01Smart-contract risk
Paraclr’s production contracts are new code. Not audited: internal review and Slither only. No independent firm has audited them. Before a mainnet launch they must pass a launch gate: the full Foundry test suite including fuzz and invariant tests, Slither with every high and medium finding fixed or justified in writing, an adversarial internal review with every critical finding fixed, and a rehearsal on a fork of Monad mainnet. Those checks reduce risk. They don’t remove it: tests only catch the problems someone thought to test for.
A bug in the clearinghouse, the oracle checks, the auctions, the backstop pools, the fee and funding accounting or the admin wiring could let someone take funds, lock funds, misprice positions, or liquidate accounts that should be healthy. Losses could be total, and could hit accounts that did nothing wrong.
The contracts depend on contracts we don’t control, AUSD and Pyth. A change or fault in those can affect Paraclr. The on-chain solvency() check compares the AUSD the contract holds with what its ledgers say it owes. It checks the books; it can’t catch a bug that records the wrong amounts.
02Oracle risk
Prices come from Pyth, a third-party oracle network. Each price update is signed off chain by Pyth and verified on chain through Pyth’s contract on Monad. Paraclr rejects a price that is too old (30 s on testnet), not positive, or whose confidence interval is too wide a share of the price (200 bps on testnet). While prices are rejected, orders, withdrawals and liquidations that need a price wait.
A price can pass every check and still be wrong or late: during an outage at the venues Pyth’s publishers watch, in a thin or manipulated market, or after a publisher fault. Your position is valued and liquidated at the oracle price, not at a price you might have got elsewhere. Keepers and the app fetch price updates from Pyth’s price service; if it is unavailable, executions and liquidations can stall.
03Order execution risk
Orders don’t fill when you submit them. You commit an order with a size, margin and the worst price you’ll accept, and it fills at the first Pyth price published at least the minimum delay after your commit (3 s on testnet). You can’t see that price when you submit.
- If the fill price is worse than your worst price, the order doesn’t fill. Once the execution window has passed (60 s on testnet) it can be cancelled and the escrowed margin returns to you.
- Prices can move a lot between commit and fill. The delay exists to stop oracle front-running; it doesn’t protect you from the market.
- Each order costs an execution fee in MON (0.1 MON on testnet) and a trading fee in AUSD (5 bps of notional on testnet), plus gas, whether or not the trade works out.
04Liquidation risk
Positions are leveraged, up to a maximum set in the contract (10x on testnet). Leverage makes losses bigger and faster. If your equity (collateral plus unrealised PnL, after fees and funding) falls below the maintenance margin (2.5% of notional on testnet), anyone can put your account into a liquidation auction.
- During the auction your account is frozen: you can’t withdraw, open or close positions. You can add collateral (deposit caps and a pause permitting); if your account becomes healthy again, the auction can be cancelled.
- A taker inherits your positions at the oracle price and is paid a discount that grows every block, up to a cap (500 bps of notional in the current defaults). You keep whatever equity is left, which can be nothing. If nobody takes the auction, it closes through a fixed-fee path (1% of notional).
- Fast markets, price gaps, oracle delays or stalled keepers can mean your account is handled late and at a worse price. You can lose your whole deposit. A shortfall beyond your collateral is absorbed by your lane’s insurance fund and then recorded as lane bad debt; it isn’t charged to you.
05Funding risk
Each market has a funding rate set by the imbalance between long and short open interest across all 8 lanes. The bigger side pays the smaller side. Funding accrues over time and is settled from your collateral when your position is touched.
Funding can be large when a market is one-sided and can change quickly. It can push your account below maintenance margin and into liquidation even if the price doesn’t move. Funding updates are sent by an operator key at most once per interval (60 s on testnet); late or missed updates change when and how much funding is charged.
06Caps, pause and parameter changes
The beta is capped on purpose: max leverage, a deposit cap per account, a TVL cap per lane, an open-interest cap per lane and market, and a minimum position size. Values on Monad testnet: 10x max leverage, 50 AUSD per account, 500 AUSD per lane, 5,000 AUSD open interest per lane and market, 10 AUSD minimum position. A cap can stop you from depositing more or growing a position. A deposit cap can also stop you from adding collateral to rescue a position near liquidation.
A guardian key can pause the protocol. A pause blocks deposits and new or larger positions; withdrawals, reducing and closing positions, and liquidations are designed to keep working while paused. Because a deposit is blocked, you can’t top up collateral during a pause.
