Threat Model and Trust Assumptions
Last updated
SatoshiNet safety is not a balance number. It is a set of verifiable exit evidence and trust boundaries.
Bitcoin L1 provides final settlement and dispute boundaries.
Indexers need cross-verification; a single indexer response is not final safety proof.
STP safety depends on valid channel state, commitment transactions, revocation material, punishment coverage, and wallet backup.
SatoshiNet nodes handle execution and block production, but do not replace Bitcoin L1 as the final boundary.
Wallets control private keys, seed phrases, authorization, and critical local state.
Agents can only read evidence and call adapters; they cannot store private keys or bypass signatures.
Core Node offline or refusing service.
Core Node broadcasting an old commitment transaction.
Wallet losing local state or backup.
Indexer divergence, unindexed state, or reorg.
Bitcoin L1 reorg.
SatoshiNet stopping block production.
Contract vulnerabilities.
Confusion between public channel contracts and private STP channel safety models.
SatoshiNet state is not unconditionally guaranteed by Bitcoin.
Indexers do not take responsibility for user private keys or authorization.
Agents do not make final signing decisions for users.
Contract assets and private channel assets have different safety boundaries.
Testnet validation does not mean mainnet has no risk.
Page Status: Planning
Last updated