Catastrophic Failure Modes¶
What Can Go Catastrophically Wrong¶
- governance approves malicious implementation and executes it.
- role-admin custody compromise silently reassigns critical roles.
- controller or deposit upgrades remove or weaken fail-closed checks.
- oracle pipeline corruption feeds fabricated finalized observations.
- reserve assumptions fail at scale and settlement cannot maintain expected protection behavior.
- operations team misses critical queue during timelock and cannot cancel in time.
Severity Notes¶
All six are protocol-critical because they can alter custody safety or payout correctness at system scale.
Prevention Priorities¶
- governance role separation and monitoring
- release artifact provenance
- incident drills for cancellation and freeze paths
- independent risk/receipt feed validation