# Paradex Markdown version of https://l2beat.com/layer2s/projects/paradex ## Summary - Total Value Secured: $22.00 M (-1.96% compared to seven days ago; canonically bridged $22.00 M, natively minted $0.00, externally bridged $0.00; 0.00% with additional trust assumptions compared to the tokens involved and the Stage assigned to the project's canonical messaging bridge) - Past day UOPS: 2.28 (+32.5% compared to seven days ago) - Gas token: ETH - Type: Other - Purposes: Universal, Exchange - Host chain: Ethereum ### Risks - Sequencer failure: No mechanism (sentiment: bad) - State validation: Validity proofs (ST) (sentiment: good) - Data availability: External (sentiment: bad) - Exit window: None (sentiment: bad) - Proposer failure: Cannot withdraw (sentiment: bad) ### About Paradex is a high-performance crypto-derivatives exchange offering zero fee and private perpetuals. ## Value Secured Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/paradex#tvs). - [TVS chart (JSON)](https://l2beat.com/api/scaling/tvs/paradex) - [TVS breakdown by token (JSON)](https://l2beat.com/api/scaling/tvs/paradex/breakdown) ## Activity Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/paradex#activity). - [Activity chart (JSON)](https://l2beat.com/api/scaling/activity/paradex) ## Data posted Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/paradex#data-posted). ## Liveness Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/paradex#liveness). ## Milestones & Incidents - 2025-12-15: [Paradex introduces privacy perps](https://x.com/paradex/status/2000680628329812320). Paradex introduces a privacy council to manage decryption keys for encrypted data availability. - 2025-11-25: [Paradex migrates to Stwo prover](https://etherscan.io/tx/0xec6c80207374c54d755f96ff0f89372425ab4fa9bb3286cbc2109b4652b00079). Paradex switches from Stone zk prover to Stwo to prove its blocks. - 2025-04-01: [Perpetual Options Launch](https://x.com/tradeparadex/status/1907041207177613610). Paradex opens perpetual options trading to all users. - 2024-11-07: [Paradex exits Open Beta](https://x.com/tradeparadex/status/1854537396714651707). Paradex launches XP Warzone Season 1 and exits Open Beta. - 2024-10-08: [Vaults Launched](https://x.com/tradeparadex/status/1843550172443512998). Paradex launches Vaults, the future of on-chain investment management. - 2024-03-26: [Paradex starts using blobs](https://twitter.com/tradeparadex/status/1768306190596153799). Paradex starts publishing data to blobs. - 2023-10-01: [Open Beta Mainnet Launch](https://twitter.com/tradeparadex). Paradex launches Open Beta on Mainnet. ## Risk summary ### Funds can be stolen if 1. a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL). ### Funds can be frozen if 2. no privacy council member discloses the decryption keys, 3. the operator censors withdrawal transaction. ### Users can be censored if 4. the operator refuses to include their transactions. ### MEV can be extracted if 5. the operator exploits their centralized position and frontruns user transactions. ## Risk analysis ### Sequencer failure No mechanism (sentiment: bad) There is no mechanism to have transactions be included if the sequencer is down or censoring. ### State validation Validity proofs (ST) (sentiment: good) STARKs are zero knowledge proofs that ensure state correctness. ### Data availability External (sentiment: bad) Encrypted data is posted on Ethereum as blobs, and a privacy council of 3 members holds the decryption keys. Users are not able to independetly reconstruct the L2 state without relying on the council members. ### Exit window None (sentiment: bad) There is no window for users to exit in case of an unwanted upgrade since contracts are instantly upgradable. ### Proposer failure Cannot withdraw (sentiment: bad) Only the whitelisted proposers can publish state roots on L1, so in the event of failure the withdrawals are frozen. ## Data availability ### Encrypted blobs via privacy council Data is posted