Adversarial valuation
Test reserve manipulation, flash liquidity, burns, virtual reserves, stale windows and withdrawal failures.
BASTIONPROTOCOLTelegramOpen terminalSECURITY / DISTINCT TRUST BOUNDARIES
Custody, market admission, oracle observations, upgrades and liquidations require separate permission boundaries.

01 / PERMISSION MAP
| Role | Capability | Boundary |
|---|---|---|
| Borrower | Deposit collateral, borrow within limits, repay, withdraw when healthy | Cannot withdraw pledged LP beyond permitted health |
| Lender | Supply the quote asset to a selected isolated market | Withdrawals constrained by available liquidity and market solvency |
| Liquidator | Repay unhealthy debt and receive bounded collateral | Must pass health, freshness and seizure checks |
| Risk authority | Admit pools, set caps, pause risk-increasing actions | Delayed parameter increases; immediate restrictive controls |
| Upgrade authority | Upgrade programs under the authority policy | Published multisig and timelock; centralization risk remains |
02 / FAILURE CONTAINMENT
Each market owns its debt book and lending assets. Bad debt is not automatically shifted to another market. Buffer support, if any, must follow a separately disclosed cap.
All markets may still share a vulnerable program or dependency. Isolation does not remove common software, operator, governance or RPC risks.
03 / BEFORE THE FIRST LOAN
Test reserve manipulation, flash liquidity, burns, virtual reserves, stale windows and withdrawal failures.
Test decimal handling, integer rounding, interest accrual, cross-market accounts and partial liquidation.
Verify independent signers, monitoring, bounded caps, incident procedures and observable upgrade controls.