---
title: "Protocol Risk Disclosure"
description: "Overlayer Labs Ltd's formal risk disclosure for the protocol, the Overlaid Assets and the OVER token. Version 1.0, last revised April 2026."
canonical_url: https://docs.overlayer.fi/legal/protocol_risk_disclosure
md_url: https://docs.overlayer.fi/legal/protocol_risk_disclosure.md
last_updated: 2026-05-05T15:42:56.000Z
---

# Protocol Risk Disclosure

> Overlayer Labs Ltd's formal risk disclosure for the protocol, the Overlaid Assets and the OVER token. Version 1.0, last revised April 2026.

**Version:** 1.0

**Last Revised:** April 2026

---

## Important Notice — Please Read Carefully

This Protocol Risk Disclosure (the "**Disclosure**") is provided by Overlayer Labs Ltd, a business company incorporated under the laws of the British Virgin Islands (the "**Operator**", "**Overlayer Labs**", "**we**", "**us**" or "**our**"), in relation to the Overlayer Protocol (the "**Protocol**"), the interfaces and services operated by or on behalf of the Operator (the "**Services**"), the digital assets generated by or through the Protocol (the "**Overlaid Assets**"), the governance and utility token of the ecosystem (the "**OVER**" token) and related ecosystem components.

The Protocol, Overlaid Assets, the OVER token and all related Services involve **novel, experimental, highly technical and rapidly evolving technology**, interacting with **public blockchains, third-party DeFi protocols, third-party stablecoins, oracles and independent infrastructure**. Their use exposes you to a **high degree of risk**, including, without limitation, the **partial or total, permanent and irreversible loss of all Digital Assets** you use, deposit, deploy, pledge, stake, lend or otherwise commit in connection with the Protocol, the Services or any integrated third party.

**This Disclosure is not exhaustive.** It describes categories of risk that the Operator considers material as of the date of this Disclosure. Additional risks may exist today that are unknown, emerging, underestimated or not yet identified, and new risks may arise over time. This Disclosure is not a substitute for, and does not replace:

(a) your own independent research, technical evaluation and due diligence;

(b) your own independent risk assessment;

(c) your own legal, regulatory, financial, tax, accounting and technical advice from qualified professionals; or

(d) the Terms of Use, the Privacy Policy, the Cookie Policy, the Legal Disclaimers, the Regulatory Overview and any other documents referenced therein, each of which is incorporated herein by reference and forms part of the legal framework governing your relationship with the Operator.

**By accessing, browsing or using the Services, by interacting directly with the Protocol, or by acquiring, holding or disposing of any Overlaid Asset or the OVER token, you acknowledge and agree that you have read, understood and unconditionally accepted this Disclosure in its entirety, that you accept every category of risk described herein, and that you do so at your own sole risk.** If you do not understand or do not accept these risks, you must not access or use the Services, must not interact with the Protocol, and must not acquire, hold or dispose of any Overlaid Asset or the OVER token.

Capitalized terms used but not defined in this Disclosure have the meanings given to them in the Terms of Use.

---

## 1. Scope and Relationship to Other Documents

### 1.1 Purpose

The purpose of this Disclosure is to provide an informational overview of certain material risks associated with interacting with the Protocol, the Services, Overlaid Assets, the OVER token, Third-Party Protocols (including, without limitation, Aave V3) and related DeFi strategies, infrastructure and markets. This Disclosure is informational only and does not constitute legal, financial, investment, tax, regulatory, accounting or other professional advice.

### 1.2 Non-Exhaustiveness and Cumulative Risks

The risks described in this Disclosure are illustrative and non-exhaustive. Risks identified in one section may reinforce, aggravate or cause risks described in another section. Adverse events may occur simultaneously, sequentially or in cascading form. The materialization of one risk can trigger, accelerate or amplify other risks, sometimes in ways that are difficult or impossible to model ex ante.

### 1.3 Relationship to Other Documents

This Disclosure is a companion to, and must be read together with, the **Terms of Use**, the **Privacy Policy**, the **Cookie Policy**, the **Legal Disclaimers** and the **Regulatory Overview** (together, the "**Legal Framework**"). In the event of any inconsistency between this Disclosure and the Terms of Use, the Terms of Use shall prevail, except in respect of specific risk descriptions, for which this Disclosure shall be read as complementary.

### 1.4 No Advice or Recommendation

Nothing in this Disclosure shall be construed as: (a) a recommendation to enter into, or refrain from entering into, any transaction; (b) an endorsement of any Digital Asset, Third-Party Protocol, Third-Party Service or strategy; (c) an assurance that any risk has been sufficiently mitigated; or (d) a prediction regarding the outcome of your activities.

### 1.5 No Exhaustive List of Mitigations

Where this Disclosure references audits, formal verification, bug bounty programmes, monitoring, circuit breakers, multi-signature governance, geo-blocking or other mitigations, such references are for informational purposes only. **No mitigation, control or safeguard described or referenced in this Disclosure constitutes a warranty, representation, promise or guarantee of security, resilience, availability, stability, solvency or value.**

---

## 2. Your Sophistication, Your Responsibility

### 2.1 Sophistication Requirement

By using any part of the Protocol, the Services or any Overlaid Asset, you represent and warrant that you possess:

(a) a working understanding of blockchain technology, public-key cryptography, self-custodial wallets, private-key management, and the mechanics of transaction signing and broadcasting;

(b) a working understanding of smart contracts, their composable interactions, and their security, economic and operational risks;

(c) a working understanding of stablecoins, liquid staking tokens, receipt tokens, wrapped assets, interest-bearing tokens and their respective risk profiles;

(d) a working understanding of DeFi lending and borrowing markets (including, without limitation, Aave V3), collateralization, liquidation, oracles and yield mechanics; and

(e) sufficient financial and technical sophistication to evaluate, assume and manage the risks described in this Disclosure, and to bear the partial or total loss of any Digital Asset you interact with.

### 2.2 Independent Research and Advice

You are solely responsible for conducting your own independent research and for consulting with your own qualified legal, financial, tax and technical advisers, in each case prior to and throughout your use of the Services, the Protocol, any Overlaid Asset or the OVER token.

### 2.3 No Reliance

You acknowledge and agree that you are not relying on the Operator, the Foundation, any other Ecosystem Entity, any contributor, any Multisig signer, any governance participant, any auditor, any analytics provider or any other person, for any representation, warranty or statement not expressly set out in the Terms of Use, and that any such representation or statement is disclaimed.

---

## 3. Smart Contract and Code Risks

### 3.1 Software Is Experimental and May Contain Defects

The Protocol consists of complex smart contracts and on-chain components deployed on one or more public blockchains. Smart contracts are software and may contain:

(a) bugs, logic errors, integer overflows or underflows, reentrancy vulnerabilities, access-control flaws, or storage collisions;

(b) economic-design flaws, incentive misalignments or emergent behaviours that deviate from the design intent;

(c) vulnerabilities in compiler, runtime, virtual machine or standard library;

(d) interoperability or composability defects that manifest only under specific combinations of inputs, states or counterparties; and

(e) backward-compatibility issues with future blockchain protocol upgrades, hard forks or network changes.

Such defects may be exploited — by identified attackers, by unknown or advanced persistent threats, by malicious insiders, or by no attacker at all (for example, by accidental triggering) — and may result in the partial or total loss of Digital Assets, unexpected behaviour, permanent freezing or destruction of positions, permissionless draining of pools, or loss of access to the Protocol.

