Misthos

Security and privacy

The controls that protect funds, keys, and contributors' data.

Funds

  • You own the vault. Misthos never takes custody. You can withdraw at any time, even while the vault is paused.
  • The agent is limited by the contract. It can only register payout wallets and propose and execute rounds, and every payout is checked against your caps. See Guardrails.
  • Hijacked accounts can't redirect pay on the spot. New or changed payout wallets wait out a cooldown.

Keys

  • The agent is a Circle developer-controlled smart-contract wallet with gas sponsored by Circle Gas Station. No raw agent private key runs in production.
  • The web app never holds a signing key. Human overrides are validated by the web app and signed by the worker.
  • Secrets live only in the hosting provider's secret store and are never logged.

The agent

  • Submitted content is untrusted. It's fenced in a per-request random boundary, and the model's output must match a strict schema.
  • Attempts to instruct the grader are detected in code and always go to a person.
  • The model never decides alone: plain rules turn flags and scores into actions, and facts like authorship override anything the model says.

The web app

  • Owners sign in with Sign-In with Ethereum (domain, chain, freshness and single-use nonce checked; EOA or ERC-1271).
  • Contributors sign in with X (OAuth 2.0 with PKCE). The X token is revoked right after reading the profile.
  • GitHub accounts are proven with "Connect GitHub" (OAuth, no scopes, token revoked immediately). Pull requests and commits are paid only when the author's GitHub id matches the connected account; typed usernames aren't trusted.
  • Payout wallets are proven with a signature over a message bound to the program, X account, wallet, chain and a single-use nonce.
  • Every state-changing request checks its origin, validates input and checks program membership.
  • Fetching submitted articles is guarded against server-side request forgery: public http(s) only, every resolved address checked, redirects re-validated, size and time limits.

Privacy

Misthos reads only the links contributors submit. It keeps the fetched content to evaluate it, the contributor's X id, handle and account age, the connected GitHub account (id and login), and payout wallet. Public audit pages show handles, wallets, amounts, summaries and hashes.

Reporting a vulnerability

Report privately through a GitHub security advisory on the repository rather than a public issue.