Skip to content

Docs

Admin powers and timelocks

What EtherFamily can change, how fast, and what it can never touch.

Design · not deployedValues on this page come from the design. Deployed addresses and settings: Contract addresses; live state: Status.

In short

Every market states who can still change it:

Who can change this market

EtherFamily can change settings for future launches through a 48-hour timelock, plus a guardian that can pause new launches. Through the same timelock it can also change which instant-exit buffer (perp shares) or issuer-screening adapter (stocks) EtherFamily's router uses for this market; that never moves funds or changes amounts. It cannot change this market's price, fee, split, fee recipient or locked position. Outside parties can still affect it: the issuer of the quote asset, Uniswap governance and price-feed operators. For perp-share markets EtherFamily also administers the vault behind the quote asset: see below.

Markets paired with a perp share add:

Vault administration

EtherFamily administers the vault behind the perp share through a 48-hour timelock: it can change the vault's bounded parameters, its operator and venue managers and, with 7 more days, its attestors, and it can wind the vault down after at least 7 days' notice. A guardian can pause deposits, and can halt redemption processing, the instant buffer and new venue deposits for up to 72 hours once a week. None of them can send the vault's on-chain USDT anywhere except into its own venue account, or stop redemption requests, claims or the emergency exit. These powers change what the perp share is worth and what it tracks, although this market itself cannot be changed.

How changes happen

  • Every contract that has settings is owned by a timelock with a 48-hour minimum delay. Only the EtherFamily Safe, a multisig wallet, can propose and execute its operations; the Safe and the guardian can cancel them. Anyone can watch a change during the delay before it takes effect.
  • A separate guardian Safe acts without delay, but only to stop things: pause new launches, disable a quote for new launches, cancel a queued operation, and the vault powers listed below. It cannot move funds and cannot undo a pause; only the timelock can.
  • Every setting has a limit written into the contract (for example a creation fee of at most 0.01 ETH, or an opening window of 1 to 20 blocks). The one exception is a quote asset's accepted USD price band, which only needs a lower and an upper value, because it affects only the opening price of new launches and creators bound that themselves.
  • Ownership transfers take two steps: the new owner has to accept.

What no one can do

  • Change a live market's price, fee, fee split or fee recipient, or touch its locked position.
  • Move the fees owed to creators or holders.
  • Mint launch tokens, or burn, freeze or tax anyone's balance.
  • Change the hook, the router, the launch tokens, the token deployers or the screening adapters: they have no admin at all.
  • Send a vault's USDT anywhere except into its own venue account, or stop a vault holder's redemption request, claim or emergency exit.

Settings for new launches change only future launches. A superseded factory is paused for new launches; its hook keeps serving the markets it created.

Powers that reach existing markets

Three powers do reach markets that already exist. All go through the timelock.

  • A perp share's instant-exit buffer. Which buffer EtherFamily's router uses for a share. It never moves funds or changes amounts.
  • A stock's screening adapter. Which adapter EtherFamily's router and fee escrow consult. It can refuse trades through EtherFamily's router, never a claim to one's own address.
  • The vault behind a perp share. Its parameters, operators, attestors and, with at least 7 days' notice, its wind-down. These change what the share is worth and what it tracks, and therefore the USD value of every market paired with it. Perp vault shares

Launch core: every role

  • Timelock (proposed and executed by the EtherFamily Safe)

    Acts on
    LaunchFactory
    Can change
    Creation fee (at most 0.01 ETH), opening value ($1,000 to $1,000,000), window length (1 to 20 blocks), the price signer, the guardian; unpausing
    Can move or affect
    Nothing directly
    Delay
    48 hours
    How to revoke it
    Rotate the Safe's signers; change the timelock's roles (48 hours)
    Who is affected
    Future creators only
  • Timelock

