Yes, if someone holds a key that can move your collateral, replace the code, set the price or close the exit, and nothing stops them using it before you can leave. Most serious venues bound those powers. The useful question is which ones a venue has kept, and whether you have a way out that does not need anyone’s permission.
A coat check makes the point. You hand over the coat and get a ticket, and the ticket feels like ownership. It is not. It is a promise from whoever holds the key to the room, and it is only as good as the rules about when they may open it without you. A perps DEX is a coat check for your collateral. The ticket is your position. The room is a vault, a bridge or a pool somebody else can sign for.
Quick answer
Yes, if its operator holds an unbounded power over your collateral: an instant upgrade key, signers over the bridge or vault, control of the oracle, or a switch that stops withdrawals. Timelocks, dispute windows and an exit you can force on-chain are what turn those powers from a risk into a rule.
Contents
- Why a perps venue is a different question from a token
- The six powers, in one table
- Admin keys and upgradeable contracts
- The bridge or vault that holds the collateral
- Whoever sets the price
- Pauses, parameters and delistings
- Where the losses land
- Off-chain matching and the escape hatch
- Rug pull, exploit or a decision?
- A check before you deposit
- If you are building one
- Frequently asked questions
Why a perps venue is a different question from a token {#different-question}
A token rug pull is about what a token contract lets its owner do to the token: print more of it, block your sale, pull the liquidity. We covered those checks in rug pull red flags.
A perpetuals venue is different because you deposit collateral into something the venue controls. Your USDC sits in a vault contract, a bridge or a shared liquidity pool. Your position’s value comes from a price feed somebody chose. Your orders may be matched off-chain. When you win, you are paid from a pool, and when a trader goes bust past their margin, somebody covers the hole.
Every one of those is a place where a person, a multisig or a validator set holds power over money that is yours. None of it is sinister by default. A venue needs to upgrade, to price, to stop trading during an attack. What matters is how each power is bounded.
The six powers, in one table {#six-powers}
This is the table to lift. The third column is the one most risk guides skip.
| Power | What it can do to your funds | What bounds it | Where you check |
|---|---|---|---|
| Admin key or upgrade authority | Replace the logic that decides who can withdraw what | A timelock long enough to exit, a multisig, a two-step handover | The venue’s contract docs; the admin address on an explorer; the audit report’s admin findings |
| Bridge or vault signers | Sign a withdrawal of pooled collateral to any address | A signing threshold, a dispute window, parties who can freeze a bad withdrawal | The bridge contract’s source and its live state |
| Oracle control | Mark your position at a price that liquidates it, or let someone withdraw against a fake profit | A median of independent sources, deviation checks, staleness limits | The oracle docs: who publishes, how often, from what |
| Pause, parameters, delisting | Stop withdrawals, raise margin until you cannot withdraw, close a market at a price they choose | Published rules, a vote with a delay, caps enforced in code | Governance docs, the parameter change history |
| Loss-sharing rules | Close your profitable position (ADL) or cut the pool you deposited into | An insurance fund sized to the open interest, a documented ADL order | The venue’s liquidation and ADL docs |
| Off-chain matching or a sequencer | Refuse to process your withdrawal | A forced-withdrawal path on-chain, and a freeze if it is ignored | Whether an escape hatch exists, and how long it takes |
The rest of the page takes each row in turn, with a real example read at its source.
Admin keys and upgradeable contracts {#admin-keys}
Most perps venues are built to be upgraded, and for good reason: the product changes every few weeks. GMX’s v2 contract architecture is a clear example of doing it openly. Funds sit in “bank” contracts, logic sits in separate contracts, and “when a logic contract is upgraded, a new version is deployed and granted the appropriate roles in RoleStore“. The bank contracts do not move. The logic that decides what they pay out does.
That design is only as safe as whoever grants the roles. GMX says it “applies most parameter changes through a ConfigTimelockController (extending OpenZeppelin’s TimelockController) that enforces time delays on sensitive updates”. A delay is the whole defence. It turns “the admin can change the rules” into “the admin can announce a change, and you can leave before it lands”.
