Security
Respect the hook. Fail closed.
HOOKWAY finds valid execution paths; it never bypasses a hook's rules. When it can't verify something, it says so and offers no route.
Trust labels
- Verified
Source verified against the deployed program and manifest reviewed by HOOKWAY.
- Known
Recognised program with a published manifest; source not independently verified.
- Unverified
No verified source or manifest review. Simulation-only guarantees.
- Upgradeable
An upgrade authority can change this hook’s rules at any time.
- High Risk
Opaque behaviour, arbitrary CPI, or recent unexplained upgrades.
- Unsupported
HOOKWAY cannot resolve this hook’s accounts or simulate it safely. No routes.
Threat model
| Threat | Why it matters | Mitigation |
|---|---|---|
| Malicious hook programs | Hooks run arbitrary code on every transfer. | Unknown hooks are never labelled safe. No manifest ⇒ raw simulation only, low confidence, explicit acknowledgement before signing. |
| Upgraded hook logic | An upgrade authority can change rules after indexing. | ProgramData last-deploy slot is checked at route time; a change since indexing invalidates the cached manifest and route. |
| Account substitution | A route could pass a look-alike account to the hook. | Every extra account is re-derived from the on-chain ExtraAccountMetaList seeds at build time; manifest seeds are only cross-checks. |
| Spoofed manifests | A program claims another hook’s manifest. | Manifests are bound to program ID + upgrade authority. Any mismatch fails closed (see $FORK). |
| Stale cache | Balances, allowlists and clocks move. | Route cache entries carry slot + TTL; the final transaction is always re-simulated immediately before signature. |
| Incorrect simulations | Policy adapters could drift from the program. | Adapters explain; chain simulation decides. A route is valid only if the real simulateTransaction passes. |
| RPC inconsistency | One RPC can lag or lie. | Simulation pins minContextSlot; live mode supports a second RPC for quorum checks on mint + program state. |
| Malicious token metadata | Names, symbols and URIs are attacker-controlled. | Metadata is rendered as text only, never as HTML; URIs are not fetched server-side without allow-listing. |
| Arbitrary CPI | Hooks can call other programs. | Simulation logs are scanned for invoked programs; unrecognised CPI downgrades confidence and raises High Risk. |
| Transaction tampering | A built transaction could be altered before signing. | SDK returns the full account list + message hash alongside the transaction so wallets can show and verify it. |
| Unsafe route assumptions | “It worked last time.” | No route is shown as valid without a fresh simulation; failures and unknowns are reported, never defaulted to success. |
Full document: SECURITY.md in the repository. HOOKWAY has not been externally audited.