Skip to main content

Security & audits

TL;DR

Standard signed orders enforce your sell amount, receiver and limit price in the settlement contract. Batch auctions mitigate common MEV; they do not remove every execution risk. Native-token, bridge, vault and OTC paths have additional contract and recovery assumptions. The governance addresses below describe the listed deployment, not every contract used by every route.

Ophis uses wallet-authorized orders and transactions. The enforced limits and recovery rules depend on the path you authorize. This page separates batch-auction settlement contracts from bridges, deposits and external escrow, and identifies the deployment and review scope behind each claim.

Custody​

Standard ERC-20 swaps use EIP-712 wallet signatures, ERC-1271 validation, or explicit onchain presigning. Funds remain in the wallet until settlement. The order fixes the sell token, sell amount, minimum buy amount (your limit price), receiver and expiry, and an authorized solver settles it on-chain within those limits. The settlement enforces the authorized sell amount and any applicable signed fee, the receiver and the minimum buy amount.

Native-token orders deposit into EthFlow before settlement. Bridge routes can deposit or burn assets before delivery and follow provider recovery rules. The optional OTC integration uses external escrow, while vault modules can authorize presigned orders. These are not the same custody or expiry model as an offchain ERC-20 order. Always check the contract, approval, receiver and minimum amount in your wallet; an immutable settlement does not prevent a compromised interface from asking you to authorize a harmful action.

Externally funded NEAR swaps start with a source-chain deposit rather than a CoW order signature. Verify the asset, amount, destination, refund address, deadline and any memo before sending. Keep the saved transfer for delivery or refund tracking. The settlement addresses below do not authenticate a NEAR deposit address or extend CoW's audit scope to NEAR, Across or Circle routes.

MEV protection by construction​

Batch-auction orders settle with a uniform clearing price per token pair. This is designed to mitigate common MEV vectors at the mechanism layer:

  • Orders are submitted offchain instead of broadcasting individual public swaps.
  • Uniform batch prices reduce ordering advantages within a token pair.
  • Signed limits constrain what a solver may execute.

When the winning settlement transaction is broadcast, its calldata can be visible in the public mempool like any transaction. The signed sell amount, receiver, and limit price remain enforced by the settlement contract. Batch settlement materially mitigates common MEV; it is not an absolute guarantee against every adversarial or infrastructure condition.

Smart contracts​

Ophis runs its own deployment of CoW Protocol's GPv2 settlement stack on Optimism, Unichain, Robinhood Chain, and Arc. The listed settlement, relayer and EthFlow contracts are immutable: they have no upgrade admin or proxy. Their bytecode and constructor wiring cannot be replaced by an Ophis operator. The separate mutable solver allowlist still affects who may settle orders; immutability does not guarantee availability.

Addresses were cross-checked against the SDK deployment map and public RPC code/relayer reads on October 1, 2026. Chain ID is part of the identity: never reuse a listed address on a different network.

ContractAddress (Optimism, chain 10)Property
GPv2Settlement0x310784c7FCE12d578dA6f53460777bAc9718B859Immutable, no admin/proxy
GPv2VaultRelayer0x83847EaB41ad9ea43809ce71569eB2e9daF51830Immutable, only ever honors the Settlement above
CoWSwapEthFlow0x764fE4aa1FF493cf39931c7923C8ff5837596504Immutable, native-ETH sells (see below)
ContractAddress (Unichain, chain 130)Property
GPv2Settlement0x108A678716e5E1776036eF044CAB7064226F714EImmutable, no admin/proxy
GPv2VaultRelayer0xaB29E2a859704C914E55566Ae9b3A7EDE25959cbImmutable, only ever honors the Settlement above
CoWSwapEthFlow0x38C03729153BCCF6a281DaF41D7C6a14C543F1D7Immutable, native-ETH sells (see below)
ContractAddress (Robinhood Chain, chain 4663)Property
GPv2Settlement0x886d9fd312F442C4E1f3cdeAE7b4AB73493e57cDImmutable, no admin/proxy
GPv2VaultRelayer0xB52C38097c19cd38238c62DD36027a7918eFa890Immutable, only ever honors the Settlement above
CoWSwapEthFlow0xC1Ee77e8a1B85D5EED702a9bB435f434408A4d29Immutable, native-ETH sells (see below)

The Robinhood settlement remains 0x886d9fd312F442C4E1f3cdeAE7b4AB73493e57cD. It is an Ophis deployment, distinct from CoW's canonical settlement address on CoW-hosted chains.

