The Hyperliquid mark

The Hyperliquid Experiment

What happens when a coin’s liquidity is paired with Hyperliquid?

Creator rewards from the pump.fun bonding curve accrue to a vault fixed at creation, which nobody can reassign afterwards. A crank claims them on a loop, splits them 50/50 between HYPE and wHYPE itself, and pairs both sides into a single Raydium pool. The pool only ever grows.

Hyperliquid in poolreading
Market capNext blockSettledLast block

Abstract

Hyperliquid is the venue that settled the argument about where a token’s value comes from. It is a purpose-built L1 running a fully on-chain order book, it took no venture money and sold nothing privately, and between 97 and 99 per cent of the fees its perpetual and spot markets produce are handed to an Assistance Fund that buys HYPE on the open market and takes it out of circulation.1 That is not a promise about revenue, it is a standing instruction executed continuously — past a billion dollars deployed and something near seven per cent of the token’s market capitalisation a year. The reusable idea is not the buyback. It is the structure underneath: a fee is the one flow a market produces whether or not anyone believes in it, and pointing that flow somewhere by a rule nobody can renegotiate is what separates policy from a press release. The hypothesis of this paper is that buying is the weaker half of what a fee can do, because a buyback removes supply and leaves the book exactly as thin as it found it, whereas the same money spent on both sides of a pair produces something a buyback cannot: depth that only moves one way. The design is four steps and one address. pump.fun’s create_v2 writes a coin_creator field once and offers no instruction to reassign it, so 0.3% of every lamport of volume accrues to a vault that no later decision can redirect. Each settlement claims that balance, spends 50% buying wHYPE back and 50% buying HYPE, and deposits both sides into a single Raydium constant-product pool. Deposits raise the pool’s invariant k = xy; the swap fees traders pay raise it too; nothing in the protocol withdraws. Since the HYPE a constant-product pool holds at price p is exactly √(kp), the reserve standing behind wHYPE at any price it returns to exceeds what stood there the last time. Where the Assistance Fund makes usage shrink supply, this makes usage accumulate a floor.

The precedent

HYPE’s genesis was on 29 November 2024, and the distribution is the part worth remembering: 310 million tokens, thirty-one per cent of supply, sent to the people who had actually used the exchange, with no manual claim to make. No venture round, no private sale, no allocation to market makers or exchanges. Whatever one thinks of what followed, the launch answered a question most launches decline to ask — who is this for — and answered it before there was a price to argue about.

The monetary design is the interesting half. Hyperliquid runs a fully on-chain order book on its own L1, and it charges for that. Between 97 and 99 per cent of what perps and spot generate goes to the Assistance Fund, which buys HYPE on the open market and removes it from circulation. No committee votes on it, no treasury decides quarterly whether this is a good moment. It runs continuously, funded by turnover rather than by a raise, and it has pushed past a billion dollars deployed at roughly seven per cent of market capitalisation a year. Coupled with HIP-2, the protocol’s own automated liquidity, the design amounts to a claim: a venue’s fees can be pointed at its token by a rule, and the rule is worth more than any promise a foundation could make about the same money.

The part worth stealing is not the buyback. Buying is a use of a fee, and a blunt one — it retires supply and leaves the order book exactly as thin as it found it. It suits an asset with the deepest book in the industry and no need of another one. The part worth stealing is the structure underneath it: a fee is the only revenue a market reliably produces, and pointing it at a monetary outcome by a rule nobody can renegotiate is what separates policy from a press release. Every coin that promises to buy itself back has the second half of that sentence and not the first. The promise is the easy half; a program that leaves no one the option of breaking it is the whole difficulty.

So: same structure, different destination. wHYPE has no exchange to run and no validators to pay, so retiring supply buys it nothing. What it has instead is the problem every small asset has — it is thin, and thinness is precisely what a reserve fixes. Spend the fee on both sides of a pair rather than on one, and the mechanism inverts: usage stops shrinking the numerator and starts growing the denominator.

