Skip to main content

Cold Vault Replacement and Emergency Sweep Address Setup Guide

ยท 8 min read
Pay Protocol Support
Pay Protocol Support
Pay Protocol BD & Support Team

This guide is intended for merchant operations and fund security teams. It covers the full workflow for cold vault replacement, emergency sweep address setup, emergency fund withdrawal address setup, and high-risk fund handling.

You can execute the process in the following order:

  • Replace the cold vault (multisig)
  • Set the emergency sweep address (multisig)
  • Set the emergency fund withdrawal address (multisig)
  • Sweep and withdraw funds from blacklisted sub-contracts

1. Cold Vault Replacementโ€‹

Overviewโ€‹

The cold vault stores large merchant balances. To avoid contamination from high-risk transactions or other security risks, merchants can replace the cold vault address through multisig. This operation requires two admin wallets (one to create the proposal, one to approve and submit on-chain) to protect fund security.

This section uses the Pro console as an example and explains the full replacement procedure.

Pre-checks
  • Make sure both admin wallets can log in and have enough gas.
  • Make sure the selected network matches the merchant's actual operating network.

Stepsโ€‹

  1. Log in with an admin wallet and go to "System Configuration -> Multi-Signature Management".

    Multisig management entry

  2. On the Multi-Signature Management page, open the "Edit Parameter Proposal" tab, click "Modify", and choose "Modify Cold Vault Address" from the "Category" dropdown.

    Select modify Cold Vault address

  3. In the "Address" dropdown, choose the target cold vault address:

    • If no replacement address exists, choose "New" and let the system generate a new cold vault address.
    • If historical addresses exist, select one of the previously used cold vault addresses.

    Choose new or historical Cold Vault address

  4. Confirm and sign with the current admin wallet to create the proposal.

  5. Sign out, switch to another admin wallet, go to "Multi-Signature Management -> Edit Parameter Proposal", find the pending proposal, and click "Approve".

    View pending Cold Vault proposal

  6. Verify the details in the approval dialog, sign with the wallet, then confirm on-chain in the wallet (a small gas fee is required).

    Approve and submit Cold Vault proposal on-chain

  7. Wait about 1 minute. When the proposal status changes to "Approved", the cold vault address replacement is complete.

    Cold Vault proposal approved

Additional Note: Finance Hot Contract Address Updateโ€‹

The finance hot contract address update follows the same multisig proposal workflow as cold vault replacement:

  1. Log in with an admin wallet, choose "Modify Finance Hot Contract Address" in "Edit Parameter Proposal", create the proposal, and sign.

    Create Finance Hot Contract address update proposal

  2. Switch to another admin wallet, approve the proposal, and confirm on-chain in the wallet.

    Approve Finance Hot Contract address update proposal

  3. Wait about 1 minute. Once status becomes "Approved", the finance hot contract address update is complete.

    Finance Hot Contract proposal approved

2. Set Emergency Sweep and Emergency Fund Withdrawal Addressesโ€‹

Overviewโ€‹

The Emergency Sweep Address and Emergency Fund Withdrawal Address are used to handle funds from high-risk sub-contracts. When a merchant's receiving sub-contract is marked as high-risk or blacklisted, funds can be swept to the Emergency Sweep Address first, then moved to a safe external wallet through the Emergency Fund Withdrawal Address. This isolates risk and protects the main contract funds.

This feature is typically used with the blacklist API. See: Blacklist API.

The full process includes three phases:

  1. Set the Emergency Sweep Address (multisig)
  2. Set the Emergency Fund Withdrawal Address (multisig)
  3. Sweep funds from high-risk sub-contracts and withdraw them to an external wallet
Standard Merchant Note

For Standard merchants, you only need to set a hot wallet address as the Emergency Fund Withdrawal Address. After sweep, funds go directly to this address, and no follow-up payout proposal is required.

Phase 1: Set the Emergency Sweep Addressโ€‹

Goal

Use a multisig proposal to define the entry address for high-risk funds. Funds from blacklisted sub-contracts will be swept here first.

  1. Log in with an admin wallet and go to "System Configuration -> Multi-Signature Management -> Edit Parameter Proposal".

    Open edit parameter proposal page

  2. Click "Modify", choose "Modify Emergency Sweep Address" in "Category", then choose the address:

    • If no Emergency Sweep Address exists yet, choose "New" to let the system generate one.
    • If historical emergency sweep addresses exist, select one for replacement.

