Risk controls
What stops opcode from doing the wrong thing, including when part of opcode is broken or compromised. Some of these controls live in the application. The ones that matter most live in the settlement program on chain and bind every OPmode fill.
It stops rather than guesses
Each of these stops OPmode quoting in the affected market until it clears. Public chart prices are a separate reference series. OPmode does not fall back to token pricing.
| Condition | Detected by |
|---|---|
| No valid Pyth equity source at most five seconds old | Publication and quote preparation, then again before returning a quote |
| The token's on-chain configuration changed, or the issuer paused it | A read of the mint for every OPmode quote request, and again by the program at every fill |
| The share multiplier changed | The mint's own schedule, and the program at every fill |
| The exchange calendar is stale or its session is closed or unverified | Every Pyth quote; calendar freshness ends after two days |
| The pricing engine cannot be reached | Every OPmode quote request |
| The published reference has expired, at most 20 seconds after its source time | Every OPmode quote request, and the program at every fill |
| The on-chain reference no longer matches its verified Pyth record in the market's OracleConfig | Every OPmode quote request, and the program at every fill |
| An independent USDC price is outside $0.99 to $1.01, or more than 60 seconds old | Publication and every OPmode quote request; the check stops quotes and never changes the price |
Limits enforced on chain
Every market's configuration carries limits that the settlement program checks at every fill. They bind opcode's own quote key as much as anyone: a quote that breaks one fails, however validly it was signed.
| Limit | Bounds | Set on the OPmode markets | Hard ceiling in the program |
|---|---|---|---|
| Fee rate | What can be charged | 5 bps | 1% |
| Price band | How far a fill may be from the reference published on chain | 1% | 10% |
| Per-trade size | The largest single fill | 100 USDC on NVDAx; 20 USDC on the other nine | — |
| Vault floors | The least each vault may hold after a fill | one token atom; 1 USDC | — |
| Turnover window | Total notional within a fixed window | 500 USDC per 60 s on NVDAx; 100 USDC per 60 s on the others | a window of at most a day |
| Quote lifetime | How long a signature is good for | 30 seconds and 64 slots | 30 seconds and 128 slots |
| Reference age | How long after its source time a published reference can be used | 20 seconds and 50 slots, fixed by the program for Pyth-verified references; the configured field is 60 seconds and 160 slots | 300 seconds and 512 slots for the configured field |
opcode issues quotes for up to 10 seconds, inside the 30-second limit. Pyth sources must be at most five seconds old when a quote is issued, and published references expire at most 20 seconds after source time. Turnover uses fixed 60-second windows, so adjacent windows can permit a larger burst. Limits can be changed only while the market is paused, and changing them voids every quote signed under the old ones.
Separate keys for separate powers
| Key | Can | Cannot |
|---|---|---|
| Quote key | Sign quotes | Do anything else on chain. It cannot withdraw, list a market, or change a limit. |
| Reference key | Nothing on the ten OPmode markets, which are in a one-way Pyth-only mode | Publish a price, sign quotes or touch funds |
| Relayer | Pay the fees to submit a Pyth-signed report for on-chain verification | Choose the price: the program accepts only the verified report's bytes |
| Emergency key | Pause | Resume, or anything else |
| Participant policy key | Write per-wallet trading approvals, which the ten OPmode markets do not require | Sign quotes, publish a price or touch funds |
| Owner wallet | List markets, set up each market's Pyth oracle, set limits while paused, rotate the quote key, pause and resume, provide founder liquidity and redeem its own LP shares, collect protocol fees, and upgrade the program | Sign quotes |
The owner wallet is one key, FyRz7wPjrFqj6RAwk1EcrJfhFaEpnChXAm21MrdGKyw6. It is the program's administrator, the pools' treasury and the program's upgrade authority. There is no multisig and no timelock, and the program is upgradeable: an upgrade signed by the owner wallet can change any rule on this page. The program refuses to register or rotate a quote key that is the same key as any of the others.
If the quote key were stolen
This is the scenario the on-chain limits exist for. A thief with the quote key could sign quotes to themselves. They could not:
- price them more than 1% from a reference the program writes only from a verified Pyth report;
- exceed the per-trade size or the fixed-window turnover cap;
- take a vault below its floor;
- withdraw anything directly;
- continue once the owner wallet or the emergency key pauses the market, which voids everything already signed.
The reference-band exposure is about 1% of the turnover cap per fixed window, which is 5 USDC of the 500 USDC cap on NVDAx and 1 USDC of the 100 USDC cap on the others. Adjacent windows can permit a larger burst; this is not a rolling-minute loss guarantee.
What protects you, specifically
- Swaps settle directly from your wallet; opcode holds no trading balance of yours to freeze, lose or lend.
- A swap moves only what your wallet signed for. There are no token approvals left behind.
- The price band applies in your favour too: an OPmode quote far from the reference is refused by the chain even if you would have signed it.
Go deeperWhat none of this covers
The issuer's powers over the token, the soundness of USDC, bugs in the program itself, the owner wallet's power to upgrade it, and Solana being unavailable. Those are on the Risks page, stated plainly.