We found the version without the delay in our own work. In our security assessment of Adrena, a perpetual futures DEX on Solana, the single Critical finding read: “Every privileged operation executes immediately, atomically, and with a single signature.” The consequence, in the report’s words: “A stolen or compromised admin key would grant immediate unrestricted protocol control”, and in the worst case “users could be trapped in their positions, accruing borrow fees with no exit path”.
Nobody was rugged. The finding describes what a stolen key could have done, and Adrena fixed it before the report closed. Admin transfer now “uses a two-step process with a fixed 48-hour delay”, and the old single-step path is gone. As the case study puts it, it was “a governance timelock gap rather than a solvency bug”. It is also the most common shape of this risk: not an operator planning theft, but a single key that would let anyone who took it act faster than users can react.
If you run a perps venue and you have never had someone enumerate every admin-gated instruction and ask what it could do in one transaction, that is what a manual smart contract audit is for.
The bridge or vault that holds the collateral {#bridge}
On an appchain venue your collateral often sits in a bridge contract on another chain, and the bridge pays out when the right people sign. That makes the signers the real custodian.
Hyperliquid’s legacy bridge on Arbitrum is a well-documented case, and its source is public. The contract’s own header says withdrawals “are approved by 2/3 of the validator power, signed by hot wallets”, then sit in a dispute period during which “any locker may lock the bridge”. Unlocking needs “a quorum of cold wallet signatures”. So the power to move the pool belongs to a supermajority of validators, and the check on it is a window in which somebody can pull the brake.
You do not have to trust the docs for the window. Ask the contract:
RPC=https://arb1.arbitrum.io/rpc
BRIDGE=0x2df1c51e09aecf9cacb7bc98cb1742757f163df7
# disputePeriodSeconds()
curl -s -X POST $RPC -H "Content-Type: application/json" \
--data '{"jsonrpc":"2.0","method":"eth_call","params":[{"to":"'$BRIDGE'","data":"0x0756183b"},"latest"],"id":1}'
# -> 0x...00c8 (200 seconds)
# lockerThreshold()
# data 0x05355e23 -> 0x...0002
# paused()
# data 0x5c975abb -> 0x...0000 (false)
# USDC held: balanceOf(bridge) on native USDC 0xaf88d065e77c8cC2239327C5EDb3A432268e5831
# data 0x70a08231 + bridge address left-padded to 32 bytes
# -> 0x...0221ab71432a6b (599,970,176.77 USDC)
We ran those reads three times on 22 September 2026, at Arbitrum block 507,826,956, and got the same answers each time. A 200-second dispute window guarding roughly $600 million. That is a real brake, and a short one: it assumes lockers are watching and act within minutes. Hyperliquid’s own docs now describe this bridge as legacy, say Circle’s CCTP is the preferred route, and state that “the legacy Arbitrum bridge holds less than 10% of the USDC supply on HyperCore”. The rest sits under a different trust model, which is the next thing to read.
The general lesson is the same on any venue. Find the contract that holds the money, find who can sign it out, and find how long anyone has to object.
Whoever sets the price {#oracle}
A perps venue does not need to touch your collateral to take it. It only needs to mark your position at the wrong price. Liquidation does the rest, and every step is working as designed.
On Hyperliquid, the oracle is the validators. They publish “spot oracle prices for each perp asset every 3 seconds”, each computed as a weighted median of several centralised exchanges, and the final price is “the weighted median of each validator’s submitted oracle prices, where the validators are weighted by their stake”. Built well, that is hard to bend. It also means the parties who sign the bridge are the parties who set the price.
The better-known oracle failures came from outside the operator. In its complaint announcement about Mango Markets, the CFTC alleged that a trader pushed up the price of MNGO on the exchanges feeding the venue’s oracle, which “jumped over 13-fold during a 30-minute span”, then used the inflated position as collateral to withdraw “over $110 million”, “draining the platform of most of the assets that had been deposited by other users”. Those are allegations, not findings. The mechanism is the point: whoever can move the price can move the collateral.
dYdX’s own post-mortem on its SUSHI and YFI incident describes a gentler version on its v3 venue in late 2023. It records the attacker withdrawing “approximately $27 million” against about $16 million deposited, by repeatedly withdrawing unrealised profit while the spot price rose on other venues.
