Risks & mitigations
We’d rather be straight with you. Every secured-lending product carries risk; here’s the honest list and how each one is mitigated.
Smart-contract risk
Section titled “Smart-contract risk”Risk: the Anvil protocol contracts could contain an undiscovered vulnerability.
Mitigations: Anvil is audited by OpenZeppelin and Trail of Bits; collateral is restricted to deeply liquid, battle-tested assets; and a conversion-route liquidity cap limits concentration. Residual risk remains, as with any smart-contract system.
Protocol-dependency risk
Section titled “Protocol-dependency risk”Risk: Anvil is a third-party protocol, and some parameters are set by its governance.
Mitigations: Helva chooses conservative configurations, monitors Anvil governance, and runs its own monitoring and liquidation path directly against the contracts — independent of Anvil’s frontend. See The Anvil protocol.
Market / liquidation risk
Section titled “Market / liquidation risk”Risk: in a sharp market drop, collateral value can fall toward the liquidation threshold.
Mitigations: conservative loan-to-value ratios; 24/7 monitoring with customizable margin-call alerts; the ability to top up unilaterally at any time; and a permissionless liquidation backstop that converts only what’s owed. See What happens if….
Exchange-rate risk (CHF loans)
Section titled “Exchange-rate risk (CHF loans)”Risk: there is no widely used CHF stablecoin, so CHF loans are secured by an EURC Letter of Credit. If the franc strengthens against the euro, that EURC covers fewer francs.
Mitigations: an FX buffer at issuance, sized by loan term; coverage watched separately from collateral; an information email, then a request for a supplementary Letter of Credit, then a loan call if the buffer is almost gone. See The FX buffer.
Counterparty / guarantee risk
Section titled “Counterparty / guarantee risk”Risk: if a liquidation falls short, the lender relies on the guarantee.
Mitigations: a first-loss reserve funds the first tranche; beyond it Helva’s guarantee applies. Shortfall probability is kept low by conservative ratios, the liquid-only collateral policy, the liquidity cap, and loan-size limits.
Banking risk
Section titled “Banking risk”Risk: fiat moves through a Swiss client account; banking relationships can see friction.
Mitigations: the client transaction account is segregated by design and intended to be bankruptcy-remote; funds are forwarded promptly (days, not weeks); and Helva targets redundant banking relationships. Where transfers see friction, Helva communicates proactively to unblock funds.
Regulatory risk
Section titled “Regulatory risk”Risk: the regulatory landscape evolves (Swiss SRO membership, EU rules, reporting frameworks).
Mitigations & status: Helva’s underlying entity is a member of a FINMA-recognised SRO. See the imprint. Contracts are under Swiss law, and reporting positioning is kept accurate over time. See Swiss legal framework and Reporting.
Beneficiary and app integrity
Section titled “Beneficiary and app integrity”Risk: a compromised app, or a wrong address in a wallet prompt, could name the wrong beneficiary or the wrong contract.
Mitigations: the address list on Verify your transactions, hosted separately from the app, and Helva’s on-chain acceptance checks before a loan is activated. An existing Letter of Credit lives on-chain. A bad app cannot rewrite it.
Oracle and protocol-owner risk
Section titled “Oracle and protocol-owner risk”Risk: Anvil’s owner can change the price oracle and the contracts without a timelock (a required delay before the change takes effect). A Pyth price can go stale.
Mitigations: Helva monitors governance and can redeem early if needed. A stale Pyth price delays a redemption until a fresh price update is supplied. It does not let a caller pick a destination. See The Anvil protocol.
Beneficiary contract upgrade risk
Section titled “Beneficiary contract upgrade risk”Risk: the beneficiary contract is upgradeable. An upgrade could change what the contract does.
Mitigations: only the 2-of-3 admin Safe can upgrade it. Upgrades and role changes are monitored. The published beneficiary address does not change. Changes are announced in the changelog.
For concrete scenarios, see What happens if….