obentoDocs Open Obento

Security

Built on audited code

The vault is a fork of YO Protocol's core contracts. Nine firms have audited that code, including Cantina, Spearbit and Zellic, and YO runs the same vault with its own deposits. The vault's code is verified on Basescan.

Obento's own additions have not had an independent audit: the profit accounting, the price oracle and the revenue contract. Read the risks before you put money in.

Who controls what

RoleHeld byCanCan't
OwnerA 48-hour timelockUpgrade contracts, add places, change rolesChange anything without a public 48-hour wait
GuardianA Safe that needs 2 of 3 signersPause and resume at once, and propose timelocked changesMove savings
OperatorAutopilotMove money between listed places, pay queued withdrawals, pauseSend money outside the vault
UpdaterAutopilotPublish the share price within its 0.1% daily bandMove money

Every change to the vault's code, its places or its roles waits 48 hours in public. You can leave before any change takes effect.

Guards

  • A closed loop. The vault reaches lending places only through fixed adapters. Each one does a single job, can't be upgraded, and always returns money to the vault.
  • Approval caps. A registry fixes how much the vault may approve to each contract.
  • A banded price. The share price can move at most 0.1% from a daily anchor.
  • No stale prices. The vault refuses deposits and withdrawals once its price is an hour old.
  • Checked moves. Autopilot simulates every transaction before it sends it.
  • A watchdog. A separate check reads the vault every minute and alerts the team if anything is off.

Report a problem

Email obentoapp@proton.me.