Pauses, parameters and delistings {#pauses}
Some of the most important powers are not about moving money at all. They are about when you are allowed to.
Pausing
When GMX’s v1 GLP pool was exploited on 9 July 2025, GMX announced that “approximately $40M in tokens has been transferred from the GLP pool to an unknown wallet”, and that trading on v1 and “the minting and redeeming of GLP” had been disabled. That was the right call during an attack. It also shows the switch exists: someone could stop every depositor from redeeming.
Parameters
In the same dYdX post-mortem, the team explains that to stop an attacker withdrawing profits, “the initial margin requirement for SUSHI-USD trades was raised to 100%”. It worked, and it was aimed at one attacker. But the lever is general. A venue that can raise margin requirements at will can freeze everyone’s ability to withdraw profit, and the post-mortem notes the new automatic version “affects the ability to withdraw unrealized profit but not liquidation prices”.
Delisting
On Hyperliquid, “validators vote on whether to delist validator-operated perps”, and if they do, positions “settle to the 1 hour time weighted spot oracle price before the scheduled delisting voting time”, per its delisting rules. In March 2025, after a squeeze on the JELLY market, Hyperliquid posted that “the validator set convened and voted to delist JELLY perps”, and that “all users apart from flagged addresses will be made whole from the Hyper Foundation”. Users were paid. It also showed that a small group could close a live market and decide how it settled.
Lock-ups
Deposits into Hyperliquid’s HLP vault carry a documented 4-day lock-up. Stated up front, that is a term, not a trap. It is still four days in which you cannot leave, whatever happens.
Where the losses land {#losses}
When a trader’s losses exceed their margin, the shortfall has to come from somewhere. The order it comes from decides whose funds are really at risk.
First comes the insurance fund. dYdX’s post-mortem records “a more than $9 million drain from the insurance fund” after the YFI crash, and states that “no user funds were compromised”. The fund did its job. The fund size relative to open interest is the number to look for, because a fund that covers one bad day may not cover two.
When the fund is not enough, venues fall back to auto-deleveraging (ADL). Hyperliquid’s ADL docs are plain about it: when an account goes negative, “the users on the opposite side of the position are ranked by unrealized pnl and leverage used” and their positions “are closed at the previous mark price”. Your winning position can be closed without your consent to keep the venue solvent. It is a documented rule, and most traders only read it once it has happened to them.
On pool-based venues there is a third layer: the pool is every trader’s counterparty. In the July 2025 GMX v1 exploit, the roughly $40 million came out of the GLP pool, which is to say out of its depositors. For the deposit-for-yield user, that makes the pool’s contract risk their risk, whether or not they ever opened a trade.
Off-chain matching and the escape hatch {#escape-hatch}
Many perps venues match orders off-chain for speed and settle on-chain. The operator then has a quieter power: it can simply not process your withdrawal.
The answer is an escape hatch that does not need the operator. StarkWare’s StarkEx engine, which has a perpetual trading mode, documents one of the clearest. A user can submit a forced withdrawal on-chain, and “if the operator does not serve the request within a specified period of time, the user can freeze the contract, and thus the exchange”. After that, “any user can withdraw directly from the frozen contract”. The freeze can be triggered by “any user”, not only the one who was ignored.
That is the property to look for on any venue with an off-chain component, and it comes down to one question: if the team disappears tomorrow, what transaction do I send, and how long until my funds are out? A venue that cannot answer has asked you to trust it.
Rug pull, exploit or a decision? {#rug-or-decision}
Everything above can be used honestly, abused by an insider, or taken over by an outsider. The label depends on who acted and whether the code did what it was meant to. GMX v1 was an exploit. Mango, per the CFTC, was alleged manipulation by a trader. JELLY was a governance decision. None of them was an operator emptying the vault.
But lost funds are lost funds, and the powers look identical from the outside. We set out how to tell the three apart from the transaction in rug pull vs exploit vs hack. For the team-level signals, communication, delivery and vesting, see when a rug pull is not a rug pull.
A check before you deposit {#check}
Ten minutes with the docs and an explorer answers most of it.
- Find the contract that holds the money. Vault, bridge or pool. If the venue does not tell you, stop there.
- Find who can upgrade it, and whether a timelock sits in front. Note the delay in hours.
