Skip to content

Governance and upgradesLink to this section

TL;DRLink to this section

  • Administrators can change the contracts that record work and calculate rewards through delayed governance operations.
  • An emergency pause stops settlement and new reward funding, not every owner action.
  • The SQK lifetime cap is fixed, but it doesn't prove that issuance is backed by work.
  • A delay gives notice; it doesn't make a malicious upgrade safe.

What can an upgrade change?Link to this section

The contracts that record work and manage rewards can be upgraded. For an owner, that means the rules you rely on also depend on the administrators who can change their code. A governance delay provides notice before an operation can execute; it doesn't prove the replacement code is safe.

Core records settled work, while Mining calculates rewards and holds the SQK used to pay claims. A malicious Core upgrade could report consistent but false work. A malicious Mining upgrade could mint all remaining SQK without work, misallocate funds, or block users.

What stays fixed?Link to this section

Token isn't upgradeable. It fixes the lifetime supply cap and permits only Mining to mint, with newly minted SQK sent to Mining. It doesn't independently check work, round processing, or the reward policy. Those checks belong to the upgradeable reward code.

The Guardian's emergency pause is narrower than an upgrade. It stops settlement and checkpoint funding through Core, but owners may still claim already funded rewards if the ownership and payment checks work. It isn't a pause of the entire system.

Technical detail: governance rolesLink to this section

The Guardian pauses Core and can change its Reporter while paused. The Reporter signs settlements; relayers submit them.

Timelock proposers schedule changes and cancellers can cancel them. After the configured delay, an eligible operation can execute through the Timelock's ProxyAdmin without Guardian or Reporter approval.

PermissionsLink to this section

Component Governance boundary
Core The Timelock's ProxyAdmin upgrades code; the Guardian separately pauses/unpauses Core and changes the Reporter while paused
Mining Upgradeable through Timelock governance; no Mining Guardian role
Token Cannot be upgraded; fixes Mining as its mint caller and recipient, and fixes the lifetime supply cap
Factory Launches and checks fresh contracts in one transaction; has no continuing Core governance power
NFT Uses fixed dependencies and ownership rules; only Mining can burn merge donors

Compatible Core upgrades must preserve stored state, work rules, and fixed difficulty.

GuaranteesLink to this section

Core has no function to change difficulty, call arbitrary contracts, or permanently lock upgrades. Settlement signatures identify the executing implementation, so a signature for one version cannot authorize another.

Token starts with zero supply and enforces its lifetime minting cap. Its mint function cannot rewrite holders' existing balances, spending allowances, or permit nonces.

AssumptionsLink to this section

Upgrade administrators must be trusted to preserve stored data and economic rules. A malicious Core upgrade could report consistent but false work that Mining's checks cannot disprove.

A malicious Mining upgrade could mint all remaining SQK without work, reuse round records, misallocate funds, corrupt rewards, or block users. Token checks neither Core work nor round processing, and enforces no per-block reward limit or separate reward-policy lock.

Mining—not Token—requires work-backed issuance, processes each round only once, and enforces a combined reward multiplier range of 1×–2× (10000–20000 basis points). The multiplier is 1× (10000 basis points), with no public multiplier setter or owner-controlled boost.

Failure behaviorLink to this section

Condition Effect
Guardian pauses Core Settlement stops; Mining checkpoint reverts CorePaused
Core paused with funded rewards Owners can still claim if NFT and Token checks work; pause alone does not block transfers, mints, or merges
Core fails required checks Affected mint, merge, or checkpoint transactions fail
Reporter change while unpaused Fails; Core must be paused and the new Reporter address unused
Timelock operation not ready Cannot execute through the normal governance path
Mint request exceeds remaining supply Token rejects the entire mint
Malicious Mining mint request within the cap Token does not check whether work backs the request

Code review, upgrade tests, and the behavior of previous deployments provide different evidence. None guarantees that replacement code is safe.