### 3.2 Audits, Formal Verification and Bug Bounties Are Not Guarantees

Where audits, formal verification, code reviews, peer review, fuzzing, invariant testing, bug bounty programmes, responsible-disclosure channels or similar security activities have been undertaken or commissioned in respect of the Protocol, they:

(a) represent point-in-time, scope-limited exercises by the relevant reviewers;

(b) depend on the assumptions, coverage, methodology, time and expertise of those reviewers;

(c) may not identify all vulnerabilities, including those arising from external dependencies, oracle data, governance decisions, upgrades or changes in the on-chain environment; and

(d) are not, and shall not be interpreted as, a representation or warranty of security, correctness, suitability, fitness for purpose, or absence of vulnerabilities or failures.

The Operator makes no assurance that all audits or reviews have been completed, that findings have been fully remediated, or that new issues will not arise subsequent to any audit or review.

### 3.3 Upgradeability, Pausability and Admin Powers

Certain components of the Protocol may be upgradeable, pausable, configurable or otherwise subject to administrative powers exercised by the Operator, the Foundation, governance participants, Multisig signers or similar actors. Such powers:

(a) may be used to respond to incidents, fix vulnerabilities, change parameters, suspend functionality, migrate liquidity, or deprecate components;

(b) may be used in ways that are adverse to particular Users, positions, strategies or Wallet addresses;

(c) may be misused, compromised, front-run or otherwise exploited;

(d) may be subject to time locks, governance processes or emergency-action procedures which may themselves fail or be manipulated; and

(e) may be irrevocably relinquished ("ossified"), limiting the ability to respond to future incidents.

You acknowledge that the existence, structure and use of administrative powers is itself a category of risk.

### 3.4 Immutable and Irreversible Deployments

To the extent smart contracts of the Protocol are deployed without upgrade mechanisms, they will continue to operate as deployed regardless of any subsequent action by the Operator, the Foundation or any other person. Defects in immutable contracts may be permanent. The Operator has no power to patch, pause, upgrade, redeploy or otherwise modify such contracts after deployment.

### 3.5 Composability Risk

The Protocol is designed to interact with Third-Party Protocols and public-blockchain primitives. Such composability creates compound risk surfaces, including:

(a) the risk that a defect, exploit, parameter change, governance action, oracle failure or insolvency event affecting a Third-Party Protocol propagates into the Protocol;

(b) the risk that a defect or exploit within the Protocol propagates into third-party systems, causing cascading liquidations, withdrawals or losses;

(c) the risk that unintended interactions occur across multiple protocols, producing unforeseen economic or technical outcomes; and

(d) the risk that new integrations, partnerships or routes introduce previously unknown vulnerabilities.

### 3.6 MEV, Front-Running, Sandwich Attacks and Transaction Ordering

Public blockchains permit the extraction of "Maximum Extractable Value" (MEV) by validators, block builders, searchers, block proposers or other market participants. You may suffer losses as a result of:

(a) front-running, back-running, sandwich attacks, or just-in-time liquidity attacks;

(b) reorganizations or reorderings of transactions (including "time-bandit" attacks); and

(c) private-mempool, flashbots or similar arrangements that privilege certain participants over others.

Mitigations such as commit-reveal schemes, MEV-protected relays, slippage tolerances or private transaction channels may reduce, but cannot eliminate, MEV-related risks.

---

## 4. Blockchain and Network Infrastructure Risks

### 4.1 Network Congestion, Delays and Failed Transactions

Public blockchains may experience congestion, high fee markets, sequencer downtime, validator outages, ordering disputes or throughput constraints. As a consequence:

(a) your transactions may fail, be delayed, be executed at unfavourable parameters, or be dropped from the mempool;

(b) time-sensitive actions (for example, liquidation avoidance, rebalancing, arbitrage or exits) may not be processed in time;

(c) you may pay significantly higher gas fees than expected; and

(d) you may incur losses as a result of stale information, delayed confirmations or reorgs.

### 4.2 Reorgs, Forks and Chain Splits

Public blockchains may experience reorganizations, hard forks, soft forks, chain splits or contentious upgrades. Such events may:

(a) invalidate previously confirmed transactions;

(b) create competing chains with divergent states, histories or communities;

(c) result in the loss or duplication of assets;

(d) cause oracles, bridges or Third-Party Protocols to behave inconsistently across chains; and

(e) force migrations, which may be imperfect, partial or harmful.

### 4.3 Consensus and Validator Risk

Public blockchains rely on the honest participation of validators, miners, sequencers or similar actors. Risks include, without limitation:

(a) 51% attacks, long-range attacks, selfish mining, or selfish-validation strategies;

(b) censorship by validators, including as a result of sanctions compliance, OFAC-inclusion of Wallet addresses, or privately coordinated exclusion;

(c) chain halts or liveness failures;

(d) finality failures or delays in deterministic finality;

(e) validator collusion; and

(f) changes in consensus algorithm, hardware requirements or economic parameters that affect decentralization, security or cost.

### 4.4 Layer 2, Rollup and Sidechain Risk

To the extent the Protocol is, or becomes, deployed on Layer 2 networks, rollups, sidechains, appchains or similar environments, additional risks apply, including:

(a) sequencer centralization, sequencer outages or sequencer misbehaviour;

(b) fraud-proof or validity-proof construction failures;

(c) bridge risk between the Layer 2 and its settlement layer (see Section 11);

(d) forced-exit mechanism failure, delays or costs;

(e) upgrade mechanisms controlled by small multisigs or administrator keys; and

(f) economic, security and decentralization properties materially different from those of the underlying Layer 1.

### 4.5 Finality Risk

You may perceive a transaction as confirmed when it has not yet reached economic or deterministic finality. Protocol operations, redemption mechanics and third-party integrations may rely on finality assumptions that are not always met, particularly on networks with probabilistic finality, during reorgs, or when operating across heterogeneous finality regimes.

---

## 5. Oracle, Data Feed and Price Information Risk

### 5.1 Oracle Dependencies

The Protocol, Third-Party Protocols and certain Services rely on oracles, price feeds, indexers, subgraphs, rate providers and other data sources, including both on-chain and off-chain components. Such data sources are essential inputs for key functions, including, without limitation, collateral valuation, liquidation triggers, exchange rates, accrual of yield, withdrawal eligibility and risk parameters.

### 5.2 Failure Modes

Oracles and data feeds may fail, become stale, deliver incorrect values, be manipulated or be censored, including as a result of:

(a) exploitation of underlying markets, low-liquidity venues, flash-loan attacks, or oracle-specific exploits;

(b) heartbeat, deviation, threshold or aggregation failures;

(c) compromise of signer keys, oracle governance or oracle infrastructure;

(d) prolonged outages, congestion, blacklisting or network partitioning;

(e) misconfiguration, including incorrect oracle addresses, thresholds or source assignments;

(f) insolvency, governance capture or deprecation of the oracle provider;

(g) upstream data vendor failures, including the failure of centralized exchanges used as reference venues; and

(h) "lag" or "tardiness" during extreme market conditions, leading to stale or diverging prices.

### 5.3 Consequences

Oracle and data-feed failures may result in, among other things: (a) unjustified, excessive or cascading liquidations; (b) misvaluation of Overlaid Assets, collateral or yield; (c) erroneous triggering of safeguards, caps or circuit breakers; (d) erroneous routing of assets to or from Third-Party Protocols; (e) incorrect display of balances, yields, APYs or risk metrics in the Interface; and (f) the inability of Users to exit positions in a timely manner.