The curve

wHYPE lives on a pump.fun bonding curve. One instruction, create_v2, mints a fixed supply into the curve account under Token-2022 and discards the mint authority in the same transaction it uses it. The mint carries an empty extension set: no transfer hook, no transfer fee, no permanent delegate, no freeze authority. That is deliberate, and unlike a promise it is verifiable in one RPC call. There is no allocation, no vesting contract and no team wallet with a cliff, because there is nothing left to allocate: the curve holds the entire supply and sells it to whoever arrives, at the price the curve quotes.

A pump.fun curve is a constant-product market against virtual reserves — the account is seeded with notional SOL it does not hold, so the opening price is finite and the curve can be traded from its first lamport without anyone providing liquidity. Buys move along it, sells move back down it, and when the real quote reserve reaches the migration threshold the curve completes and the position graduates to the pump AMM as an ordinary pool. Two properties of that arrangement matter here, and both belong to a program we did not write and cannot amend:

  1. The reward is a protocol constant. Every trade against the curve — and every trade against the AMM pool after graduation — pays a fee of which the creator leg is a flat 0.3% of quote volume, charged to buyer and seller alike. Unlike the protocol fee beside it, it does not scale with market capitalisation or trade size, and graduation does not interrupt it.
  2. coin_creator is written once and cannot be reassigned. pump.fun records the creator on the bonding curve at creation and accrues the creator’s rewards to a program-derived address seeded by it. There is no instruction in that program to change the field. The destination is therefore decided in the transaction that creates the coin and is thereafter beyond the reach of the person who created it.

That field points at a vault keypair rather than at a person. From the first trade the revenue has exactly one destination, and reaching it requires nobody to remember, agree, or still be interested a year from now.

The distinction worth holding onto is the same one §1 draws about the Assistance Fund. This is not a promise to spend rewards a particular way, which is the ordinary form of the claim and is worth precisely nothing. It is a statement about which address the rewards are payable to, enforced by a program that neither we nor anyone else can amend.

Why Hyperliquid

The reserve asset is fixed for the life of the coin, because the pool is never withdrawn from — a reserve you can change is a reserve you can be talked out of, and a pool you can rotate is a pool someone eventually rotates at the worst possible moment. So the choice is made once, in source, and it is HYPE.

The case is not that HYPE appreciates; nobody here is forecasting that. It is that its bid does not depend on anyone continuing to care about wHYPE. HYPE is the fee token of a venue with real revenue, and that revenue is already pointed at buying it — which means the reserve behind this coin is itself accumulating a bid from a mechanism that has nothing to do with us and does not know we exist. A reserve denominated in it is a claim on someone else’s order book rather than on our own narrative, which is the only kind of reserve worth holding.

On Solana that means the bridged representation, and it was checked rather than assumed before it was written into the source: a classic SPL mint rather than Token-2022, so Raydium’s CPMM pools it without restriction; nine decimals; and a null freeze authority, so no account holding it can be frozen — a stronger guarantee than the wrapped BTC and ETH alternatives offer. Depth is roughly $5.9 million in the deepest pool against some $87 million of daily volume across thirty pairs, and the aggregator fills a whole SOL at under a hundredth of a per cent of price impact. A block moves a fraction of that.

Disclosure. HYPE is native to Hyperliquid’s own L1. What this pool holds is a bridged representation on Solana, and its mint authority belongs to the bridge that issues it. Because this protocol never withdraws from its pool, bridge failure is not a position anyone here can exit — it is a permanent exposure, and it is the largest single risk on this page. It is stated here rather than in a footnote because a reader who stops after §3 should still have read it.

The revenue

The only money entering this system is the creator leg of the pump.fun trading fee. If V is cumulative quote volume, the revenue is

dR = 0.0030 · dV(1)

and that is the entire monetary base. No emission, no inflation, no treasury sale, no second round. wHYPE is never created after the curve is seeded; it is only ever bought back with money the market itself paid in.

