Hyperliquid perps · HyperEVM testnet

Keep the position. Get paid if the wick comes.

A fixed USDC payout if the oracle price touches a level just above your liquidation price before expiry. Your position stays open; the payout comes from a USDC pool on HyperEVM. It does not stop a liquidation and does not cover your full loss.

Testnet only · Mock funds, no real payout · Not insurance · Not an offer · Not available to US, UK or Ontario persons or sanctioned jurisdictions

The wick touched the level. The pool paid; the position stayed open.

Drag the price head down to the level, or focus it and press the arrow keys. Keeper check every ~3 s; every 1 s near the level.

Your setup

Side
Duration
Volatility · a preset, not live

Perp BTC BTC only in this estimate (max leverage 40×)

Estimate SIM

Cover price
$2.44 per $100 payout
Liquidation
8.86 % below entry
Level
7.95 % below entry
Touch chance (model, before tail adjustment)
< 0.01 %
Priced chance (tail floor from Hyperliquid history)
2.0 %Why higher than the model

LIVE · testnet oracle · reading…

Liquidation modelled for an isolated position opened at this price (first margin tier); yours may differ.

Payout cap: your position's margin

Illustrative estimate, not a quote. Volatility is a preset, not live.

BTC long 10×, 1d, volatility normal 40 %: liquidation 8.86 % below entry, level 7.95 % below entry, cover price $2.44 per $100 payout. Illustrative estimate, not a quote. Volatility is a preset, not live.

01 · The wick

A wick touches the liquidation price, then reverses.

The two defences today are lower leverage and a stop-loss.

A stop closes the position, often at the bottom of a wick, and slips in a gap. Cover keeps the position open and pays cash.

Neither defence keeps the trader in the trade.

  • >$19B liquidated across crypto on 10 Oct 2025 Source: Coinglass 2025 annual report
  • ≈6,300 Hyperliquid wallets in loss, >1,000 fully liquidated, 10 Oct 2025 Source: CoinDesk, 2025-10-11
  • ≈$1.76B liquidated on Hyperliquid in Sept 2026 Source: compass.trade, on-chain fills

Lower leverage

The position survives, but it is smaller.

Stop-loss

Price came back. The position did not.

Cover

The level is touched, the payout lands and the position stays open.

Scripted path, not market data.

02 · How it works

Six parts. One trigger rule.

Select a part to watch it work. The stage runs on your setup from the instrument above.

01 Quote

The pricing engine estimates the chance that the oracle touches your level within the duration and signs a quote that is valid for about 30 seconds.

Quote valid for about 30 seconds. Signed with EIP-712 by the engine; the contract recovers the signer.

SIM · your setup as a quote, not a signed quote

buyer
your wallet
perp
BTC
side
long
level
7.95 % below spot
payout
$100
price
$2.44
expiry
1d after purchase
deadline
about 30 s after issue
nonce
one-time
  • The contract rejects a quote after its deadline, about 30 seconds after it was issued.
  • Each quote carries a one-time nonce; the contract marks it used.

02 Buy cover

You send the signed quote to the pool contract, which checks the signature, your open position and its limits, takes the cover price and reserves the full payout.

Purchase checks, in contract order, for your setup testnet settings

  1. Signature, buyer, deadline, unused nonce on chain
  2. Perp on the allowlist (BTC) passes
  3. Duration at most 7 days passes
  4. Payout at least 1 USDC ($100 here) passes
  5. Cover price at least 0.20 % of the payout passes
  6. Oracle within 0.30 % of the quoted spot on chain
  7. Level not already breached passes
  8. Level at least 0.56 % from spot (0.25 % on chain, plus room for 0.30 % oracle drift) passes
  9. Position exists, same side, payout at most its margin on chain
  10. Locked payouts at most 80 % of capacity, 50 % per perp on chain
  11. Sales at most 25 % of assets per hour; one buyer at most 25 % of that on chain

Cover price taken; the full payout is reserved.

The engine runs the same level and capacity floors before it signs, so a refused setup never gets a quote.

03 Oracle

The contract reads the Hyperliquid perp oracle price on-chain through a HyperEVM precompile, so no outside price feed is involved.

Oracle price, read on-chain. Validator median of 8 venues, read through precompile 0x…0807.

LIVE · BTC · HyperEVM testnet oracle · reading… …

  • Hyperliquid liquidates on the mark price; cover triggers on the oracle price.
  • So the default level sits 1 % above the liquidation price, toward spot.

04 Keeper

A keeper watches every active cover and calls trigger when the oracle price reaches the level; anyone else may call it too.

Keeper sweep. Every ~3 s, every 1 s near a level. trigger() is permissionless.

  • Anyone may call trigger(); it pays only if a call before expiry sees the oracle at or past the level.
  • A wick shorter than the poll can be missed; the pricing effect is about 0.007 % of the level at σ 40 %.

05 Pool

Underwriters deposit USDC and earn the cover prices; each payout is reserved at sale, so the pool cannot sell more cover than it can pay.

Payout locked at sale. The full payout is reserved in the pool when the cover is sold.

SIM · your setup

$100 payout reserved at sale

$2.44 cover price, counted when the cover settles

  • Locked payouts stay at or below 80 % of capacity and 50 % per perp (testnet settings).
  • A cover price counts for underwriters only when its cover settles.

06 Payout

The fixed USDC payout goes to your wallet in the trigger transaction; if the level is never touched before expiry, nothing is paid and the cover price stays with the pool.

Payout in the trigger transaction. No touch before expiry: no payout; the cover price stays with the pool.