ContractAddress (Arc, chain 5042)Property
GPv2Settlement0x78799F98276efba1EdeeD32eae03a3fd8Cdfec3AImmutable, no admin/proxy
GPv2VaultRelayer0x895505F1FE6D762296685fF4a8201782FFdCB8E9Immutable, only ever honors the Settlement above

Arc deployment configuration is recorded in the Arc release sources. SDK v0.4.3 includes Arc signing and approval helpers; use chain ID 5042 and do not substitute another chain's addresses. Arc has no supported EthFlow deployment; use its ERC-20 token interfaces for batch orders. These immutability claims do not cover token issuers, bridges or every external contract a route touches.

The core settlement derives from CoW Protocol. Its upstream audits are relevant to shared code, but are not an audit of every Ophis modification or deployment:

Ophis-specific contract changes reviewed in internal/tool-assisted security reviews include a hardened GPv2AllowListAuthentication (two-step manager transfer) and partner-fee settlement-buffer handling. Ophis also maintains frontend, solver, bridge and integration code. A review of those contract changes is not a blanket audit of every component or later release.

Audit methodology and tools​

Ophis used the following open-source security skills, guidance, analysis tools, and formal-verification technology across applicable review scopes.

Reproducible scope and results are recorded in the repository's audit/ and docs/audits/ reports. A tool or proof applies only to the scope named in its report; for example, an access-control proof does not prove unrelated Rust or TypeScript code. Use of Pashov or Trail of Bits skills and tools is not an organizational audit, endorsement or certification by those firms.

Native-ETH sells (EthFlow)​

Selling native ETH is placed as an on-chain order to the immutable CoWSwapEthFlow contract, which is constructor-wired to the Settlement and WETH. The placement transaction authorizes the limit price and receiver; it is not an offchain EIP-712 order signature. Unfilled deposits are refundable by you on-chain after the order expires, so even if no solver ever settles it, you reclaim your ETH directly from the contract without trusting any operator.

Solver governance​

In the Optimism settlement deployment listed below, the mutable governance surface is the solver allowlist (which addresses may settle batches). Its governance is:

  • Adding a solver, or changing the allowlist's manager or implementation, flows through an on-chain 24-hour TimelockController: every such change is publicly visible and delayed a full day before it can take effect.
  • The timelock's proposer and executor is a 2-of-3 multisig (Gnosis Safe, hardware-wallet signers); the deployer's admin rights were renounced and the timelock self-administers.
  • A misbehaving solver can be evicted in a single transaction by the multisig: fast removal is allowed; only additions and upgrades are delayed.
ContractAddress (Optimism)
Solver allowlist (GPv2AllowListAuthentication)0xAAA13bC6C1A505ccE6B4BF262fdDf4c703B9BD70
TimelockController (24h)0x8fEe42897a0113BbeC86e4caCCaC5787D7AEC373

Key custody​

The documented governance and fee custody use multisigs:

  • The protocol multisig and the partner-fee multisig are each a 2-of-3 Gnosis Safe with hardware-wallet signers: no single key can move governance or fees.
  • Settlement transactions use operational solver keys. Solver authorization does not waive order validation or let a solver exceed an order's limits. Safe threshold and membership are onchain properties; hardware-key custody is an operational policy, not something an address alone proves.

The partner-fee multisig (0x858f0F5eE954846D47155F5203c04aF1819eCeF8) holds collected protocol fees separately from trader balances. Route-specific contracts can hold native-token or bridge deposits as described above. See Fees & rebates for how the fee is calculated.

Infrastructure​

  • The trading backend is self-hosted behind Cloudflare; only the public orderbook API is internet-reachable, and the settlement driver is bound to loopback only.
  • The settlement signing key is held under OS-level isolation (dedicated no-shell account, restrictive permissions, rendered to RAM at runtime), not in plaintext alongside the application.
  • On-chain state is read through a multi-source RPC consensus layer that fails closed: if the sources disagree or are unavailable, the driver stops rather than acting on an unverified view.
  • The frontends use app-specific Content-Security-Policy headers. The swap app permits unsafe-eval, broad HTTPS connections and embedding for its integrations; the landing policy is tighter. The sites are deployed from a branch-protected, SHA-pinned CI pipeline with signed build provenance, and the edge enforces HTTPS.

Ophis-specific code​

The code unique to Ophis is open source and auditable end to end:

ComponentWhat it is
FrontendA fork of the CoW Swap frontend with the natural-language intent layer.
Intent-parser proxyA Cloudflare Pages Function in front of LibertAI Qwen 3.6 27B; the model key is held server-side. See the Intent API.
Rebate indexerIndexes the volume-tier rebates that accrue to traders. See Fees & rebates.

Source: github.com/ophis-fi/ophis.

Reporting a vulnerability​

Responsible disclosure is welcome. Email clement@aleph.cloud with the subject prefix [OPHIS SECURITY]; see SECURITY.md for the full policy and response targets.

Operator contact: contact form.