Caps, fees, leverage, margins, auction and funding settings, the oracle configuration and roles can be changed by the owner, a multisig acting through a timelock. Each change is scheduled on chain and waits out the timelock delay (10 min on testnet) before it applies. A change can make your position worse, for example a higher maintenance margin. If you disagree with a scheduled change, the delay is your time to leave.
07Keeper liveness
Keepers run by the operator execute orders, run liquidation auctions and update funding. They are software on servers: they can crash, run out of gas money, fall behind or be attacked.
- If they stop, committed orders wait and then expire, and you have to cancel them to get margin back.
- Liquidations run late, and late liquidations lose more. Losses beyond the lane’s insurance fund are recorded as lane bad debt, which can mean not every account in that lane can be paid in full.
- Funding isn’t updated on time.
Anyone can execute orders and start auctions by supplying a Pyth price update, so Paraclr doesn’t depend on our keepers alone. But nobody is obliged to step in.
08Backstop LP risk
If you deposit into a lane’s backstop pool, the pool takes that lane’s liquidation auctions and inherits the positions. Its value moves with the market until an operator role reduces that exposure. You can lose some or all of your deposit, most likely during exactly the crashes the pool exists for.
Withdrawals can be blocked while the pool doesn’t have enough margin for its exposure. Returns are shown as earned since deploy. They don’t predict future returns, and no yield is promised.
09Stablecoin risk (AUSD)
Collateral, PnL, fees and backstop deposits are all in AUSD, a stablecoin issued by Agora. Paraclr doesn’t issue, back or redeem AUSD, and has no control over it.
- AUSD can lose its peg to the US dollar, briefly or for good. Your balance loses value with it.
- Markets are priced from USD price feeds and settled in AUSD. A depeg breaks the assumption that the two are equal, which can distort PnL and liquidations.
- Like many fiat-backed stablecoins, AUSD may carry issuer controls such as freezing addresses; check Agora’s documentation. If the clearinghouse’s own address were affected, all collateral in it could be stuck.
10Admin and key risk
The owner is a multisig behind a timelock. If enough of its signers are compromised or act in bad faith, they can schedule harmful changes. The timelock delay gives users time to notice and exit, but only if someone is watching and you can get out in time.
The guardian, ops and keeper keys are hot keys on servers. A stolen guardian key can pause deposits and new positions; a stolen keeper or ops key can execute orders and send funding updates. By design none of them can change parameters, and the deployer gives up its powers after deployment. Read the contracts to check; the code, not this page, decides what each key can do.
11Chain, wallet and interface risk
- Monad is a young network. Outages, congestion, reorganisations, RPC failures and gas spikes can delay or block your transactions, including the one that would have saved a position. You need MON for gas and execution fees.
- If you lose access to your passkey, embedded wallet or keys, nobody can recover your funds. Phishing sites and fake tokens exist. Check the URL, and check contract addresses against the testnet list on our landing page (from
deployments/10143.json) and the Monad testnet explorer. - The website and app are a convenience. They can be down, show stale numbers, or be blocked where you are. The contracts can be used directly.
12Demo results aren't a forecast
The benchmark runs, Conflict X-ray and auction results on our landing page come from a demo stack: local anvil or Monad testnet, a test token, a simulated price feed, synthetic accounts and keeper-run demo takers. They show how the mechanism behaved in those runs. They don’t predict what happens on mainnet with real traders, real prices and real liquidity.
13Regulatory and jurisdiction notice
Leveraged derivatives are regulated, restricted or banned in many countries. Paraclr is not licensed or registered as an exchange, broker or any other regulated business anywhere [LEGAL REVIEW: confirm].
- Don’t use Paraclr if you are a resident of, located in, or organised in [RESTRICTED JURISDICTIONS: legal review to complete], if you are on a sanctions list, or if you act for someone who is. The interface may block some locations; getting around that, for example with a VPN, breaks the terms.
- You are responsible for knowing whether using Paraclr is legal for you, and for your taxes.
- Laws change. A change could force the interface to stop serving some users or the beta to wind down.
14No guarantee of recovery
Blockchain transactions can’t be reversed. If you send funds to the wrong address, sign a malicious transaction, or lose funds to a bug or an exploit, they may be gone for good.
There is no deposit insurance, no government protection scheme, and no promise from NetLayer Labs or anyone else to make up losses. The lane insurance funds are a protocol mechanism for liquidation shortfalls, not insurance for users. After an incident we may try to help, for example by pausing, but we can’t promise to recover anything.
Use only what you can afford to lose.