Skip to content
SECTION 12 / 15

Admin powers

Exactly what the VIRUS admin can and cannot do, the timelocks, and the Pons owner powers that reach VIRUS viruses.

§Two sets of powers

A virus is subject to two independent authorities:

  • The VIRUS admin, the owner of VirusRegistry (intended to be a multisig in production), and the owner of VirusTreasury. Their powers are limited by code to future launches and to treasury funds.
  • The Pons owner and the Pons fee sweep operator. Pons powers are defined by Pons contracts that VIRUS does not control, and some of them reach existing viruses.

Both are listed here in full. The VIRUS admin's list is enforced by VIRUS code; the Pons list is taken from the published Pons source (VERIFIED_PONS, published source is not proof of deployed bytecode).

§VIRUS admin

§The admin can

Power Function Effect Delay
Pause new launches registry.setLaunchesPaused(bool) inoculate and registerVirus revert while paused. Nothing else is affected. None
Disable a host for new launches registry.setHostDisabled(host, bool) New viruses on that host are refused. Existing viruses are unaffected. Reversible. None
Change the treasury for future viruses registry.proposeTreasury(addr) → executeTreasury(); cancelTreasury() Feeders deployed after execution pay the new treasury. The coordinator also sends new inoculation fees there. 2 days (TREASURY_DELAY), then a 7-day window (EXECUTION_WINDOW) after which the proposal expires
Change the coordinator setInitialCoordinator(addr) once at deployment, then proposeCoordinator(addr) → executeCoordinator(); cancelCoordinator() A new coordinator governs future launches only. It must use the same feeder factory and Pons factory the registry pinned at deployment. 2 days (COORDINATOR_DELAY), then a 7-day window after which the proposal expires
Transfer registry ownership transferOwnership(addr) → the new owner calls acceptOwnership() Two-step handover. Until accepted
Withdraw treasury funds treasury.withdraw(token, to, amount), treasury.withdrawETH(to, amount) (treasury owner) Moves tokens or ETH held by the treasury. Evented (Withdrawn, EthWithdrawn). None

Every admin action emits an event: LaunchesPausedSet, HostDisabled, TreasuryUpdateProposed / TreasuryUpdateCancelled / TreasuryUpdated, CoordinatorUpdateProposed / CoordinatorUpdateCancelled / CoordinatorUpdated, and the OpenZeppelin ownership events. A pending treasury or coordinator change is readable at any time (pendingTreasury, pendingTreasuryAt, pendingCoordinator, pendingCoordinatorAt), so the 2-day delay is a public warning period. A proposal that is not executed within 7 days of becoming executable expires and must be proposed again, which restarts the warning period.

§The admin cannot

Cannot Why
Stop feed() feed() checks no pause flag; recordFeed is not pausable; feeders have no owner (security invariant 11).
Stop claimDev() Same (invariant 12).
Change an existing virus's host, developer, treasury or split They are immutable clone arguments or compiled constants; clones cannot be upgraded (invariants 1, 3, 4, 5).
Redirect existing fees The feeder is the Pons creator fee recipient and has no function that transfers that role (invariant 6).
Touch a developer's booked balance devOwed is paid only to the immutable developer; the treasury has no reference to feeders; the feeder grants no allowance (invariants 9, 10).
Recover burned host Burns destroy tokens through _burn (invariant 8).
Take host out of a feeder The feeder has no rescue or sweep function (invariant 15).
Edit a registry record No function edits an existing host's depth or an existing virus record.
Rebind or reuse a feeder Binding is one-shot on both sides, in the factory and in the feeder.
Swap the feeder code or the Pons factory The registry pins the feeder factory and the Pons factory when the first coordinator is set. A replacement coordinator that uses different ones is refused (WiringMismatch).
Forge accounting for an existing host registerVirus accepts only a feeder the pinned factory created and bound to that exact child, configured for the same registry, host, developer, treasury and Pons factory. Only such feeders can write burns and fees, and their code burns and pays for real.
Enable Pons buyback on a virus Only the creator recipient (the feeder) could, and it has no such function (invariant 21).
Approve a host on Pons, or open the Pons launch gate Both are Pons-owner powers. VIRUS never bypasses the Pons whitelist (invariant 26).
Use the coordinator The coordinator has no admin, no receive and no trade function.
Upgrade anything There are no proxies except the immutable feeder clones.
Renounce ownership renounceOwnership() reverts on the registry and the treasury, so the registry can never be left paused with no owner.

§What a coordinator change can and cannot do

The feeder factory accepts calls only from registry.coordinator(), so a new coordinator decides how future viruses are launched, including the treasury and developer it writes into new feeder configs. It cannot alter existing viruses: feederFactory.bind refuses a feeder or virus that is already bound, registerVirus refuses a virus that is already registered, and every existing feeder's configuration is fixed in its code. It cannot invent accounting either: the registry only accepts feeders created and bound by the pinned factory, with a configuration that matches the registration, so every recorded burn is a real burn. A proposed coordinator is visible for 2 days before it can take effect, and must share the pinned feeder factory and Pons factory.

