Controller eras
Controller rotation or recovery increments generation, invalidating signed envelopes from the previous era.
TWIX Meta is a CosmWasm smart-account authorization layer. An ordinary Ethereum EOA signs domain-separated EIP-191 intents; the smart account recovers the controller, validates the full envelope, and emits native Cosmos messages only when every security condition passes.
Recipient, amount, relay fee, account, controller, chain, nonce, generation and expiry live inside signed intent boundaries. The relayer cannot silently rewrite them.
v0.2 expands the original proof into a security model designed to constrain authority instead of making a smart account generically omnipotent.
Controller rotation or recovery increments generation, invalidating signed envelopes from the previous era.
Execute, admin, recovery and session authorization use independent nonce spaces and signed domains.
Max-per-transaction and block-window budgets account for native action value plus relay fees.
Sessions have their own epoch, nonce, expiry, permission bitmask and native spend budgets.
Current controller authorizes the change; the proposed new controller independently accepts it.
Optional recovery requires guardian authorization, new-controller acceptance and a minimum delay.
Fees are signed, capped and optionally bound to one exact Cosmos relayer.
Controller Wasm execution requires explicit account permission and an allowlisted target; sessions cannot use generic Wasm in v0.2.
The factory can control future account templates. Existing individual Meta Accounts are instantiated without a Wasm admin.
The two deployments are intentionally separate so new security work cannot retroactively change the evidence produced by v0.1.
cosmos1qhcf6sr7xtr9zaw6wk7s44209yctdv4ykzf2hy7vuk8vkwjn3z3ssdfyfk04D5F17D8A7CF6D6FA8C30B9E01CFC6435061D15822EB97BB630B841A466E447cosmos1xw0rqrjgekrerjrz55n09ezuajcdw2pqp204w2kdsya7szmx55ssug3f89cosmos14u8hrq7tez3e3pdlhyg4jtgp6jk3jdyzfq9vl3srzclzxl6680qq9np325