The Gavel Protocol — Risk Disclaimers
Version: 2.2 Last updated: 23 June 2026 Applies to: Interaction with the Gavel Protocol smart contracts deployed on Arbitrum One
PUBLISHER: This document is published by Jamie Frame in his personal capacity as the author of the Gavel Protocol open-source software. It describes the risks associated with interacting with the Protocol itself, regardless of how users access it. It is displayed on the thegavel.io interface (operated by Aletheia Analytics SASU) and accompanies the Protocol's source code repository.
General Risk Notice
The Gavel Protocol is experimental decentralised software. Interacting with the Protocol involves significant risks, including the possible total loss of your digital assets. You should not use the Protocol with funds you cannot afford to lose.
The Gavel Protocol is open-source software authored by Jamie Frame and deployed permissionlessly on the Arbitrum One blockchain. It has no operating entity. It functions autonomously according to its deployed code, which cannot be modified by any party. Any user can interact with the Protocol directly via smart contract calls, with or without using any web interface.
This document describes the risks associated with interacting with the Protocol. It applies regardless of how you access the Protocol — whether through the interface at thegavel.io, through direct smart contract interaction, or through any other means.
By interacting with the Protocol, you confirm that you understand and accept the risks described below. This is not an exhaustive list — decentralised finance involves risks that may not be fully foreseeable.
Smart Contract Risk
The Gavel Protocol consists of smart contracts deployed on the Arbitrum One network. These contracts are immutable once deployed: they sit behind minimal ERC1967 proxies whose implementations contain no upgrade function (they are not UUPS), so the contract logic cannot be changed by any party — including the author. The contracts were deployed on 6 May 2026 on Arbitrum One (chain ID 42161). The deployer account no longer holds administrative control, and ownership of the relevant contracts has been transferred to a 2-of-3 Gnosis Safe. The authoritative list of deployed contract addresses, with verified-source links, is published in the Protocol's source-code repository.
Reference: https://github.com/JamieFrame/The-Gavel-Protocol/blob/main/docs/deployed-contracts.md
Smart contracts may nonetheless contain undiscovered bugs, vulnerabilities, or logic errors that could result in the permanent loss of funds deposited into or interacting with the Protocol. The Protocol's smart contracts underwent an independent security review — a Sherlock collaborative audit finalised on 15 April 2026, which returned no High or Critical severity findings, with all Medium and Low findings resolved and fix-reviewed. The full report is published at:
https://github.com/JamieFrame/The-Gavel-Protocol/blob/main/docs/audit/2026-04-15-Sherlock-Collaborative-Audit.pdf
No audit guarantees the absence of vulnerabilities.
A limited set of administrative powers is retained on-chain, held by a multi-signature (Gnosis Safe) wallet. These powers are: emergency pause and unpause; configuration of the optional Curation Layer (the token and collection whitelists and fee parameters on ListingService and NFTListingService); and the setting of position-NFT metadata (setBaseURI). None of these powers can alter loan terms, balances, collateral, or the Protocol's business logic. The emergency pause authority is intended to be progressively renounced as the Protocol matures. Until then, there is a residual risk that these retained powers could be misused if the multi-signature wallet were compromised — but their scope is limited to pausing the Protocol and to configuring the curation layer, and cannot reach existing loans, deposited collateral, or contract logic.
Security Review and Responsible Disclosure
The publication of an audit report does not constitute a warranty, certification, insurance policy, or guarantee that the Protocol is free from defects or vulnerabilities. No public bug bounty programme is in place at the date of this document. Security issues may be reported through the responsible disclosure channel at security@thegavel.io.
Market and Price Risk
The value of digital assets fluctuates, sometimes dramatically and without warning. The Gavel Protocol does not use price oracles and does not enforce collateralisation ratios. This means:
For borrowers: If the value of your collateral declines significantly, you may find that the collateral you deposited is worth less than the loan you received. You remain obligated to repay the full loan amount to recover your collateral, regardless of market conditions.
For lenders: If the borrower defaults and you claim the collateral, that collateral may be worth significantly less than the loan amount you provided. The Protocol provides no guarantee that collateral value will exceed the loan value at any point during the loan term or at maturity.
For all users: The interest rates discovered through the Protocol's auction mechanism reflect market conditions at the time of the auction. Past rates are not indicative of future rates. Market conditions, liquidity, and participant behaviour can change at any time.
Default and Counterparty Risk
The Gavel Protocol facilitates peer-to-peer lending. Each loan is a direct economic relationship between a borrower and a lender, mediated by a smart contract. No party other than the borrower and the lender is a party to any loan. The Protocol does not verify the identity, financial position, regulatory status, tax status, solvency, or intentions of any borrower or lender.
Borrower default occurs when a loan is not repaid by the maturity date plus the grace period. On default, the lender may claim the borrower's collateral. The Protocol does not assess borrower creditworthiness, enforce repayment, or provide any recovery mechanism beyond collateral seizure.
