BETA — mainnet live (chain 482120); features are still being finished. Transparency →
Bitcoin Swap BETA Chain 482120
Developers · Concepts

Trust model

Who controls what and what they can do — know this before you integrate.

Concepts › Trust model

This page lists who holds which permissions on each contract, so you can decide how much trust is appropriate before onboarding users.

Summary

Owner permissions by contract

ContractOwner can
USDwmint without limit; change name/symbol
TokenFactory · price-tracker tokenschange the minter, change mint caps, change name/symbol, transfer token ownership
OracleRebalancerchange parameters (threshold, step, daily cap…), set the keeper, pause, withdraw the contract's assets
ClpPoolscreate pools, enable/disable individual pools, change the minimum fee (up to 10%), pause; withdraw Owner-provided liquidity. sweep only recovers funds sent by mistake — it cannot withdraw pool depth
OracleAMMdeposit/withdraw liquidity, change spread / per-trade cap / max price age, change the price feed, change the peg ratio, pause
BtcwPriceFeed · PriceHubwrite prices manually (ownerSubmit), change the updater, change the price-jump limit
Bridge routers (4)pause, enable the allowlist, and every permission of a Hyperlane warp route: change the ISM, hook, remote routers — meaning it is technically possible to allow vault withdrawals without a matching deposit

All of these permissions can be read in the verified source code on the explorer. We are not aware of any permission outside the list above.

Integration risks

Code: BETA — not independently audited. Internal testing and rehearsals on a fork of the live chain are no substitute for an audit.

What you should do

Self-verifiable figures (genesis, block cadence): Transparency page.