A delta-neutral synthetic dollar on Solana. Spot collateral is offset by an equal-notional perpetual short, so the pair holds a dollar rather than a direction. What that pair earns is perpetual carry — a market rate that has a sign, not a return.
%%{init: {'theme': 'base', 'themeVariables': {
'primaryColor': '#232B45',
'primaryTextColor': '#EFE7D8',
'primaryBorderColor': '#3FBFA0',
'lineColor': '#8E96A3',
'secondaryColor': '#8A6A3B',
'tertiaryColor': '#0D0F14',
'fontFamily': 'monospace'
}}}%%
flowchart LR
D["Deposit<br/>SOL or LST"] --> G{"Gate<br/>net carry and<br/>hedge capacity"}
G -->|"below floor"| X["Issuance declined"]
G -->|"clear"| L["Spot leg<br/>long"]
G -->|"clear"| S["Perp short<br/>equal notional"]
L --> P["Net delta near zero<br/>the pair holds a dollar"]
S --> P
P --> C["Carry accrues<br/>with a sign"]
P --> K["Keeper watches the band"]
K -->|"past threshold"| RB["Rebalance"]
RB --> PR["commit_rebalance_proof<br/>program recomputes, does not trust the keeper"]
The hedge is opened before collateral is accepted, not after. A synthetic dollar minted first and hedged later is unhedged for exactly as long as that gap lasts.
The interface is built around one image: a single spotlight, a taut wire between two anchor posts, and a figure crossing it with a balance pole.
.
( ) <- single fixture, no other light
|
============+============ <- the wire: delta-neutral
A
o-------+-------o <- balance pole
^ ^
opal green magenta
spot long perp short
balanced -> both tips read at the same brightness
drifting -> one tip brightens, the pole leans, the wire oscillates
stressed -> the safety net surfaces out of the dark
Every visual state maps to a protocol state. The pole leaning is delta drift. The pole returning level is the keeper rebalancing. The net appearing is the insurance buffer taking a bounded share of negative carry. Nothing on the page is decoration for its own sake.
Spot-plus-perp is a known structure and several protocols run it. Three things are choices about what gets published.
| Carry carries its sign | It is a market rate, and a market rate can sit negative for months. Every window on record is shown — 24h, 7d, 30d — each with its coverage, because picking a window is how you tell whichever story you prefer. When a window holds too few samples to be a continuous record, that is stated rather than rounded away. |
| Issuance closes itself | Net carry and available hedge capacity are read before collateral is accepted. Below the floor, or without capacity, the protocol declines. The gate is in the program, not in an operations manual. |
| Venue economics stay separate | An order-book venue pays funding to a short. A pool-based venue charges that same short a borrow fee. Opposite signs, reported as separate rows, never summed into one flattering number. |
| Repository | Language | Contents |
|---|---|---|
| poyz | Rust | Anchor program, IDL, venue mapping contract, protocol specifications |
| poyz-sdk | TypeScript | SDK, CLI, risk buffer model, proof verifier |
git clone https://github.com/poyzfi/poyz-sdk
cd poyz-sdk && npm install && npm run build
node packages/cli/dist/cli.js statusThe program exposes 30 instructions covering issuance, redemption, keeper bonding and slashing, venue state reporting, funding settlement, the insurance buffer, and staking.
velocity 1 primary
jupiter-perps 2 overflow and redundancy
adrena 3 reserved
flash-trade 4 reserved
simulated 255 rejected in live mode
Identifiers start at 1 on purpose. Zero is reserved for unset, so a field that was never written cannot be silently attributed to the primary venue.
A rebalance commitment carries the recomputed delta, the venues touched, and a hash over the execution set. The encoder and the verifier are both public, so a proof can be checked independently of the keeper that produced it — and the program itself recomputes rather than accepting the keeper's number.
Stated here rather than in a footnote, because a reader deserves them before the pitch.
| Risk | Why it is real |
|---|---|
| Carry turns negative and stays there | The short leg is paid only while the market is net long. When it is not, the position bleeds. This has happened, and the published record shows it. |
| Hedge venues fail | Three Solana perpetual venues have died or been drained inside eighteen months. A hedge is only as good as the venue holding it. |
| The short is liquidated in a gap | A fast move against the short leg with insufficient margin ends the hedge, and the position stops being delta-neutral at the worst possible moment. |
| Capacity binds and is never published | A hedge is only as large as the book that can absorb it. Size that cannot be hedged is size that cannot be issued. |
An insurance buffer absorbs a bounded share of negative carry before it reaches holders. Bounded is the operative word. It is a buffer, not a floor.
| Audit | Not yet audited |
| Mainnet | Program not deployed |
| Issuance | Disabled in the deployed frontend until both of the above change |
| Numbers | Read from the live API at request time. Where a value has not been measured, nothing is rendered in its place |