There is no insurance, guarantee fund, or compensation scheme protecting lenders against borrower default, unless a lender independently arranges such protection.
Liquidity Risk
There is no guarantee that any auction will attract bids. A borrower may create an auction and receive no offers, or receive offers only at unfavourable rates. Similarly, there is no guarantee that loan positions listed on the marketplace will find buyers.
The Protocol does not provide or guarantee liquidity. Liquidity comes only from participants acting on-chain for their own account, which may include Aletheia Analytics acting as principal with its own assets. No participant, including Aletheia Analytics, is under any obligation to create auctions, place bids, buy positions, sell positions, maintain markets, or provide liquidity at any time.
Aletheia Analytics Own-Account Activity
Aletheia Analytics may interact with the Protocol for its own account, as principal, using its own assets. Where it does so, it acts as an ordinary on-chain participant and may become the economic counterparty of other Protocol participants. This does not create any service commitment, mandate, fiduciary duty, execution obligation, financing commitment, liquidity commitment, rate commitment, or guarantee owed by Aletheia Analytics to any user.
Aletheia Analytics does not act through the Protocol as an agent, broker, custodian, portfolio manager, credit intermediary, liquidity provider, or adviser for users. Users should not assume that Aletheia Analytics will participate in any auction, purchase any position, support any market, refinance any loan, or take any action to reduce user losses.
Blockchain and Network Risk
The Protocol is deployed on Arbitrum One, a Layer 2 rollup built on Ethereum. Your use of the Protocol depends on the correct functioning of both networks. Risks include:
- Network congestion may cause delays in transaction processing, potentially affecting time-sensitive operations such as loan repayment before maturity or bid placement during an auction.
- Gas price fluctuations may make transactions unexpectedly expensive.
- Sequencer downtime on Arbitrum may temporarily prevent all Protocol interactions. During such an outage, you will not be able to repay loans, place bids, or manage positions.
- Network reorganisations could, in rare circumstances, cause confirmed transactions to be reversed.
- Bridge risk: Assets on Arbitrum depend on the security of the Arbitrum bridge to Ethereum. A bridge failure or exploit could affect the value or transferability of assets on the network.
No party has control over either network's infrastructure, availability, or performance.
Irreversibility
All transactions on the Arbitrum blockchain are irreversible once confirmed. If you send funds to the wrong address, approve the wrong transaction, set incorrect auction parameters, or make any other error, no party can reverse or correct the transaction.
You are solely responsible for verifying all transaction details before signing and broadcasting any transaction through your wallet.
User-Selected Parameters Risk
The Protocol executes the parameters submitted by users through their wallets. Users are solely responsible for selecting and verifying all transaction parameters, including token address, collateral amount, loan amount, repayment amount, auction duration, loan maturity, bid amount, repayment deadline, recipient address, approvals, and any other value entered or confirmed before signing.
Incorrect parameters may result in unfavourable economic terms, failed transactions, loss of funds, inability to recover collateral, excessive repayment obligations, or exposure to assets or counterparties that the user did not intend to select. No party can correct or reverse an on-chain transaction after it has been confirmed.
Key Management Risk
You access the Protocol through your own digital wallet (such as MetaMask). The security of your assets depends entirely on the security of your private keys, seed phrases, and wallet software.
If you lose access to your wallet or your private keys are compromised, no party can recover your assets, cancel your loans, or take any action on your behalf. No one has access to your private keys and no one can assist with wallet recovery.
Wallet Approval and Signature Risk
Interacting with the Protocol may require users to approve ERC-20 token transfers, approve NFT transfers, sign transactions, or sign messages through their wallet. Users should review every approval and signature request carefully before confirming it.
Approving the wrong contract, granting excessive allowances, approving an NFT operator, or signing a malicious transaction may result in loss of assets. Users remain responsible for monitoring and revoking token or NFT approvals where appropriate. No party can revoke approvals or recover assets on a user's behalf.
Regulatory and Legal Risk
The legal and regulatory status of decentralised finance protocols, digital assets, and related activities is uncertain, evolving, and varies by jurisdiction. Future changes in law or regulation could:
- Restrict or prohibit your ability to use the Protocol in your jurisdiction
- Affect the tax treatment of your lending, borrowing, or trading activity
- Impose licensing or registration requirements on users
- Affect the legal enforceability of smart contract-based agreements
You are solely responsible for understanding and complying with the laws applicable in your jurisdiction. Access to the thegavel.io interface is additionally governed by that interface's own terms of use, which may restrict availability or eligibility for residents of certain jurisdictions; those terms are separate from this document and do not restrict the permissionless Protocol itself. This document does not provide legal or tax advice.
