Cosigner Security
Cosignatures on orders allow an order book to offer users the ability to gaslessly cancel their listings and offers. To guard against bad actors order books MUST keep the private keys of the cosigning accounts secure and SHOULD use short expirations on cosignatures so that signed but unexecuted cosignatures are unlikely to be used after the maker has cancelled their order off-chain.
If the private key to a cosigner account has been exposed the order book MUST destroy the cosigner through Payment Processor on all chains that it was used as an order cosigner so that it may not be used to fill off-chain cancelled orders. Cosigners cannot be recovered after they have been destroyed on Payment Processor.
Destroy a Cosigner
- Use the cosigner private key to sign the message
COSIGNER_SELF_DESTRUCT. - Call
destroyCosigneron Payment Processor with the cosigner address and message signature. See encodeDestroyCosigner.
