Risks

Trading involves significant risk. You should only trade with funds you can afford to lose. dreamDEX is a decentralized protocol and its use involves technical and market risks.

dreamDEX provides a high-performance, non-custodial trading environment, but users should be aware of the inherent risks associated with decentralized finance (DeFi).

Technical Risks

Smart Contract Vulnerabilities

All deposits, order matching, and settlement occur via smart contracts on the Somnia blockchain. While these contracts undergo rigorous internal testing and external audits, they may contain undiscovered bugs or vulnerabilities that could lead to loss of funds. See Audits for the current audit status.

Blockchain Infrastructure

As an on-chain protocol, dreamDEX depends on the Somnia blockchain. Network downtime, congestion, or consensus failures could prevent users from placing, cancelling, or filling orders.

Upgradeable Contracts

The spot DEX contracts (SpotPool, SpotStopOrderRegistry) are deployed behind upgradeable beacons. Upgrades are controlled by the protocol owner and are designed to ship security fixes and improvements, but any upgrade introduces the risk of unintended changes in behavior. See Audits for how upgrades are validated.

Market Risks

Liquidity Risk

While dreamDEX aims to attract deep liquidity through its yield-bearing collateral model, certain markets or extreme conditions may experience wider spreads or reduced liquidity, making it difficult to execute large orders at desired prices.

Price Risk

Spot trades execute at the price determined by the order book at the time of fill. Market orders and aggressive limit orders may fill across multiple price levels, resulting in an average fill price worse than the top of book. Use limit orders to control your worst acceptable price.

Protocol Risks

Protocol Upgrades

As an evolving protocol, dreamDEX may undergo upgrades. While these are designed to improve the system, changes to parameters or logic could impact trading strategies.

Parameter Changes

Configurable parameters — including order book constraints (tick size, lot size, minimum quantity), stop-order registry settings, and fee rates — can be updated by the protocol owner via on-chain transactions. Material changes will be announced ahead of time where possible.

Account and Key Risks

Your trading balance sits in a smart account. The key that signs for it is a Privy-managed embedded key created at your first login. It is not a key you hold, and the app never exposes it. Consequences worth knowing:

  • Your login is full control. Anyone who can complete your login (an email code, a social account, or the wallet you connect) can sign in as you and move everything in the account.
  • Your login wallet may be a second owner. On the current account type (new accounts, and accounts moved to it), logging in with a wallet makes the app add that wallet as a second owner of the account, without a prompt. Either owner can act alone, so a compromised wallet can move funds directly on-chain and remove the app's key. Email and social logins get no second owner unless a wallet is linked to the login later. The app cannot remove an owner today, and if you remove your wallet as an owner with another Safe tool, the app adds it back the next time you open it.
  • A new login is a new account. Your account is derived from your login's embedded key, so logging in with an email or wallet that is not linked to your existing login creates a different, empty account. Funds do not follow.
  • Limited third-party access. The app's key is not exposed, so outside sites such as allowance-revocation tools cannot sign with it and can only read your account. If your wallet was added as a second owner, that wallet can operate the account directly on-chain. Revoking an approval is not yet possible in the app.

If you think your login is compromised, move funds out of the account first, then open a support ticket. When withdrawing, check the recipient address: if you logged in with a wallet, the field is prefilled with that wallet, which may be the compromised part.