Skip to content
KIMP

Admin keys and timelock

KIMP has a pause-only guardian Safe (4-of-7) and a 48-hour timelock on every parameter change. Core contracts are non-upgradeable.

KIMP minimizes privileged control. There are two privileged roles. The guardian can pause markets. The timelock executes governance decisions after a 48-hour delay. No other key can change the protocol.

Roles#

RoleHolderPower
GuardianSafe multisig, 4-of-7 signersPause markets only
TimelockGovernance executor with a 48-hour delayAll parameter changes and source switches

In the contracts, every parameter setter is onlyTimelock, and pause is onlyGuardian.

The guardian#

The guardian is a Safe multisig that requires 4 of 7 signers. Its only power is to pause markets. A pause stops new exposure. The guardian exists to limit damage during an incident while governance prepares a response.

What the guardian cannot do#

ActionGuardian
Pause marketsYes
Move user collateral or pool assetsNo
Change fees, leverage, limits or OI capsNo
Change index sources or reporter rulesNo
Slash reporters or resolve disputesNo
Upgrade or replace contract logicNo
Mint, move or burn $KIMPNo
Change Verified Lane rulesNo

The timelock#

All parameter changes pass through a 48-hour timelock. This includes listed assets, index sources such as the Upbit Oracle switch, leverage, fee parameters and Verified Lane rules. Proposals follow the governance process: forum discussion, on-chain proposal, 5-day vote with quorum, 48-hour timelock, then execution.

The delay gives every user and LP time to review a queued change and exit before it takes effect.

Non-upgradeable core#

Core contracts are non-upgradeable. There are no upgradeable proxies over custody or settlement logic. New versions deploy side by side with the existing contracts, and liquidity migrates by governance decision. Users are never moved to new code without their own action.

Emergency procedures#

  1. 1Detect. An issue is identified through monitoring, a reporter flag, a dispute or a responsible disclosure.
  2. 2Pause. If user funds or index integrity are at risk, the guardian pauses the affected markets.
  3. 3Communicate. Status is published on X at @KimpGiwa and in these docs.
  4. 4Remediate. Governance queues a parameter change through the timelock, or a fixed version is deployed side by side.
  5. 5Resume. Markets are unpaused once the issue is resolved and the change has cleared the timelock.

Signers#

Guardian signer identities and the Safe address will be published in these docs before mainnet. Any change to the signer set is announced on X at @KimpGiwa.