What Hillfort protects against, and what it does not
A vault is only useful if you know where its walls end. This page is the frank version.
What Hillfort protects against
A stolen owner key
If someone gets your private key or seed phrase, they can request a withdrawal, but they cannot execute it before the delay ends (24h by default). The request is public. You cancel it from the owner wallet or the backup wallet, then rescue everything to the backup wallet. The thief leaves with nothing.
A malicious signature or approval
A signature that tricks your wallet into approving a transfer only reaches tokens that sit in the wallet. Tokens in the vault cannot be moved by an approval; they can only leave through a withdrawal request, and that request waits.
A compromised device
Malware on your everyday computer or phone has the same problem as a thief: it can start a withdrawal, it cannot finish it quickly, and the backup wallet on a separate device can stop it.
Losing your own key
With the silence clause on, a vault whose owner has gone quiet for 12 months can be claimed by the backup wallet after a public notice of 30 days. Lost keys stop being a total loss.
Inheritance
The same clause lets a trusted person take over the vault if you are gone, without a custodian, a lawyer or a password written in a drawer.
What it does not protect against
Smart contract bugs
The contracts are not deployed and have not been audited. A bug in the vault could lock or lose funds. Until an audit is published, treat Hillfort as unproven. See Risks and disclaimers.
An issuer pausing or freezing a Stock Token
Stock Tokens and USDG are issued by companies, and those companies can pause transfers, freeze addresses or change their contracts. The vault holds the token; it cannot override the issuer. If an issuer freezes a token, it is frozen inside the vault too.
Both keys compromised
If a thief holds the owner key and the backup key, they can request, undo your cancellations and rescue to themselves. Two keys on one seed phrase are one key. Keep the backup wallet on separate hardware, with a separate seed, in a separate place.
Tokens kept outside the vault
Hillfort only protects what is inside. Tokens left in your wallet for convenience are as exposed as they ever were. The vault is not a setting on your wallet; it is a place you have to put things.
Ignoring a pending withdrawal
If a withdrawal you did not make sits unnoticed for the whole delay, it executes. Hillfort gives you time; it does not watch for you. Choose a delay long enough to notice, and check the vault from more than one device.
A backup wallet on the same seed phrase
Said once more because it is the most common mistake: if the backup wallet is derived from the same seed as the owner wallet, every protection above collapses. Use a different seed.
Market risk
Hillfort does nothing about the price of what you hold. Assets in the vault are idle in this version: no yield, no hedging, no trading. A Stock Token that falls in value falls in value inside the vault too.
The short version
Hillfort turns "my key was stolen" from an instant loss into a race you are set up to win. It does not make the key unstealable, it does not audit itself, and it cannot act for you. The rest is up to how you set it up: a real cold backup wallet, a delay you can live with, and the habit of looking.
