Security and Risk
An honest account of what can go wrong and how the design responds.
CUSP manages risk. It does not pretend to remove it. Here is what can actually go wrong, and what the design does about each one.
The risks
- Resolution risk: a market can resolve against a financed position faster than any liquidation can react. The response is to value collateral conservatively and pull borrowing capacity before resolution through the origination gate, so nothing is financed through the window where it can gap to zero.
- Liquidity risk: depth can vanish at the exact moment a position needs clearing. The conservative mark values collateral at what selling into current bids would really fetch, and liquidation runs through bonded specialists instead of bots that sell into an empty book.
- Oracle and venue risk: CUSP depends on the venue's authoritative record and on it eventually paying out. Inputs come from that record rather than display feeds, and settlement exposure is priced with conservatively inflated failure assumptions.
- Model risk: any valuation can be wrong. The launch posture caps total credit by first-loss capital, so senior depositors are covered by arithmetic while the calibration record is still short, and every score is published for anyone to check.
- Smart-contract risk: code can have faults. This one is shared with every on-chain system; it is addressed through review and through the public transparency record.
Audits and formal reviews will be listed here once complete. This page is updated as that work is published.
Nothing on this page or anywhere in these docs is investment, legal, or tax advice. The docs describe protocol design; the formal treatment of every mechanism is in the CUSP whitepaper.