Skip to main content

Safety and Governance

shMonad v1.2 adds several safety controls around accounting, upgrades, and emergency operations. The short version: code upgrades are delayed by timelock, emergency controls remain fast, and core value-changing paths are protected by a pooled share-rate circuit breaker.

Key Facts at a Glance​

Code upgradesDelayed by a 3-day governance timelock.
Operational controlsControlled by the FastLane operations Safe for immediate response.
Pooled share-rate circuit breakerChecks that selected operations do not decrease the virtual pooled shMON exchange rate.
Frozen modeBlocks validator operating-loop actions like crank and coinbase processing.
Closed modeBlocks new deposits, traditional unstake actions, hMON mint/conversion, and isolated stake actions.
TransfersshMON ERC-20 transfers and hMON transfers remain live unless another protocol-specific constraint applies.

Pooled Share-Rate Circuit Breaker​

The pooled share-rate circuit breaker protects the shMON exchange rate around operations that should be neutral or positive for pooled shMON holders.

Before a guarded operation runs, the protocol snapshots pooled equity and real shMON supply. After the operation, it checks that the virtual-offset pooled rate did not decrease:

(next equity + 1) / (next supply + virtual offset)
>=
(previous equity + 1) / (previous supply + virtual offset)

This guard applies broadly because many features can affect pooled equity indirectly. Examples include:

  • Standard shMON deposits and atomic exits
  • Traditional unstake request and completion
  • hMON zero-yield deposits and hMON-to-shMON conversion
  • Validator rewards and boost-yield paths
  • Agent withdrawal from committed shMON
  • Isolated stake deposit, exit, completion, and deactivated-validator claim paths
info

The circuit breaker is a rate guard, not a full solvency proof. It checks selected entrypoints against the same virtual-rate model used for share pricing. It does not predict future validator behavior, future liability realization, or every possible external condition.

Frozen vs Closed​

frozen and closed are different safety modes.

Operation familyFrozenClosed
Global / validator crankBlockedAllowed
Coinbase processingBlockedAllowed
Standard shMON deposit / mintAllowedBlocked
Atomic withdraw / redeemAllowedAllowed
Traditional unstake request / completeAllowedBlocked
Policy commit / uncommitAllowedAllowed
Zero-yield deposit / hMON-to-shMON conversionAllowedBlocked
hMON transferAllowedAllowed
Isolated stake depositBlockedBlocked
Isolated unstake / complete / claimAllowedBlocked

Frozen mode primarily protects the validator operating loop. Closed mode primarily stops new state expansion and delayed-liability flows while preserving transfers and atomic exits where possible.

Upgrade Timelocks​

v1.2 separates code-upgrade authority from day-to-day operational authority.

Code upgrades are controlled by a 3-day timelock:

  • ShMonad proxy upgrades
  • Holistic MON / hMON proxy upgrades
  • Coinbase beacon implementation upgrades

Operational and emergency controls remain with the FastLane operations Safe:

  • Freeze and close status
  • Validator add, deactivate, and coinbase migration actions
  • Fee and commission settings
  • Policy-agent membership
  • Owner-only coinbase settlement actions

This split is intentional. Code changes get a public delay, while safety operations that may need quick response remain immediately executable by the Safe.

Principal Deficit Response​

During validator accounting, shMonad compares the protocol's expected validator principal against Monad staking precompile state. If the precompile reports less validator principal than shMonad expects, the protocol treats that as an invariant violation.

In that case, shMonad can freeze and close the protocol for investigation instead of silently writing down pooled or isolated stake accounting. This is separate from the pooled share-rate circuit breaker and is intended for unexpected principal-deficit scenarios.

What This Means for Users​

  • You can verify safety flags and upgrade authority on-chain.
  • A closed protocol does not mean all token movement stops.
  • hMON transfers can continue even when new hMON minting and hMON-to-shMON conversion are blocked.
  • Atomic exits are designed to remain available while liquidity exists.
  • Traditional unstaking and isolated exits may be blocked while closed because they create or settle delayed liabilities.