Pear Vault Servicevia Shieldify
Zealynx reviewed the Pear vault service, the NestJS backend that isolates Privy credentials and owns all vault-related state for Pear's Hyperliquid ecosystem, delivered as an external contractor engagement for Shieldify. The review covered the full custody and signing surface: EIP-712 request authentication and RS256 JWT verification, the Privy-backed agent-wallet signing path used to sign Hyperliquid orders, vault creation and deactivation workflows on HyperEVM, agent operations such as approvals, unified-account configuration and swap-and-transfer, the deposit and withdrawal event indexer, and the NAV poller behind the chart APIs. Emphasis was placed on what a compromised or merely over-privileged caller can sign, on authority that outlives the role that granted it, and on the atomicity of workflows that move funds across the service, Privy and the chain. Findings were raised as issues throughout the engagement, each labelled with a severity and an evidence level recording whether it was demonstrated against the running service or established by source analysis. Mitigation review is underway; the report and findings are being prepared for publication.
0C0H0M0L0IHyperliquidTypescripttypescriptnestjsbackend