loading activity…
DESIGN SPECNOTHING DEPLOYED

Leverage

Leveraged Hooks is a credit module for hooked pools — and the first Hookr block Hookr does not intend to write itself. This is the marketplace it arrives through: who is allowed to publish a module that can lose your money, what they have to put behind it, and what $HOOKR does about it.

The module

TIER 3 · CREDIT AND LEVERAGEBOND 250,000+ $HOOKRTHIRD-PARTY

Leveraged Hooks

Credit extended by the market itself, rather than by a lending pot parked beside it. A trader posts equity in the pool's quote asset and the market sells them the token on margin: the tokens they acquire are the collateral, locked in the position, and the market records what they owe back to it. One pool, one liquidity base, spot and credit on the same balance sheet — the LPs who provide depth for trading are the same LPs financing the position. Opening, closing and liquidating all execute through that pool.

THE SHARP EDGE

Leverage multiplies losses at exactly the rate it multiplies gains, and a liquidation is the system working rather than failing. The part a liquidity provider has to read twice: the same liquidity now carries credit risk it did not carry before. When a position cannot be closed for enough to cover what it owes, the shortfall is bad debt against that market — the reserve absorbs the first of it, and past the reserve it is the pool's own balance sheet, which means the LPs. Providing liquidity to a leverage-enabled market is underwriting, not just market making.

Leveraged Hooks turn a market's trading liquidity into lending liquidity as well.

The primitive underneath it: A hook-controlled AMM with an expanded balance sheet. A hook sits where liquidity, price discovery, execution, settlement and LP accounting meet. It can inspect a swap before it runs, apply the market's own policy, reconcile what actually happened afterwards, and keep state between transactions. That is enough to turn an ordinary swap into a balance-sheet transaction with rules attached.

THE SHARP EDGE

It does not create capital, and nothing here is free. The hook's power is narrower and more useful than that: it can refuse a trade the market cannot afford, and it can remember what the trade left behind.

The five blocks that exist today are ours, and they are immutable once a pool graduates. A marketplace changes that in one specific way: code Hookr did not write starts running next to other people’s money. Everything below is the answer to that — not a review process, which is a person’s opinion, but a bond, which is a balance.

One pool, one liquidity base

The question a credit module has to answer first is where the money comes from. The familiar answer is a second pot of lenders beside the market. This design takes the other one, and the option it rejected is written down beside the option it took.

NOT THIS
A separate lending vault

Lenders deposit the quote asset into a second pot, borrowers draw from it, and the pool is only where the trade executes. It is the familiar arrangement and it works.

It splits one market into two liquidity bases that have to be bootstrapped, incentivised and balanced separately, and it leaves the pool's own depth idle while a vault beside it does the financing.

THIS
The market extends the credit

No second pot. The pool sells the token on margin out of the liquidity that is already there, and books what the trader owes back to it. Same market, same liquidity, same LPs, financing and trading against one balance sheet.

Liquidity is provided once and does more than one job, and there is no second market to bootstrap before a token can have credit at all.

THE SHARP EDGE

The trade is concentration. One balance sheet doing both jobs means a credit loss and a trading loss land in the same place, on the same providers, at the same time — which is exactly when a market is least able to absorb either.

What the market owns, and what it is owed

Credit extended by the market is only sound if the market can still say what it is worth. The identity below is the whole of it, and the error it rules out is the one that would let a market believe it is solvent while it is not.

quote asset + market-owned tokens + performing debt receivable − bad debt
NO DOUBLE COUNT

The tokens locked as a borrower's collateral and the debt that borrower owes are two sides of one position, not two assets. Counting both would inflate the market by the size of its own lending book.

NOTHING MINTED

Nothing is minted to make a position. The market hands over exposure it already had and takes back cash plus a claim — the claim is why the sheet still balances, and the claim is also the part that can go bad.

Uniswap v4 — execution

Every open, close and liquidation is a swap against the pool, and every one of them settles in full inside its own transaction. Nothing is left owing at the v4 layer.

Hookr — credit

The position that outlives the transaction is recorded by the module: collateral held, debt in the quote asset, interest accrued, health, and the price at which the position is liquidated.

One position, in arithmetic

An invented token and round numbers, to show how the accounting moves. Nothing here is a measurement, a quote, or a projection.

TRADER POSTS
2 ETH

Their own capital — the equity in the position.

MARKET FINANCES
2 ETH

Extended out of the pool's own liquidity.

EXPOSURE OPENED
~4 ETH of the token

Bought through the pool and locked as collateral.

MARKET BOOKS
2 ETH receivable

Plus interest, owed back to the market.

Closing sells the collateral back through the same pool. The proceeds repay the market's principal first, then interest and fees, and whatever is left is the trader's.

THE SHARP EDGE

If the position is closed for less than it owes, the trader's equity goes first and in full. Only what is missing after that is the market's problem.

WHAT THE MODULE TRACKS
COLLATERAL

The tokens bought on margin, locked in the position.

DEBT

What is owed back to the market, denominated in the quote asset.

INTEREST

Accrues against the debt at a rate that moves with utilisation.

HEALTH

How far the position sits from the point where it is closed for it.

LIQUIDATION PRICE

Derived from the pool's own price and the risk parameters.

