Skip to main content
This page describes implemented controls in the reviewed source. It does not certify a deployed version or establish an audit or bounty program.

Contract controls

Pool pause blocks deposit, redemption, and borrow, while repayment accounting stays available. AccountManager pause also blocks liquidation, while owner repayment and settlement remain available. Standalone collateral top-ups and explicit account close also omit the manager pause check. Registry queue methods apply immediately before configuration finalization, so timelock protection must not be assumed during bootstrap. Separate flags must be checked independently.

Upgrade and execution policy

Contracts expose privileged upgrade paths where listed in the reference. AccountManager’s live post-exec/post-borrow health gate defaults to true but can be disabled by admin. Do not claim immutable deployment behavior or an unconditional live health check after every strategy action.

Liquidation and data limits

Liquidation takes remaining collateral, including external positions handled by dedicated exit/transfer paths. It is not a capped fixed-bonus seizure. Plain-collateral pricing failure blocks the liquidation attempt; other missing valuation data has different handling. Historical fixtures, cached dashboard data, and configured addresses cannot establish that a transaction is currently safe or executable. Read the selected contracts and simulate the actual operation.

Application signing

Freighter and configured Privy flows sign transactions through the wallet adapter. Mercury credentials remain in server routes. Copilot delegated signing adds explicit wallet binding and signer consent; external signing-service operation is outside these two source trees. No public audit conclusion, bounty terms, or incident-response promise is inferred from filenames or development comments. See Review Scope.