Snitch
← back to blog
·Snitch Team

Security tools should not hold your keys

There is a temptation to make a security product powerful by giving it write access: auto-pause the contract, auto-move funds to a safe wallet. Every one of those powers is also a way to drain you if the product is wrong or compromised.

The design rule

Snitch is read-only by construction. It watches public chain state and the mempool. It never signs, never holds funds, and never needs a private key. A total compromise of Snitch yields no ability to move a single wei of yours.

Who acts on the alert

You or your automation. The alert is signed, so your response playbook can verify the source before acting. The decision stays where the keys are.