  • The payout is capped by your position's margin.
  • A liquidation without an oracle touch does not pay.

A long cover pays when the oracle price is at or below the level; a short cover when it is at or above.

A liquidation without an oracle touch does not pay.

Only on Hyperliquid

  1. At purchase the contract reads the buyer's real perp position through precompile 0x…0800.
  2. Cover can only be bought against a real position in the same direction, and the payout is capped by that position's margin.
  3. The oracle is read on-chain through precompile 0x…0807, so settlement needs no outside oracle.

03 · The price

Priced from Hyperliquid's own tail.

σ = max(EWMA, 30-day realized) from Hyperliquid mainnet hourly candles → GBM touch probability → tail floor fitted on Hyperliquid history → × 1.2. The math runs off-chain; solvency is enforced on-chain.

BTC long, $100 payout, volatility 32-50 %, illustrative, not a quote
Level below spot1 day7 days
5 % $3.73-9.61 $33.07-56.48
8 % $1.14-3.29 $15.51-32.28
12 % $0.49-1.17 $9.64-16.12
20 % $0.43 $6.12-8.60

Long durations close to liquidation are expensive by design. The instrument above is the estimator. This table adds the wider grid.

Evidence

  • 206 vs 0.45 In the far tail the plain model expected 0.45 touches in 258,079 windows; there were 206.
  • 15 of 256 Out of sample, 15 of 256 buckets priced below realized frequency.
  • 2.46 % BTC's daily low reached 6 % below the open on 2.46 % of days (Oct 2024-Sep 2026).

Source: Numera calibration report (Hyperliquid mainnet candles: BTC, ETH, SOL, HYPE).

04 · Underwriters

The other side of every cover.

  • Underwriters deposit USDC into the pool, an ERC-4626 vault, and earn cover prices minus payouts through the share price.
  • A cover price counts only when its cover settles.
  • Each payout is reserved in full when the cover is sold.
  • Caps (testnet settings): locked payouts stay at or below 80 % of capacity and 50 % per perp. New sales pause if payouts in one window exceed 15 % of assets.
  • Underwriters bear the payouts, including any from a wrong or compromised quote.
  • Testnet only, mock USDC, no independent audit. We publish no yield or return figures; testnet results are not returns.

Reservation toy

SIM · toy pool, not the live pool

0 payouts locked · 0 % of capacity

Nothing is locked. Sell a cover first.

Live ledger

LIVE · MOCK v2 pool · reading… TESTNET DEMO POOL
Total assets
…
USDC (test tokens)
Free
…
USDC (test tokens)
Locked
…
USDC (test tokens)
Covers
…
team test runs
Paused
…
pause flag

MOCK v2 pool 0x493c14a92da0905b06a91a1e87a75d4bff75e4a6

The demo pool runs on team-set prices; every cover in it was bought by the team in test runs. These are not user purchases.

Read in your browser from HyperEVM testnet (chain 998). A dash means the read failed; no number is ever filled in.

Exits are queued (testnet settings)

  1. Request requestRedeem
  2. Wait 10 min withdrawDelay
  3. Withdraw within 1 h claimWindow

05 · Proof

One staged run, on the record.

BTC long · level 1 % below spot · payout 10 mUSDC · price 0.434298 mUSDC · 1h

  1. 484 buyCover
  2. 485
  3. 486
  4. 487
  5. 488 setPrice
  6. 489
  7. 490
  8. 491 trigger(3)

3 s by block timestamps · one staged run on the MOCK pool, 2026-10-02

  1. block 65,840,484 · buyCover · status 1

    cover 3 bought from an engine quote · not reached yet

  2. block 65,840,488 · setPrice · status 1

    staged price drop, 50 bps past the level · not reached yet

  3. block 65,840,491 · trigger(3) · status 1

    keeper call, 10 mUSDC paid · not reached yet

Not yet

  • No mainnet, no real USDC, no real funds.
  • No independent audit; an internal security review only.
  • A keeper trigger on a real oracle touch with the HyperCore-source pool is not yet proven; it is proven on the MOCK pool only.
  • No public testnet app yet.

06 · Early access

Join the waitlist

Leave your email and we will write when the next testnet round opens. A Telegram or X handle is optional. No wallet, no keys.

Waitlist · HyperEVM testnet

Used only to tell you when the next testnet round opens.

07 · Questions

Questions

Does cover trigger on the mark price or the oracle price?

On the oracle price. Hyperliquid liquidates on the mark price, so the default level sits 1 % above the liquidation price, toward spot. A liquidation without an oracle touch does not pay.

What if a wick is shorter than the keeper's poll?

The keeper checks every ~3 s, and every 1 s near a level. A wick shorter than that can be missed; the pricing effect is about 0.007 % of the level at σ 40 %.

Who can call trigger()?

Anyone. A cover pays only if a trigger() call before expiry sees the oracle at or past the level on-chain.

Is this live?

Testnet only, mock USDC, not audited, no public app yet.

Who controls the pool?

Changes to the signer, limits, allowlist and guardian are timelocked: 10 min on testnet; the mainnet target is at least 48 h. The guardian can pause sales at once but can never unpause.

Who can join?

Anyone aged 18 or older who is not a resident of, located in, or a citizen of the US, the UK, Ontario (Canada) or a sanctioned jurisdiction. The form asks you to confirm this, and requests that arrive from the US, the UK or a comprehensively sanctioned country are refused.

What do you store?

Your email address, your Telegram username and X handle if you gave them, the notice version you agreed to, your jurisdiction confirmation and the time you joined. A salted IP hash is kept for 24 hours against spam. The privacy notice has the details. Read the privacy notice