Protocol

Risks

What can go wrong for borrowers, lenders and liquidators, and what the program does and doesn't protect against.

Program and adapter bugs

The program and its two adapters hold every borrowed dollar. A bug that lets funds leave custody, values an account wrongly, or miscounts debt is a direct loss, usually to lenders. The program checks every account it touches, every token balance after every call into a target, and every move from the transaction's own instruction list; checks reduce this risk, they don't remove it.

Save's liquidity

Save counts only what its reserve could pay out right now, after its own borrowers have taken their share. If Save is fully lent out, or its rolling withdrawal limits are used up:

  • Save deposits count for nothing, which can push an account below 1.00 without its owner doing anything,
  • receipts can't be redeemed until cash returns, so neither the owner nor a liquidator can unwind them,
  • liquidations proceed in pieces, as Save pays out.

Keeping most of an account in cash or the Orca LP limits how much this matters.

The Orca LP and SOL's price

The LP counts only its USDC side. When SOL falls, traders sell SOL into the pool for USDC, the pool's USDC shrinks, and so does your counted LP. A 30% fall takes about 16% off the USDC side. An account that is mostly LP crosses 1.00 sooner than its owner may expect; the health calculator shows how soon.

Target upgrades

Each adapter is pinned to the deployed version of its target. If Save or Orca upgrades, the adapter stops, and because every valuation reads both targets, every move, borrow, open and liquidation stops with it until a new registration is in place. While that lasts:

  • owners can repay from their wallets and then release their assets,
  • lenders can withdraw against the pool's cash,
  • accounts can't be liquidated, so unhealthy debt can grow into a loss.

Target pauses and failures

If a target pauses, freezes its vaults or is exploited, whatever credit accounts hold there is stuck with it, and so is the debt it backs. Yoke has no way to recover funds from a failed target.

Orca's legacy pool

The LP adapter uses Orca's legacy constant-product pool, which Orca's SDK marks as deprecated. If it is wound down, LP positions have to be removed and the adapter replaced.

USDC

USDC's issuer can freeze any USDC token account, including the pool's vault and any account's custody. Frozen USDC can't repay, be withdrawn, or be liquidated.

For lenders

  • Bad debt from an account liquidated without enough USDC is a loss shared by every share.
  • Withdrawals need cash in the pool, which can be scarce at high utilization.
  • See Supplying USDC.

For liquidators

  • An account can recover between your read and your transaction; the liquidation then fails and costs the fee.
  • Save's cash limits can make a liquidation smaller than the account.
  • Removing an LP position pays out at the pool's price at that moment, within the limits you set.

What the program doesn't do

  • It doesn't read any price feed, so it can't be fooled by one, and it can't value SOL.
  • It doesn't swap, so it can't turn SOL into USDC to repay debt.
  • It can't recover funds from a failed target or a frozen token account.
  • It has no administrator instruction that moves user funds.

Next

Yoke

One credit account across Save and Orca, on Solana.

Follow on X
© 2026 YokeYoke is software on Solana; every transaction is signed by your own wallet. Borrowing, lending and liquidating can lose money. Read the risks first.