### 5.4 Interface Data May Be Stale, Incorrect or Delayed

Information displayed on the Interface (including balances, yields, APYs, TVL, utilization, risk metrics and analytics) is provided for convenience, is typically sourced from a combination of on-chain and off-chain data, and may be stale, incomplete, incorrect, delayed or otherwise unreliable. **You should always independently verify critical data on-chain before relying on it for any transaction, strategy or decision.**

---

## 6. Off-Chain Infrastructure, DNS and Phishing Risk

### 6.1 Interface Is Not the Protocol

The Interface is distinct from the Protocol. You may interact with the Protocol directly on-chain, without using the Interface. The continued availability, accuracy, reliability or security of the Interface is not necessary for the Protocol to function, and any outage, misconfiguration or compromise of the Interface does not affect the on-chain state of the Protocol.

### 6.2 Third-Party Infrastructure Dependencies

The Interface and related off-chain services depend on a variety of third-party infrastructure providers, including, without limitation: hosting providers, CDNs, DNS registrars and resolvers, RPC endpoint providers, indexers, subgraph providers, analytics platforms, error monitors and wallet-connection libraries. Failures, outages, misconfigurations, compromises or malicious conduct by any such provider may cause the Interface to be unavailable, inaccurate, misleading or harmful.

### 6.3 DNS Hijacking, BGP Hijacking and Routing Attacks

The Interface, Website and related domains may be subject to DNS hijacking, BGP hijacking, TLS certificate fraud, routing attacks or similar incidents. Such attacks may redirect you to malicious websites that impersonate the Interface but are operated by attackers, possibly leading to the theft of Digital Assets, credentials or signing approvals. You should verify domains, URLs and certificates before connecting a Wallet or signing any transaction.

### 6.4 Phishing, Clone Sites and Malicious Extensions

You may be targeted by phishing campaigns, clone websites, typosquatting, fake mobile applications, impersonation on social networks, malicious browser extensions, malicious Wallet connectors, fraudulent "support" operators and similar attacks. Such attacks can trick you into signing transactions that approve the transfer, withdrawal, seizure or burning of Digital Assets. **The Operator will never request your private keys or seed phrases, and will not instruct you to sign transactions from unofficial websites or channels.**

### 6.5 Supply-Chain and Dependency Risk

The Interface, related off-chain services and even smart contracts may depend on third-party libraries, packages, SDKs, modules, infrastructure images or developer tooling. Supply-chain attacks (for example, compromised packages, dependency confusion, malicious updates or compromised build pipelines) may introduce vulnerabilities or malicious code beyond the Operator's immediate control.

### 6.6 Account, Credential and Device Compromise

Credentials, devices, browsers, extensions, clipboards and hardware used to access the Services or sign transactions may be compromised by malware, keyloggers, clipboard hijackers, remote-access trojans, operating-system vulnerabilities, physical theft or social engineering. Such compromise may result in the loss of Digital Assets. You are solely responsible for the operational and physical security of your devices and credentials.

---

## 7. Overlaid Asset-Specific Risks

### 7.1 Nature of Overlaid Assets

Overlaid Assets are **non-custodial, DeFi-native receipt tokens**. They are designed to represent, in a programmable and composable manner, a cryptographic claim in rem against smart-contract-held positions in one or more underlying Digital Assets allocated into Third-Party Protocols. Overlaid Assets are:

(a) **not** bank deposits, money-market fund units, e-money, electronic money tokens (EMTs), asset-referenced tokens (ARTs), payment stablecoins, or other regulated products;

(b) **not** a direct claim against the Operator, the Foundation, any Ecosystem Entity or any other legal person for redemption in any fiat currency or at any fixed par value;

(c) **not** insured by any deposit-insurance scheme, guarantee fund, insurance policy, sponsor or underwriter; and

(d) redeemable only on a crypto-to-crypto basis pursuant to the code of the relevant smart contracts, and subject to the risks described in this Disclosure.

### 7.2 No Peg Management

The Operator does not actively manage, defend or guarantee any price, peg, parity or stability of any Overlaid Asset. Any price-correspondence between an Overlaid Asset and an underlying asset arises from smart-contract composition, market dynamics, arbitrage incentives and the mechanics of the relevant Third-Party Protocols, and may break, deviate, be delayed, suspended or fail.

### 7.3 Secondary Market Deviation

Overlaid Assets may trade on secondary markets (including decentralized exchanges, automated market makers or centralized exchanges, if any), at prices that deviate significantly from the value of the underlying positions. Such deviation may be caused by:

(a) insufficient liquidity, thin order books or shallow pools;

(b) market sentiment, stress conditions, panic selling, arbitrage frictions or delays;

(c) fee structures and path inefficiencies;

(d) perceived or actual tail risks in the underlying strategies or Third-Party Protocols;

(e) broader crypto-market volatility or contagion; and

(f) manipulation, wash-trading, coordinated selling, or other adversarial market conduct.

Price dislocations may be large, persistent or permanent.

### 7.4 Redemption Mechanics and Availability

Redeeming an Overlaid Asset for the underlying Digital Asset depends on the functioning of the Protocol's smart contracts and on the operational status of the relevant Third-Party Protocols (including liquidity, withdrawal caps, pauses, utilization ratios and oracle availability). Redemption may be delayed, throttled, capped, suspended, paused or indefinitely unavailable in circumstances including, without limitation:

(a) utilization spikes or liquidity crunches in Third-Party Protocols;

(b) parameter changes by Third-Party Protocol governance;

(c) exploits, insolvency or pausing of Third-Party Protocols;

(d) smart-contract upgrades, migrations or emergency actions;

(e) oracle, bridge or infrastructure failures; and

(f) regulatory or enforcement actions.

You may be unable to exit positions when you want, or at all, and may suffer severe slippage or total loss.

### 7.5 Yield Variability and Negative Returns

Any yield, interest, incentive or reward associated with an Overlaid Asset is:

(a) **not** paid, granted, promised or guaranteed by the Operator, the Foundation or any other Ecosystem Entity from its own balance sheet, reserves, profits or any other source;

(b) **passed through** programmatically from Third-Party Protocols (including, without limitation, Aave V3) and the underlying deposits, and driven by market forces (such as borrowing demand and utilization ratios) that are entirely outside the control of the Operator;

(c) variable and subject to change at any time, and may be reduced, suspended or eliminated;

(d) capable of turning negative, for example where Third-Party Protocol fees, losses, slashing-like events, liquidity events or adverse parameter changes outweigh gross yield;

(e) subject to gross-versus-net considerations (including fees, spreads, withdrawals, haircuts, performance drag and tax); and

(f) in no event to be relied upon as a predictor of future performance.

### 7.6 Blacklisting, Freezing and Forced Redemptions at Underlying Level

Underlying assets held within Third-Party Protocols (for example, USDC, USDT or similar stablecoins) may be frozen, blacklisted, seized, redeemed selectively, paused or otherwise restricted by their issuers, regulators, courts or third parties. Such actions at the underlying level will flow through to the relevant Overlaid Assets and may materially impair their value, liquidity, redeemability or operability. The Operator has no power or ability to prevent, reverse, mitigate or compensate for any such action.

### 7.7 Wrapper-Chain Amplification

Where an Overlaid Asset is itself used as collateral, input or liquidity in another DeFi protocol, or is "wrapped" further, additional layers of risk apply, including: (a) amplification of oracle and price-discovery risk; (b) cross-protocol contagion; (c) cascading liquidations; (d) liquidity-fragmentation effects; and (e) inability to unwind positions without unwinding dependent wrappers first.

