Skip to main content

Security model

The signer group today​

The FROST signer group holds frFB's mint authority (frFB-AUTH, 2:102485) on Bitcoin and fb-vault's custody key on Fractal, at the same taproot address on both chains. The protocol is 6-of-9: six seats must sign.

Not yet independent signers

Today all nine seats run on a single host, operated by SUBFROST, from a key set up by a single trusted dealer. The 6-of-9 threshold is therefore a property of the protocol, not yet an operational security boundary: the operator could produce a signature on its own. Until federation is complete, frFB custody trusts SUBFROST as operator.

Federation is in progress. External co-signer firms will each run their own seat, on their own infrastructure, from the published v2.0.0-rc1 release binaries. This page will be updated when it lands.

What holds by construction, today:

  • Signers talk over an encrypted overlay. Group traffic runs over SUBFROST's peer-to-peer network, onion-routed and sealed with a hybrid post-quantum key exchange (Kyber + X25519). It is not exposed as a public endpoint.
  • Each signer co-signs only what it derived itself. Every signer runs the same published program against chain state and builds the mint transaction on its own. It signs a proposal only if it is byte-for-byte the transaction it derived. A proposal it did not derive gets no signature.
  • Fail-closed AUTH preflight. Nothing is signed unless a replay shows mint authority returning to the group (see below).

What does not hold yet: independent operators and hosts. With every seat under one operator, these checks constrain the signing software, not the operator.

Your deposit​

  • Your intent is in your address. The gateway address is derived from the intent bytes (recipient, sweep fee, action). Change one byte and it is a different address, so nobody can re-point a deposit after the fact. Always derive the address yourself, or with a client that does (the SUBFROST apps and subfrost-cli recompute and compare before showing it).
  • The action names a route and its bounds, nothing else. Every contract id (frFB, frBTC, the pools, frUSD, FIRE) comes from the signers' own configuration. The group wires every transfer, so a route can only ever move the frFB minted for that deposit.
  • Every step refunds to your recipient. If any leg reverts, what it held (frFB, frBTC, frUSD) is returned to the recipient script, never to the group or anyone else.

Fail-closed before signing​

Before the group signs a mint, it replays the complete transaction against current Bitcoin state (simulatetransaction) and only signs on a positive answer:

  • Mint authority must come home. The replay must show frFB-AUTH landing, whole, on the group's own output. An unavailable, unreadable or ambiguous answer means nothing is signed that round.
  • Every route leg must execute and meet its minimum. A main leg that would fail drops the route and the deposit is minted as plain frFB. A gas leg that would fail is dropped alone and its share joins the main route.
  • BTC must clear the floor. The frBTC reaching every unwrap (a BTC route or a BTC gas leg) must clear the unwrap floor, or that leg is dropped.
  • No answer is not a yes. If the replay cannot be read, routes are dropped (plain frFB is always safe) or the round waits.

Upgrades without surprises​

  • Existing addresses keep their meaning: version-1 actions decode and execute exactly as before, and their bytes are pinned by test vectors that the signers and the wallet core both assert.
  • FIRE, frUSD and the gas split use action version 2. A signer that does not know version 2 delivers such a deposit as plain frFB; it can never misread it.
  • Clients offer version-2 routes only while the gateway service's /v1/vault reports routes.max_action_version = 2, which the operator sets only after every signer runs it.
  • On Fractal, fb-vault and FB-SIGIL are compiled into the protofractal indexer, which refuses every deploy: no transaction can replace them. Rotating fb-vault's signer key requires bearing FB-SIGIL (22:4222), which sits inside the vault.

What you are trusting​

  • SUBFROST, as the operator of all nine signer seats until federation, to mint only what fb-vault recorded and to run the published route programs. After federation, the 6-of-9 threshold across independent operators.
  • The pools a route trades on, for price: your minimums bound the worst case, and a miss refunds rather than fills badly.
  • For BTC routes and BTC gas, the frBTC signer, to pay out the unwrap.
  • For STABLE, the frUSD peg-out and its EVM payout path (Across).