Risk & Security
This document outlines the risks and security considerations of using Unbound.Risk Categories
1. Strategy Risk
Negative Funding Periods- Risk: Funding rates can turn negative (~16% of time)
- Mitigation: PositionManager closes positions when funding < -0.01%
- Impact: Reduced yield during negative periods, but no losses from payments
- Risk: Imbalance between wBTC value and short position
- Mitigation: Automatic rebalancing when delta > 5%
- Impact: Brief periods of directional exposure
2. Exchange Risk
Extended Exchange Custody- Risk: USDC collateral is held on Extended exchange
- Impact: If Extended is hacked/insolvent, USDC portion at risk
- Mitigation: Extended uses Starknet validity proofs
3. Smart Contract Risk
Vault Contract Bugs- Risk: Bugs could lock or lose funds
- Mitigation: Simple ERC-4626 design, open source code
- Risk: Poor rates during wBTC ↔ USDC swaps
- Mitigation: Slippage protection + AVNU best routing
4. Operator Risk
Backend Downtime- Risk: Backend services go offline
- Impact: No new deposits processed, no rebalancing
- Mitigation: Funds remain safe; manual recovery possible
- Risk: Private key stolen
- Impact: Attacker could withdraw from Extended
- Mitigation: Secure key storage, monitoring
Position Risks
Price Movement (Hedged)
The delta-neutral design hedges price risk:| BTC Move | wBTC in Vault | Short PnL | Net Position |
|---|---|---|---|
| +10% | +$250 | -$250 | ~$0 |
| -10% | -$250 | +$250 | ~$0 |
Liquidation Risk
With 2x leverage on USDC portion:- Liquidation occurs if BTC rises ~50% without rebalancing
- PositionManager monitors margin ratio
- Conservative leverage minimizes this risk
Security Measures
| Measure | Implementation |
|---|---|
| Key Security | Environment variables, not in code |
| Queue System | On-chain deposit/withdrawal queues |
| Access Control | Operator-only functions for processing |
| Signature Verification | NAV updates require operator signature |
Best Practices for Users
- Start Small: Test with small amounts first
- Understand Risks: Funding can be negative, exchange has custody
- Monitor: Check position status regularly
- Diversify: Don’t put all funds in one vault
Emergency Procedures
If Backend Goes Down
- Funds remain in Extended + vault
- Owner can manually recover using operator wallet
- wBTC in vault is always accessible
Full Recovery
- Close all positions on Extended
- Withdraw USDC to operator wallet
- Forward USDC to vault contract
- Users withdraw their proportional share