### 7.8 Reclassification Risk

Notwithstanding the intended legal characterization of Overlaid Assets as receipt tokens (see the Regulatory Overview), a Governmental Authority or court may reach a different conclusion. Reclassification of Overlaid Assets as EMTs, ARTs, "payment stablecoins," securities, collective-investment-scheme units, insurance products, bank deposits or other regulated instruments could result in additional obligations, restrictions, forced migrations, wind-downs, freezing orders or penalties that materially and adversely affect Overlaid Assets, Users and the Protocol. See Section 15 below for further detail on regulatory risk.

---

## 8. Underlying Stablecoin and Reference Asset Risk

### 8.1 Dependency on Third-Party Stablecoins

The economic function of many Overlaid Assets depends directly or indirectly on third-party stablecoins (such as USDC, USDT, DAI, PYUSD, FDUSD or similar instruments), their issuers, their reserves, their banking relationships and their peg-maintenance practices. The Operator does **not** control, operate, supervise, guarantee, endorse or assume responsibility for any such stablecoin or its issuer.

### 8.2 De-Pegging Risk

Third-party stablecoins may lose their peg, either temporarily or permanently, for reasons including, without limitation:

(a) loss or impairment of reserve assets (for example, banking failures, reserve-asset repricing, or counterparty default);

(b) run-on-the-issuer dynamics and redemption bottlenecks;

(c) regulatory intervention, enforcement or shutdown;

(d) loss of banking partners or correspondent relationships;

(e) oracle failure that misrepresents the peg;

(f) severe market stress, liquidity crises or broader crypto-market contagion; and

(g) loss of confidence in the issuer's solvency, management or compliance posture.

Small or temporary de-peggings may cause large, non-linear effects on Overlaid Assets and Users. Severe or prolonged de-peggings may result in permanent loss of value.

### 8.3 Reserve, Transparency and Audit Risk

Stablecoin issuers vary in the composition, segregation, custody, audit frequency and transparency of their reserves. Attestations, audits and disclosures by stablecoin issuers may be incomplete, delayed, materially inaccurate or unreliable. Reserves may include non-cash instruments (such as commercial paper, Treasuries, repo, money-market funds or crypto-collateral), each with its own risk profile.

### 8.4 Freezing, Seizing and Blacklisting by Issuers

Many stablecoin issuers retain the technical and legal ability to freeze, seize, blacklist or burn stablecoin balances held by specific addresses, or to comply with orders from courts, regulators or law-enforcement agencies. Such actions, if applied to balances held within the Protocol's smart contracts or within Third-Party Protocols that the Protocol integrates, may cause:

(a) a proportional impairment of the relevant Overlaid Assets;

(b) the inability of Users to redeem or transfer specific balances;

(c) cascading effects on yield, collateral or liquidation mechanics; and

(d) permanent, unrecoverable loss.

### 8.5 Regulatory Action Against Stablecoin Issuers

Enforcement actions, rulings, reforms or shutdowns affecting stablecoin issuers (for example, under the GENIUS Act in the United States, MiCA in the European Union, the UK stablecoin regime, Hong Kong, Singapore, or similar regimes) may materially and adversely affect the availability, value and legal status of third-party stablecoins, and by extension Overlaid Assets. Such effects may occur suddenly, with little or no notice, and may be irreversible.

### 8.6 Discontinuation or Migration

A stablecoin issuer may discontinue, rename, migrate or fork its stablecoin, or may switch its technological or legal structure. Such events may cause breakage of integrations, delisting, forced conversion, loss of liquidity or other adverse effects on Overlaid Assets.

---

## 9. Third-Party Protocol and Counterparty Risk

### 9.1 Routing to Third-Party Protocols

The Protocol is designed to route deposited Digital Assets into one or more Third-Party Protocols (including, without limitation, Aave V3 and any successors, forks, equivalents or newly integrated protocols). Each Third-Party Protocol:

(a) is independently developed, deployed, governed and operated, and is not controlled, supervised, audited or endorsed by the Operator;

(b) has its own smart contracts, economic design, governance processes, parameters and failure modes;

(c) is subject to its own terms of service, risk disclosures, governance decisions and legal and regulatory framework; and

(d) may change, upgrade, pause, deprecate, fork or discontinue its protocol at any time.

Your use of the Protocol therefore entails exposure to each relevant Third-Party Protocol and to all of its risks.

### 9.2 Governance, Parameter and Upgrade Risk at Third-Party Level

Third-Party Protocols are governed by their own token holders, delegates, councils, multisigs, risk committees, or similar bodies. Such governance may, among other things:

(a) change collateral factors, interest-rate curves, liquidation thresholds, reserve factors, utilization caps, isolation parameters or supply/borrow caps;

(b) add, remove or restrict supported assets (including underlying stablecoins relevant to Overlaid Assets);

(c) upgrade contracts, migrate pools, or introduce new mechanics;

(d) pause markets, freeze withdrawals, or perform emergency actions;

(e) whitelist or blacklist specific addresses or interfaces; and

(f) approve or reject integrations with other DeFi protocols (including, potentially, the Protocol itself).

Adverse governance decisions may materially and irreversibly affect your positions, yields, risk profile or ability to exit.

### 9.3 Exploits, Insolvency and Bad Debt

Third-Party Protocols have historically been subject to exploits, governance attacks, oracle manipulations, economic-design failures, cascading liquidations, insolvency and "bad debt" events. Such events can result in sudden, large and irreversible losses that flow through to Users of the Protocol. Insurance, safety modules, treasury reserves or similar mechanisms, where they exist at Third-Party Protocol level, are not guarantees and may be insufficient or may fail.

### 9.4 Liquidity Crunches and Utilization Spikes

Lending and borrowing markets integrated with the Protocol may experience liquidity crunches, where utilization reaches or approaches maximum levels, making withdrawals slow, costly or unavailable. You may be unable to redeem Overlaid Assets for the underlying Digital Asset during such periods, and prevailing yield and borrowing rates may fluctuate dramatically.

### 9.5 Cross-Protocol Contagion

Adverse events in one Third-Party Protocol may propagate to others, and to the Protocol itself, via shared dependencies (oracles, stablecoins, collateral, governance tokens), liquidations, correlated risk factors or broader market sentiment. Historical precedent shows that DeFi contagion can be rapid and non-linear.

### 9.6 Centralized Counterparties in the Supply Chain

Although the Protocol is designed to be non-custodial, certain inputs and outputs may depend on centralized counterparties, including stablecoin issuers, custodians used by stablecoin issuers, oracle providers, bridge operators, RPC providers and data vendors. Such counterparties carry their own operational, credit, regulatory and counterparty risks (including the risk of default, hack, asset freeze, blacklisting or regulatory action).

### 9.7 Integration with Permissioned or Institutional Layers

Future integrations of the Protocol with permissioned or institutional layers (for example, institutional DeFi pools such as Aave's "Horizon" or equivalents) may introduce additional KYC, whitelisting, compliance or operational requirements, or may create dependencies on regulated counterparties whose failure, default, suspension or regulatory treatment could adversely affect Users.

---

## 10. Collateralization, Liquidation and Health-Factor Risk

### 10.1 Collateralization Mechanics

Certain Third-Party Protocols to which the Protocol routes Digital Assets operate on a collateralized basis. Users (directly or indirectly through the Protocol) may be subject to loan-to-value ratios, health-factor thresholds, isolation-mode rules, borrow caps, supply caps or similar mechanisms.

