Admin keys and timelock
KIMP has a pause-only guardian Safe (4-of-7) and a 48-hour timelock on every parameter change. Core contracts are non-upgradeable.
KIMP minimizes privileged control. There are two privileged roles. The guardian can pause markets. The timelock executes governance decisions after a 48-hour delay. No other key can change the protocol.
Roles#
| Role | Holder | Power |
|---|---|---|
| Guardian | Safe multisig, 4-of-7 signers | Pause markets only |
| Timelock | Governance executor with a 48-hour delay | All parameter changes and source switches |
In the contracts, every parameter setter is onlyTimelock, and pause is onlyGuardian.
The guardian#
The guardian is a Safe multisig that requires 4 of 7 signers. Its only power is to pause markets. A pause stops new exposure. The guardian exists to limit damage during an incident while governance prepares a response.
What the guardian cannot do#
| Action | Guardian |
|---|---|
| Pause markets | Yes |
| Move user collateral or pool assets | No |
| Change fees, leverage, limits or OI caps | No |
| Change index sources or reporter rules | No |
| Slash reporters or resolve disputes | No |
| Upgrade or replace contract logic | No |
| Mint, move or burn $KIMP | No |
| Change Verified Lane rules | No |
The timelock#
All parameter changes pass through a 48-hour timelock. This includes listed assets, index sources such as the Upbit Oracle switch, leverage, fee parameters and Verified Lane rules. Proposals follow the governance process: forum discussion, on-chain proposal, 5-day vote with quorum, 48-hour timelock, then execution.
The delay gives every user and LP time to review a queued change and exit before it takes effect.
Non-upgradeable core#
Core contracts are non-upgradeable. There are no upgradeable proxies over custody or settlement logic. New versions deploy side by side with the existing contracts, and liquidity migrates by governance decision. Users are never moved to new code without their own action.
Emergency procedures#
- 1Detect. An issue is identified through monitoring, a reporter flag, a dispute or a responsible disclosure.
- 2Pause. If user funds or index integrity are at risk, the guardian pauses the affected markets.
- 3Communicate. Status is published on X at @KimpGiwa and in these docs.
- 4Remediate. Governance queues a parameter change through the timelock, or a fixed version is deployed side by side.
- 5Resume. Markets are unpaused once the issue is resolved and the change has cleared the timelock.
Signers#
Guardian signer identities and the Safe address will be published in these docs before mainnet. Any change to the signer set is announced on X at @KimpGiwa.