Tax and Reporting Risk
Lending, borrowing, receiving repayments, claiming collateral, selling loan positions, buying loan positions, receiving interest, realising gains or losses, or transferring digital assets may have tax, accounting, reporting, or record-keeping consequences. These consequences may differ depending on the user's jurisdiction, status, residence, activity, and the factual treatment of each transaction.
The Protocol does not calculate, withhold, report, or pay taxes on behalf of users. Users are solely responsible for maintaining their own records and obtaining independent tax, accounting, and legal advice where necessary.
Restricted Jurisdictions and U.S. Persons
The thegavel.io interface may be unavailable to, or contractually restricted for, users located in certain jurisdictions, including sanctioned jurisdictions and the United States, as specified in the applicable terms of use. The absence of technical blocking at interface level does not mean that you are eligible to use the interface or that your use is lawful in your jurisdiction.
Before using the interface, users should be required to confirm that they are not a U.S. Person, are not located in the United States, are not subject to sanctions, and are not located in a jurisdiction where use of the interface or Protocol would be unlawful. This confirmation should be implemented at least through the terms of use and, preferably, through an explicit first-wallet-connection acknowledgement.
Launch Asset Scope
At launch, the curated interface-level asset scope is limited. WBTC is the only listed collateral token, and USDC and USDT are the only listed loan tokens. WETH and DAI are not listed at launch and may be assessed only in a later phase. No NFT collection is listed at launch: the NFT lending functionality may be deployed and visible, but it is not usable through the curated interface until a collection has been reviewed and added to the relevant whitelist.
The relevant token addresses on Arbitrum One are: USDC (native) 0xaf88d065e77c8cC2239327C5EDb3A432268e5831; USDT 0xFd086bC7CD5C481DCC9C85ebE478A1C0b69FCbb9; WBTC 0x2f2a2543B76A4166549F7aaB2e75Bef0aefC5B0f.
Sanctions, Freezing and Blacklisting Risk
Certain digital assets used with the Protocol, including centrally issued stablecoins, may be subject to issuer controls, sanctions screening, address freezing, blacklisting, or other restrictions imposed by token issuers, infrastructure providers, regulators, or other third parties. These restrictions may apply without warning and may affect a user's ability to transfer, repay, receive, claim, or otherwise use affected assets.
A freeze, blacklist, sanctions measure, or third-party restriction may prevent a transaction from completing even if the Protocol itself functions as intended. No party associated with the Protocol controls the policies of token issuers, bridge operators, wallet providers, RPC providers, infrastructure providers, or public authorities.
Token-Specific Risks
Digital assets used with the Protocol carry their own risks independent of the Protocol itself:
- Stablecoin depegging: Stablecoins used as loan tokens (such as USDC or USDT) may lose their peg to the reference currency, affecting the real value of loans and repayments.
- Token contract risk: Even tokens on the ListingService whitelist may have undiscovered vulnerabilities in their own smart contracts.
- Issuer risk: Centralised token issuers (such as Circle for USDC or Tether for USDT) may freeze or blacklist addresses, which could prevent the Protocol from processing transfers involving those tokens.
- Wrapped asset risk: Wrapped tokens (such as WBTC) depend on the custody and minting practices of their issuer. A failure of the custodian could affect the value of the wrapped asset.
The ListingService whitelist is a technical safety filter applied by a curation layer. It does not constitute a guarantee of any token's safety or value. See the Token Curation Methodology document for details.
NFT Collateral and Collection Risk
The Protocol includes NFT lending functionality. At launch, no NFT collection is listed through the curated interface. If NFT collections are listed in the future, NFT collateral may involve additional risks, including subjective valuation, extreme illiquidity, limited trading history, unreliable floor prices, wash trading, metadata changes, broken or centralised metadata storage, collection-specific smart contract defects, royalty or marketplace restrictions, fraud, impersonation, intellectual property disputes, and sudden loss of market demand.
A listed NFT collection should not be understood as safe, valuable, liquid, authentic, legally cleared, or suitable as collateral. Users remain solely responsible for assessing the value, authenticity, liquidity, and legal risks of any NFT collateral.
Oracle-Free Design: Benefits and Limitations
The Gavel Protocol deliberately does not use external price oracles. This design choice eliminates an entire category of risk (oracle manipulation, stale prices, oracle failure) that has caused significant losses in other DeFi protocols.
However, the absence of oracles also means:
- No automatic liquidation. Unlike protocols such as Aave or Compound, the Gavel Protocol does not liquidate undercollateralised positions. If collateral value drops below the loan value, the loan continues until maturity. This is a feature of the Protocol's fixed-term design, not a flaw — but it means lenders must assess collateral risk themselves rather than relying on protocol-level safeguards.
- No protocol-enforced collateralisation ratios. The Protocol accepts any collateral amount for any loan amount. The market (lenders bidding in auctions) determines what collateral ratios are acceptable, not the Protocol.
