Docs
Admin powers and timelocks
What EtherFamily can change, how fast, and what it can never touch.
Design · not deployedValues on this page come from the design. Deployed addresses and settings: Contract addresses; live state: Status.
In short
Every market states who can still change it:
Who can change this market
EtherFamily can change settings for future launches through a 48-hour timelock, plus a guardian that can pause new launches. Through the same timelock it can also change which instant-exit buffer (perp shares) or issuer-screening adapter (stocks) EtherFamily's router uses for this market; that never moves funds or changes amounts. It cannot change this market's price, fee, split, fee recipient or locked position. Outside parties can still affect it: the issuer of the quote asset, Uniswap governance and price-feed operators. For perp-share markets EtherFamily also administers the vault behind the quote asset: see below.
Markets paired with a perp share add:
Vault administration
EtherFamily administers the vault behind the perp share through a 48-hour timelock: it can change the vault's bounded parameters, its operator and venue managers and, with 7 more days, its attestors, and it can wind the vault down after at least 7 days' notice. A guardian can pause deposits, and can halt redemption processing, the instant buffer and new venue deposits for up to 72 hours once a week. None of them can send the vault's on-chain USDT anywhere except into its own venue account, or stop redemption requests, claims or the emergency exit. These powers change what the perp share is worth and what it tracks, although this market itself cannot be changed.
How changes happen
- Every contract that has settings is owned by a timelock with a 48-hour minimum delay. Only the EtherFamily Safe, a multisig wallet, can propose and execute its operations; the Safe and the guardian can cancel them. Anyone can watch a change during the delay before it takes effect.
- A separate guardian Safe acts without delay, but only to stop things: pause new launches, disable a quote for new launches, cancel a queued operation, and the vault powers listed below. It cannot move funds and cannot undo a pause; only the timelock can.
- Every setting has a limit written into the contract (for example a creation fee of at most 0.01 ETH, or an opening window of 1 to 20 blocks). The one exception is a quote asset's accepted USD price band, which only needs a lower and an upper value, because it affects only the opening price of new launches and creators bound that themselves.
- Ownership transfers take two steps: the new owner has to accept.
What no one can do
- Change a live market's price, fee, fee split or fee recipient, or touch its locked position.
- Move the fees owed to creators or holders.
- Mint launch tokens, or burn, freeze or tax anyone's balance.
- Change the hook, the router, the launch tokens, the token deployers or the screening adapters: they have no admin at all.
- Send a vault's USDT anywhere except into its own venue account, or stop a vault holder's redemption request, claim or emergency exit.
Settings for new launches change only future launches. A superseded factory is paused for new launches; its hook keeps serving the markets it created.
Powers that reach existing markets
Three powers do reach markets that already exist. All go through the timelock.
- A perp share's instant-exit buffer. Which buffer EtherFamily's router uses for a share. It never moves funds or changes amounts.
- A stock's screening adapter. Which adapter EtherFamily's router and fee escrow consult. It can refuse trades through EtherFamily's router, never a claim to one's own address.
- The vault behind a perp share. Its parameters, operators, attestors and, with at least 7 days' notice, its wind-down. These change what the share is worth and what it tracks, and therefore the USD value of every market paired with it. Perp vault shares
Launch core: every role
Timelock (proposed and executed by the EtherFamily Safe)
- Acts on
- LaunchFactory
- Can change
- Creation fee (at most 0.01 ETH), opening value ($1,000 to $1,000,000), window length (1 to 20 blocks), the price signer, the guardian; unpausing
- Can move or affect
- Nothing directly
- Delay
- 48 hours
- How to revoke it
- Rotate the Safe's signers; change the timelock's roles (48 hours)
- Who is affected
- Future creators only
Timelock
- Acts on
- QuoteRegistry
- Can change
- Which quotes new launches may use, their price sources, bounds and maximum ages; the instant-exit buffer of a perp share and the screening adapter of a stock
- Can move or affect
- Which buffer and which screening EtherFamily's router uses in existing perp and stock markets; never amounts or funds
- Delay
- 48 hours
- How to revoke it
- As above
- Who is affected
- Future creators; users of EtherFamily's router in perp and stock markets
Timelock
- Acts on
- FeeEscrow
- Can change
- The treasury address, in two steps
- Can move or affect
- Nothing: balances are kept per market
- Delay
- 48 hours
- How to revoke it
- As above
- Who is affected
- Where EtherFamily's own share goes
Guardian (a Safe, separate signers)
- Acts on
- LaunchFactory, QuoteRegistry, timelock
- Can change
- Pause new launches; disable a quote for new launches; cancel queued timelock operations
- Can move or affect
- Nothing. It cannot unpause: only the timelock can
- Delay
- None
- How to revoke it
- The timelock replaces the guardian (48 hours)
- Who is affected
- Future creators
Treasury (a Safe)
- Acts on
- FeeEscrow, LaunchFactory
- Can change
- Nothing
- Can move or affect
- Claims EtherFamily's share of each market; receives creation fees and stray token balances. It cannot touch the creator's or holders' share
- Delay
- None
- How to revoke it
- The timelock sets a new treasury, which must accept (48 hours)
- Who is affected
- EtherFamily only
Price signer (a signing-service key in a hardware or managed key store)
- Acts on
- LaunchFactory, stock quotes only
- Can change
- The opening price of new stock launches, within the registry's bounds, at most 300 seconds old, usable once, bound to the launch's parameters
- Can move or affect
- Nothing after a market opens
- Delay
- None
- How to revoke it
- The timelock replaces it (48 hours); meanwhile the guardian can disable stock quotes or pause launches
- Who is affected
- Creators and first buyers of new stock launches
Screening adapter (a contract without admin)
- Acts on
- Router, fee escrow, factory
- Can change
- Nothing
- Can move or affect
- Can refuse router trades and redirected payouts in a stock market; cannot move funds, and never applies to a claim paid to the claimant itself
- Delay
- None
- How to revoke it
- The timelock points the registry to another adapter (48 hours)
- Who is affected
- Stock-market users of EtherFamily's router
LaunchHook, launch tokens, token deployers, LaunchRouter
- Acts on
- The markets themselves
- Can change
- Nothing: no admin code exists
- Can move or affect
- Nothing
- Delay
- Not applicable
- How to revoke it
- Not applicable
- Who is affected
- Nobody
Web app, indexer, route and quote service, price-signing hosts
- Acts on
- Off-chain
- Can change
- The routes, quotes, prices, statuses and disclosures shown
- Can move or affect
- No on-chain power. A compromised service could propose bad routes; the app checks routes against an independent reference and the wallet simulates every transaction
- Delay
- None
- How to revoke it
- Redeploy; rotate keys
- Who is affected
- App users
Perp vaults: every role
Perps are disabled; these roles exist only in the design until a vault opens.
