01 / System overview
A self-custody application coordinating user intent, transaction simulation and isolated signature requests.
Transaction simulation and permission isolation were strengthened following the assessment.
02 / Architecture diagram
N1User Session
N2Intent Parser
N3Simulation Engine
N4Signer Boundary
N5Network Gateway
03 / Assessment scope
Transaction construction
Signature requests
Session management
Recovery process
Malicious-token handling
04 / Threat model
T-01
Intent substitution
T-02
Session capture
T-03
Blind signing
T-04
Malicious token callback
05 / Findings by severity
High1
A transaction-intent boundary could be made ambiguous.
Medium3
Session scope and simulation consistency.
Low2
Recovery messaging and defensive defaults.
06 / Remediation timeline
Day 01–04Client and signer-boundary mapping
Day 05–10Hostile transaction and token simulation
Day 11–14Permission-isolation retest
07 / Current status
Remediation validated
All findings were tracked through the described remediation phase. Status reflects the case-study review lifecycle.
08 / Case-study summary
“Transaction simulation and permission isolation were strengthened following the assessment.”
Technical case study — not an audit certificate