Concepts › Trust model
This page lists who holds which permissions on each contract, so you can decide how much trust is appropriate before onboarding users.
Summary
- A single Owner wallet (0x4aFd0A931176103d704Ff0d696614d4E10d74A4a) owns every contract on both chains. No multisig, no timelock: every change takes effect in the next block.
Owner permissions by contract
| Contract | Owner can |
|---|---|
| USDw | mint without limit; change name/symbol |
| TokenFactory · price-tracker tokens | change the minter, change mint caps, change name/symbol, transfer token ownership |
| OracleRebalancer | change parameters (threshold, step, daily cap…), set the keeper, pause, withdraw the contract's assets |
| ClpPools | create pools, enable/disable individual pools, change the minimum fee (up to 10%), pause; withdraw Owner-provided liquidity.
sweep only recovers funds sent by mistake — it cannot withdraw pool depth |
| OracleAMM | deposit/withdraw liquidity, change spread / per-trade cap / max price age, change the price feed, change the peg ratio, pause |
| BtcwPriceFeed · PriceHub | write prices manually (ownerSubmit), change the updater, change the price-jump limit |
| Bridge routers (4) | pause, enable the allowlist, and every permission of a Hyperlane warp route: change the ISM, hook, remote routers — meaning it is technically possible to allow vault withdrawals without a matching deposit |
All of these permissions can be read in the verified source code on the explorer. We are not aware of any permission outside the list above.
Integration risks
Code: BETA — not independently audited. Internal testing and rehearsals on a fork of the live chain are no substitute for an audit.
What you should do
- Read
paused(),allowlistEnabled()and price age before every action — don't hardcode them. - Monitor parameter-change events (
ParamsSet,PausedSet,UpdaterSet,MinFeeSet,AllowlistEnabledSet…) if you hold user funds. - Cap the amount users deposit at what you are prepared to lose.
Self-verifiable figures (genesis, block cadence): Transparency page.