Rule Craft
DocsThreat modelMenu

Security

Threat model

Who might attack a pool with rules, and what stops them.

Snipers at open

Bots buying in the first block. Mitigated by Snipe Guard's per-block cap and guard tax.

A creator changing rules later

Mitigated by freezing every parameter at creation. RuleCraftHook has no owner and no function that edits a live pool.

A creator pulling liquidity

Mitigated by Liquidity Timelock on the founding position, which the launcher holds and releases only to the creator after the unlock time. The unlock time is readable on the pool page before buying.

An admin taking funds

There is none to take them. No contract has an owner; the launcher's one-time setHook only wires the hook, and the treasury and protocol share are fixed in the registry constructor.

Look-alike hooks

Anyone can deploy a hook and call it anything. Check the hook address against the published RuleCraftHook address on the contracts page.

Front-end compromise

Your wallet shows what you sign. Contract addresses are listed in the docs, the footer and on chain; compare before signing.