    Acts on
    QuoteRegistry
    Can change
    Which quotes new launches may use, their price sources, bounds and maximum ages; the instant-exit buffer of a perp share and the screening adapter of a stock
    Can move or affect
    Which buffer and which screening EtherFamily's router uses in existing perp and stock markets; never amounts or funds
    Delay
    48 hours
    How to revoke it
    As above
    Who is affected
    Future creators; users of EtherFamily's router in perp and stock markets
  • Timelock

    Acts on
    FeeEscrow
    Can change
    The treasury address, in two steps
    Can move or affect
    Nothing: balances are kept per market
    Delay
    48 hours
    How to revoke it
    As above
    Who is affected
    Where EtherFamily's own share goes
  • Guardian (a Safe, separate signers)

    Acts on
    LaunchFactory, QuoteRegistry, timelock
    Can change
    Pause new launches; disable a quote for new launches; cancel queued timelock operations
    Can move or affect
    Nothing. It cannot unpause: only the timelock can
    Delay
    None
    How to revoke it
    The timelock replaces the guardian (48 hours)
    Who is affected
    Future creators
  • Treasury (a Safe)

    Acts on
    FeeEscrow, LaunchFactory
    Can change
    Nothing
    Can move or affect
    Claims EtherFamily's share of each market; receives creation fees and stray token balances. It cannot touch the creator's or holders' share
    Delay
    None
    How to revoke it
    The timelock sets a new treasury, which must accept (48 hours)
    Who is affected
    EtherFamily only
  • Price signer (a signing-service key in a hardware or managed key store)

    Acts on
    LaunchFactory, stock quotes only
    Can change
    The opening price of new stock launches, within the registry's bounds, at most 300 seconds old, usable once, bound to the launch's parameters
    Can move or affect
    Nothing after a market opens
    Delay
    None
    How to revoke it
    The timelock replaces it (48 hours); meanwhile the guardian can disable stock quotes or pause launches
    Who is affected
    Creators and first buyers of new stock launches
  • Screening adapter (a contract without admin)

    Acts on
    Router, fee escrow, factory
    Can change
    Nothing
    Can move or affect
    Can refuse router trades and redirected payouts in a stock market; cannot move funds, and never applies to a claim paid to the claimant itself
    Delay
    None
    How to revoke it
    The timelock points the registry to another adapter (48 hours)
    Who is affected
    Stock-market users of EtherFamily's router
  • LaunchHook, launch tokens, token deployers, LaunchRouter

    Acts on
    The markets themselves
    Can change
    Nothing: no admin code exists
    Can move or affect
    Nothing
    Delay
    Not applicable
    How to revoke it
    Not applicable
    Who is affected
    Nobody
  • Web app, indexer, route and quote service, price-signing hosts

    Acts on
    Off-chain
    Can change
    The routes, quotes, prices, statuses and disclosures shown
    Can move or affect
    No on-chain power. A compromised service could propose bad routes; the app checks routes against an independent reference and the wallet simulates every transaction
    Delay
    None
    How to revoke it
    Redeploy; rotate keys
    Who is affected
    App users

Perp vaults: every role

Perps are disabled; these roles exist only in the design until a vault opens.

  • Vault admin: the timelock

    Acts on
    PerpVault, NavOracle
    Can change
    Bounded vault parameters, the operator, venue managers, opening the vault, attestors and the quorum (in two steps), scheduling a wind-down
    Can move or affect
    No path to move the vault's USDT. Changes what the share is worth and what it tracks: attestor changes take 7 more days, a wind-down at least 7 days' notice
    Delay
    48 hours, plus 7 days for attestors and the quorum
    How to revoke it
    Rotate the Safe's signers
    Who is affected
    Every holder of the share, and every market paired with it
  • Guardian (a Safe)

