aequa
US sessionMint USDq

Reference

Program

aequa is one Anchor program on Solana. Its accounts hold every vault, its instructions are every action in the app, and a short list of rules holds whatever anyone calls.

Program
one, on Solana
USDq, sUSDq
SPL Token, 6 decimals
USDq mint authority
a program address
USDq freeze authority
none

Roles

RoleHeld byCan
Admina Squads multisig at launch, governance after the handoffset_params within ranges, add_collateral, set_roles, unpause
Guardiana fast-response keypause any path, including cover_deficit
Keeperthe hedge deskswap, bridge_out
Reporterthe reporting servicereport_hedge
Upgrade authoritya Squads multisig at launch, governance after the handoffprogram upgrades
Hedge Councilan MPC wallet, off chainthe hedge account's master key: approving the trading key, withdrawals to the landing account

Everything else, from minting to the cranks, is open to anyone. Handoff describes how governance takes over the admin and upgrade roles.

Instructions

InstructionWho calls itWhat it does
mint_with_usdc, redeem_for_usdcanyonethe USDC paths
mint_with_collateral, redeem_for_collateralanyone, with a signed Pyth pricethe xStock paths
stake_usdq, start_usdq_cooldown, claim_usdqanyonesUSDq
stake_aequa, start_aequa_unstake, withdraw_aequaanyonestAEQUA
distribute, land_usdc, buyback, cover_deficit, sell_slashedanyonethe cranks
swap, bridge_outkeeperthe desk's two moves
report_hedgereporterthe hedge account's figures
pauseguardian, adminstops a path
unpause, set_params, add_collateral, set_rolesadminconfiguration, within ranges

Accounts

Each account sits at an address derived from the program's address and its seeds.

AccountSeedsHolds
Config["config"]roles, fees and tiers, the split, caps and buckets, the cushion, the yield cap, cooldowns, the bridge route, pause flags
Collateral["collateral", mint]the mint, its four Pyth Pro feeds, session bands, hourly buckets, spot cap and perp market
Reserve["reserve"]the latest hedge report, the bridge totals, the last distribution, the deficit streak
UsdqVault["susdq_vault"]total assets, the vesting in progress, the sUSDq mint
UsdqCooldown["susdq_cooldown", owner]your locked USDq and its unlock time
AequaPool["aequa_pool"]AEQUA and shares in the pool, the reward stream, the buyback counters
AequaStake["aequa_stake", owner]your shares and cooldown start

Token accounts

Address seedsHolds
["collateral_vault", mint]each xStock
["buffer"], ["landing"]USDC
["susdq_assets"], ["susdq_silo"]USDq behind sUSDq, and USDq cooling
["reserve_fund"], ["protocol"]the Reserve Fund and the protocol vault, in USDq
["aequa_pool_vault"], ["slash_sale"]staked AEQUA, and AEQUA set aside for a backstop sale

What always holds

  1. USDq is minted in three places only: a mint path, against a deposit valued in the same instruction; fee routing, backed by that deposit; and distribute, bounded by both the surplus and the yield cap of 5 bps of supply a day.
  2. Collateral leaves a vault only to a redeemer through redeem_for_collateral, or to the buffer through swap.
  3. Buffer USDC leaves only through redeem_for_usdc, swap, and bridge_out to the fixed route.
  4. The protocol vault's only outflow is buyback. The Reserve Fund's only outflow is a burn that makes up a shortfall.
  5. Collateral value always comes from the live vault balance, the mint's multiplier and a verified Pyth price.
  6. Every parameter stays inside its hard-coded range.

Collateral handling

RuleDetail
AllowlistBy mint address; tokens with the same symbol exist on other mints.
AdmissionTransfer fee zero, transfer-hook program unset, confidential-transfer auto-approve off, mint not paused. Checked on every use; a change closes that collateral's paths.
BalancesRead from the vault on every use, never from a counter.
VaultsOne vault per collateral mint; every movement uses transfer_checked.
MultiplierRead from the mint in the same instruction, with its scheduled change applied at its time.
Corporate actionsFrom 24 h before a multiplier change to 1 h after, the collateral's xStock paths close.
Issuer pauseA paused mint closes its xStock paths; the USDC paths keep running.
ArithmeticRaw u64 amounts with u128 in between; every amount paid out rounds down.

Why plain SPL tokens

USDq and sUSDq use the original SPL Token program, so lending markets, AMMs and wallets read them with no extension checks. sUSDq is a plain share token rather than an interest-bearing mint: an integrator reads one exchange rate from the program's state.