### 10.2 Liquidations

When collateralization ratios or health factors breach applicable thresholds, liquidation mechanisms may be triggered, which can:

(a) result in the forced sale of collateral at unfavourable prices;

(b) cascade across positions, Wallets, strategies and protocols;

(c) be accelerated by oracle failures, gas-price spikes, network congestion or adverse market conditions; and

(d) cause losses materially greater than the initial collateral impairment.

### 10.3 Liquidator Behaviour and Incentives

Liquidations are executed by third-party liquidator bots and MEV participants acting on their own account. They are not agents of the Operator, the Foundation or any Ecosystem Entity. Their incentives, strategies, failures or delays can materially affect the speed, price and completeness of liquidations.

### 10.4 Bad Debt and Socialized Losses

If liquidation mechanisms fail to fully cover debts (for example, due to oracle lag, extreme volatility, insufficient liquidity or sudden depegs), residual "bad debt" may accumulate in Third-Party Protocols. Such bad debt may be absorbed by reserve factors, safety modules, suppliers or — in some cases — socialized across Users in ways that reduce Overlaid Asset value or availability.

### 10.5 Failure of Circuit Breakers and Safeguards

Circuit breakers, price-deviation limits, pause mechanisms, supply caps and other safeguards, where they exist, may themselves fail, be triggered erroneously, or be bypassed. A triggered safeguard may prevent you from exiting positions or realizing value at critical times.

---

## 11. Bridge, Cross-Chain and Interoperability Risk

### 11.1 Bridges Are High-Risk Infrastructure

To the extent the Protocol, the Services or Users rely on cross-chain bridges, messaging layers or interoperability solutions (including native bridges, third-party bridges, optimistic bridges, canonical bridges, lock-and-mint bridges or intent-based bridges), additional risks apply. Bridges have historically been among the most frequently exploited components of the blockchain ecosystem.

### 11.2 Failure Modes

Bridge and interoperability failures may include, without limitation:

(a) multi-signature compromise, validator compromise or signer collusion;

(b) exploits of bridge contracts, message-verification logic or replay protections;

(c) forgery or misattribution of messages across chains;

(d) failed or delayed fraud/validity proofs;

(e) liquidity exhaustion on destination chains;

(f) mismatches in asset issuance between source and destination chains;

(g) insolvency, censorship or shutdown of bridge operators;

(h) regulatory action against bridge operators or relayers; and

(i) chain re-orgs at the source that invalidate bridged state at the destination.

### 11.3 Wrapped and Bridged Asset Risk

Assets bridged across chains (including wrapped stablecoins or wrapped representations of Overlaid Assets) may trade at a discount or premium, lose peg to their canonical form, become illiquid, or be marked as irredeemable. Such events may cause permanent loss.

---

## 12. Market, Volatility and Liquidity Risk

### 12.1 Extreme Volatility

Crypto-asset markets, including markets for stablecoins, Overlaid Assets, the OVER token and any Digital Assets you may hold, are highly volatile. Prices can fluctuate dramatically over short periods, reach extreme highs or lows, become effectively illiquid, or fall to zero.

### 12.2 Illiquidity and Slippage

Even relatively liquid Digital Assets may, under stress, become effectively illiquid. You may be unable to buy, sell, swap, bridge or redeem assets at or near prevailing quoted prices. You may incur severe slippage, widened spreads, path inefficiencies, routing failures or partial fills.

### 12.3 Flash Crashes and Deleveraging Spirals

Correlated sell-offs, flash crashes, cascading liquidations, deleveraging spirals and systemic shocks may cause sudden, simultaneous losses across multiple assets, protocols and venues. Historical DeFi and broader crypto markets have experienced such events; future markets may experience worse.

### 12.4 Market Manipulation

Crypto-asset markets may be subject to manipulation techniques, including pump-and-dump schemes, wash trading, spoofing, layering, oracle manipulation, coordinated sell-offs, governance attacks and "bank run" dynamics orchestrated on social media. Such manipulation may materially affect prices, liquidations and peg stability.

### 12.5 Correlation and Diversification Illusions

The historical behaviour of Digital Assets, including purported "diversification" benefits, may fail to hold in stress conditions. Correlations tend to rise sharply during crises, and apparent diversification may provide no protection.

---

## 13. Governance, Multisig, DAO and Token-Holder Risk

### 13.1 Governance of the Protocol

Certain aspects of the Protocol, the Services, parameter settings, upgrades, treasury actions, emissions schedules or integrations may be subject to on-chain governance, off-chain governance, Multisig signers, councils, committees or similar mechanisms. Governance actors may include the Foundation, the Operator, ecosystem contributors, third-party delegates or OVER token holders.

### 13.2 Attacks on Governance

Governance mechanisms may be captured, attacked or manipulated, including through:

(a) accumulation of voting power by hostile actors;

(b) flash-loan-based voting or borrow-to-vote strategies;

(c) vote-buying or bribery markets;

(d) collusion among delegates or Multisig signers;

(e) social-engineering or compromise of signer keys;

(f) proposal spam, denial-of-service, or quorum manipulation; and

(g) insider conflicts, apathy or insufficient quorum.

Malicious, negligent or self-interested governance actions can be difficult to reverse and may cause material, irreversible losses to Users.

### 13.3 Multisig Risk

Multisigs rely on the integrity, availability and security of individual signers and their key-management practices. Multisigs are subject to:

(a) signer compromise, coercion or extortion;

(b) key loss or signer death/incapacity, which may cause liveness failures;

(c) collusion among signers;

(d) phishing, malicious signing and blind signing;

(e) operational and procedural errors; and

(f) jurisdictional, legal or regulatory actions directed at signers.

Where Multisigs are controlled, in whole or in part, by parties unaffiliated with the Operator or the Foundation, the Operator has no control over their actions or inactions and shall not be liable for the consequences thereof.

### 13.4 Governance Apathy and Capture Over Time

Over time, governance participation may decline, leading to concentrated decision-making by a small number of active participants. This increases the risk of capture, misalignment, or decisions adverse to Users.

### 13.5 Changes to Tokenomics and Economic Parameters

Governance or contributor processes may result in changes to tokenomics (including emissions, lock-ups, vesting, burn rates, fee splits, treasury allocations) and economic parameters (including yield distribution, reserve factors, fee structures or integration lists). Such changes may materially affect the value, utility and risk profile of Overlaid Assets, the OVER token and User positions.

---

## 14. OVER Token-Specific Risk

### 14.1 Nature of OVER

The OVER token is intended solely as a utility and governance token used to coordinate the Overlayer ecosystem. It is not, and shall not be construed as:

(a) a security, investment contract, share, bond, note, derivative, collective-investment-scheme unit, equity, debt, profit share or revenue share under any applicable Law;

(b) a claim against the Operator, the Foundation or any Ecosystem Entity for payment, repayment, dividends, distributions, interest or redemption;

(c) a payment instrument, electronic money, stablecoin or similar product; or

(d) a guarantee or evidence of future returns, ecosystem success, protocol growth or market value.

### 14.2 No Intrinsic Value

OVER has no intrinsic value, and the Operator makes no representation or guarantee that OVER will retain any particular value, develop or maintain a liquid secondary market, or serve any particular future utility. You should not acquire, hold or trade OVER with any expectation of profit.

### 14.3 Emissions, Dilution and Supply Changes

The supply of OVER may be affected by emissions, unlocks, vesting, burns, buy-backs, issuance to contributors or ecosystem programmes, changes to tokenomics decided by governance, migrations to successor tokens, or similar events. Such events may cause dilution, dilution-equivalent effects or loss of value.

