How it works
Five pieces: a vault, a delay, a cancel button, a backup wallet and an optional silence clause. Each one is simple. Together they make a stolen key almost useless.
The vault
A Hillfort vault is a small smart contract that belongs to one wallet, the owner wallet. You create it once. There is exactly one vault per owner wallet, and it cannot be shared.
The vault holds Stock Tokens, USDG and any other ERC-20 token. You deposit by sending tokens to it, the way you would send them to any address. Deposits are instant and carry no Hillfort fee (network gas still applies on mainnet).
Inside the vault, assets are idle. In this first version there is no lending, no yield and no trading. The vault's only job is to hold, and to let go slowly.
The delay
Nothing leaves the vault immediately. To take tokens out, the owner requests a withdrawal. The request names the tokens and the amounts. From that moment a timer runs. Only when the timer ends can the owner execute the withdrawal and receive the tokens.
- The default delay is 24h.
- The owner can pick any delay from 6h to 7 days, in steps of 1h.
- The request is public on-chain from the moment it is made. Anyone, including your other devices and your backup wallet, can see it.
The delay also guards the settings that could make the vault weaker:
- Lengthening the delay applies at once. Making the fort stronger never has to wait.
- Shortening the delay waits for the current delay first. A thief cannot cut the delay to 6h and withdraw in the same breath.
Cancelling
While a withdrawal is pending, it can be cancelled by the owner wallet or by the backup wallet. Cancelling is free, can happen at any time during the delay, and takes effect immediately. The tokens stay exactly where they were.
Cancelling is the normal response to a request you do not recognise. If you did not ask for the withdrawal, someone else holds your key, and your next move is the rescue described below.
The backup wallet
When you create the vault you name a second wallet, the backup wallet. It should be a separate cold wallet with its own seed phrase, kept offline, and it must never share a seed phrase with the owner wallet. A backup on the same seed is no backup at all: whoever has one has both.
In day-to-day use the backup wallet can do two things:
- Cancel any pending withdrawal, at any time during the delay.
- Rescue the whole vault: move every token to the backup wallet in one step. Rescue is only possible while a withdrawal is pending. In a quiet vault with nothing pending, the backup wallet can move nothing.
Rescue is the emergency exit. If a withdrawal appears that you did not make, the owner key is gone. Cancel it, then rescue everything to the backup wallet before the thief tries again. Rescue is free.
Changing the backup wallet waits for the current delay, like every change that could weaken the vault. Until the delay ends, the old backup wallet keeps its powers.
The silence clause
The silence clause is optional. It answers a different question: what happens to the vault if the owner disappears, through a lost key, an accident or death?
When the clause is on:
- If the owner takes no action on the vault for 12 months, the backup wallet can start a claim.
- A claim opens a public notice period of 30 days.
- During the notice period, any action by the owner cancels the claim. A single deposit, a settings change, anything.
- If the notice period ends without an owner action, the backup wallet can finalize the claim and receive everything in the vault.
Turning the silence clause on waits for the current delay. Turning it off is immediate, because that only makes the vault stricter.
The silence clause covers two cases the delay alone cannot: lost keys, where you can no longer act as the owner, and inheritance, where the backup wallet belongs to someone you trust to take over.
Putting it together
A normal withdrawal: request, wait 24h (or whatever delay you chose), execute. A withdrawal you did not make: cancel, then rescue. A vault whose owner has gone silent: 12 months of silence, a claim, 30 days of notice, finalize.
Every number above is a protocol parameter. Parameters lists them all, and Fees explains the one fee.