    Select modify emergency sweep address

  3. Connect the wallet and sign to create the proposal.

    Sign to create emergency sweep address proposal

  4. Sign out, switch to another admin wallet, go to "Multi-Signature Management -> Edit Parameter Proposal", find the pending proposal, and click "Approve".

    View pending emergency sweep address proposal

  5. Verify details in the approval dialog, sign with the wallet, and confirm on-chain (a small gas fee is required).

    Approve and submit emergency sweep address proposal on-chain

  6. Wait about 1 minute. When status becomes "Approved", Emergency Sweep Address setup is complete.

Phase 2: Set the Emergency Fund Withdrawal Addressโ€‹

Goal

Use a multisig proposal to define the safe outbound address that receives funds after emergency sweep.

The setup flow is identical to Emergency Sweep Address setup. In the "Category" dropdown, choose "Modify Emergency Fund Withdrawal Address".

  1. Log in with an admin wallet, choose "Modify Emergency Fund Withdrawal Address" in "Edit Parameter Proposal", select "New" or a historical address, click "Submit", and sign.

    Create emergency fund withdrawal address proposal

  2. Switch to another admin wallet and approve the proposal.

    Approve emergency fund withdrawal address proposal

  3. Confirm on-chain in the wallet (a small gas fee is required), then wait for status to become "Approved".

    Confirm emergency fund withdrawal address proposal on-chain

Standard Merchant Note

At this phase, Standard merchants only need to set a hot wallet as the Emergency Fund Withdrawal Address. Funds swept to the Emergency Sweep Address will then move to this hot wallet automatically, with no follow-up payout operation.

Phase 3: Sweep High-Risk Funds and Withdraw to an External Walletโ€‹

Prerequisite

Make sure proposals in Phase 1 and Phase 2 are both "Approved" before executing follow-up sweep and withdraw actions.

After both addresses are configured, you can sweep and withdraw funds from blacklisted sub-contracts.

1. Sweep Funds from High-Risk Sub-Contractsโ€‹

  1. Go to "Funds -> Sweep".

    Open funds sweep page

  2. Switch to the "Blacklist" tab, select the sub-contracts to sweep, and click "Batch Sweep".

  3. Confirm the transaction in the wallet and wait for sweep to complete.

    Confirm batch sweep transaction

2. One-Click Fund Withdrawal from Emergency Sweep Address to Emergency Fund Withdrawal Addressโ€‹

  1. Go to "Asset Details" and click "Emergency Withdraw" in the top-right corner.

    Enter emergency fund withdrawal from asset details

  2. On the Emergency Withdraw page, check "Total Balance of Emergency Sweep Address". After funds are confirmed in place, click "One-Click Fund Withdrawal".

    Execute one-click fund withdrawal on emergency fund withdrawal page

  3. If the page shows "Finance Hot Contract max limit is not set for some currencies", configure finance hot contract limits via multisig first. See: Modify Merchant Configuration with Multisig.

    Prompt to set Finance Hot Contract max limit

  4. After configuration, click "One-Click Fund Withdrawal" again and confirm on-chain in the wallet. Funds will move from the Emergency Sweep Address to the Emergency Fund Withdrawal Address.

    Run one-click fund withdrawal again and confirm on-chain

Edition Difference

For Standard merchants, funds are transferred directly to the configured emergency fund withdrawal hot wallet, and the process ends here. The next step, "3. Payout from Emergency Fund Withdrawal Address", only applies to Pro merchants.

3. Payout from Emergency Fund Withdrawal Address (Pro Merchants)โ€‹

  1. Go to "Asset Details -> Emergency Withdraw -> Payout from Emergency Fund Withdrawal Address" and click "Payout".

    Open payout from emergency fund withdrawal address

  2. In the payout dialog, choose the currency (e.g., USDT), fill in destination address and amount, optionally click "Add Row" for batch payouts, then click "Submit".

    Fill payout details and submit proposal

  3. Sign the payout proposal with the finance wallet.

  4. Sign out, switch to another finance wallet, approve the payout proposal via multisig, and confirm on-chain in the wallet.

    Multisig approve payout proposal and submit on-chain

  5. Wait for confirmation. Funds in the Emergency Fund Withdrawal Address will be transferred to the specified external wallet.