docs reference
Risks
Oracle, smart contract, capacity and basis risk.
Every role in STALL carries risk. Cover buyers can pay premiums and receive nothing when they needed a payout. Underwriters and stakers can lose most or all of their capital in a single halt. This page sets out the main risks known today; it is not exhaustive, and nothing in it is financial advice.
Oracle failure or late flag
STALL pays on the Chainlink L2 Sequencer Uptime Feed and nothing else, so anything that goes wrong with the feed goes wrong with STALL.
- Failure or misconfiguration. The feed could fail, stop updating or be misconfigured, either at the source or in STALL's oracle configuration. Settlement could then be delayed, or produce a result that does not match what happened.
- Late flag. If the down status is reported late, the measured halt duration is shorter than the halt itself. A halt of 65 min whose down status is recorded 10 min late measures 55 min, and the 1 h tier is not triggered.
- Measured versus experienced. The halt duration that counts is the one measured from the feed's status timestamps. It can differ from the duration reported on a status page and from the disruption individual users experienced. Disruption that the feed does not record as a halt pays nothing.
- Message delivery. Status reaches the feed on Base through messages from Ethereum. Problems with that route would affect when and how a halt is recorded.
There is no claims process to correct a reading after the fact. See Trigger and oracle.
Smart contract risk
The STALL contracts are not deployed and no audit has been published. Smart contracts can contain bugs. A bug in cover, vault, staking or settlement logic could cause a total loss for cover buyers, underwriters and stakers, or prevent payouts from being made. An audit, if one is published, reduces this risk but does not remove it.
Vault capacity
- Cover may be unavailable. Cover cannot be bought in a tier that is at capacity. A cover buyer may not be able to buy the payout size or tier they want, when they want it.
- Underwriters can lose most of their deposit in a single halt. In example D, underwriters in a 15 min vault at capacity lose 881,200 USDC net on 1,000,000 USDC deposited.
- Losses are correlated. A halt triggers every cover position in a tier at once, and a long halt triggers every shorter tier with it. Spreading cover across many cover buyers does not diversify the risk.
- Locked capital. Vault assets that back active cover cannot be withdrawn until those positions expire.
See Underwriting vaults.
Short halts that never reach a tier
A tier is triggered only when the halt duration exceeds its threshold. Halts that fall short pay nothing, whatever they cost:
- A 14 min halt pays nothing on any tier.
- A 59 min halt pays nothing on the 1 h tier.
- A 2 h 50 min halt pays nothing on the 3 h tier.
Basis risk
Cover pays a fixed payout size, not the cover buyer's actual loss. A cover buyer can suffer a large loss in a halt that does not exceed their tier's threshold and receive nothing. When cover is triggered, the payout can be larger or smaller than the loss. Choosing the payout size and tier that match a given exposure is the cover buyer's responsibility.
$STALL value
First-loss capital is staked $STALL. Stakers can lose their stake in a single halt, and the market value of $STALL can also fall for reasons unrelated to any halt. How staked $STALL is valued against USDC liabilities has not been finalised, so the effect of a fall in its value on capacity and on the protection it gives underwriters is not yet defined. See valuing staked $STALL.
Governance risk
$STALL stakers govern tiers, rates and oracle configuration, and fees are subject to governance. Parameters can change. Stakers' interests are not identical to those of cover buyers or underwriters. These docs do not specify how parameter changes would apply to cover positions that are already active.
Regulatory uncertainty
The legal treatment of parametric smart-contract products, staking and tokens varies between jurisdictions and may change. That could restrict who can use STALL or require changes to how it works. STALL cover is not an insurance policy, and cover buyers should not expect the protections that apply to regulated insurance.
Dependency on Base and USDC
- Base. STALL runs on Base, so a halt that triggers cover also stops STALL. Payouts can only be made after the restart; the longer the halt, the longer cover buyers wait. Changes to how Base is sequenced or to how the feed is delivered could require changes to STALL's configuration.
- USDC. Premiums, vault deposits and payouts are in USDC. STALL depends on USDC holding its value and remaining transferable. USDC's issuer can block transfers to and from specific addresses; how a payout to a blocked address would be handled has not been specified.
STALL is not affiliated with Base, Coinbase or Chainlink, and none of them stands behind STALL cover.