Security

Respect the hook. Fail closed.

HOOKWAY finds valid execution paths; it never bypasses a hook's rules. When it can't verify something, it says so and offers no route.

Trust labels

  • Verified

    Source verified against the deployed program and manifest reviewed by HOOKWAY.

  • Known

    Recognised program with a published manifest; source not independently verified.

  • Unverified

    No verified source or manifest review. Simulation-only guarantees.

  • Upgradeable

    An upgrade authority can change this hook’s rules at any time.

  • High Risk

    Opaque behaviour, arbitrary CPI, or recent unexplained upgrades.

  • Unsupported

    HOOKWAY cannot resolve this hook’s accounts or simulate it safely. No routes.

Threat model

ThreatWhy it mattersMitigation
Malicious hook programsHooks run arbitrary code on every transfer.Unknown hooks are never labelled safe. No manifest ⇒ raw simulation only, low confidence, explicit acknowledgement before signing.
Upgraded hook logicAn upgrade authority can change rules after indexing.ProgramData last-deploy slot is checked at route time; a change since indexing invalidates the cached manifest and route.
Account substitutionA route could pass a look-alike account to the hook.Every extra account is re-derived from the on-chain ExtraAccountMetaList seeds at build time; manifest seeds are only cross-checks.
Spoofed manifestsA program claims another hook’s manifest.Manifests are bound to program ID + upgrade authority. Any mismatch fails closed (see $FORK).
Stale cacheBalances, allowlists and clocks move.Route cache entries carry slot + TTL; the final transaction is always re-simulated immediately before signature.
Incorrect simulationsPolicy adapters could drift from the program.Adapters explain; chain simulation decides. A route is valid only if the real simulateTransaction passes.
RPC inconsistencyOne RPC can lag or lie.Simulation pins minContextSlot; live mode supports a second RPC for quorum checks on mint + program state.
Malicious token metadataNames, symbols and URIs are attacker-controlled.Metadata is rendered as text only, never as HTML; URIs are not fetched server-side without allow-listing.
Arbitrary CPIHooks can call other programs.Simulation logs are scanned for invoked programs; unrecognised CPI downgrades confidence and raises High Risk.
Transaction tamperingA built transaction could be altered before signing.SDK returns the full account list + message hash alongside the transaction so wallets can show and verify it.
Unsafe route assumptions“It worked last time.”No route is shown as valid without a fresh simulation; failures and unknowns are reported, never defaulted to success.

Full document: SECURITY.md in the repository. HOOKWAY has not been externally audited.