Latest dispatch — bonded liquidity live on Robinhood ChainEnter the vault →
Risk & Security

Honest about what can go wrong.

DeFi is not risk-free. Here's exactly how we bound, monitor, and mitigate every failure mode — and what we don't promise.

Exposure caps

No strategy can hold more than a hard-coded share of the vault. Caps are enforced on-chain by the LAE.

Bond slashing

Every project posts a bond. If depth SLA breaks, the bond is slashed to make LPs whole first.

Emergency controls

A multisig-guarded kill switch can pause any module. Pausing never blocks user withdrawals from safe modules.

Failure scenarios

What happens when things break.

A strategy underperforms

The LAE de-allocates within one block. LPs feel a proportional drawdown capped by that strategy's max share.

Bounded
A project abandons its pair

Depth SLA violation triggers the bond slash. Proceeds top up rLP price before any loss reaches LPs.

Bond-covered
Oracle failure

Risk Engine trips a circuit breaker. Deposits, allocations and rebalances pause. Withdrawals continue from unaffected modules.

Paused
Smart-contract exploit

Emergency multisig pauses affected module. Insurance fund and treasury absorb losses up to disclosed limits.

Insurance
What MerryVault guarantees
  • Exposure caps are enforced on-chain and cannot be bypassed.
  • Bonds are held in the vault contract and slashed by code, not committee.
  • Withdrawals from unaffected modules always remain open.
  • All events are public and reproducible from chain history.
  • The team cannot rug — no privileged migration or upgrade without timelock.
What it does NOT guarantee
  • Principal protection — you can still lose money.
  • Fixed APY — yield varies with markets and utilization.
  • Instant exits — cooldowns and epochs are real.
  • Coverage of every exploit — insurance fund is capped and disclosed.
  • Regulatory suitability — availability depends on your jurisdiction.
Audits & security

Reviewed. Instrumented. Watched.

Three independent audits, continuous monitoring, and a public bug bounty program with a $2M ceiling.

Trail of Bits
Q2 2026
CLV, LAE, Risk Engine
Spearbit
Q3 2026
Strategy Modules v2
OpenZeppelin
Q4 2026
Bond & slashing logic
Immunefi Bounty
Ongoing
Live · up to $2M