Docs

Resources

Security

What Socket's design rules out, what has been tested, what hasn't been done yet, and the risks that remain yours.

What the design rules out#

  • No admin keys. Neither the Socket program nor the built-in hooks program has an owner, a pause switch, a fee switch or a withdrawal authority. Tokens leave a vault only through a swap, a position's owner withdrawing or collecting, or a pool's creator collecting surcharges its hook recorded.
  • Governance reaches listings only. The listing program's one authority is Socket's governance. It can list or remove a hook and burn a removed hook's stake. It holds no pool tokens and has no instruction in Socket's programs.
  • No changes after creation. A pool's tokens, fees, hook, permissions, caps and hook accounts are fixed when it is created.
  • Hooks can't touch funds. A hook never receives a vault, a token account, a position account or a user's signature. It can only answer with a fee and a surcharge, each bounded by the pool, or refuse.
  • All or nothing. Every hook call happens inside the same transaction as the operation. A failing or misbehaving hook reverts everything, including its own writes.
  • Accounts are checked, not trusted. Every operation checks the token program, the pool's and position's addresses, mints, authorities and token account state, and every hook account against the pool's list.

What has been tested#

Each check is recorded with the date it ran and the SHA-256 of the binaries it tested. In summary:

LayerTestsWhat they cover
CLMM math13Tick conversion, rounding, exact input and output, crossings, fee carry, liquidity bounds; four property tests of 128 cases each.
Hook interface and built-in hooks15ABI, permissions, the dynamic-fee EWMA, timed TWAP observations, the range-order lifecycle, domain endpoints.
Compiled programs in a Solana test VM9Real SPL Token transfers and rollbacks; hostile hook replies, malformed data, wrong phase, reentry, nested return data; surcharge consent; all 64 tick boundaries.
SDK and API32Account validation, serialization, the math port against the Rust crate, every API route, real PostgreSQL indexing.

Beyond these suites, full SDK workflows ran against a local validator loaded with the same binaries, including exact-input and exact-output swaps. The app was also tested end to end: swaps, deposits, fee collection, withdrawal, pool creation, and a range order placed, filled and withdrawn.

Risks that remain yours#

Hooks#

A pool's hook is code that runs in every trade through it. Within its permissions it can set the fee as high as the pool's max fee, add a surcharge up to the cap, or refuse trades. Check a pool's face in the app: the lit contacts are what its hook may do. Built-in hooks are labeled by name; anything else shows as External hook.

Program upgrades#

A pool fixes its hook's address, not the code at that address. If a program is deployed as upgradeable, whoever holds its upgrade authority can change its behavior. Check the upgrade authority of the Socket program, the built-in hooks program and any external hook you rely on.

Concentrated liquidity#

A position earns only while the price is in its range, and ends up entirely in one token when the price leaves it. If the price moves and stays, the position is worth less than holding the tokens would have been.

Range orders#

A filled range order blocks swaps back into its range until its owner withdraws. That protects the owner, and it can make a pool unusable for traders in the meantime.

TWAP readers#

The TWAP hook reports this pool's own trading. A pool with little liquidity is cheap to move. If you use its mean tick as a price, choose a window long enough, and a pool deep enough, that moving it costs more than it could earn.

Quotes#

Quotes come from finalized state and the API's arithmetic. Execution happens at the latest state. Your protection is the slippage limit the program enforces and the simulation the app runs before you sign.

Bounded by design#

Some limits are deliberate and won't be patched away: 64 initialized tick boundaries per pool, eight hook accounts, classic SPL tokens only, no transferable positions, no negative surcharges (rebates), no dynamic seeds for hook accounts. See Bounds.