Paper100 has an admin key with a short, fixed list of powers. Everything it can do is below. Everything else is impossible by construction.
The admin can
- Add a market.
- Update a market's caps and impact parameters within hard bounds: maximum leverage at most 100,
baseRateat most 20 % (2,000 bps), every fee at most 5 % (500 bps). - Pause and unpause new opens, for all markets at once. Closes, liquidations, deposits, withdrawals and claims keep working while opens are paused.
- Retire a market, permanently. Retiring freezes the newest book price; new opens revert, and positions close and liquidate against the frozen price without a proof.
- Set the RedStone signer set and threshold. The threshold can never go below 3.
- Set the project token mint and the holder threshold for the win fee discount.
- Set the treasury token account and the keeper address.
- Hand the admin role to another key in two steps:
transfer_adminproposes, andaccept_admin, signed by the new key, completes.
The admin cannot
- Move your
availableorlockedbalance, or withdraw on your behalf. - Touch
lp_cash, the queue line, claims or paper rewards. - Mint, burn or move paper.
- Change a position once it is open.
- Change the program's code. Paper100 has no upgrade path.
The keeper
The engine gives the keeper a single power: opening and closing trading sessions on equity markets. Paper100 lists only SOL, BTC and ETH, which trade around the clock, so in practice the keeper has no power over trading that any other account lacks. Everything it does (posting prices, executing, liquidating, sweeping) is permissionless.
The admin, keeper and treasury addresses are stored in the Config account. See Program and accounts.