Docs · 7 of 8

Control and risks

Who can change what, what nobody can change, and what can go wrong.

Who can do what

PartyCanCannot
Timelock (the developer proposes; 48 hours; anyone executes)Lower the tax. Change the vault’s bounded parameters, the operator, the oracle attester, the question and the freshness window.Raise the tax. Move ETH, seats or tokens. Change the sink, the split, the launch schedule or the liquidity gate. Upgrade anything.
DeveloperClaim the developer balance. Change the developer address. Release vested PUPATE.Anything else.
OperatorApprove and revoke IMD pairings for seats the vault holds.Move anything. Sign anything else.
AnyoneFlush, buy, settle, adopt, burn, run the auctions, report, release vesting, execute matured timelock operations.

The developer’s income

  • 10% of the tax, which is 0.6% of each trade at the standing rate. It accrues in the vault and is claimed by the developer address.
  • 5% of supply, vested in a straight line over 365 days.
  • Nothing from the pool’s fee. IMD holds the liquidity position.

That share also pays for running the thing: 0.5 IMD per oracle report (four a day), keeper gas, and a machine and an assistant subscription for each seat put to work. If the developer stops paying, the system degrades but does not lock: anyone may pay for and submit a report, and the purchase reward makes that worthwhile when a seat can be bought.

Reviews

The contracts were reviewed twice by agents that had not seen the design’s reasoning, once for the hook and the feed and once for the vault. Both found real problems, all of which were fixed before this site was written; the findings and their outcomes are in the repository’s review log. The IMD swarm reviews the launch again on its own terms. None of this is a formal audit, and IMD itself has none.

Known risks

The tax can be avoided in other pools.
The token is a plain ERC-20, so anyone can open another pool and trade there untaxed. The launch pool holds 85% of supply and this site trades through it, which keeps most volume there, but the leak grows with success. Lowering the tax narrows it.
Scanners will flag the launch.
For the first 93 minutes the buy tax is far above what token scanners treat as normal. It is meant to be.
The reference price can be pushed.
Wash sales move a median. The rise limit holds the vault to 25% per 6 hours, the tolerance to 105% of the reference, and the split to at most 70% of the strategy share. A sustained push can still raise the reference by about a quarter every six hours for as long as the oracle reports it.
Seats may not sell.
After 14 days a seat sits at 1.1× until bought. Capital is tied up if the market falls under that.
Seat yield may be thin.
Earnings are split across every connected seat in the swarm. The design works without them, as a tax-and-flip strategy.
The oracle may stop.
Buying halts and the split falls back to 50/50, with the seat pot accumulating unspent, until reports resume.
The sink is fixed.
If the vault ever refused deposits, collected tax would stay in the PoolManager as claims. It accepts plain ETH by design.
Two integrations are unexercised.
Pairing a contract-held seat and the floor question are confirmed on Sepolia before mainnet, not before.
A competitor exists.
Another strategy runs on the same collection with a tax that cannot be avoided, because its token was not launched through IMD.
This documentation describes a mechanism. It makes no statement about returns. The tax that applies to your trade is always shown beside the button on the Feed page.