Security & controls

What the protocol can do, what it cannot do, and what users should still treat as risk.

Short version

DCA Onchain is self-custodial: user funds sit in each user's own strategy account, and only the user can withdraw. The automation can trigger scheduled buys, but it cannot change a user's strategy, redirect assets, or withdraw on a user's behalf. Admins can change protocol configuration, including fees within hard on-chain caps, but they cannot take user balances from strategy accounts.

User guarantees

GuaranteeHow it worksImportant limit
Withdraw anytimeWithdrawals live on the user strategy account and remain available even when batch execution is paused.Withdrawing closes the strategy permanently.
Strategy settings stay fixedOwner, target asset, amount, frequency, yield setting, and yield adapter are locked after creation.To change settings, withdraw and create a new strategy.
The executor has a narrow roleThe executor can only trigger scheduled buys through the batch contract.If automation is delayed or fails, buys can be delayed.
Scheduled pulls are boundedEach strategy account only releases its configured per-period USDC amount during execution.Underfunded accounts are skipped or paused depending on the path.
Failed output delivery is recoverableIf sending purchased assets to the strategy owner fails, the amount is tracked as pending and can be claimed.The user must claim pending output manually.

Admin powers

Ownership of every administrative contract is held by a TimelockController, so configuration changes are queued publicly on chain and cannot take effect for two days. Active and completed operations are available on the public governance page. A separate guardian, a 2-of-3 Safe, holds only the powers that would be useless if delayed. Admin powers are intentionally limited to configuration and emergency controls.

Admin canAdmin cannot
Change protocol fees within hard on-chain caps, after the two-day delay.Withdraw funds from a user's strategy account.
Configure supported assets, swap routes, approved yield implementations, the oracle, and the treasury address, after the two-day delay.Change an existing user's target asset, amount, frequency, owner, or yield setting.
Pause new strategy creation or batch execution, instantly (guardian).Block a user from withdrawing their remaining funds, paused or not.
Change the executor address, instantly (guardian).Bypass the batch contract's checks during execution, or lower the oracle floor.
Recover tokens accidentally stranded in contracts that should not hold funds at rest.Use that recovery path to pull normal user balances from strategy accounts.

The split is the point: everything that could redirect where money goes is slow and visible, and the two instant powers cannot redirect anything. Rotating the guardian is itself owner-gated, so a compromised guardian cannot entrench itself.

Fee changes

Protocol fees are global settings. If the owner changes a fee, the new value applies to existing strategies going forward, and only after the two-day delay. The contracts enforce maximums on-chain:

  • Execution fee: capped at 1% of the USDC collected for a batch.
  • Yield fee: capped at 30% of positive yield earned.

There is no referral share to configure. No contract computes, stores, or pays one.

Execution protections

During a batch, the contract checks that each account's target asset matches the batch asset, and that the swap output clears an independent on-chain price floor. The amount swapped is derived from what the contract actually collected, net of the fee, rather than from a figure the executor supplies. If these checks fail, the batch reverts instead of executing at an unsafe price or into the wrong asset.

The batch executor keeps none of the funds it moves: whatever it collects is distributed within the same transaction, and the check is that its balances are unchanged rather than empty, since anyone can send it stray tokens. User funds live in user strategy accounts, and purchased assets are forwarded to the strategy owner or tracked as claimable if delivery fails.

Because the execution fee is taken in USDC before the swap, the whole purchased amount belongs to the accounts that funded it. There is no fee cut applied to the asset you receive.

Operational risks

Self-custodial does not mean risk-free. Users should understand these dependencies before depositing:

  • Smart contracts can still contain bugs.
  • Automation can be delayed by host outages, RPC issues, gas issues, or keeper failures.
  • Price feeds, Uniswap, Aave, the underlying chain, and RPC providers are external dependencies.
  • Admin configuration mistakes can pause execution or disable an asset until corrected.
  • Market prices can move between quote and execution.
  • The protocol is newly launched on Base mainnet. The end-to-end lifecycle was verified by a single-account mainnet canary; broader multi-account behaviour is covered by the invariant, fuzz, and fork test suite and by monitoring, not by long production history.

For a more detailed list of centralized dependencies and failure modes, see Trust & failures.

Security review

The contracts were reviewed, and issues found during that process were resolved in source and covered by regression tests. Security-sensitive paths carry regression tests, accounting math is covered by invariant and fuzz tests, and integration paths are covered by fork tests against Base mainnet state.

Separately, the deployed governance configuration was audited on chain: that the timelock owns every administrative contract, that its minimum delay is two days, that the role grants resolve only to expected holders, and that the deploying address retained no privilege.

Neither reduces risk to zero, and neither is a guarantee that the protocol is bug-free.