Skip to main content
This page is for wallets, protocols, and apps that call the wstO vault directly. Addresses are listed on Contracts.
wstO is not ERC-4626. It has no mint, withdraw, or max* functions, and deposit and redeem take extra slippage and deadline arguments. Do not use a generic ERC-4626 adapter.

Functions

All amounts are in base units, and deadlines are Unix timestamps in seconds.
Previews and conversions revert instead of falling back to 1:1 when the vault holds no O or has no supply. To check whether deposits are open, call depositsPaused() on the Protocol Config returned by config().

Approvals

Permit approves wstO only, never the underlying O. Read the EIP-712 domain with eip712Domain() instead of hardcoding it. On every deployed vault it is { name: "Wrapped Staked O", version: "1", chainId, verifyingContract: vault }.

Quote, then protect

  1. Take minShares from previewDeposit, or minAssets from previewRedeem, less the user’s slippage tolerance.
  2. Quote again right before submitting. If a preview returns 0, block submission, because the call would revert.
  3. Before a deposit, compare previewRedeem(previewDeposit(assets)) with assets. minShares cannot show the O lost to rounding, and this check can.
  4. Simulate the transaction and decode the custom errors below.
There are no fees. The only loss is rounding down, which stays in the vault: less than the value of one share base unit per deposit, and at most one O base unit per redemption. Because the exchange rate never decreases, a fresh previewRedeem result is a safe minAssets.

Receivers to reject

The vault rejects address(0), 0x…01, 0x…02, and the vault itself as the receiver of deposit and redeem. It still accepts some destinations from which nothing can ever move. Integrations must reject:
  • the Permanent Share Sink as the receiver of redeem, because the O would leave the vault for an address that can never move it;
  • the O token contract as any receiver;
  • a plain wstO transfer to the vault address.
Send shares to the Permanent Share Sink only when the intent is to lock them permanently.

Do not

  • Do not send O directly to the vault. It mints no wstO, raises the rate for every holder, and cannot be recovered.
  • Do not expose burn in a user interface. It destroys wstO for nothing in return.
  • Do not use exchangeRate() as a price oracle. Donations can raise it at any time.

Errors

Events

Scan history in bounded windows starting from the vault creation block on Contracts. Public RPCs limit eth_getLogs ranges, for example to 500 blocks on Base and 50,000 blocks on Robinhood Chain, and are not archive nodes.