Safety and Governance
shMonad v1.2 adds several safety controls around accounting, upgrades, and emergency operations. The short version: code upgrades are delayed by timelock, emergency controls remain fast, and core value-changing paths are protected by a pooled share-rate circuit breaker.
Key Facts at a Glance
| Code upgrades | Delayed by a 3-day governance timelock. |
| Operational controls | Controlled by the FastLane operations Safe for immediate response. |
| Pooled share-rate circuit breaker | Checks that selected operations do not decrease the virtual pooled shMON exchange rate. |
| Frozen mode | Blocks validator operating-loop actions like crank and coinbase processing. |
| Closed mode | Blocks new deposits, traditional unstake actions, hMON mint/conversion, and isolated stake actions. |
| Transfers | shMON ERC-20 transfers and hMON transfers remain live unless another protocol-specific constraint applies. |
Pooled Share-Rate Circuit Breaker
The pooled share-rate circuit breaker protects the shMON exchange rate around operations that should be neutral or positive for pooled shMON holders.
Before a guarded operation runs, the protocol snapshots pooled equity and real shMON supply. After the operation, it checks that the virtual-offset pooled rate did not decrease:
(next equity + 1) / (next supply + virtual offset)
>=
(previous equity + 1) / (previous supply + virtual offset)
This guard applies broadly because many features can affect pooled equity indirectly. Examples include:
- Standard shMON deposits and atomic exits
- Traditional unstake request and completion
- hMON zero-yield deposits and hMON-to-shMON conversion
- Validator rewards and boost-yield paths
- Agent withdrawal from committed shMON
- Isolated stake deposit, exit, completion, and deactivated-validator claim paths
The circuit breaker is a rate guard, not a full solvency proof. It checks selected entrypoints against the same virtual-rate model used for share pricing. It does not predict future validator behavior, future liability realization, or every possible external condition.
Frozen vs Closed
frozen and closed are different safety modes.
| Operation family | Frozen | Closed |
|---|---|---|
| Global / validator crank | Blocked | Allowed |
| Coinbase processing | Blocked | Allowed |
| Standard shMON deposit / mint | Allowed | Blocked |
| Atomic withdraw / redeem | Allowed | Allowed |
| Traditional unstake request / complete | Allowed | Blocked |
| Policy commit / uncommit | Allowed | Allowed |
| Zero-yield deposit / hMON-to-shMON conversion | Allowed | Blocked |
| hMON transfer | Allowed | Allowed |
| Isolated stake deposit | Blocked | Blocked |
| Isolated unstake / complete / claim | Allowed | Blocked |
Frozen mode primarily protects the validator operating loop. Closed mode primarily stops new state expansion and delayed-liability flows while preserving transfers and atomic exits where possible.
Upgrade Timelocks
v1.2 separates code-upgrade authority from day-to-day operational authority.
Code upgrades are controlled by a 3-day timelock:
- ShMonad proxy upgrades
- Holistic MON / hMON proxy upgrades
- Coinbase beacon implementation upgrades
Operational and emergency controls remain with the FastLane operations Safe:
- Freeze and close status
- Validator add, deactivate, and coinbase migration actions
- Fee and commission settings
- Policy-agent membership
- Owner-only coinbase settlement actions
This split is intentional. Code changes get a public delay, while safety operations that may need quick response remain immediately executable by the Safe.
Principal Deficit Response
During validator accounting, shMonad compares the protocol's expected validator principal against Monad staking precompile state. If the precompile reports less validator principal than shMonad expects, the protocol treats that as an invariant violation.
In that case, shMonad can freeze and close the protocol for investigation instead of silently writing down pooled or isolated stake accounting. This is separate from the pooled share-rate circuit breaker and is intended for unexpected principal-deficit scenarios.
What This Means for Users
- You can verify safety flags and upgrade authority on-chain.
- A closed protocol does not mean all token movement stops.
- hMON transfers can continue even when new hMON minting and hMON-to-shMON conversion are blocked.
- Atomic exits are designed to remain available while liquidity exists.
- Traditional unstaking and isolated exits may be blocked while closed because they create or settle delayed liabilities.