as encrypted blobs on Ethereum using a random symmetric key per state update. Such symmetric key is also posted, but encrypted to the privacy council members public keys. Each member can recover the symmetric key and decrypt the data. The council has 3 members and at least one is required to disclose the decryption keys to reconstruct the L2 state. Users cannot independently reconstruct the L2 state without relying on the council members. **Risks** - Funds can be frozen if no privacy council member discloses the decryption keys. **References** - [Privacy Perps - Paradex docs](https://docs.paradex.trade/trading/privacy) ## State derivation ### Node software SN stack-compatible node software can be used, please find the Paradex-specific node setup guide [in their docs](https://docs.paradex.trade/documentation/paradex-chain/node-setup).The [Juno](https://github.com/NethermindEth/juno) node software can be used to reconstruct the L2 state entirely from L1. The feature has not been released yet, but can be found in this [PR](https://github.com/NethermindEth/juno/pull/1335). ### Compression scheme Paradex uses [stateful compression since v0.13.4](https://docs.starknet.io/architecture/data-availability/#v0_13_4). ### Genesis state There is no non-empty genesis state. ### Data format The data format has been updated with different versions, and the full specification can be found [here](https://docs.starknet.io/architecture/data-availability/). ## State validation ### Validity proofs Each update to the system state must be accompanied by a ZK proof that ensures that the new state was derived by correctly applying a series of valid user transactions to the previous state. These proofs are then verified on Ethereum by a smart contract. ## Upgrades & Governance ## Updates Shown as an interactive chart or widget on [the HTML page](https://l2beat.com/layer2s/projects/paradex#updates). ## Operator ### The system has a centralized operator The operator is the only entity that can propose blocks. A live and trustworthy operator is vital to the health of the system. **Risks** - MEV can be extracted if the operator exploits their centralized position and frontruns user transactions. ### Users can't force any transaction There is no general mechanism to force the sequencer to include the transaction. **Risks** - Users can be censored if the operator refuses to include their transactions. **References** - [Censorship resistance of Starknet - Forum Discussion](https://community.starknet.io/t/censorship-resistance/196) ## Withdrawals ### Regular messaging The user initiates L2->L1 messages by submitting a regular transaction on this chain. When the block containing that transaction is settled, the message becomes available for processing on L1. ZK proofs are required to settle blocks. Note that the message request can be censored by the Sequencer. **Risks** - Funds can be frozen if the operator censors withdrawal transaction. **References** - [Withdrawing is based on l2 to l1 messages - Starknet documentation](https://book.cairo-lang.org/ch16-04-L1-L2-messaging.html#sending-messages-from-starknet-to-ethereum) ### Emergency exit There is no generic escape hatch mechanism as Starknet cannot be forced by users into a frozen state. Note that a freezing mechanism on L2, to be secure, requires anti-censorship protection. ## Permissions ### Ethereum #### Actors ##### Paradex Multisig 2 Addresses: [0xFF57A3bB6465501c993acF8f3b29125a862661C0](https://etherscan.io/address/0xFF57A3bB6465501c993acF8f3b29125a862661C0) A Multisig with 3/6 threshold. * Can upgrade **with no delay** * StarkgateManager * StarkgateRegistry * USDC Bridge * Paradex * Can interact with USDC Bridge * disable the withdrawal limit and manage the security agent role that can enable it * enable the withdrawal limit * manage critical access control roles related to upgrades and set the proxy governor that can upgrade the implementation * Can interact with Paradex * Permissioned to manage the Operator role, finalize the application configuration, and change the OS program hash, aggregator program hash, OS-config hash, fee collector, or message cancellation delay ##### SHARP Multisig Addresses: [0x21F9eC47b19d95b5C2DDFB6Ae5D4F92fAdacAEc4](https://etherscan.io/address/0x21F9eC47b19d95b5C2DDFB6Ae5D4F92fAdacAEc4) A Multisig with 2/4 threshold. * Can upgrade **with 8d delay** * SHARPVerifierCallProxy [via: - acting directly with 8d delay] * Can interact with SHARPVerifierCallProxy * Administer the CallProxy's `GOVERNANCE_ADMIN` and role-admin hierarchy. This AccessControl role is separate from the outer proxy governor that schedules implementation upgrades * Grant and revoke application roles, including the `APP_GOVERNOR` role that controls caller-specific fallback routes * Route fallback calls from specific callers to a still-active registry in the default verifier's reference chain. This principally determines which verifier and bootloader configuration processes their proof submissions; the proxy's explicit `isValid` entry point always queries the default target ##### Paradex Multisig Addresses: [0x0a64d3D7747549aF6d65C225D56ac8f71e436B93](https://etherscan.io/address/0x0a64d3D7747549aF6d65C225D56ac8f71e436B93) A Multisig with 3/6 threshold. * Can upgrade **with no delay** * Paradex * Can interact with Paradex * Permissioned to manage the Operator role, finalize the application configuration, and change the OS program hash, aggregator program hash, OS-config hash, fee collector, or message cancellation delay ##### StarkgateManager Addresses: [0x279b87139f2e89D7ce44c3056D2876fDEAB29BAE](https://etherscan.io/address/0x279b87139f2e89D7ce44c3056D2876fDEAB29BAE) Acts as a central contract to manage StarkGate bridge escrows (add new ones, deactivate existing, change configs) when given the Manager role from the respective escrows. * Can interact with USDC Bridge * deactivate bridging for deposits into the escrow ##### 2 EOAs Addresses: [0x09d1ad25B369A0C48Bdf4CaAb85aFd08a3f07044](https://etherscan.io/address/0x09d1ad25B369A0C48Bdf4CaAb85aFd08a3f07044) (EOA 1), [0xC70ae19B5FeAA5c19f576e621d2bad9771864fe2](https://etherscan.io/address/0xC70ae19B5FeAA5c19f576e621d2bad9771864fe2) (EOA 2) * Can interact with Paradex * Permissioned to regularly post L2 state updates and choose an available data-availability entry point. Under the current implementation, every update still needs a fact accepted by SHARP and cannot bypass the pinned program and config hashes ##### EOA 3 Addresses: [0x40060493a280915e2df7b46f8A9f251156080C39](https://etherscan.io/address/0x40060493a280915e2df7b46f8A9f251156080C39) * Can interact with StarkgateManager * enroll new tokens, deactivate existing ones (for deposits) or block tokens from being added to the Multibridge * manage critical access control roles related to upgrades and set the proxy governor that can upgrade the implementation * Can interact with StarkgateRegistry * manage critical access control roles and the role that can upgrade the implementation ##### 2 EOAs Addresses: [0x27aFEd9831209B58Cf24fa241E028dD1e80Fb17D](https://etherscan.io/address/0x27aFEd9831209B58Cf24fa241E028dD1e80Fb17D) (EOA 4), [0x3e87462D152DFDeD22b6AC5bcde702B20ed70CB6](https://etherscan.io/address/0x3e87462D152DFDeD22b6AC5bcde702B20ed70CB6) (EOA 5) * Can interact with USDC Bridge * enable the withdrawal limit ## Smart contracts ### Ethereum #### Paradex Addresses: [0xF338cad020D506e8e3d9B4854986E0EcE6C23640](https://etherscan.io/address/0xF338cad020D506e8e3d9B4854986E0EcE6C23640#code), [0x9961D34D3baE6914635c882e8FE382e14E0F172A](https://etherscan.io/address/0x9961D34D3baE6914635c882e8FE382e14E0F172A#code) (Implementation (Upgradable)), [0x0a64d3D7747549aF6d65C225D56ac8f71e436B93](https://etherscan.io/address/0x0a64d3D7747549aF6d65C225D56ac8f71e436B93#code) (Admin), [0xFF57A3bB6465501c993acF8f3b29125a862661C0](https://etherscan.io/address/0xFF57A3bB6465501c993acF8f3b29125a862661C0#code) (Admin) Central