Skip to main content

Risks

Oro is being prepared for local and testnet validation. It is not ready for mainnet funds until the operational and security checklist is complete.

Early-stage protocol

Oro should be treated as a controlled validation project until testing, audits, and operational hardening are complete.

Main risks

Bridge risk:

The system depends on correct message handling between EVM and Aztec. Message formats, replay protection, and Outbox consumption must stay consistent across contracts and services.

Oracle risk:

Minting depends on fresh price data. The oracle uses multiple sources and fails closed when stale, but source quality and operational security remain important.

Relayer risk:

The relayer improves UX but becomes operationally important once it submits live transactions. It needs limits, monitoring, and a clear recovery path.

Liquidity risk:

ORO targets dollar value, but early versions may have limited liquidity. A future market layer can help, but it should not replace collateral rules.

Upgrade risk:

Principal contracts should keep stable integration addresses and preserve storage layout across upgrades.