Note what equation (1) does not depend on. Not price — a fee is charged on turnover, so a coin trading sideways on constant volume funds blocks at exactly the rate one trading upward does. Not holders, who need do nothing at all. Not us. The only input is that people trade, which is the same input the Assistance Fund runs on and the reason both mechanisms keep working through a drawdown that would end any scheme funded by a treasury.

What closes a block

A block here does not close on a clock. Time is not what the system is waiting for — money is — and a schedule that settled on a timer would spend most of its transactions deploying dust and paying fees to do it. A block closes when the vault holds enough for the settlement to be worth its own cost.

Two quantities set that threshold and only one of them is a policy choice. The first is the deployment floor: below roughly 0.020 SOL the two swaps lose more to fees and slippage than they deliver into the pool, so a settlement below it is a settlement that makes the reserve smaller. The second is not a threshold at all but a real cost — creating the Raydium pool for the first time pays that program’s protocol fee and rent on the pool state, both token vaults, the LP mint and the observation account, about 0.250 SOL, and it is paid at deposit time. It is therefore withheld from the swap budget rather than merely required beforehand. The distinction is the difference between working and not: a settlement that clears a gate and then spends its whole balance on the two legs still arrives at pool creation with nothing to pay with.

BlockTargetVolume impliedWhy
00.285 SOL95 SOLOpens the market: deployment floor, gas reserve, and the rent the pool’s six accounts require.
1…n0.035 SOL12 SOLDeposits into a pool that already exists. Rent is a one-time cost and drops out forever.

The volume column is the honest reading of the difficulty. At 0.3% of volume a steady-state block is 12 SOL of trading — not a number anyone has to believe in, just the arithmetic of the reward rate against the threshold. If volume is thin, blocks are far apart. If volume never comes, no block ever closes, and §8 shows precisely what that costs the holder: nothing.

Inside a settlement

A settlement is five steps, executed in order, each a separate transaction signed by the vault. They are separate on purpose: one transaction spanning a reward claim, two aggregator swaps and a pool deposit exceeds what a Solana transaction can carry, and pretending otherwise would produce a protocol that works on paper and reverts on chain.

  1. Read. The unclaimed balance of the creator vault PDA is read across both pump programs — the bonding curve and the AMM — because the revenue moves from one to the other at graduation, and a settlement that only knew about the first would silently stop finding money on the day it succeeded. Below 0.003 SOL nothing is claimed, so a quiet minute costs one RPC call rather than a wasted transaction.
  2. Claim. The vault signs collect_coin_creator_fee, the gas wallet pays for it, and the rewards land in the vault as native SOL. Claiming and deploying are separate decisions, deliberately: gating the claim on the deployment threshold strands money, because rewards claimed once sit in the vault and the next claim is judged alone. Anything worth more than the transaction that collects it is collected. After graduation the pump AMM pays in wrapped SOL, so the wrapped account is closed in the same step and unwrapped back to lamports — otherwise the balance grows in an account nothing downstream ever looks at.
  3. Measure. The deployable amount is read from the vault balance, not from what this claim produced, so a remainder left by an earlier block is picked up rather than forgotten. The gas reserve and — until the pool exists — the pool rent are subtracted first. If what is left is under the floor, the block is recorded as waiting, with the exact shortfall, and nothing is spent.
  4. Two buys. 50% of the deployable balance buys wHYPE and 50% buys HYPE, each a separate aggregator route out of the vault’s own SOL, bounded at 3% slippage. Separate transactions, so a route that can fill one leg but not the other fails cleanly with the other leg already banked in the vault, where the next block will find it.
  5. Deposit. Both balances go into the pool described in §7 — created on the first block, deposited into on every one after.
Trade0.3% of volumeVaultcreator fee accruesClaiminto native SOLBuy back50% of the blockBuy HYPE50% of the blockwHYPE/HYPE pooldeposited, never withdrawn
Figure 1One block. The wHYPE bought back and the HYPE bought against it enter the same pool in the same transaction, and the pool is the venue the next trade pays its fee into — which is the only sense in which this thing is a flywheel. Every arrow is a signature by one address, the vault.

