Reference
Program
aequa is one Anchor program on Solana. Its accounts hold every vault, its instructions are every action in the app, and a short list of rules holds whatever anyone calls.
- Program
- one, on Solana
- USDq, sUSDq
- SPL Token, 6 decimals
- USDq mint authority
- a program address
- USDq freeze authority
- none
Roles
| Role | Held by | Can |
|---|---|---|
| Admin | a Squads multisig at launch, governance after the handoff | set_params within ranges, add_collateral, set_roles, unpause |
| Guardian | a fast-response key | pause any path, including cover_deficit |
| Keeper | the hedge desk | swap, bridge_out |
| Reporter | the reporting service | report_hedge |
| Upgrade authority | a Squads multisig at launch, governance after the handoff | program upgrades |
| Hedge Council | an MPC wallet, off chain | the hedge account's master key: approving the trading key, withdrawals to the landing account |
Everything else, from minting to the cranks, is open to anyone. Handoff describes how governance takes over the admin and upgrade roles.
Instructions
| Instruction | Who calls it | What it does |
|---|---|---|
mint_with_usdc, redeem_for_usdc | anyone | the USDC paths |
mint_with_collateral, redeem_for_collateral | anyone, with a signed Pyth price | the xStock paths |
stake_usdq, start_usdq_cooldown, claim_usdq | anyone | sUSDq |
stake_aequa, start_aequa_unstake, withdraw_aequa | anyone | stAEQUA |
distribute, land_usdc, buyback, cover_deficit, sell_slashed | anyone | the cranks |
swap, bridge_out | keeper | the desk's two moves |
report_hedge | reporter | the hedge account's figures |
pause | guardian, admin | stops a path |
unpause, set_params, add_collateral, set_roles | admin | configuration, within ranges |
Accounts
Each account sits at an address derived from the program's address and its seeds.
| Account | Seeds | Holds |
|---|---|---|
Config | ["config"] | roles, fees and tiers, the split, caps and buckets, the cushion, the yield cap, cooldowns, the bridge route, pause flags |
Collateral | ["collateral", mint] | the mint, its four Pyth Pro feeds, session bands, hourly buckets, spot cap and perp market |
Reserve | ["reserve"] | the latest hedge report, the bridge totals, the last distribution, the deficit streak |
UsdqVault | ["susdq_vault"] | total assets, the vesting in progress, the sUSDq mint |
UsdqCooldown | ["susdq_cooldown", owner] | your locked USDq and its unlock time |
AequaPool | ["aequa_pool"] | AEQUA and shares in the pool, the reward stream, the buyback counters |
AequaStake | ["aequa_stake", owner] | your shares and cooldown start |
Token accounts
| Address seeds | Holds |
|---|---|
["collateral_vault", mint] | each xStock |
["buffer"], ["landing"] | USDC |
["susdq_assets"], ["susdq_silo"] | USDq behind sUSDq, and USDq cooling |
["reserve_fund"], ["protocol"] | the Reserve Fund and the protocol vault, in USDq |
["aequa_pool_vault"], ["slash_sale"] | staked AEQUA, and AEQUA set aside for a backstop sale |
What always holds
- USDq is minted in three places only: a mint path, against a deposit valued in the same instruction; fee routing, backed by that deposit; and
distribute, bounded by both the surplus and the yield cap of 5 bps of supply a day. - Collateral leaves a vault only to a redeemer through
redeem_for_collateral, or to the buffer throughswap. - Buffer USDC leaves only through
redeem_for_usdc,swap, andbridge_outto the fixed route. - The protocol vault's only outflow is
buyback. The Reserve Fund's only outflow is a burn that makes up a shortfall. - Collateral value always comes from the live vault balance, the mint's multiplier and a verified Pyth price.
- Every parameter stays inside its hard-coded range.
Collateral handling
| Rule | Detail |
|---|---|
| Allowlist | By mint address; tokens with the same symbol exist on other mints. |
| Admission | Transfer fee zero, transfer-hook program unset, confidential-transfer auto-approve off, mint not paused. Checked on every use; a change closes that collateral's paths. |
| Balances | Read from the vault on every use, never from a counter. |
| Vaults | One vault per collateral mint; every movement uses transfer_checked. |
| Multiplier | Read from the mint in the same instruction, with its scheduled change applied at its time. |
| Corporate actions | From 24 h before a multiplier change to 1 h after, the collateral's xStock paths close. |
| Issuer pause | A paused mint closes its xStock paths; the USDC paths keep running. |
| Arithmetic | Raw u64 amounts with u128 in between; every amount paid out rounds down. |
Why plain SPL tokens
USDq and sUSDq use the original SPL Token program, so lending markets, AMMs and wallets read them with no extension checks. sUSDq is a plain share token rather than an interest-bearing mint: an integrator reads one exchange rate from the program's state.