How it works
Hedge desk
The hedge desk is the service that keeps the reserve at its shares: it resizes the shorts, moves margin between the chains and keeps the buffer in its band. On Solana it can call two instructions, and neither can send anything anywhere but the reserve's own accounts.
- Delta tolerance
- 0.5% of supply
- Leverage band
- 2x–4x
- Buffer band
- 5%–15%
- Swap bound
- 50 bps from the Pyth price
- Hedge report
- every 60 s
The loops
The desk runs a few loops, each with one trigger and one response:
| Loop | When | Response |
|---|---|---|
| Delta | a pair's spot and short differ by more than 0.5% of supply | the desk resizes the short |
| Margin | leverage above 4x | the desk sends USDC from the buffer to Hyperliquid |
| Margin | leverage below 2x | the council withdraws the extra margin to the landing account |
| Buffer | below 5% | the desk sells spot, closes the matching short and returns the freed margin |
| Buffer | above 15% | the desk buys spot, opens the matching short and sends margin |
| Corporate action | a multiplier change is scheduled | that collateral's xStock paths close for the window |
Deposits net against each other first: xStock mints bring spot, USDC mints bring cash, and the desk trades only what is left over.
What the desk can do
On Solana, the desk holds the keeper role. It can call two instructions:
swap: exchanges buffer USDC and a collateral vault through Jupiter. The amount out must clear the Pyth price less 50 bps, or the swap fails.bridge_out: sends buffer USDC over Circle's CCTP V2 to the forwarder fixed in the program's config.
It cannot mint USDq, send collateral or USDC anywhere else, or change a destination. Every movement the desk makes lands in a vault of the program or in the hedge account.
The hedge account
The shorts sit in one account on HyperCore, Hyperliquid's trading layer, trading SP500 and XYZ100 on trade.xyz.
| Key | Held by | Can |
|---|---|---|
| Master key | the Hedge Council, in an MPC wallet (for example 3 of 5) | approve the trading key; withdraw, only to the landing account on Solana |
| Agent key | the desk | place and cancel orders, nothing else |
The agent key can't sign a transfer or a withdrawal on Hyperliquid, so the desk trades the account without being able to move its USDC. The council holds the master key in MPC because Hyperliquid's own multi-sig would need every order signed by the threshold.
The USDC route
Margin moves between the chains on one fixed route in each direction:
Solana to HyperCore
- BufferSolanabridge_out burns USDC through CCTP V2
- ForwarderHyperEVMdeposits its whole balance; anyone may call it
- CoreDepositWalletHyperEVMcredits the hedge account
- Hedge accountHyperCoremargin for the shorts
HyperCore to Solana
- Hedge accountHyperCorethe council withdraws to Solana's CCTP domain
- LandingSolanathe only place withdrawals can go
- BufferSolanaland_usdc moves it here; anyone may call it
The forwarder on HyperEVM is an immutable contract with one public function: deposit its whole USDC balance into Circle's CoreDepositWallet for the hedge account. On the way back, the only place a withdrawal can land is the landing account, a vault of the program, and land_usdc moves it into the buffer.
In flight
USDC on the route is counted in NAV the whole way. Four running totals track it, two kept by the program and two by the report:
in flight = (bridged_out_total − credited_total)
+ (withdrawn_total − landed_total)- bridged_out_total
- sent by bridge_out, counted on Solana
- credited_total
- credited to the hedge account, from the report
- withdrawn_total
- withdrawn from the hedge account, from the report
- landed_total
- moved into the buffer by land_usdc, counted on Solana
On the Reserve tab, in-flight USDC shows as plus cells in the composition, and the moving segment of the route map lights.
The report
Every 60 seconds a reporting service signs report_hedge with the hedge account's value, each perp's short notional and whether it is trading, and the two totals above. It is the only way Hyperliquid's figures reach the program.