Every step above is signed by one keypair and no other: the wallet wHYPE was launched from, which is what pump.fun recorded as its creator and therefore the only key that can claim anything. It pays its own transaction fees, holds the rewards between blocks, and owns the resulting position. That is what makes the process auditable from outside — there is exactly one address to watch, and every lamport that has ever entered it has left in one of two directions, both of which end in the pool.

The pool

The reserve is not held in a treasury account. It is held as one side of a Raydium CPMM position — a constant-product market of the form xy = k, the same curve Uniswap v2 popularised, where x is the wHYPE reserve and y the HYPE reserve and every trade moves along the hyperbola they define.

Choosing that over a concentrated-liquidity market is the single most consequential design decision on this page, and it is made on the strength of what a constant-product position does not require. It has no price range, so there is no band to pick at deposit time and no position to rebalance when price leaves it. It never goes one-sided, so the reserve cannot be quietly converted into wHYPE by a move nobody was awake for. It accepts a deposit at any price, so a settlement can execute at whatever the market is doing that minute without a keeper judging whether the moment is favourable. And it requires no management, which is the property that matters most for a position intended to be held for the life of the coin by a process nobody maintains. A concentrated position outperforms it on capital efficiency and demands, in exchange, exactly the discretionary attention this protocol is designed not to have.

The pool address is not stored anywhere. It is a program-derived address seeded by the CPMM program, its fee configuration, and the two mints in canonical order, so it can be recomputed from first principles at any time. That is what makes the create-once rule in §6 robust: the keeper does not consult its own records to decide whether the market exists, it derives the address and asks the chain. A ledger that was empty, stale or wrong would still not cause a second pool, and a second pool would split the reserve across two markets and make every depth figure on this page a sum of things a trader cannot actually trade against.

Creating the pool opens six accounts — the pool state, a vault for each mint, the LP mint, the observation account that carries the price oracle, and the program’s own fee account — which is the 0.250 SOL of rent §5 withholds from the first block’s swap budget. Every block after it is an add_liquidity into a market that already exists.

One mechanical detail decides whether that deposit succeeds. A constant-product pool takes both sides at its own ratio, which is never exactly the ratio the market just sold us — the two legs are bought at the aggregator’s price and deposited at the pool’s, seconds apart. So the wHYPE side is capped at what the HYPE side covers at the pool’s current ratio, with headroom for the slippage bound the SDK adds to the derived amount, and the remainder stays in the vault for the next block. Without that cap the deposit demands HYPE the vault does not hold and reverts — every block, forever, with both balances growing behind it.

Trading fees paid to this pool accrue inside it, to the reserves themselves, rather than being paid out to a claimant. The pool therefore grows both when a block settles and when anyone trades against it, which is the fact §8 turns into a proposition.

What accumulates

Write x for the wHYPE reserve of the pool, y for its HYPE reserve, and k = xy for the invariant. A swap leaves k unchanged but for the fee it pays into the pool, which raises it. A deposit raises it. Nothing else touches it, and the protocol has no withdrawal step at all.

Proposition 1 (Monotone depth). kn+1kn for every block n, with strict inequality whenever a block settles or a trade occurs.

Proof. Three operations act on the pool. A swap of size d with fee φ moves the invariant to (x + d)(ydy/(x+d(1−φ))) ≥ k, with equality only at φ = 0. A deposit scales both reserves by 1 + ε, ε > 0, giving (1+εk > k. A withdrawal would scale them down — and there is no instruction anywhere in this protocol that performs one. A quantity acted on only by operations that do not decrease it is non-decreasing.

Depth is not the interesting statement on its own, though. What a holder wants to know is what stands behind the coin at a price they might actually sell into, and for a constant-product pool that has an exact answer. At price p = y/x, the two reserves are determined by k and p alone:

y = √(kp),   x = √(k/p)(2)

Proposition 2 (The floor has no downward step). Fix any price p. The HYPE held by the pool whenever wHYPE trades at p is non-decreasing in time, and strictly increases with every settled block.