Starknet rollup contract. For every state update it derives a SHARP fact from the state-transition output and either the Starknet OS or aggregator program hash, checks that fact through the configured SHARP call proxy, and requires the output's OS-config hash to match. It also processes L1 <-> L2 messages and stores the finalized L2 state. * Roles: * **admin**: Paradex Multisig, Paradex Multisig 2 * **operators**: EOA 1, EOA 2 Can be upgraded by: Paradex Multisig with no delay, Paradex Multisig 2 with no delay #### CpuVerifierAllSolidity_2026_13 Addresses: [0x015381651F240Ed6C44122dCba6Cf807c9442CD6](https://etherscan.io/address/0x015381651F240Ed6C44122dCba6Cf807c9442CD6#code) Immutable Solidity verifier for one Cairo CPU layout. It checks the STARK proof using layout-specific constraint, OODS, Merkle, FRI, and periodic-column helper contracts. The SHARP verifier can select any configured layout by `cairoVerifierId`. #### CpuVerifierDex_2026_13 Addresses: [0x0cD0cDf0132c566db61B691BCEEBA2c4D8cA5CdC](https://etherscan.io/address/0x0cD0cDf0132c566db61B691BCEEBA2c4D8cA5CdC#code) Immutable Solidity verifier for one Cairo CPU layout. It checks the STARK proof using layout-specific constraint, OODS, Merkle, FRI, and periodic-column helper contracts. The SHARP verifier can select any configured layout by `cairoVerifierId`. #### CairoBootloaderProgram Addresses: [0x24105e6697AdD9B4B1BDE04079a91BDFCCa24A47](https://etherscan.io/address/0x24105e6697AdD9B4B1BDE04079a91BDFCCa24A47#code) Stores the complete compiled Cairo outer bootloader used as the top-level program of a SHARP proof. The SHARP verifier copies these words into public memory, pinning this exact executable onchain independently of the separately committed simple, applicative, and recursive-verifier programs. #### CpuVerifierRecursive_2026_13 Addresses: [0x2867A4509B0969531641A42a3D4A9B0A07109B6B](https://etherscan.io/address/0x2867A4509B0969531641A42a3D4A9B0A07109B6B#code) Immutable Solidity verifier for one Cairo CPU layout. It checks the STARK proof using layout-specific constraint, OODS, Merkle, FRI, and periodic-column helper contracts. The SHARP verifier can select any configured layout by `cairoVerifierId`. #### CpuVerifierSmall_2026_13 Addresses: [0x30F3AB988Cb00fe3Fb5ab891F50c13684770419b](https://etherscan.io/address/0x30F3AB988Cb00fe3Fb5ab891F50c13684770419b#code) Immutable Solidity verifier for one Cairo CPU layout. It checks the STARK proof using layout-specific constraint, OODS, Merkle, FRI, and periodic-column helper contracts. The SHARP verifier can select any configured layout by `cairoVerifierId`. #### MemoryPageFactRegistry_2023_9 Addresses: [0x40864568f679c10aC9e72211500096a5130770fA](https://etherscan.io/address/0x40864568f679c10aC9e72211500096a5130770fA#code) Permissionless commitment calculator and registry used by the Solidity STARK verifiers. Anyone may submit a public-memory page and interaction elements; the contract computes its hash and cumulative product and registers the fact key committing to them, which the CPU verifier must bind to the proof. It is part of the proof verifier, not an application-level program registry. A malicious or nonconforming implementation can break public-memory soundness; binding to a different honest registry generally causes a liveness failure instead. #### SHARPVerifierCallProxy Addresses: [0x47312450B3Ac8b5b8e247a6bB6d523e7605bDb60](https://etherscan.io/address/0x47312450B3Ac8b5b8e247a6bB6d523e7605bDb60#code), [0x3597c5CBCbCB30079a0bD2A68cDE5f98272f9feb](https://etherscan.io/address/0x3597c5CBCbCB30079a0bD2A68cDE5f98272f9feb#code) (Implementation (Upgradable)), [0x21F9eC47b19d95b5C2DDFB6Ae5D4F92fAdacAEc4](https://etherscan.io/address/0x21F9eC47b19d95b5C2DDFB6Ae5D4F92fAdacAEc4#code) (Admin) Upgradeable call router through which Starknet and other applications access SHARP fact registries. It uses `call`, not `delegatecall`, so facts and immutable verifier configuration