SECURITY
Risks
Known risks and limitations from the contract repo.
- Smart contract risk. The contracts are unaudited release-candidate code and may contain bugs.
- Oracle/feed staleness. Production feed age defaults to
24h. Weekend or holiday mints can revert with stale feeds; redeem-for-stocks does not depend on feeds. - DEX liquidity risk. Mint and redeem-for-ETH depend on available Uniswap V4 route depth and frontend-supplied per-component slippage minima.
- Robinhood tokenized-stock issuer risk. Component tokens may pause transfers, apply blocklists, or have issuer-controlled restrictions. Paused transfers can become claims, but broad restrictions can still require operational handling.
- Adapter and route configuration risk. V4 adapter routes require correct stock/USD feeds and ETH/USD configuration for sanity and NAV math.
- Buyback execution risk. FeeCollector buybacks are rate-limited, but keepers still need sane off-chain minimum output calculations. Buyback requires a Sushi V2 BENTO/WETH pool; until one is seeded, fees accumulate in the collector without burning.
- External token risk. BENTO is launched through the pons.family factory and its pool liquidity is locked by pons contracts; Bento Protocol has no control over the pons factory, locker, or fee-claim mechanics.
See the contracts repo RISKS.md for the canonical engineering risk notes.