Skip to main content
RiskEngine values collateral and debt in USD WAD and exposes borrow, withdrawal, execution, and liquidation checks.

Health factor

HF = collateral_usd / debt_usd. Healthy means strictly greater than 1.1; a priced account with debt at or below 1.1 is liquidation eligible, subject to execution checks. get_health_factor returns a WAD u128, or u128::MAX for zero debt. For a new gross borrow B, the standalone guard evaluates (C + B) / (D + B). Existing borrowed proceeds already included in C are not added a second time. AccountManager/SmartAccount fast paths and net borrow credits must also be respected; this formula is not a transaction quote.

Collateral valuation

Plain tokens use registered metadata, native decimal conversion, and canonical oracle feeds. Explicitly revoked collateral is excluded. Tracking positions use Registry TrackingMeta: LP pool USD value is 2 × min(USD value of each reserve side), not the unrestricted sum of both sides. Freeze/revocation and missing data can remove collateral value. Borrow/withdraw snapshots may use cached Blend/LP values; liquidation reads its own snapshot and external positions. LP collateral is not categorically zero.

Liquidation-safe reads

liquidation_snapshot returns (collateral_usd_wad, debt_usd_wad, unpriceable_plain). AccountManager refuses liquidation when unpriceable_plain is true. Missing debt resolution or debt prices receive conservative maximum-value treatment. Some unavailable external collateral contributes zero. A displayed HF is therefore insufficient to guarantee liquidation execution. AccountManager may use SmartAccount prechecks instead of calling these standalone guards. Its admin-configurable live gate also controls post-borrow RiskEngine checks. Admin can pause guarded operations, change Registry, transfer administration in two steps, and upgrade WASM. Read deployment and liquidation configuration getters to inspect the selected contracts.

Function signatures

These signatures are copied from the reviewed Rust implementation. env is supplied by Soroban and is not a transaction argument. Result errors and panics must be handled by the caller; simulation does not guarantee later execution. Public methods include privileged and internal-contract callbacks, not just user entrypoints.

__constructor

get_liquidation_config

get_deployment_config

is_borrow_allowed

lp_position_usd_wad

account_usd_totals

account_usd_totals_liq_safe

has_unpriceable_plain_collateral

is_deposit_borrow_allowed

is_withdraw_allowed

is_account_healthy

get_health_factor

get_health_factor_threshold

get_current_total_balance

get_total_balance_liq_safe

get_current_total_borrows

get_total_borrows_liq_safe

debt_usd_wad

is_still_healthy_after_execute

is_currently_healthy

liquidation_snapshot

is_account_healthy_liq_safe

mul_wad_down

upgrade

set_registry

propose_admin

accept_admin

set_paused

is_paused

Source reference

  • Protocol_V1_Soroban_testnet/contracts/RiskEngineContract/src/risk_engine.rs