remain at each target registry. The explicit `isValid` entry point always queries the default target. Other calls handled by the fallback, principally proof submissions, can be routed per caller to a still-active registry in the default target's reference chain. The default target can be replaced by SHARP Multisig after 8d. * Roles: * **admin**: SHARP Multisig * **appGovernor**: SHARP Multisig * **appRoleAdmin**: SHARP Multisig * **governanceAdmin**: SHARP Multisig Can be upgraded by: SHARP Multisig with 8d delay #### SHARPVerifier Addresses: [0x4956bda1d23F75B988644329c5B06BD1494a72b6](https://etherscan.io/address/0x4956bda1d23F75B988644329c5B06BD1494a72b6#code) Immutable GPS statement verifier shared by Starknet and other StarkWare systems. It verifies a STARK proof of the exact Cairo bootloader stored onchain, forces the bootloader configuration into public memory, and registers a fact for every bootloader task. A fact is also considered valid when it exists in the time-limited reference fact registry. #### SHARPVerifier_2026_13_1 Addresses: [0x5C1Ce45534A9c5f7F3E6683Cd79a8ad57EE3a9fe](https://etherscan.io/address/0x5C1Ce45534A9c5f7F3E6683Cd79a8ad57EE3a9fe#code) Immutable GPS statement verifier shared by Starknet and other StarkWare systems. It verifies a STARK proof of the exact Cairo bootloader stored onchain, forces the bootloader configuration into public memory, and registers a fact for every bootloader task. A fact is also considered valid when it exists in the time-limited reference fact registry. #### CpuVerifierDexWithBitwise_2026_13 Addresses: [0x6a67796ee97700B5B5f5aFBCFFDCbc5F80803F11](https://etherscan.io/address/0x6a67796ee97700B5B5f5aFBCFFDCbc5F80803F11#code) Immutable Solidity verifier for one Cairo CPU layout. It checks the STARK proof using layout-specific constraint, OODS, Merkle, FRI, and periodic-column helper contracts. The SHARP verifier can select any configured layout by `cairoVerifierId`. #### CpuVerifierStarknet_2026_13 Addresses: [0x71574057D12541ccDa98643aC56441838353A26D](https://etherscan.io/address/0x71574057D12541ccDa98643aC56441838353A26D#code) Immutable Solidity verifier for one Cairo CPU layout. It checks the STARK proof using layout-specific constraint, OODS, Merkle, FRI, and periodic-column helper contracts. The SHARP verifier can select any configured layout by `cairoVerifierId`. #### SHARPVerifier_2026_13_2 Addresses: [0x7Da1225C752ab37E610a242D9D8a0548262E3fF7](https://etherscan.io/address/0x7Da1225C752ab37E610a242D9D8a0548262E3fF7#code) Immutable GPS statement verifier shared by Starknet and other StarkWare systems. It verifies a STARK proof of the exact Cairo bootloader stored onchain, forces the bootloader configuration into public memory, and registers a fact for every bootloader task. A fact is also considered valid when it exists in the time-limited reference fact registry. #### CpuVerifierRecursiveLargeOutput_2026_13 Addresses: [0xbe0F8F150Fd10798524B4de80eD75751658CAEF3](https://etherscan.io/address/0xbe0F8F150Fd10798524B4de80eD75751658CAEF3#code) Immutable Solidity verifier for one Cairo CPU layout. It checks the STARK proof using layout-specific constraint, OODS, Merkle, FRI, and periodic-column helper contracts. The SHARP verifier can select any configured layout by `cairoVerifierId`. #### MemoryPageFactRegistry Addresses: [0xe583BcDE0160b637330b27a3ea1F3c02ba2eC460](https://etherscan.io/address/0xe583BcDE0160b637330b27a3ea1F3c02ba2eC460#code) Permissionless commitment calculator and registry used by the Solidity STARK verifiers. Anyone may submit a public-memory page and interaction elements; the contract computes its hash and cumulative product and registers the fact key committing to them, which the CPU verifier must bind to the proof. It is part of the proof verifier, not an application-level program registry. A malicious or nonconforming implementation can break public-memory soundness; binding to a different honest registry generally causes a liveness