### 14.4 Illiquidity and Market Risk

Secondary markets for OVER, where they exist, may be thin, manipulable, subject to delistings, or shut down. OVER may be difficult or impossible to sell at any particular time or price.

### 14.5 Governance Participation Risks

Participation in governance (including voting, delegating, submitting proposals or operating a signer key) involves risks, including time and attention costs, liability exposure in certain jurisdictions, and potential personal consequences resulting from governance decisions (for example, regulatory scrutiny). You are solely responsible for evaluating and managing such risks.

### 14.6 Regulatory Reclassification of OVER

Notwithstanding the intended utility and governance characterization of OVER, a Governmental Authority or court may reach a different conclusion. Reclassification as a security, financial instrument, regulated token or similar product may trigger additional obligations, restrictions or enforcement actions that materially and adversely affect OVER holders, liquidity venues, the Operator, the Foundation and the ecosystem.

---

## 15. Regulatory, Legal and Enforcement Risk

### 15.1 Evolving and Uncertain Legal Environment

The legal, regulatory and tax treatment of crypto-assets, DeFi protocols, stablecoins, receipt tokens, wrapped assets, governance tokens, on-chain lending and related activities is uncertain, evolving and inconsistent across jurisdictions. New Laws, regulations, guidance, interpretations, rulings, enforcement priorities and judicial decisions may:

(a) restrict, suspend, prohibit, require modifications to, or shut down the Protocol, the Services, Overlaid Assets, the OVER token or integrations with Third-Party Protocols;

(b) require registration, licensing, authorization, whitepaper notification, passporting or other consents that have not been obtained;

(c) impose reporting, disclosure, tax, AML/CFT, sanctions, market-abuse, investor-protection or consumer-protection obligations;

(d) expose Users, the Operator, the Foundation, contributors, governance participants, Multisig signers or counterparties to civil penalties, administrative fines, injunctions, disgorgement or criminal sanctions; and

(e) result in forced redemptions, freezes, asset seizures or compelled cooperation with Governmental Authorities.

### 15.2 Reclassification Risk — MiCA

Notwithstanding the intended classification of Overlaid Assets as "crypto-assets other than ARTs or EMTs" under Title II of MiCA (see the Regulatory Overview and the MiCA Classification paper):

(a) ESMA, EBA, the European Commission, national competent authorities or courts may classify Overlaid Assets as EMTs, ARTs or other regulated instruments;

(b) activities undertaken by the Operator, the Foundation or Ecosystem Entities may be classified as CASP services, triggering licensing and conduct-of-business obligations;

(c) forthcoming MiCA guidance (Level 2 and Level 3 measures), and evolving industry interpretations, may reshape the regulatory perimeter;

(d) MiCA's "fully decentralized" carve-out may be interpreted narrowly, exposing components of the ecosystem to the full weight of the regulation; and

(e) divergent interpretations across EU Member States may create additional complexity.

### 15.3 Reclassification Risk — GENIUS Act and U.S. Framework

Notwithstanding the intended classification of Overlaid Assets as "Receipt Tokens" outside the "Payment Stablecoin" definition of the GENIUS Act (see the Regulatory Overview and the GENIUS Act Classification paper):

(a) the U.S. Treasury, the Federal Reserve, the OCC, the SEC, the CFTC, state regulators (including the NYDFS), or courts may classify Overlaid Assets as "Payment Stablecoins," "endogenously collateralized stablecoins," securities, commodities, derivatives, money-services-business products, or similar regulated instruments;

(b) the "pass-through yield" theory — that yield on Overlaid Assets is not paid by the Operator but arises from Third-Party Protocols — may be challenged;

(c) enforcement actions under the Securities Act, Securities Exchange Act, CEA, BSA or state money-transmitter Laws may be brought against participants in the ecosystem;

(d) sanctions, AML/CFT and related obligations may be imposed on, or expanded with respect to, "distributed ledger protocols," front-end operators, software developers, governance participants or Multisig signers; and

(e) state-level requirements (including state money-transmitter licences or similar) may be applied in ways that affect the availability of the Services.

### 15.4 Other Jurisdictions

Regulators in the United Kingdom (FCA/HMT), Singapore (MAS), Hong Kong (SFC/HKMA), Japan (FSA), the United Arab Emirates (VARA/ADGM/DFSA), the European Economic Area, Switzerland (FINMA), South Korea (FSC), Australia (ASIC/AUSTRAC), Canada (CSA/OSFI) and other jurisdictions are developing or implementing their own regimes affecting crypto-assets, stablecoins and DeFi. Such regimes may apply to you, to the Operator, to the Foundation, to Third-Party Protocols or to Users in those jurisdictions, and may materially affect the availability, legal characterization or economic treatment of Overlaid Assets, the OVER token and the Services.

### 15.5 Enforcement Actions Against Third Parties

Enforcement actions against Third-Party Protocols, stablecoin issuers, validators, block builders, bridge operators, custodians, exchanges or governance participants may indirectly, but materially, affect the Protocol, the Services, Overlaid Assets, the OVER token and Users. Examples include: freezes of reserve accounts; wind-downs of stablecoin issuers; delistings from major venues; sanctions on specific Wallets or smart contracts (including mixing services); restrictions on validator participation; and forced disclosure orders.

### 15.6 Geographic Restrictions and Access Controls

The Operator may, at any time and without notice, restrict, suspend or terminate access to the Services from particular jurisdictions (including through IP-based geo-blocking, Wallet screening, sanctions screening and similar tools). Such restrictions may occur abruptly and without liability, and may prevent you from accessing, managing or exiting your positions via the Interface. Users remain responsible for complying with all Laws applicable to them.

### 15.7 Litigation and Private Claims

The Operator, the Foundation, Ecosystem Entities, contributors, Multisig signers, Third-Party Protocols and others may become subject to private litigation, class actions (where not otherwise waived), arbitration, mass-action or similar proceedings, the outcomes of which are inherently uncertain and may materially affect the ecosystem.

### 15.8 Retroactive Application of Rules

New rules, guidance or interpretations may be applied retroactively in some jurisdictions, exposing prior activity (including prior transactions in Overlaid Assets or OVER) to regulatory or tax reassessment.

---

## 16. Sanctions, AML/CFT and Compliance Risk

### 16.1 Sanctions Screening

The Operator may screen Wallet addresses, IP addresses and jurisdictions for sanctions, OFAC, EU, UK, UN and analogous restrictions. You may be denied access to the Services, or your Wallet may be blocked by third-party front-ends, analytics providers or validators, for reasons including but not limited to:

(a) direct listing on a sanctions or restricted-party list;

(b) direct or indirect exposure to sanctioned addresses, mixers, hackers, ransomware operators or illicit actors;

(c) residence in, presence in, or citizenship of a Prohibited Jurisdiction;

(d) beneficial ownership by a sanctioned person; or

(e) heuristic or cluster-based compliance determinations by third-party providers.

Such measures are inherently imperfect and may produce false positives or false negatives. You are solely responsible for complying with all applicable sanctions and AML/CFT Laws.

### 16.2 Tainted Funds and Third-Party Blacklisting

Digital Assets you hold or use may, without your knowledge, have been previously associated with sanctioned, illicit or high-risk activity. Such "taint" may cause:

(a) blacklisting by stablecoin issuers (resulting in freezing or burning of balances);

(b) rejection by centralized exchanges, custodians or banking partners when you attempt to exit positions;

(c) delays, refusals or forced disclosures during any fiat on-ramp or off-ramp; and

(d) enforcement attention from Governmental Authorities.

