Verified registry

Bots

Recurring-buy (DCA) positions · non-custodial escrow

Experimental, reviewed, not audited. Written with OpenZeppelin's security primitives, TWAP-protected against sandwich attacks, tested (13 tests, including two reentrancy vectors) and run through Slither — full write-up in contracts/README.md. That is real work, not a substitute for an independent paid audit. Only the deposit principal you put in is ever at risk — nobody, including us, can withdraw it but you — but size positions as unaudited code, not audited code.

Not deployed yet. The contract is written, tested and statically analysed (see the notice above and the contracts/ directory in the repo), but deploying it is a decision with immediate financial-security consequences — it becomes a public, fundable address the moment it's live. That step is deliberately manual: someone runs contracts/script/deploy-dca.mjs with their own key, from their own machine. Nothing here does it automatically.

Once deployed, set NEXT_PUBLIC_DCA_VAULT_ADDRESS to bring this page live.

RWA_SPEC.md Phase 7 — recurring buy of stocks/baskets (v4/USDG). A second vault, contracts/src/DcaVaultV4.sol, ports this same design to Uniswap v4 + USDG for tokenized-stock/basket positions — written, tested (15 checks) and statically analysed, same as the vault above, but with one documented difference: v4 has no built-in historical-price oracle the way v3 does, so its anti-sandwich floor is weaker unless a position names a trusted on-chain price oracle (see that contract's own doc comment). Not deployed, and — per RWA_SPEC.md's own gate — not going to mainnet before an independent audit; this page will get its own v4 section, behind its own NEXT_PUBLIC_DCA_VAULT_V4_ADDRESS flag, once that happens.