aequa
US sessionMint USDq

How it works

Hedge desk

The hedge desk is the service that keeps the reserve at its shares: it resizes the shorts, moves margin between the chains and keeps the buffer in its band. On Solana it can call two instructions, and neither can send anything anywhere but the reserve's own accounts.

Delta tolerance
0.5% of supply
Leverage band
2x–4x
Buffer band
5%–15%
Swap bound
50 bps from the Pyth price
Hedge report
every 60 s

The loops

The desk runs a few loops, each with one trigger and one response:

LoopWhenResponse
Deltaa pair's spot and short differ by more than 0.5% of supplythe desk resizes the short
Marginleverage above 4xthe desk sends USDC from the buffer to Hyperliquid
Marginleverage below 2xthe council withdraws the extra margin to the landing account
Bufferbelow 5%the desk sells spot, closes the matching short and returns the freed margin
Bufferabove 15%the desk buys spot, opens the matching short and sends margin
Corporate actiona multiplier change is scheduledthat collateral's xStock paths close for the window

Deposits net against each other first: xStock mints bring spot, USDC mints bring cash, and the desk trades only what is left over.

What the desk can do

On Solana, the desk holds the keeper role. It can call two instructions:

  • swap: exchanges buffer USDC and a collateral vault through Jupiter. The amount out must clear the Pyth price less 50 bps, or the swap fails.
  • bridge_out: sends buffer USDC over Circle's CCTP V2 to the forwarder fixed in the program's config.

It cannot mint USDq, send collateral or USDC anywhere else, or change a destination. Every movement the desk makes lands in a vault of the program or in the hedge account.

The hedge account

The shorts sit in one account on HyperCore, Hyperliquid's trading layer, trading SP500 and XYZ100 on trade.xyz.

KeyHeld byCan
Master keythe Hedge Council, in an MPC wallet (for example 3 of 5)approve the trading key; withdraw, only to the landing account on Solana
Agent keythe deskplace and cancel orders, nothing else

The agent key can't sign a transfer or a withdrawal on Hyperliquid, so the desk trades the account without being able to move its USDC. The council holds the master key in MPC because Hyperliquid's own multi-sig would need every order signed by the threshold.

The USDC route

Margin moves between the chains on one fixed route in each direction:

Solana to HyperCore

  1. BufferSolanabridge_out burns USDC through CCTP V2
  2. ForwarderHyperEVMdeposits its whole balance; anyone may call it
  3. CoreDepositWalletHyperEVMcredits the hedge account
  4. Hedge accountHyperCoremargin for the shorts

HyperCore to Solana

  1. Hedge accountHyperCorethe council withdraws to Solana's CCTP domain
  2. LandingSolanathe only place withdrawals can go
  3. BufferSolanaland_usdc moves it here; anyone may call it

The forwarder on HyperEVM is an immutable contract with one public function: deposit its whole USDC balance into Circle's CoreDepositWallet for the hedge account. On the way back, the only place a withdrawal can land is the landing account, a vault of the program, and land_usdc moves it into the buffer.

In flight

USDC on the route is counted in NAV the whole way. Four running totals track it, two kept by the program and two by the report:

in flight = (bridged_out_total − credited_total)
          + (withdrawn_total − landed_total)
bridged_out_total
sent by bridge_out, counted on Solana
credited_total
credited to the hedge account, from the report
withdrawn_total
withdrawn from the hedge account, from the report
landed_total
moved into the buffer by land_usdc, counted on Solana

On the Reserve tab, in-flight USDC shows as plus cells in the composition, and the moving segment of the route map lights.

The report

Every 60 seconds a reporting service signs report_hedge with the hedge account's value, each perp's short notional and whether it is trading, and the two totals above. It is the only way Hyperliquid's figures reach the program.