Neither the Protocol nor the Operator has any power to reverse, compensate for, or prevent such consequences.

### 16.3 Tornado-Cash-Style Designations and Smart-Contract Sanctions

Governmental Authorities have in recent years designated, or attempted to designate, smart contracts (including mixing services) as sanctioned "entities." Any such designation that affects the Protocol, its dependencies, its Third-Party Protocols, its underlying stablecoins, or the Wallets of Users, may have immediate and severe consequences, including the inability to interact with protocol components, forced migrations, or enforcement exposure for Users.

### 16.4 Cooperation with Law Enforcement

The Operator may cooperate, voluntarily or under legal compulsion, with Governmental Authorities, law-enforcement agencies, regulators and courts. Such cooperation may include the disclosure of information, the blocking of Wallet addresses or jurisdictions, the preservation of data, the freezing or restriction of access, and the provision of technical assistance.

---

## 17. Tax Risk

### 17.1 Complexity of DeFi Taxation

The tax treatment of interacting with the Protocol, acquiring, holding or disposing of Overlaid Assets or the OVER token, receiving yield, participating in governance, providing liquidity, farming rewards, wrapping or unwrapping assets, bridging, swapping or liquidating is complex, jurisdiction-specific and subject to change.

### 17.2 Potential Tax Events

Potential tax events may include, without limitation: acquisition and disposal of Digital Assets; swaps between Digital Assets; wrapping or unwrapping of Digital Assets; receipt of yield or rewards; liquidation of collateral; token migrations or airdrops; participation in governance incentives; and cross-chain transfers. Each event may be characterized differently across jurisdictions (for example, as ordinary income, capital gains, VAT, withholding tax, or otherwise).

### 17.3 No Reporting from the Operator

The Operator does not provide tax advice, does not issue tax forms or reports on your behalf, does not verify your tax residency, and is not responsible for determining or paying any taxes applicable to you. It is your sole responsibility to calculate, withhold, collect, declare, report, pay and document all taxes arising from your activities.

### 17.4 Retroactive Taxation and Enforcement

Tax authorities may in some jurisdictions apply new interpretations, classifications or enforcement priorities retroactively. You may become liable for taxes, penalties or interest with respect to activities that you considered, at the time, non-taxable or neutrally taxable.

---

## 18. Cybersecurity and Operational Risk

### 18.1 Cyber Threat Environment

The Operator, the Foundation, Users, contributors, Third-Party Protocols and all participants in the broader ecosystem are continuous targets of cyber attacks, including, without limitation: phishing, spear-phishing, social engineering, credential theft, session hijacking, SIM-swap attacks, malware, ransomware, supply-chain attacks, API compromise, advanced persistent threats, and state-sponsored operations.

### 18.2 Wallet and Signing Security

Your self-custodial Wallet is a primary target. Risks include:

(a) blind signing of malicious transactions, including approvals for unlimited token spending;

(b) permit-style signature phishing;

(c) compromised browser extensions impersonating legitimate Wallets;

(d) malicious "claim" or "airdrop" sites;

(e) clipboard hijackers replacing addresses at the moment of copying;

(f) firmware or hardware-wallet supply-chain tampering;

(g) seed-phrase exposure (photos, cloud backups, screenshots); and

(h) physical coercion or "wrench attacks."

You are solely responsible for the operational and physical security of your Wallet, credentials, devices and seed phrases.

### 18.3 Operational Incidents

The Services, the Interface and related infrastructure may experience outages, misconfigurations, deployment errors, staff errors, contractor errors or insider events. Such incidents may prevent you from accessing the Interface, receiving accurate information, or signing transactions. Although the Operator maintains incident-response processes, such processes are imperfect and may fail or be delayed.

### 18.4 Key and Access-Management Risk

The Operator, the Foundation, Multisig signers, oracle operators and Third-Party Protocols rely on the secure management of cryptographic keys and administrative credentials. Compromise or loss of such keys or credentials may cause outages, unauthorized actions, protocol pauses or permanent impairment.

### 18.5 Social-Media and Impersonation Risk

The ecosystem is frequently targeted by impersonation of official accounts, fake airdrop announcements, fake support channels, fake "urgent migration" notices and similar scams on social networks (such as X (Twitter), Telegram, Discord and similar platforms). The Operator and the Foundation communicate only through their official channels published on the Website. You should independently verify any announcement, link or address before acting.

---

## 19. Data, Privacy and Reputational Risk

### 19.1 Public Nature of Blockchain Data

Your Wallet addresses, transaction history, token balances, interactions with protocols and governance participation are publicly visible on public blockchains, potentially for perpetuity, and may be associated with your identity through on-chain analytics, off-chain leaks or voluntary disclosure. You should consider this carefully before interacting with the Protocol or the Services.

### 19.2 Clustering and Heuristic De-Anonymization

Sophisticated analytics providers, researchers, adversaries and Governmental Authorities may use clustering techniques, heuristic linking and off-chain correlation to associate Wallet addresses with individuals or entities. Such de-anonymization may have regulatory, tax, reputational, safety or personal consequences for you.

### 19.3 Reputational Contagion

Your public association with specific Wallet addresses, protocols, governance actions or transactions (including unknowingly tainted flows) may have reputational consequences, including with employers, financial institutions, counterparties or Governmental Authorities. The Operator does not and cannot control or mitigate such consequences.

---

## 20. Concentration, Systemic and Contagion Risk

### 20.1 Dependency on a Limited Set of Counterparties

Depending on its configuration at any given time, the Protocol may rely on a limited number of stablecoins, Third-Party Protocols, oracles, bridges, chains or service providers. Concentration in any of these layers creates material single-points-of-failure. Diversification, where it exists, may not be effective in stress scenarios.

### 20.2 Systemic DeFi Risk

The broader DeFi ecosystem is interconnected via shared dependencies. Stress in one layer may propagate rapidly through others. Historical events have demonstrated that DeFi contagion can be fast, non-linear and difficult to contain. Future events may be worse.

### 20.3 Macroeconomic, Monetary and Banking Risk

Crypto-asset markets, stablecoin reserves and issuer banking relationships are sensitive to macroeconomic conditions, monetary policy (including central-bank interest-rate decisions, quantitative tightening or easing), fiscal policy, banking-sector stability (including bank runs, bail-outs or resolutions of banks that hold stablecoin reserves) and currency crises. Adverse macroeconomic events may materially and adversely affect stablecoin pegs, DeFi yields, liquidity and overall risk.

---

## 21. Operational User-Side Risk

### 21.1 User Error

Once confirmed on a blockchain, transactions are generally irreversible. You may suffer losses as a result of:

(a) sending Digital Assets to the wrong address;

(b) using the wrong chain, network or version of an asset;

(c) approving the wrong contract or granting unlimited allowances;

(d) accepting unreasonable slippage tolerances;

(e) misconfiguring parameters (for example, collateralization levels, withdrawal amounts or strategy selections);

(f) signing transactions constructed by malicious sources; and

(g) failing to account for gas fees, network congestion or timing.

The Operator has no ability and no obligation to recover or reverse such losses.

### 21.2 Loss of Access

Loss of private keys, seed phrases, hardware wallets, signing devices or authentication factors generally results in permanent loss of access to Digital Assets. There is no recovery mechanism within the Protocol, and the Operator has no ability to restore access.

### 21.3 Inheritance and Continuity

Digital Assets held in self-custodial Wallets may be lost upon death, incapacitation or other life events of the holder, unless appropriate inheritance and continuity planning has been implemented. Such planning is your sole responsibility.