- Interest rates reflect market conditions, not algorithmic targets. Rates may be higher or lower than on other platforms, and may vary significantly between auctions.
Position NFT Risks
When a loan is created, the Protocol mints Position NFTs representing the borrower's and lender's positions. These NFTs are the sole means of exercising rights under the loan (repayment, collateral claim, marketplace trading).
- If you transfer your Position NFT to another address, that address gains full rights over the loan position. Transfers are irreversible.
- If your Position NFT is lost, stolen, or sent to an inaccessible address, you lose the ability to repay your loan (borrower) or claim collateral on default (lender).
- Position NFTs may be traded on the Protocol's marketplace or on external NFT marketplaces. No party controls secondary market pricing or liquidity for Position NFTs.
This document does not constitute a regulatory classification analysis of Position NFTs, loan positions, or any digital asset under financial instruments, securities, lending, tax, or other applicable laws.
Secondary Market Position Risk
Buying or selling a Position NFT or loan position on a secondary market involves specific risks. The price of a position may not reflect the economic value of the underlying loan, collateral, repayment obligation, time remaining to maturity, probability of default, liquidity, or legal and tax consequences of the position.
A buyer of a lender position may acquire exposure to a loan that is close to default, undercollateralised in economic terms, difficult to value, or supported by collateral that later becomes illiquid or impaired. A buyer of a borrower position may assume obligations or risks that are not apparent from price alone. Users should review the underlying loan data directly before buying, selling, or transferring any position.
Interface Availability
The Gavel Protocol can be accessed through multiple means. One such means is the web interface at thegavel.io, which is operated by a third party (Aletheia Analytics SASU) as a free public service. This interface is not the Protocol itself.
- The interface may be unavailable, interrupted, or discontinued at any time, for any reason.
- If the interface becomes unavailable, the Protocol continues to operate on the blockchain. Users can interact directly with the Protocol's smart contracts without the interface.
- Use of the interface is subject to its own terms of use, which are separate from this document and from the Protocol itself, and which may restrict availability or eligibility in certain jurisdictions.
- Documentation for direct interaction with the Protocol is available at:
https://github.com/JamieFrame/The-Gavel-Protocol/blob/main/docs/direct-access-guide.md
The Risk Disclaimers should be made available through a standalone page, a persistent footer link, and contextual warnings before sensitive interactions such as auction creation, collateral deposits, bid placement, position purchases, and loan management actions.
The availability of any specific interface is not guaranteed by any party. The Protocol itself, as autonomous software, continues to function as long as the Arbitrum network is operational.
Phishing, Imitation and Malicious Interface Risk
Users may be exposed to phishing websites, fake interfaces, malicious wallet prompts, fraudulent support accounts, counterfeit documentation, fake token addresses, fake NFT collections, or impersonation attempts. Users should verify URLs, contract addresses, repository links, wallet prompts, and transaction details independently before interacting with any interface or smart contract.
No party will ask users to disclose private keys, seed phrases, recovery phrases, or wallet passwords. Any request for such information should be treated as fraudulent.
Data and Analytics
Any data, analytics, or information displayed through interfaces or tools accessing the Protocol is provided for informational purposes only and may contain errors, delays, or inaccuracies. You should not rely on any such information as the sole basis for any financial decision.
This includes but is not limited to yield curve data, interest rate benchmarks, credit surface visualisations, and other analytics derived from Protocol activity. These are market data products that describe past Protocol activity; they do not constitute financial advice, trading signals, or recommendations.
Nothing displayed to you constitutes financial, investment, tax, or legal advice. No party recommends any particular transaction, strategy, rate, or asset.
Summary
Interacting with the Gavel Protocol involves accepting the risk of financial loss, including the potential total loss of your digital assets. The Protocol operates autonomously: no party manages loans, sets rates, intermediates between borrowers and lenders, or guarantees any outcome. Beyond the limited administrative powers described under Smart Contract Risk — which cannot reach loan terms, balances, collateral, or logic — there is no operator overseeing Protocol activity, and no party bears responsibility for losses arising from Protocol interactions.
Aletheia Analytics may separately interact with the Protocol for its own account, as principal, but does not thereby assume any obligation to users and does not provide a lending, brokerage, custody, execution, liquidity, advisory, or portfolio-management service through this document.
If you do not understand these risks or are not prepared to accept them, you should not interact with the Protocol.
The Gavel Protocol is open-source software authored by Jamie Frame in his personal capacity, released under the MIT licence, and deployed on the Arbitrum One blockchain. This document is published by Jamie Frame as protocol-level documentation to inform users of the risks involved in protocol interaction. It does not create any obligation, warranty, or guarantee on the part of any party. The thegavel.io interface, through which this document may be displayed, is operated by Aletheia Analytics SASU as a separate commercial service.
