> For the complete documentation index, see [llms.txt](https://docs.polygen.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.polygen.io/more-info/technical-documentation/contract-upgrades-admin-keys-hacks-and-exploits.md).

# Contract upgrades, admin keys, hacks & exploits

* TaaE tokens have fixed scope and duration.&#x20;
* Every phase change, from bootstrap, distribution and redemption is one-way with predictable timing.&#x20;
* The final state of the system is that hodlers receive rewards and slowly drop out to the underlying asset as a one-way move, or hold a frozen asset indefinitely if they choose to.&#x20;
* Every new token event requires a new Trust with its own lifecycle.&#x20;
* If a vulnerability is found in a version of the Trust the theoretical maximum damage of an exploit is capped at the current locked reserve across the pool and token across vulnerableTrust contracts.&#x20;
* By versioning and newly deploying Trust contracts, any fix to a discovered exploit will be available for all new Trust contracts after that point. There are no admin keys as the Trust performs all administrative tasks on the child contracts.