Proof. By (2) the HYPE reserve at price p is √(kp), which is strictly increasing in k for p > 0. By Proposition 1, k is non-decreasing and rises at every settlement. Composition of an increasing function with a non-decreasing one is non-decreasing.

The corollary is the part worth reading twice. A drawdown does not undo a block. If wHYPE round-trips to a price it visited before, it finds a pool holding strictly more HYPE than it did the last time it stood there, because the intervening blocks deposited and the intervening trades paid fees, and neither is reversible by price action. The market’s remaining freedom is where to trade — not what is underneath it.

01234567pricereserve per tokenblock 0block n
Figure 2Schematic, not measured. Price is free; the reserve is not. The lower series has no downward step available to it as long as no instruction withdraws liquidity and no instruction mints — which is a statement about the code, and §7 is honest about who holds the key that currently enforces it.

Proposition 3 (Idleness is the worst case). If volume stops, the state does not move. No block settles, no reserve is spent, and nothing is lost but time.

Proof. By (1) revenue is proportional to volume, so zero volume accrues nothing and the vault never reaches target. A settlement below target is not attempted, and no other instruction spends the pool. The failure mode is therefore a pause, not a reversal.

What these propositions do not say. They do not say wHYPE has a redemption value: the HYPE is in a trading pool, not an escrow, and the only way to reach it is to sell into the pool at whatever price that selling produces. They do not say the price cannot fall — a constant-product pool has no floor price, and a large enough sell moves it arbitrarily far. They do not say a holder is made whole; the position that accumulates HYPE is the pool’s, not the holder’s. What they say is narrower and, we think, the only claim of this kind that survives contact with arithmetic: the depth behind wHYPE at any given price is a ratchet, and the ratchet is turned by trading rather than by anyone’s continued goodwill.

Who runs it

pump.fun fixes the reward destination, the aggregator executes the swaps, and Raydium’s CPMM holds the reserve. None of those three are ours. The settlement cycle in §6 is: a keeper runs it on a 60-second loop, and it holds the key to the launch wallet.

That key cannot mint, because create_v2 discards the mint authority at creation. It cannot redirect the rewards, because coin_creator is immutable in pump.fun’s program. It cannot freeze, tax or claw back a transfer, because the mint carries no extension that would allow it. It can do exactly one thing the propositions above assume it will not: the position belongs to that same wallet, so the key that deposits could also withdraw. Propositions 1 and 2 therefore hold on the operator today and on the chain only once a settlement program owning the position does. Read them that way rather than as a guarantee already in force.


Notes

  1. HYPE’s genesis distribution was on 29 November 2024; the Assistance Fund share of fees and the figures for what it has deployed are as reported through 2026. The history in §1 is offered as precedent for the structure of this mechanism, not as any association with Hyperliquid, the Hyper Foundation, or anyone who works on either — none of whom have anything to do with this coin.
  2. pump.fun charges a total trading fee of which the creator leg is one part; every figure here quotes the creator leg only — the 0.3% of volume this protocol actually receives — never the total the trade pays. The rest is not ours and is nowhere counted. The bonding curve program is 6EF8rrecthR5Dkzon8Nwu78hRvfCKubJ14M5uBEwF6P.
  3. The pool is a Raydium constant-product market, CPMMoo8L3F4NbTegBCKVNunggL7H1ZpdTHKxQB5qKP1C, and its address is derived from the two mints rather than stored, so §7’s create-once rule holds even against a record of ours that is empty or wrong. The reserve figure in the masthead is read from that pool’s own vaults, net of the protocol, fund and creator fees Raydium accrues inside them and excludes from the curve — not summed from what we deposited.
  4. The reserve mint is 98sMhvDwXj1RQi5c5Mndm3vPe9cBqPrbLaufMXFNMh5g. Verify it against the bridge’s own documentation before trusting anything above; a wrapper is only as good as the contract minting it, and §3 is the disclosure, not this note.
  5. Every parameter quoted in the prose — the split, the thresholds, the slippage bound, the reward rate — is imported from the same module the keeper reads, so the document cannot drift from the process it describes. If a parameter changes, every number here changes with it.