sica-fondt/core/docs/plans/M4-wallets.md

3.6 KiB

M4 — Wallets (sovereign custody)

1. Component

The economy organ's vault: sovereign, local-hosted, our-custody-only cryptocurrency wallets. Each wallet binds to exactly one Trader (M5) — strictly 1:1 both directions. A single wallet handles multiple chains internally (EVM, Solana, etc.). A trader without a wallet cannot access the Marketplace (M1). Wallets hold keys, sign transactions, and enforce wallet-level trade limits. Tax is collected on trader income and routed to the Verschwörern Veregeister wallets (stub — M0).

2. Status / certainty

DESIGN-FIRST · ABSENT. Role C4 (sovereign custody is a hard requirement); implementation C1.

3. Language & location

TBD · src/economy/wallets/. Needs cryptographic key management (secp256k1 for EVM, ed25519 for Solana, etc.)

4. Does / does-not

  • Does: generate and store private keys locally (never transmitted); sign transactions on behalf of the bound trader; enforce per-wallet spending limits (daily, per-transaction); track wallet balance and transaction history; collect tax on realized income and stage for transfer to Verschwörern Veregeister wallets; bind 1:1 to a Trader (M5).
  • Does-not: decide what to trade (Trader decides); route to chain (Marketplace does); hold keys for the organism's other wallets (Verschwörern Veregeister are separate); delegate custody to any third party — ever.

5. Interface contract

  • sign(wallet_id, tx: UnsignedTransaction) -> SignedTransaction — signs with the wallet's key. Only the bound trader can request signing.
  • balance(wallet_id) -> { chain, assets: [{ token, amount }] }.
  • spending_check(wallet_id).
  • taxes are out of scope

6. Dependencies & stubs

  • M5 Traders — 1:1 binding; stub: canned trader ID.
  • M1 Marketplace — signing requests come through marketplace only; stub: direct sign call.
  • Blockchain nodes — balance queries and tx broadcast; stub: simulated chain state.
  • Verschwörern Veregeister wallets — tax destination; stub: log transfer.

7. Invariants / laws

  • L1 (C5): sovereign custody only — private keys are generated locally, stored locally, and never leave the wallet. No custodial service, no exchange deposit, no trust with external parties. Our keys, our coins.
  • L2 (C5): 1:1 trader binding — each wallet is bound to exactly one trader. A trader cannot use another trader's wallet. The Marketplace enforces this.
  • L3 (C4): signing requires Marketplace confirmation — a wallet will not sign a transaction that didn't receive direct authorization from Marketpakce (M1-L1). No direct signing API for traders.
  • L4 (C4): spending limits are wallet-level — independent of Conductor or Marketplace limits. Defense in depth: even if other rules fail, the wallet itself caps exposure.
  • L5 (C4): tax collection is automatic — realized income triggers tax staging. The trader cannot opt out. OUT OF SCOPE

8. Build steps

  1. Implement key generation and secure storage.
  2. Implement transaction signing for one chain.
  3. Implement trader binding and Marketplace-only signing enforcement.
  4. Implement algorithmic limits.

9. Tests

Custody: private key never appears in any response, messages, or log. Binding: wrong trader cannot sign. Trade limits: over-limit transaction rejects; risk :: reward ratio below-limit rejects. Tax: out of scope. Multi-chain: every chain produces valid signatures.

10. Open items

  • Key storage format.
  • Which chains to support initially. (all of them)
  • Spending limit configuration (correction: This is algorithmic and hardcoded.)
  • Key rotation / backup strategy.