§Deployment defaults

The deployment script (DeployVirus.s.sol):

  • deploys VirusTreasury, VirusRegistry, VirusFeederFactory and VirusLaunchCoordinator, and wires the coordinator into the registry once;
  • leaves launches paused (setLaunchesPaused(true)), to be unpaused by the admin after accepting ownership and passing the runbook checks;
  • starts an Ownable2Step handover of the registry to VIRUS_ADMIN and of the treasury to VIRUS_TREASURY_OWNER (defaulting to VIRUS_ADMIN); ownership is pending until the admin accepts;
  • refuses to run on chain 4663 unless VIRUS_MAINNET_APPROVAL holds an exact approval phrase (security invariant 23);
  • checks after deployment that the registry's coordinator and treasury, the paused flag, the factory's registry, and the coordinator's Pons factory and feeder factory are all as intended.

§Pons owner and operator powers that affect viruses

Pons ownership uses Ownable2Step, and renounceOwnership() always reverts on the Pons factory (VERIFIED_PONS F21). These powers are permanent.

§Over existing viruses

Power Function Effect on a virus VIRUS response
Redirect creator fees setCreatorFeeRecipient(token, new) → 3-day timelock → 3-day window in which anyone may call executeCreatorFeeRecipientChange Future creator fees stop reaching the feeder. A matured proposal supersedes creator transfers. (VERIFIED_PONS F13) Detected through pendingCreatorFeeRecipient and CreatorFeeRecipientChangeProposed and shown on the virus page. The feeder marks itself severed and keeps claiming whatever was already credited to it. This is the largest trust assumption (BLOCKED_BY_PONS B5).
Rescue curve fees rescueCurveFees(token) The curve pays the protocol and creator recipients directly, bypassing the escrow. (F18) The feeder accounts by balance, so directly delivered host is fed normally.
Rescue pool fees rescuePoolFees(poolId) The hook pays protocol and creator directly, including balances in the virus token. (H5) Host is fed normally; virus tokens are destroyed with burnStrayVirus().
Force a swept graduation forceSweptGraduation Allowed only when the pool seed is not viable. (F17) Shown as the Pons phase.
Rescue swept reserves rescueSweptGraduation(token, recipient) After 7 days in Swept, the owner sends the swept reserves to a recipient and the launch ends in Rescued, with no market. (F17) Route shows the hop as rescued. Before then, anyone can try to move the launch forward with the permissionless, retryable createGraduatedPool.
Disable buyback setBuybackEnabled(token, false) The owner may only disable. (F14) No effect: buyback is already off on every virus.

§Over post-graduation fee conversion

Role Function Effect VIRUS response
Fee sweep operator sweepPoolFees(poolId, minConversionQuoteOut, minBuybackTokensOut) as operator Only the operator can sweep a pool when virus-denominated fees are pending, converting them and crediting the feeder in host (H3, H4). Status AWAITING_PONS_SWEEP until it does (BLOCKED_BY_PONS B4). The operator address is memeHook.feeSweepOperator().

§Over future launches

Power Function Effect VIRUS response
Pair approval setPairTokenApproved, setPairTokenEconomics Decides which tokens can be hosts at all, and each host's phantom reserve and graduation threshold. (F3, F4) Shows "PONS PAIR APPROVAL REQUIRED". Never requests approval itself (B1).
Launch gate launchEnabled, whitelistedLaunchers Decides who may launch. (F6) Requires the gate for both you and the coordinator. LAB MODE when closed (B2).
Fee policy and launch configs Fee policy on the meme hook, launch configs on the factory Changes the base fee, protocol share, hook fee and other terms of future launches. Existing launches keep their frozen policy. (B7) Read live; pinned per launch by digest and tax.
Creator tax cap maxCreatorTaxBps If lowered below the tax VIRUS needs, launches revert with CreatorTaxUnreachable. LAB MODE banner "VIRUS FEE TARGET EXCEEDS PONS CREATOR-TAX CAP".
Launch fee launchFee ETH due per launch. Read live, shown separately.
Official launch router launchForwarder / launchTokenFor Exclusive to Pons's forwarder. (X3) VIRUS uses its own atomic coordinator (B8).

§Summary

The VIRUS admin can slow down or stop the creation of new viruses and change where future treasury fees go, with public delays for the treasury and the coordinator. Nothing the VIRUS admin can do changes an existing virus's economics, redirects its fees, or stops its feeder.

The Pons owner can change the terms of future launches and, for existing viruses, can redirect future creator fees after a 3-day timelock, rescue fees and stuck reserves, and (through the operator) decides when post-graduation virus-denominated fees are converted. See Risks.