Concepts › Trust model
This page lists who holds which permissions on each contract, read from the chain and the contract sources on 4 Oct 2026, so you can see exactly what each role can and cannot do.
Summary
- Two owner wallets. Contracts deployed up to 2 Oct 2026 are owned by 0x4aFd0A931176103d704Ff0d696614d4E10d74A4a; contracts deployed from 2 Oct 2026 (sealed bridge routes, WBTCw pool, USDw-hub pools, Earn) by 0xB17bdA8F14EEb9fd67B34810A2e1E82A737Ad952. Neither is a multisig and there is no timelock.
- No owner at all: WBTCw, SwapRouter, Multicall3, and the Uniswap V2 pair and router.
- Bridged assets are checkable live: Proof of reserve compares WBTCw and USDC.e on this chain with the WBTC and USDC locked on Arbitrum One, straight from both chains.
Owner permissions by contract
| Contract | Owner | Owner can |
|---|---|---|
| Sealed bridge routes: BTCw native vault, USDC.e (482120); WBTC and USDC routers (Arbitrum One) | 0xB17b…d952 | pause the route and manage its allowlist — nothing else. The verification module is fixed at deployment, the remote router is enrolled once and cannot be changed, the hook cannot be changed, and there is no owner withdrawal |
| WBTCw | none | no owner, no pause, no mint function. New WBTCw is minted only when the vault sends BTCw released against WBTC locked on Arbitrum;
it goes to the beneficiary (0xB17b…d952), which has no other power. Anyone can unwrap with withdraw |
| SimpleEarn · FixedEarn · StakedBTCw | 0xB17b…d952 | create or disable markets, pause new deposits, take back the part of the reward budget not yet paid out (reclaim), recover tokens sent by
mistake (sweep, which excludes deposits and booked rewards). FixedEarn: set term rates and the per-asset rate floor; a rate setter may move
rates within [minSetterAprBps, maxSetterAprBps]. StakedBTCw: change the unstake cooldown (up to MAX_COOLDOWN, only while paused).
Withdrawals, claims, redemptions and unstaking keep working while paused; the owner has no function that moves a depositor's principal |
| EarnPriceSource | 0xB17b…d952 | change the price sources and the maximum price age |
| UsdClpPools | 0xB17b…d952 | create pools, enable/disable pools, change the minimum fee, pause; add or remove Owner-provided liquidity; sweep tokens sent by mistake |
| UsdRebalancer | 0xB17b…d952 | change parameters, set keepers, pause, withdraw its own inventory (it mints nothing) |
| Uniswap V2 factory | feeToSetter 0xB17b…d952 | turn on the protocol fee (feeTo, 1/6 of the 0.30% fee); currently off. Pairs and router have no owner |
| USDw | 0x4aFd…74A4a | mint without limit; change name/symbol |
| TokenFactory · price-tracker tokens | 0x4aFd…74A4a | change the minter, change mint caps, change name/symbol, transfer token ownership |
| OracleRebalancer | 0x4aFd…74A4a | change parameters (threshold, step, daily cap…), set the keeper, pause, withdraw the contract's assets |
| ClpPools | 0x4aFd…74A4a | create pools, enable/disable individual pools, change the minimum fee (up to 10%), pause; withdraw Owner-provided liquidity.
sweep only recovers funds sent by mistake — it cannot withdraw pool depth |
| OracleAMM · OracleTokenAMM (ETHw) | 0x4aFd…74A4a | deposit/withdraw liquidity, change spread / per-trade cap / max price age, change the price feed, change the peg ratio, pause |
| BtcwPriceFeed · PriceHub | 0x4aFd…74A4a | write prices manually (ownerSubmit), change the updater, change the price-jump limit |
| USDC / USD₮0 ⇄ USDw routes (R-40, 2 routers on each chain) | 0x4aFd…74A4a | pause, enable the allowlist, and every permission of a standard Hyperlane warp route: change the ISM, the hook and the remote routers |
All of these permissions can be read in the contract sources. We are not aware of any permission outside the list above.
What you can read before every action
paused(),allowlistEnabled()and the price age (updatedAt) — read them instead of hardcoding them.- Parameter-change events:
ParamsSet,PausedSet,UpdaterSet,MinFeeSet,AllowlistEnabledSet,TermSet,AssetFloorSet,CooldownSet. - Bridged supply against the locked collateral: Proof of reserve.
Self-verifiable figures (genesis, block cadence): Transparency page.