- Find who can sign money out, the threshold, and any dispute window. Read the live values, not the blog post.
- Read the oracle page. Who publishes, from what sources, how often, and what happens when sources disagree.
- Read the pause and parameter powers. Who can stop withdrawals or raise margin, and whether there is a delay or a vote.
- Read the ADL and insurance fund rules, and compare the fund to open interest.
- Find the escape hatch. A forced withdrawal you can send yourself, and the time it takes.
- Read the audit reports, not the badges. Check that the admin findings were fixed rather than acknowledged, and that the audited commit is what is deployed. An audit covers one version of the code, which is why audits expire.
If you are building one {#building}
Every power in the table has a legitimate job, and a venue without them would be unsafe in its own way. The aim is to bound them, and to publish the bounds.
- Put a timelock in front of every parameter and upgrade that touches collateral, and make admin handover two-step.
- Keep the signing threshold on bridges and vaults above any single party, and make the dispute window long enough for someone to actually use it.
- Document pause, delisting and ADL rules before you need them, including what they cannot do.
- Give users a forced exit that works without you.
- Watch the live system, not only the code. A timelock only protects users if someone notices the queued change.
That last point is what post-deployment monitoring is for: detectors built around your own protocol’s rules, so a queued admin change, a price moving outside its band or a bridge withdrawal pattern gets seen while there is still time to act. The design half is a manual smart contract audit, line-by-line review by the core team, starting at $5,000 with two rounds of fix verification included. The reports are public, including Adrena’s, in our audit portfolio.
None of it makes a venue safe. It makes the venue’s powers visible, bounded and slow, which is the difference between a coat check with rules and a room anyone with the key can empty.
Frequently asked questions {#faq}
Can a perps DEX rug pull your funds?
Yes, if its operator holds an unbounded power over your collateral. That means an admin key that can upgrade contracts with no delay, signers who can move the bridge or vault, control of the price oracle, or a switch that can stop withdrawals. Most serious venues bound these powers with timelocks, signing thresholds, dispute windows and forced-exit paths. The check is which powers exist and what bounds each one.
Where is my collateral held on a perps DEX?
In a contract the venue controls: a vault, a bridge to an appchain, or a shared liquidity pool. Your position is a claim on that contract. Hyperliquid’s legacy bridge on Arbitrum, for example, releases USDC when two thirds of validator power signs a withdrawal, after a dispute period that read 200 seconds on 22 September 2026.
Can a perps DEX stop me withdrawing?
Often, yes. Venues can pause withdrawals during an attack, raise margin requirements so unrealised profit cannot be withdrawn, lock vault deposits for a set period, or delist a market and settle it. dYdX raised one market’s initial margin to 100% in 2023 to stop an attacker withdrawing profits. The protection is a forced-withdrawal path you can use without the operator.
What is auto-deleveraging on a perps DEX?
Auto-deleveraging (ADL) closes profitable positions on the other side of a bankrupt account when the insurance fund cannot cover the loss. Hyperliquid ranks affected users by unrealised profit and leverage and closes their positions at the previous mark price. It keeps the venue solvent, and it means a winning position can be closed without your consent.
Is an insurance fund a guarantee?
No. An insurance fund absorbs losses from liquidations that fail, until it runs out. dYdX’s v3 insurance fund lost more than $9 million in the November 2023 YFI incident, and dYdX said no user funds were compromised. The number to check is the fund’s size against the venue’s open interest.
Can a perps DEX operator manipulate the oracle?
It depends on who publishes the price. On some venues the validators themselves publish it, as a stake-weighted median of exchange prices. Outsiders can also manipulate thin markets that feed an oracle: the CFTC alleged that a trader moved Mango Markets’ oracle price more than 13-fold in 30 minutes and withdrew over $110 million. Look for multiple independent sources, deviation checks and staleness limits.
Does an audit mean a perps DEX cannot take my funds?
No. An audit documents the powers in the code and whether they are bounded. It does not remove keys the team holds, and it covers one version of the code. In Fidesium’s assessment of Adrena, the single Critical finding was an admin key that could act instantly with no timelock. It was fixed with a 48-hour two-step transfer before the report closed. Read the admin findings and check they were fixed.



