Will & Key
Home › Security

Security, audit and contract status

Will & Key is live software with an immutable contract. Its current version has internal tests and reviews by AI agents, and no completed independent audit. Verify the evidence before using it.

Updated 28 September 2026

Current risk status: version 2 is live and not independently audited. It was written in response to a preliminary audit of version 1, performed in September 2026 by AI auditing agents at the project's request and not independent, which reported 47 findings (5 medium, 21 low, 21 informational). Since then version 2 has been reviewed only by AI agents of the same kind that wrote it: the audit's five fix-review rounds and a pre-launch review. Do not use material value until an independent third-party audit is complete. A full-duration Base Sepolia lifecycle test of version 2 has not been completed either.

Read the preliminary audit

Deployments on Base

ContractAddressStatus
InheritanceVault, version 20xA07b59d9249A996604A5fF482f1E564EdeE3A774Live since 28 September 2026
InheritanceVault, version 10xC821849A1D74959753450409b594b23eCE7fEe2fRetired: new vaults refused (see version 1)
Reminder billing0x60749aF621180de1DC05DB4f3d158D09dE979dC6Retired: every payment reverts

Version 2 was deployed on 28 September 2026 in Base block 51900754, transaction 0x4bbd4b1d74924f64e0c817ff1815ade20a0141094c091003ec1f527b86413e8e. Its constructor set the administrator and the fee recipient (the Ledger key 0x883C821103B5415C53B11E584D3592205B5CdCA3 for both) and the claim fee (0.5%), and fixed for the life of the contract the tokens a vault can hold: USDC, WETH, cbBTC and EURC, with WETH as the wrapped native token (see which tokens). The administrator, the fee recipient and the fee can change later only as described under administrator powers; the token list cannot change at all.

Paid reminder sales are disabled on this website and, since 26 September 2026, on chain as well. The administrator set the retired billing contract's monthly price to the largest value the contract can store, so every payment to it now reverts and it records no new paid time. Only the administrator could reverse that. The transaction, in Base block 51,823,544: 0xf3485b1b4ec0f887838a2eec5181c3815e68913bc23b68570c3b635693a56cca. The reminder service it once paid for no longer runs. Do not send funds to it or call it directly. Refund requests for earlier payments are handled under the terms.

Bytecode evidence

Version 2's runtime bytecode, read from Base after its deployment on 28 September 2026, and its source:

Version 2 has one immutable variable: the wrapped native token's address (WETH), which the deployment writes into the runtime code. So the code on chain is the compiled runtime with that address filled into one 32-byte slot, whose position is in the compiler output (immutableReferences). Basescan's verification allows for it; to compare by hand, fill the slot first.

The retired contracts have no immutable variables, so their compiled runtime and their on-chain code are the same bytes. On 10 August 2026 both were compared byte-for-byte with the local compiler artifacts and matched, and both are source-verified on Basescan. Their fingerprints, re-read from Base on 26 September 2026:

Earlier versions of this page labelled the two keccak-256 values as SHA-256. The values were right; the label was wrong. To reproduce any of them with Foundry's cast, replacing ADDR with a contract address:

Hashing the hex text instead of the bytes gives a different SHA-256 value. The build settings of all three contracts are Solidity 0.8.28, optimizer on with 200 runs, EVM target cancun. The source repository contains compiler settings, deployment records, tests, audit scope and the review reports. Version 1's deployed source is contracts/InheritanceVault.sol at the tag v1-base; a renamed copy, so that both versions compile side by side, is kept as contracts/v1/InheritanceVaultV1.sol.

Administrator powers

The administrator (owner) of all three contracts, and the fee recipient of both vault contracts, is a single Ledger hardware-wallet key, 0x883C821103B5415C53B11E584D3592205B5CdCA3. It is one key, not a multisig; moving administration to a multisig is recommended. Version 2 named it in its constructor, so it has held both roles there since the deployment on 28 September 2026, and the key that sent the deployment never held either. On version 1 and the billing contract it took over from the deploy key on 24 September 2026, in five transactions:

On the version 2 vault contract the administrator can do exactly this:

It cannot add or remove a token, take anything from a vault balance or credit beyond the settlement fee, change a beneficiary or any vault setting, cancel an owner withdrawal, block a valid claim settlement, raise a vault's fee above its creation-time ceiling, or make a raise, or a switch of fees back on, take effect in less than 30 days. Those limits are arithmetic in the bytecode, not promises. They rest on the fixed token list, whose tokens each live at one address and never change a balance on their own, and on every token payout, and every ETH payout to an address with code, being measured. They describe Will & Key, not token issuers: the issuers of USDC, EURC and cbBTC can pause, blocklist or upgrade their tokens, and so freeze every vault in that token at once, because all vaults in a token share one balance at the vault contract.

On version 1 the same key can pause or unpause creation, change the claim fee at once with no delay, change or unset the fee recipient, sweep surplus in any token, and transfer ownership in two steps. On the retired reminder contract it can change the price, withdraw its balance and transfer ownership.

Known limits of version 2

These are part of the design, disclosed rather than fixed. The mechanism page explains each one.

The retired version 1

Version 1, 0xC821849A1D74959753450409b594b23eCE7fEe2f, was the live vault from 9 August 2026 until 28 September 2026. It is immutable, so it could not be fixed or switched off. It was retired instead:

Review and testing

The contract is non-upgradeable. A serious contract finding requires a new deployment and a clearly communicated migration; it cannot be silently patched. The creation pause cannot stop deposits into existing vaults, so a migration notice would ask owners to withdraw in full, which closes the vault.

Website security

The interface is a static Cloudflare Pages deployment. Runtime dependencies are self-hosted. A restrictive Content Security Policy blocks third-party scripts, framing, objects, workers and unapproved network destinations. Chain-derived values are rendered with text nodes rather than HTML injection.

Report a vulnerability

Never publish working exploit details, a seed phrase or private key. Open a minimal GitHub issue asking for a private contact channel, identifying only the affected component and whether funds may face immediate risk. A report is not automatically eligible for a bounty; no bounty program is currently promised.