failure instead. #### SHARPVerifier_2026_13_3 Addresses: [0xE67515a751291445B85b2F176c1eCdf08e86b406](https://etherscan.io/address/0xE67515a751291445B85b2F176c1eCdf08e86b406#code) Immutable GPS statement verifier shared by Starknet and other StarkWare systems. It verifies a STARK proof of the exact Cairo bootloader stored onchain, forces the bootloader configuration into public memory, and registers a fact for every bootloader task. A fact is also considered valid when it exists in the time-limited reference fact registry. #### CpuVerifierPerpetual_2026_13 Addresses: [0xFFC7974cd74b95f631f454cd787AAc28F0476b44](https://etherscan.io/address/0xFFC7974cd74b95f631f454cd787AAc28F0476b44#code) Immutable Solidity verifier for one Cairo CPU layout. It checks the STARK proof using layout-specific constraint, OODS, Merkle, FRI, and periodic-column helper contracts. The SHARP verifier can select any configured layout by `cairoVerifierId`. #### StarkgateRegistry Addresses: [0xc50E4DF59aad8Ab494d10d2B66a90C9F0298f280](https://etherscan.io/address/0xc50E4DF59aad8Ab494d10d2B66a90C9F0298f280#code), [0x61D146CfE95Dc5Ba6d9c5d9C83c39C1bff018bD3](https://etherscan.io/address/0x61D146CfE95Dc5Ba6d9c5d9C83c39C1bff018bD3#code) (Implementation (Upgradable)), [0xFF57A3bB6465501c993acF8f3b29125a862661C0](https://etherscan.io/address/0xFF57A3bB6465501c993acF8f3b29125a862661C0#code) (Admin) A simple registry that maps tokens to their StarkGate escrows. It also keeps a list of tokens that are blocked from being added to StarkGate. * Roles: * **admin**: Paradex Multisig 2 * **govAdmin**: EOA 3 Can be upgraded by: Paradex Multisig 2 with no delay #### USDC Bridge Addresses: [0xE3cbE3A636AB6A754e9e41B12b09d09Ce9E53Db3](https://etherscan.io/address/0xE3cbE3A636AB6A754e9e41B12b09d09Ce9E53Db3#code), [0xDcbD52FFaF81BF0aA5bD38B0c15F60345e8Eec86](https://etherscan.io/address/0xDcbD52FFaF81BF0aA5bD38B0c15F60345e8Eec86#code) (Implementation (Upgradable)), [0xFF57A3bB6465501c993acF8f3b29125a862661C0](https://etherscan.io/address/0xFF57A3bB6465501c993acF8f3b29125a862661C0#code) (Admin) Standard Starkware bridge escrow (single token). Withdrawals can be throttled to 0% of the locked funds per 24 hours. * Roles: * **admin**: Paradex Multisig 2 * **govAdmin**: Paradex Multisig 2 * **manager**: StarkgateManager * **secAdmin**: Paradex Multisig 2 * **secAgent**: EOA 4, EOA 5, Paradex Multisig 2 Can be upgraded by: Paradex Multisig 2 with no delay #### CpuFrilessVerifier Addresses: [0x03Fa911dfCa026D9C8Edb508851b390accF912e8](https://etherscan.io/address/0x03Fa911dfCa026D9C8Edb508851b390accF912e8#code), [0x217750c27bE9147f9e358D9FF26a8224F8aCC214](https://etherscan.io/address/0x217750c27bE9147f9e358D9FF26a8224F8aCC214#code), [0x630A97901Ac29590DF83f4A64B8D490D54caf239](https://etherscan.io/address/0x630A97901Ac29590DF83f4A64B8D490D54caf239#code), [0x78Af2BFB12Db15d35f7dE8DD77f29C299C78c590](https://etherscan.io/address/0x78Af2BFB12Db15d35f7dE8DD77f29C299C78c590#code), [0x8488e8f4e26eBa40faE229AB653d98E341cbE57B](https://etherscan.io/address/0x8488e8f4e26eBa40faE229AB653d98E341cbE57B#code), [0x9E614a417f8309575fC11b175A51599661f2Bd21](https://etherscan.io/address/0x9E614a417f8309575fC11b175A51599661f2Bd21#code), [0xC879aF7D5eD80e4676C203FD300E640C297F31e3](https://etherscan.io/address/0xC879aF7D5eD80e4676C203FD300E640C297F31e3#code), [0xe9664D230490d5A515ef7Ef30033d8075a8D0E24](https://etherscan.io/address/0xe9664D230490d5A515ef7Ef30033d8075a8D0E24#code) #### CairoBootloaderProgram_2022_7 Addresses: [0x5d07afFAfc8721Ef3dEe4D11A2D1484CBf6A9dDf](https://etherscan.io/address/0x5d07afFAfc8721Ef3dEe4D11A2D1484CBf6A9dDf#code) #### MemoryPageFactRegistry_2022_7 Addresses: [0xFD14567eaf9ba941cB8c8a94eEC14831ca7fD1b4](https://etherscan.io/address/0xFD14567eaf9ba941cB8c8a94eEC14831ca7fD1b4#code) The current deployment carries some associated risks: - Funds can be stolen if a contract receives a malicious code upgrade. There is no delay on code upgrades (CRITICAL).