---

## 22. Forward-Looking Statements and Uncertainty

### 22.1 Nature of Forward-Looking Statements

Documentation, whitepapers, litepapers, roadmaps, blog posts, social-media posts, community calls, governance discussions, pitch materials and other public communications by the Operator, the Foundation, contributors or third parties may contain forward-looking statements regarding, among other things, product development, tokenomics, reserve indices, integrations, ecosystem growth, anticipated yields, market opportunities or strategic direction.

### 22.2 Inherent Uncertainty

Forward-looking statements are based on current expectations, estimates, assumptions, plans and information, each of which may change materially. Actual events, results, developments, parameters, integrations and outcomes may differ materially from those expressed or implied. **No forward-looking statement is a representation, warranty, guarantee, promise or commitment of future performance or future action.**

### 22.3 No Obligation to Update

The Operator, the Foundation and the Ecosystem Entities undertake no obligation to update, revise or publicly release any revision of any forward-looking statement to reflect events, circumstances or information that become known after the statement was made, except to the extent required by applicable Laws.

---

## 23. No Guarantees; No Advice

### 23.1 No Guarantees

Nothing in this Disclosure, the Services, the Documentation, the Interface, the Protocol or any communication by or on behalf of the Operator, the Foundation or any other person:

(a) guarantees any yield, return, price, peg, liquidity, capital protection, availability, security or outcome;

(b) promises, ensures or represents that any particular strategy, pool, Third-Party Protocol or integration will remain operative or profitable;

(c) provides assurance that regulatory treatment will remain unchanged; or

(d) constitutes a warranty, representation, commitment or promise of any kind, save as expressly set out in the Terms of Use.

### 23.2 No Advice; Suitability Is Your Responsibility

Nothing in this Disclosure, the Services, the Documentation, the Interface or any communication by or on behalf of the Operator constitutes, or is intended to constitute, investment, financial, legal, tax, accounting or other professional advice, or a recommendation, solicitation, or invitation to engage in any transaction. **You are solely responsible for determining the suitability of any activity, strategy, pool, Third-Party Protocol or Digital Asset for your own circumstances, objectives and risk tolerance.**

---

## 24. Emerging and Unknown Risks

### 24.1 Novelty of the Technology

Blockchain, DeFi and related technologies are novel and rapidly evolving. New risks may arise, and existing risks may change, at any time. Risks that are currently unknown, unappreciated or underestimated may become material in the future. The materialization of previously unknown risks may cause severe, sudden and irreversible losses.

### 24.2 Black-Swan Events

The ecosystem may be exposed to "black-swan" events — rare, high-impact occurrences that are extremely difficult or impossible to predict. Historical precedents include major exchange failures, stablecoin collapses, bridge exploits, validator failures and systemic deleveraging. Future such events may occur with little or no warning.

### 24.3 Quantum, Cryptographic and Algorithmic Advances

Advances in cryptanalysis, quantum computing, algorithmic optimization or adversarial-AI capabilities may, in the future, compromise cryptographic primitives underlying public blockchains, private keys, smart contracts and related systems. Such advances may render certain assets, positions or systems insecure or obsolete.

---

## 25. User Acknowledgements and Responsibilities

### 25.1 Your Acknowledgements

By accessing or using any part of the Services or the Protocol, by acquiring, holding, transferring or disposing of any Overlaid Asset or the OVER token, or by interacting with any Third-Party Protocol in connection with the foregoing, you:

(a) acknowledge that you have read, understood and unconditionally accepted this Disclosure in its entirety;

(b) confirm that you satisfy the sophistication requirement set out in Section 2;

(c) accept that the risks described in this Disclosure, together with others not described or not yet known, apply to you;

(d) accept that you may lose, partially or entirely and permanently, any and all Digital Assets you use in connection with the Protocol or the Services;

(e) agree that you are solely responsible for your decisions, transactions, strategies and risk management;

(f) agree that the Operator, the Foundation, the Ecosystem Entities and all other Operator Parties (as defined in the Terms of Use) shall have no liability for any loss, damage, cost or expense arising from the materialization of any risk described in this Disclosure or otherwise inherent in your use of the Services or the Protocol, except to the extent expressly provided in the Terms of Use; and

(g) agree that if any statement in this Disclosure is or becomes inaccurate, unclear or incomplete with respect to your circumstances, you shall not rely on it and shall obtain independent professional advice.

### 25.2 Your Ongoing Responsibilities

You are responsible at all times for:

(a) monitoring relevant governance channels, documentation, announcements and protocol parameters, and deciding whether to remain in, adjust or exit your positions in light of changes;

(b) securing your Wallets, devices, credentials and operational environment;

(c) verifying domains, URLs, contract addresses and integrations before each interaction;

(d) maintaining compliance with all Laws applicable to you (including sanctions, AML/CFT, tax, consumer-protection, securities and reporting Laws);

(e) evaluating, on an ongoing basis, the suitability of your activities for your circumstances, objectives and risk tolerance; and

(f) obtaining independent professional advice as you consider appropriate.

---

## 26. Interaction with the Terms of Use

### 26.1 Integration

This Disclosure is incorporated by reference into the Terms of Use. Its contents supplement, and do not limit, the risk, disclaimer, assumption-of-risk, limitation-of-liability, indemnification and dispute-resolution provisions of the Terms of Use.

### 26.2 Limitation of Liability

**All disclaimers, assumption-of-risk provisions, warranty exclusions, limitations of liability, aggregate liability caps, class-action waivers, arbitration agreements and indemnification obligations set out in the Terms of Use apply with equal force to the subject matter of this Disclosure.** No statement in this Disclosure shall be read as creating any additional liability of the Operator, the Foundation, any other Ecosystem Entity or any Operator Party.

### 26.3 Governing Law and Dispute Resolution

This Disclosure is governed by, and shall be construed in accordance with, the laws of the British Virgin Islands, and any dispute, claim or controversy arising out of, or in connection with, this Disclosure shall be resolved in accordance with Sections 18 and 19 of the Terms of Use (including the BVI IAC arbitration agreement and the class-action waiver).

---

## 27. Updates to This Disclosure

The Operator may modify this Disclosure from time to time to reflect changes in the Protocol, the Services, Third-Party Protocols, applicable Laws, our understanding of the risk landscape, or for any other reason. When we do so, we will update the "Last Revised" date at the top of this Disclosure and, where reasonably practicable, provide additional notice through the Website or Official Channels.

**You are responsible for reviewing this Disclosure periodically. Your continued access to, or use of, the Services, the Protocol, Overlaid Assets or the OVER token after the effective date of any modification constitutes your acknowledgement and acceptance of the modified Disclosure.**

If you do not agree with any modification, you must immediately cease all access to and use of the Services and the Protocol, and must not acquire, hold, transfer or dispose of any further Overlaid Assets or OVER tokens in reliance on the prior version.

---

## 28. Contact

If you have questions regarding this Disclosure or the risks described herein, please contact us at:

**Email:** business@overlayer.fi

**Mailing Address:** Overlayer Labs Ltd, as disclosed on the Website.

**The Operator does not provide personalized advice, recommendations or opinions on the suitability of any transaction, strategy or Digital Asset for you.**

---

*This Protocol Risk Disclosure is designed to operate in conjunction with the Terms of Use, the Privacy Policy, the Cookie Policy, the Legal Disclaimers and the Regulatory Overview, each as made available through the Website and updated from time to time.*
