AXIS Docs

Using AXIS

Security and trust

What the smart contract can do and what are the safety guardrails.

What the contract can do#

The AXIS contract can move your tokens only through an allowance you granted it, and only to settle fills of your own orders at your price or better, or to pay for trades and swaps you signed, within the limits you confirmed explicitly. It cannot move more than your allowance or touch tokens you did not approve. Allowances and your funds article explains how allowances work and how the AXIS app sizes them.

No custody#

AXIS never holds user funds between transactions. Tokens pass through the contract only inside the transaction that settles a trade, swap hop or crossfill, and every call pays out everything it receives. There is no pool of deposits that could be stolen, and nothing gets stuck in the contract if trading is paused. Tokens sent to the contract address directly, outside AXIS calls, cannot be recovered.

What you sign#

For a trade or swap you sign one call to the AXIS contract. When your allowance needs to grow or is about to expire, the same signature also covers an approval on the token you sell, with a fixed amount and expiry. You never sign payments to specific counterparties: the contract pays them out of your allowance, and only for fills within your limit.

Important

Before you sign, check that the assets, amount and limit price are what you expect.

Immutable code#

The contract has no upgrade function. Nobody, including AXIS developers, can change its code after deployment. A future version would have to be deployed as a separate contract. The source code is published at github.com/axis-markets/orderbook.

The safety admin#

The contract has a safety admin account with a very limited set of functions:

Function name in contract What it does
freeze Pauses or resumes trading. This is the emergency switch.
delegate Hands the safety admin role to another account.
set_oracle Points the contract to another price oracle.
set_floor Sets the minimum order value denominated in USD.
set_listing_min_days Sets how many days of oracle price feeds a new market provisions on creation.
set_ledger_time Sets the expected ledger close time (5 seconds by default).

The safety admin cannot:

  • change the contract's code,
  • move or spend anyone's tokens,
  • create, change, fill or cancel orders,
  • close or delist markets,
  • change the price of any order,
  • add trading fees.

Every admin action is public. A freeze call publishes a freeze event, and the other five publish a config event with the new settings. Developers can find the details in Safety admin and invariants.

What frozen mode means for you#

If the safety admin freezes the contract:

  • Frozen: trades, market orders, swaps, crossfills, new limit orders, order updates, opening markets and price refreshes.
  • Still working: canceling orders, changing allowances, and reading orders and markets.

Your orders and allowances stay as they are, and your tokens stay in your wallet, free to use. Nothing is stranded, because the contract holds no funds between transactions. When trading resumes, your open orders can fill again. The AXIS app shows "Trading is temporarily frozen by the safety admin" in the order form while the contract is frozen.

Oracle trust#

The Reflector oracle provides the USD prices for the minimum order value check. It never sets the price of a fill. An oracle that stops providing prices for more than 72 hours straight can potentially block new limit orders. It cannot move funds or change the price you trade at. See What the oracle is used for.

Off-chain services cannot move funds#

The Indexer, AXIS APIs and apps read public data and build transactions. None of them can move your tokens without a transaction you sign. If one of them fails or misbehaves, the worst outcomes are a poor quote, a wrong display or a failed transaction. Since any developer can create a custom interface for AXIS contract, a dishonest app could still ask you to sign a bad limit price, so check read what your wallet asks you to sign.

Open source#

Component Repository Notes
AXIS contract github.com/axis-markets/orderbook Source of the Soroban smart contract
JS client github.com/axis-markets/js-client MIT license, @axis-markets/client on npm
Indexer github.com/axis-markets/indexer MIT license, @axis-markets/indexer on npm

Practical safety tips#

  1. Read the wallet prompt. Confirm assets, amounts and the limit price before signing.
  2. Watch orders backing. An "N% backed" notification in the interface means some fills of that order will be skipped. Top up your balance, renew the allowance by placing an order that sells the token, or cancel the order.
  3. Cancel old orders. Cancel your open orders once you transfer funds that backed them, so no unbacked orders are left behind.