Product guide · risk controls
Security & invariants
Security depends on the deployed code, its configuration, the selected assets, and the permissions assigned to each role. The following points describe the intended design. They are not a substitute for reviewing the verified Ethereum contracts and an independent audit before launch.
| Goal | Intended behavior |
|---|---|
| Basket backing | Vault balances should meet the configured backing requirements for shares in circulation. |
| Limited asset movement | Assets should leave custody only through redemption or approved, bounded swaps. |
| Redemption access | Administrative roles should not be able to pause or arbitrarily block in-kind redemption. |
| Fixed asset set | The basket should use the assets selected at deployment; rebalance requests should not add new assets. |
| Restricted guardian | Guardian powers should be limited to documented safety actions and role management. |
| Role | Intended permissions | Intended restrictions |
|---|---|---|
| Guardian | Pause minting, lower an active supply cap, and manage specified roles. | No asset withdrawals, redemption pause, cap increase, or changes to fixed basket rules. |
| Rebalancer | Submit rebalance requests within configured limits. | No minting, arbitrary transfers, or access to unrelated administrative functions. |
| Holder | Transfer shares and redeem under the deployed rules. | No authority over the vault's administrative configuration. |
The existing contract repository contains unit, fuzz, invariant, adversarial, and network fork tests. Those results apply to the code and configuration that were tested; they do not certify a new deployment, new assets, or a different network. The Ethereum V2 release should be tested against its final configuration and independently audited before launch.
- Invariant tests exercise backing and asset-movement rules across generated action sequences.
- Adversarial tests cover hostile routers, reentrancy, restricted tokens, and boundary conditions.
- Fork tests exercise contract behavior against deployed contracts on the configured network.
- Configuration review checks token addresses, oracle feeds, units, roles, fees, and supply limits.
- Asset issuer risk. Tokenized assets may be subject to issuer terms, transfer restrictions, or freezes that can affect deposits and redemptions.
- Oracle risk. Stale or incorrect prices can disrupt valuation and rebalance checks even when redemption does not rely on prices.
- Software risk. The V2 Ethereum contracts have not launched. No code is risk-free; review audits, verified source, and deployment parameters before use.
- Market risk. Basket values can fall, liquidity can change, and transaction execution may incur fees or slippage.
Before launch
The previous deployment is not the Ethereum V2 release. Review the new contract addresses, verified source, audit results, and configuration when they are officially published.