Security model
What Orblivion is trusted with, what it isn't, what protects your funds at each layer, and what is left over. Read it before you give an agent real money.
The trust model#
Orblivion is non-custodial: it never holds your funds or your keys. It plans, simulates and relays; your key, on your machine, signs.
| Orblivion is trusted to | Orblivion is not trusted with |
|---|---|
| find a good route and quote it honestly | your funds: every transaction is one your key signs, or one a session you signed allows |
| relay what you sign, promptly | who gets paid, what leaves your wallet, which tokens, the fee, the deadline, the size, the minimum output: the SDKs read all of these from the transaction itself |
| tell the truth about the screens it runs (whether a token can be sold, whether it taxes transfers) and about Dossier's verdict | anything a server could change behind your back: the SDKs pin the chain, the contracts, the co-signer and the disclosure table, and refuse a server that disagrees |
Three layers protect a trade, from the strongest:
- The chain. What you sign is exactly what runs: the router's commands, the recipient, the minimum output, the deadline. For sessions, the root's caveats bound what any key can do: targets, methods, ETH per trade and per day, the number of trades, the expiry and who may redeem.
- Your client. The SDKs decode and check every transaction before your key signs it, and check what was mined afterwards. They don't import Orblivion's server code, so a bug in the server isn't a bug in them. See what the SDK checks.
- The co-signer, for sessions. A separate service with its own key, its own price readings and its own records, which co-signs a session trade only after its own checks. See Sessions.
Orblivion's own policy (the fee schedule, slippage caps, reference prices, size limits, the as-built relay) sits on top and catches bad data and mistakes. A compromised API server controls that layer, which is why the other three don't depend on it.
The co-signer's address is public#
Every session's root delegates to Orblivion's co-signer, and every hosted agent's executor is attested by it:
0x75211e73ceaf6f647783293258f0d6bc6a63e780It is public by design. The SDKs pin it, and refuse a server that names any other co-signer at a grant (CONFIG_MISMATCH) or an executor attestation it didn't sign (EXECUTOR_ATTESTATION). That stops the attack that matters here: a compromised server asking you to sign a session whose two keys it holds. Knowing the address gives nobody any power: the co-signer can't redeem a session on its own (only the executor can), and it holds no funds.
What is protected, and what isn't#
| Threat | What stops it | What is left |
|---|---|---|
| A server that builds a transaction paying someone else, pulling more, or charging more | the SDKs decode the calldata and refuse it before signing; the relay sends only what Orblivion built for your key | nothing, if you use an SDK or check as it does |
| A server that lies about price | the minimum output is held to the SDKs' own Chainlink readings, or their own quote of the same route for a token without a feed | for a token without any independent price, the SDKs' own quote of the same pool is the bound |
| A wallet extension or relay that rewrites your transaction | the SDKs compare the mined transaction with what they signed | the rewritten transaction is caught after it lands, not before |
| A pool pushed just before your trade | the route's price is checked against an independent reference where there is one; the minimum output bounds the rest | a token with no independent reference relies on the minimum output and the SDK's own quote |
| A honeypot or a transfer tax | Orblivion's buy-then-sell simulation discloses it, and it needs your acceptance | a token that behaves differently for your wallet than for the screen's, or changes after its screen, can still trap what you buy |
| An impersonator of a real project | Dossier Shield's verdict and its policies | without Shield, nothing checks a token's identity; Dossier's verdict is Orblivion's word and can be wrong |
| A stolen API key | it can't move funds; it lasts at most 30 days; POST /api/v1/auth/revoke ends it, and the wallet alone can end every key with POST /api/v1/auth/revoke-all | it can pause, stop or switch on that wallet's hosted agents within sessions already signed |
| A stolen executor key | each trade needs a co-signed leaf for one exact call, once, for two minutes | the executor's own gas money |
| Both session keys stolen | the root's caveats: ETH per trade, per day and in total, the ERC-20 budget, the expiry | within those caps, funds can go anywhere at any price. See If a key is stolen. |
| A stolen main key | nothing: it owns the wallet | everything in the wallet |
Accepting a risk loosens none of the checks above. Accepting HIGH_PRICE_IMPACT or AMOUNT_HOOK lets a trade be planned and signed; it never lowers its minimum, widens its price band or changes the call. And accepting UNSCREENED is in effect accepting HONEYPOT: see Tokens and risks.
What is public#
Your trades are public. Robinhood Chain has no public mempool, but its sequencer broadcasts every transaction it orders within milliseconds, and the chain itself is public. Anyone can see each agent's trades, their sizes and its wallet in near real time.
- Orbio's Incognito covers an agent's reasoning, not its trades. It encrypts the prompt to a model running in a trusted enclave, so Orbio doesn't see the owner's strategy or the agent's reasoning. The trades the agent then makes are as public as anyone's.
- There is no private relay. Ordering is first come, first served with no fee auction, so classic mempool sandwiching isn't possible, but trading right behind a visible trade is. Keep your slippage tight.
- Simulating a trade reveals it to the RPC provider that runs the simulation, shortly before it is sent.
Keys and secrets#
| Secret | Where it lives | If it leaks |
|---|---|---|
| Your wallet's main key | only on your machine | everything in the wallet |
| An executor key you run yourself | on the agent's machine | nothing beyond co-signed trades; see above |
| A hosted agent's executor key | only in Orblivion's signing service; the API servers see its address | as above |
| Your API key | your agent's environment. Orblivion stores only its SHA-256. | acting as your wallet at Orblivion, without moving funds; revoke it |
| A webhook secret | your server. Orblivion's signing service keeps it encrypted; the API servers never hold it. | requests to your webhook that pass its signature check; rotate it |
Orblivion never asks for a private key or a seed phrase, in any form.
Hardening your agent#
- Use a dedicated wallet that holds only what the agent trades.
- Set
maxNotionalUsd(max_notional_usd) in the client, andmaxFeeBps(max_fee_bps) to the most you mean to pay: 25 for an agent that trades only majors without Shield. - Pin what you can:
expect.feeRecipientandexpect.version. - Prefer a session over a hot main key for an autonomous agent: short, with small caps.
- Never let a model's output, a web page or a token's name decide
accept_risks. Set them in code, or in the session the owner signs. - Revoke approvals and sessions you no longer use (
POST /api/v1/live/revoke,/live/session/revoke). - Treat every string from the API (token names, symbols, risk details) as untrusted text: escape it before you display it.
Reporting a vulnerability#
Please report security issues privately to [email protected], not in a public issue. Include what you found, how to reproduce it, and its impact. We will acknowledge your report, keep you informed, and credit you if you wish. Please don't access other people's data or funds, and give us reasonable time to fix an issue before you disclose it.