    Acts on
    PerpVault, NavOracle
    Can change
    Pause deposits; freeze settlement, the buffer and venue deposits for at most 72 hours once a week; revoke venue managers; remove attestors while the quorum holds; discard a disputed report; cancel timelock operations
    Can move or affect
    Cannot move assets, unpause, unfreeze early, or block redemption requests, claims, cancellations or the emergency exit
    Delay
    None
    How to revoke it
    The timelock replaces the guardian (48 hours)
    Who is affected
    New depositors; queued redemptions, for up to 72 hours per freeze
  • Operator (a hot key on the executor host)

    Acts on
    PerpVault
    Can change
    Nothing
    Can move or affect
    Sends free USDT into the vault's own venue account, within limits that keep queued redemptions funded; cancels the vault's own pending venue withdrawal
    Delay
    None
    How to revoke it
    The timelock replaces the operator (48 hours); the guardian can freeze venue deposits
    Who is affected
    Holders
  • Hot and standby venue managers (separate custodians)

    Acts on
    The vault's Synthetix account
    Can change
    Delegated keys and subaccounts
    Can move or affect
    Withdraw to the vault only, by the venue's API rule rather than an on-chain check; create trading keys
    Delay
    None
    How to revoke it
    The guardian revokes them in minutes, unless the venue's permission registry is paused
    Who is affected
    Holders
  • Trading session keys (expire within 24 hours)

    Acts on
    The vault's Synthetix account
    Can change
    Nothing
    Can move or affect
    Trade any market, any size up to the venue's maximum, in either direction; the venue offers no way to limit them
    Delay
    None
    How to revoke it
    Expiry, or removal by a manager
    Who is affected
    Holders: losses up to the account's equity
  • Attestors (at least one independent of EtherFamily)

    Acts on
    NavOracle
    Can change
    Nothing
    Can move or affect
    The reported value within the on-chain bounds; which withdrawals are the vault's; whether reports arrive at all
    Delay
    None
    How to revoke it
    The guardian removes one at once while the quorum holds; the timelock adds one (7 days plus 48 hours)
    Who is affected
    Holders; deposits and redemptions at settlement
  • Buffer provider (its own key)

    Acts on
    PerpShareBuffer
    Can change
    Spread and caps, within limits fixed at deployment
    Can move or affect
    Its own inventory only
    Delay
    None
    How to revoke it
    Not applicable: its own capital
    Who is affected
    Buffer traders
  • Reference-pool keeper (optional; an EtherFamily key in a managed key store)

    Acts on
    A plain Uniswap pool of the share against USDC or USDT, funded by EtherFamily
    Can change
    Its own liquidity range and when it re-centres it
    Can move or affect
    EtherFamily's own capital, and the pool price that screeners and other routers show. EtherFamily's app and router never price shares from this pool
    Delay
    None
    How to revoke it
    Withdraw or re-key EtherFamily's position (immediate)
    Who is affected
    Traders using that pool
  • Keepers (anyone)

    Acts on
    PerpVault, NavOracle
    Can change
    Nothing
    Can move or affect
    Submit signed reports and run the vault's bookkeeping steps; every such step is checked on-chain
    Delay
    None
    How to revoke it
    Not applicable
    Who is affected
    Nobody
  • Executor, attestor, indexer and web hosts

    Acts on
    Off-chain
    Can change
    No on-chain power of their own
    Can move or affect
    Which orders are sent (executor), which data is signed (attestors), and which routes, quotes and values the app shows
    Delay
    None
    How to revoke it
    Redeploy; rotate the keys above
    Who is affected
    Users who rely on the app; the app labels the age and status of every value

Parties outside EtherFamily hold powers too: Uniswap governance, the issuers of the quote assets, the perp venue's operators and the price-feed operators. External powers

Who holds the keys

The Safe's signers and threshold, the guardian and the treasury are owner decisions that have not been made, and nothing is deployed. Once contracts are deployed, the addresses holding each role and their delays are published from the deployment manifest on Contract addresses.

Sources: EtherFamily contracts specification §4.1, §6.1, §11 (design); perp vault NAV and redemption §9.2 and vault specification §10 (design); ADR 0012.