Vault admin: the timelock
- Acts on
- PerpVault, NavOracle
- Can change
- Bounded vault parameters, the operator, venue managers, opening the vault, attestors and the quorum (in two steps), scheduling a wind-down
- Can move or affect
- No path to move the vault's USDT. Changes what the share is worth and what it tracks: attestor changes take 7 more days, a wind-down at least 7 days' notice
- Delay
- 48 hours, plus 7 days for attestors and the quorum
- How to revoke it
- Rotate the Safe's signers
- Who is affected
- Every holder of the share, and every market paired with it
Guardian (a Safe)
- Acts on
- PerpVault, NavOracle
- Can change
- Pause deposits; freeze settlement, the buffer and venue deposits for at most 72 hours once a week; revoke venue managers; remove attestors while the quorum holds; discard a disputed report; cancel timelock operations
- Can move or affect
- Cannot move assets, unpause, unfreeze early, or block redemption requests, claims, cancellations or the emergency exit
- Delay
- None
- How to revoke it
- The timelock replaces the guardian (48 hours)
- Who is affected
- New depositors; queued redemptions, for up to 72 hours per freeze
Operator (a hot key on the executor host)
- Acts on
- PerpVault
- Can change
- Nothing
- Can move or affect
- Sends free USDT into the vault's own venue account, within limits that keep queued redemptions funded; cancels the vault's own pending venue withdrawal
- Delay
- None
- How to revoke it
- The timelock replaces the operator (48 hours); the guardian can freeze venue deposits
- Who is affected
- Holders
Hot and standby venue managers (separate custodians)
- Acts on
- The vault's Synthetix account
- Can change
- Delegated keys and subaccounts
- Can move or affect
- Withdraw to the vault only, by the venue's API rule rather than an on-chain check; create trading keys
- Delay
- None
- How to revoke it
- The guardian revokes them in minutes, unless the venue's permission registry is paused
- Who is affected
- Holders
Trading session keys (expire within 24 hours)
- Acts on
- The vault's Synthetix account
- Can change
- Nothing
- Can move or affect
- Trade any market, any size up to the venue's maximum, in either direction; the venue offers no way to limit them
- Delay
- None
- How to revoke it
- Expiry, or removal by a manager
- Who is affected
- Holders: losses up to the account's equity
Attestors (at least one independent of EtherFamily)
- Acts on
- NavOracle
- Can change
- Nothing
- Can move or affect
- The reported value within the on-chain bounds; which withdrawals are the vault's; whether reports arrive at all
- Delay
- None
- How to revoke it
- The guardian removes one at once while the quorum holds; the timelock adds one (7 days plus 48 hours)
- Who is affected
- Holders; deposits and redemptions at settlement
Buffer provider (its own key)
- Acts on
- PerpShareBuffer
- Can change
- Spread and caps, within limits fixed at deployment
- Can move or affect
- Its own inventory only
- Delay
- None
- How to revoke it
- Not applicable: its own capital
- Who is affected
- Buffer traders
Reference-pool keeper (optional; an EtherFamily key in a managed key store)
- Acts on
- A plain Uniswap pool of the share against USDC or USDT, funded by EtherFamily
- Can change
- Its own liquidity range and when it re-centres it
- Can move or affect
- EtherFamily's own capital, and the pool price that screeners and other routers show. EtherFamily's app and router never price shares from this pool
- Delay
- None
- How to revoke it
- Withdraw or re-key EtherFamily's position (immediate)
- Who is affected
- Traders using that pool
Keepers (anyone)
- Acts on
- PerpVault, NavOracle
- Can change
- Nothing
- Can move or affect
- Submit signed reports and run the vault's bookkeeping steps; every such step is checked on-chain
- Delay
- None
- How to revoke it
- Not applicable
- Who is affected
- Nobody
Executor, attestor, indexer and web hosts
- Acts on
- Off-chain
- Can change
- No on-chain power of their own
- Can move or affect
- Which orders are sent (executor), which data is signed (attestors), and which routes, quotes and values the app shows
- Delay
- None
- How to revoke it
- Redeploy; rotate the keys above
- Who is affected
- Users who rely on the app; the app labels the age and status of every value
Parties outside EtherFamily hold powers too: Uniswap governance, the issuers of the quote assets, the perp venue's operators and the price-feed operators. External powers
Who holds the keys
The Safe's signers and threshold, the guardian and the treasury are owner decisions that have not been made, and nothing is deployed. Once contracts are deployed, the addresses holding each role and their delays are published from the deployment manifest on Contract addresses.
Sources: EtherFamily contracts specification §4.1, §6.1, §11 (design); perp vault NAV and redemption §9.2 and vault specification §10 (design); ADR 0012.