Security & disclosures
What we have — and have not — proven
ZecVault is not audited. Real-money draws stay disabled until independent security audits and legal review are complete and published here.
Audit reports
- Protocol specificationSeeking independent cryptographic review.Not started
- Reference implementationInternal unit tests only.Not started
- Settlement & key managementRequired before any real-money draw.Not started
- Legal & regulatory reviewReal-money draws disabled until complete.Not started
Administrative permissions
| Role | Can | Cannot |
|---|---|---|
| Operator spending key | Sign treasury payouts. | Change a published snapshot, seed, or winner without detection. |
| Coordinator | Open/close draws, delay settlement, censor entries before close. | Pick winners or claim prizes without a credential. |
| Viewing key holders (public) | See treasury inflows. | Spend funds or see participant identities. |
Threat model
- Operator manipulation: mitigated by seed pre-commitment and a post-close public beacon.
- Duplicate claims and replay: mitigated by nullifiers stored under a unique constraint.
- Payout redirection: mitigated by binding the nullifier to the payout address.
- Phishing: ZecVault never asks for seed phrases or spending keys. Any page that does is fake.
- Deanonymization: shielded transactions protect amounts and parties, but deposit timing can leak. We do not claim complete anonymity.
- Censorship: the coordinator could ignore a deposit before close. Depositors can prove inclusion of their memo transaction and publicly contest a snapshot.
Responsible disclosure
Report vulnerabilities to security@zecvault.fun. Please allow 90 days before public disclosure. We will acknowledge reports within 72 hours.