Functions
All amounts are in base units, and deadlines are Unix timestamps in seconds.depositsPaused() on the Protocol Config returned by config().
Approvals
Permit approves wstO only, never the underlying O. Read the EIP-712 domain with
eip712Domain() instead of hardcoding it. On every deployed vault it is { name: "Wrapped Staked O", version: "1", chainId, verifyingContract: vault }.
Quote, then protect
- Take
minSharesfrompreviewDeposit, orminAssetsfrompreviewRedeem, less the user’s slippage tolerance. - Quote again right before submitting. If a preview returns 0, block submission, because the call would revert.
- Before a deposit, compare
previewRedeem(previewDeposit(assets))withassets.minSharescannot show the O lost to rounding, and this check can. - Simulate the transaction and decode the custom errors below.
previewRedeem result is a safe minAssets.
Receivers to reject
The vault rejectsaddress(0), 0x…01, 0x…02, and the vault itself as the receiver of deposit and redeem. It still accepts some destinations from which nothing can ever move. Integrations must reject:
- the Permanent Share Sink as the receiver of
redeem, because the O would leave the vault for an address that can never move it; - the O token contract as any receiver;
- a plain wstO
transferto the vault address.
Do not
- Do not send O directly to the vault. It mints no wstO, raises the rate for every holder, and cannot be recovered.
- Do not expose
burnin a user interface. It destroys wstO for nothing in return. - Do not use
exchangeRate()as a price oracle. Donations can raise it at any time.
Errors
Events
Scan history in bounded windows starting from the vault creation block on Contracts. Public RPCs limit
eth_getLogs ranges, for example to 500 blocks on Base and 50,000 blocks on Robinhood Chain, and are not archive nodes.