines adversary types, enumerates attack paths, maps each to mitigating safety layers (see [shared/safety-layers.md](/docs/prd-shared/safety-layers.md)), and maintains a residual risk register for attacks that are not fully mitigated.

***

## 1. Attacker Taxonomy

| Adversary                      | Motivation                                                                   | Capabilities                                                                          | Examples                                                |
| ------------------------------ | ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------- | ------------------------------------------------------- |
| **Malicious vault creator**    | Steal depositor funds via vault manipulation                                 | Full control of vault parameters at creation; can set deceptive strategy descriptions | Honeypot vaults, rug-pull via parameter changes         |
| **Compromised manager agent**  | Drain vault via unauthorized transactions                                    | Prompt-injected or key-compromised agent with manager role                            | AIXBT hack ($106K), agent wallet compromise             |
| **External MEV bot**           | Extract value from vault operations                                          | Mempool observation, sandwich attacks, JIT manipulation                               | Standard MEV on deposit/withdraw/rebalance              |
| **Prompt-injected agent**      | Execute unauthorized operations via LLM manipulation                         | Indirect prompt injection via data feeds, MCP tools, or context corruption            | ClawHub campaign (335 malicious skills), CVE-2025-59944 |
| **Oracle manipulator**         | Inflate NAV for profitable withdrawal or deflate for cheap share acquisition | Flash loan price manipulation, oracle feed corruption                                 | Flash-loan-based NAV inflation                          |
| **Griefing attacker**          | Deny service or degrade performance without direct profit                    | Spam transactions, dust deposits, registry pollution                                  | ERC-4626 inflation attack, withdrawal queue spam        |
| **Identity thief**             | Use stolen ERC-8004 identity to access high-tier vault operations            | Stolen wallet keys, social engineering of identity NFT transfer                       | Identity NFT theft for Sovereign-tier access            |
| **Compromised infrastructure** | Extract keys or manipulate execution environment                             | Physical access to TEE hardware, compromised cloud VM                                 | TEE.Fail, Battering RAM ($50 hardware attacks)          |

***

## 2. Attack Trees

### 2.1 Malicious Vault Creator

```
Goal: Steal depositor funds
├── Path A: Deploy vault with hidden extraction mechanism
│   ├── Set deceptive disclosure (strategy hash points to fake document)
│   │   └── Mitigated: D-024 mandatory disclosure; depositors verify on-chain
│   ├── Configure extreme fees (100% performance fee)
│   │   └── Mitigated: Immutable FeeModule caps (5% mgmt, 50% perf)
│   └── Create circular meta-vault dependency
│       └── Mitigated: Factory circularity check (D-046, depth limit 2)
│
├── Path B: Change parameters post-creation to extract funds
│   ├── Lower minReputation to allow colluding agents
│   │   └── Mitigated: Parameter changes require ParameterDecisionTable timelock (D-059)
│   ├── Add malicious adapter to siphon funds
│   │   └── Mitigated: Adapter add requires longTimelock (3-7 days) + data attestation hash (D-060)
│   └── Modify hook logic to redirect fees
│       └── Mitigated: Hook kill-switch (D-058); hook logic immutable post-deployment
│
└── Path C: Abandon vault with depositor funds locked
    ├── Stop rebalancing, let positions decay
    │   └── Mitigated: am-AMM (D-012) allows competitive takeover; forceDeallocate exits
    └── Refuse to process withdrawals
        └── Mitigated: ERC-4626 withdraw is permissionless; circuit breaker enables emergency mode
```

### 2.2 Compromised Manager Agent

```
Goal: Execute unauthorized transactions
├── Path A: Direct key compromise
│   ├── Steal agent's private key
│   │   └── Mitigated: Layer 1 (TEE key management); keys never in agent memory
│   └── Compromise TEE environment
│       └── Mitigated: D-036 (TEE is defense-in-depth, not defense-in-total); Layer 4 (time-delayed proxy)
│
├── Path B: Prompt injection
│   ├── Inject via MCP tool response
│   │   └── Mitigated: Layer 2.5 (MCP Integrity Verification, 96% detection)
│   ├── Inject via data feed
│   │   └── Mitigated: Layer 2 (data/decision separation, CaMeL dual-LLM)
│   └── Inject via memory corruption
│       └── Mitigated: Layer 2.5 (memory integrity hashing)
│
└── Path C: Authorized but harmful operations
    ├── Execute trades with excessive slippage
    │   └── Mitigated: Layer 6 (pre-flight simulation); Layer 7 (on-chain slippage caps)
    ├── Rebalance into unfavorable positions
    │   └── Mitigated: Layer 4 (time delay for elevated operations); Layer 5 (cancel authority)
    └── Drain vault via many small transactions under limits
        └── Mitigated: Per-day aggregate caps (even for Sovereign tier); continuous dampening (D-043)
```

### 2.3 Oracle Manipulator

```
Goal: Manipulate NAV for profitable deposit/withdrawal
├── Path A: Flash-loan price manipulation
│   ├── Manipulate V4 pool spot price
│   │   └── Mitigated: D-067 (no-spot-assumptions); TWAP validation (10-30 min window)
│   └── Manipulate external oracle feed
│       └── Mitigated: D-021 (multi-oracle aggregation); 2% divergence auto-pause
│
├── Path B: Oracle staleness exploitation
│   ├── Wait for oracle to go stale, exploit stale NAV
│   │   └── Mitigated: D-062 (staleness gates widen spreads; 100% staleness disables NAV pricing)
│   └── Front-run oracle update with foreknowledge
│       └── Mitigated: D-062 (NAV rate-of-change clamp, 50 bps max per snapshot)
│
└── Path C: NAV inflation via donation
    ├── Donate tokens directly to vault contract
    │   └── Mitigated: Internal asset accounting (not balanceOf); D-017 virtual shares
    └── Donate via intermediary contract
        └── Mitigated: Same -- internal accounting ignores external balance changes
```

### 2.4 Griefing Attacker

```
Goal: Deny service or degrade performance
├── Path A: ERC-4626 inflation attack
│   └── Mitigated: D-017 (_decimalsOffset of 3-6); internal asset accounting
│
├── Path B: Withdrawal queue spam
│   ├── Submit many small withdrawal requests
│   │   └── Mitigated: Minimum withdrawal amount; gas costs make dust unprofitable
│   └── Cancel and resubmit repeatedly
│       └── Mitigated: Request cooldown period; reputation impact for frivolous requests
│
├── Path C: Factory registry pollution
│   ├── Deploy thousands of empty vaults
│   │   └── Mitigated: ERC-8004 registration cost; vault creation gas cost
│   └── Deploy vaults with misleading names/descriptions
│       └── Mitigated: D-024 mandatory disclosure; off-chain curation/filtering by aggregators
│
└── Path D: Identity spam
    ├── Register many ERC-8004 identities for Sybil attacks
    │   └── Mitigated: Registration cost in ERC-8004; operator matching; TraceRank (D-044)
    └── Transfer identity NFTs rapidly
        └── Mitigated: Reputation decay on transfer (30-day linear recovery); velocity signal detection
```

***

## 3. Residual Risk Register

Attacks that are NOT fully mitigated by current defenses. Each entry describes the residual risk, its severity, and planned future mitigations.

| Risk ID | Description                                      | Severity | Current Mitigation                                            | Residual Exposure                                                             | Planned Future Mitigation                                                |
| ------- | ------------------------------------------------ | -------- | ------------------------------------------------------------- | ----------------------------------------------------------------------------- | ------------------------------------------------------------------------ |
| RR-1    | Prompt injection bypass (12% rate per Anthropic) | High     | Layer 2 + 2.5 (88% catch rate)                                | 12% of sophisticated attacks may bypass prompt defenses                       | CaMeL capability tokens (D-040); multi-agent defense pipeline            |
| RR-2    | TEE hardware compromise                          | Medium   | D-036 (TEE as defense-in-depth); Layer 4 (time-delayed proxy) | Compromised TEE + monitoring failure = key extraction possible                | HSM/KMS for production keys (D-010); proxy module completion             |
| RR-3    | Novel ERC-8004 attack vectors                    | Medium   | Adapter pattern absorbs interface changes                     | ERC-8004 is still in Draft status; unknown attack surfaces                    | SBT milestone locks, behavioral anomaly detection (v1+1)                 |
| RR-4    | Cross-vault contagion                            | Low      | D-046 (depth limit 2); factory-level insurance (deferred)     | If meta-vault A holds shares in vault B, B's failure impacts A                | Cross-vault insurance (D-015, D-039); composition depth enforcement      |
| RR-5    | Oracle consensus failure                         | Low      | D-021 (multi-oracle); D-067 (no-spot-assumptions)             | If all oracles fail simultaneously, NAV falls back to idle-only valuation     | D-030 (fee-implied vol as zero-cost backup oracle)                       |
| RR-6    | Regulatory action against ERC-8004               | Low      | Adapter pattern allows registry swap                          | Regulatory prohibition of agent identity standard would break identity gating | Alternative identity providers; adapter can route to non-8004 registries |
| RR-7    | Smart contract bug in vault core                 | High     | Audit (P5); invariant tests; fork tests                       | Pre-audit code has unknown vulnerability probability                          | Formal verification of core invariants; bug bounty program               |

***

## 4. Threat-to-Layer Mapping

Summary mapping each adversary type to the safety layers that defend against them.

| Adversary                  | Primary Defense Layers                           | Secondary Defense Layers                      |
| -------------------------- | ------------------------------------------------ | --------------------------------------------- |
| Malicious vault creator    | 7 (on-chain guards), 3 (policy engine)           | 9 (reputation), 0 (identity)                  |
| Compromised manager agent  | 4 (time-delayed proxy), 5 (cancel authority)     | 1 (TEE), 3 (policy engine), 6 (simulation)    |
| External MEV bot           | 7 (on-chain slippage caps), 10 (circuit breaker) | LaunchFeeHook, TWAMM rebalancing              |
| Prompt-injected agent      | 2 (prompt defense), 2.5 (MCP integrity)          | 4 (time delay), 5 (cancel authority)          |
| Oracle manipulator         | 10 (NAV circuit breaker), D-067 (no-spot)        | D-062 (staleness gates), D-021 (multi-oracle) |
| Griefing attacker          | 0 (identity gate), 7 (on-chain guards)           | Gas costs, minimum amounts                    |
| Identity thief             | 0 (reputation decay on transfer)                 | Velocity signal detection, 9 (reputation)     |
| Compromised infrastructure | 4 (time-delayed proxy), 1 (TEE as depth)         | 3 (policy engine), 5 (cancel authority)       |