Reconciled against what happened, not what was quoted

The purchase executes through the real market, so the trader receives whatever that market actually gave them — after depth, fees, slippage and their own price impact. The position is then written from that figure rather than from the estimate that preceded it, and the whole operation either completes or reverts.

THE TRADER SPECIFIES
Equity postedTarget leverageWorst acceptable entry priceLeast collateral they will acceptHighest borrow rate they will pay
THE MARKET CHECKS FIRST
Liquidity standing behind the token right nowCredit already outstanding against this marketCapacity left under the ceilingUtilisation, and what it is doing to the borrow rateWhether the price signal is currently trustworthyExpected price impact of the purchase itselfDepth a liquidation would have to sell intoMinimum collateralisation for the size requestedWhether the market is in its protected state
THE SHARP EDGE

Leveraged demand is real demand. The buy moves the price like any other buy, and a larger position moves it more, so the leverage a trader asks for is partly paid for in the price they get. There is no separate venue where the position is filled more kindly.

Liquidation starts early, on purpose

A position is closed for it well before its collateral merely equals what it owes. The gap has to cover the swap fee on the way out, the liquidator's incentive, the price impact of the sale itself, interest still accruing, any lag in the price signal, and whatever the market does while the unwind is executing.

01

Collateral is sold back through the same market

02

Principal and interest are repaid

03

The liquidator takes a bounded incentive

04

Anything left over goes back to the trader

05

Any shortfall is written down as bad debt against the market

A credit receivable is never valued above what its collateral can realistically be sold for through the market that would have to liquidate it.
THE SHARP EDGE

Early is not safe, only earlier. Selling collateral into the market that priced it pushes that price down as it goes, which is the same reflexive move that made the position unhealthy — so capacity is set against the depth a sale could actually clear, not against a headline liquidity figure that no liquidation could ever use.

The same liquidity, doing more than one job

Liquidity is provided once. With credit running against it, that one position can be paid from more than one place — which is also the point at which providing it stops being only market making.

01

Swap fees, as before

02

Interest on the credit the market extends

03

Liquidation fees when a position is closed for it

THE SHARP EDGE

Three fee streams are three fee streams, not a rate and not a forecast — a market with no borrowers pays exactly the first one. The module's own fee is not among them: that one is carved out of the take the market already charges and splits to the developer, the backers, Hookr.fun and the reserve, so running a module costs an LP something before it pays them anything. And the same liquidity that earns the other two is the liquidity standing behind the debt: an LP here is underwriting positions, and bad debt past the reserve is theirs.

WHAT AN LP IS TAKING ON
A borrower defaultingA liquidation that executes too lateThe market's own price being pushedReflexive selling as collateral is unwoundUtilisation so high that little is withdrawableDelay or queueing on the way outThe contracts themselves

Borrow interest is the price of carrying that list, not a bonus on top of market making. The aim is not to advertise a bigger number to liquidity providers — it is a market where the extra revenue is matched by exposure that is named, measurable and bounded.

One deposit, one claim on the whole market

An LP deposits once and receives a share of the Hookr market rather than a bare pool position. That share is a claim on everything the market holds, not only the part of it currently sitting on the curve.

A SHARE IS A CLAIM ON
01

The underlying Uniswap liquidity

02

Uncollected swap fees

03

Performing leverage debt

04

Accrued borrow interest

05

Liquidation proceeds

06

Market reserves

07

Realised bad debt

THE SHARP EDGE

The last line is not decoration. A share of the balance sheet is a share of its losses as well as its holdings, and it is marked against what the credit book can actually recover rather than what it says on its face. This also means a production version has to manage or wrap the underlying position — an LP cannot get this claim by adding liquidity to the pool directly and hoping.

Withdrawal is part of the credit design

Depending on how much of the market is lent out, a withdrawal may settle immediately from available liquidity, be capped at a portion of the liquid assets, enter a queue, come out as a proportional claim on the outstanding receivables, or carry an exit fee that rises with utilisation.

What it may never do is let the first LPs out with all of the liquid quote asset while the LPs who remain carry every open loan.

THE SHARP EDGE

Every one of those options is a cost to somebody, and the honest version of this design does not pretend otherwise: an LP in a heavily borrowed market may wait, may exit in instalments, or may pay to leave now. A market that promised instant exit at full value under any conditions would be promising something its own balance sheet cannot fund.

How much credit a market may write

A market with shallow liquidity should never be able to write deep debt. The ceiling is recomputed from the market's own condition, and the way its inputs combine matters more than the list of them.

credit capacity = min(liquidity, liquidation depth, $HOOKR backing, protocol limit)
MARKET LIQUIDITY

How much depth actually stands behind the token.

EXECUTABLE LIQUIDATION DEPTH

Not what the pool holds — what a liquidation could actually sell into without gapping.

VOLATILITY

How far the price can travel before a liquidation can be executed.

UTILISATION

How much of the ceiling this market has already lent against.

ORACLE QUALITY

How trustworthy the market's own price signal currently is.

$HOOKR BONDED BEHIND THIS MARKET

Per market, and not double-pledged across markets. Distinct from the publisher's bond behind the module itself and from module backers' delegated bond, which answer for the code rather than for this market's credit line.

PROTOCOL LIMIT

A ceiling the protocol keeps regardless of what any single market's own numbers say.

THE RULE THAT KEEPS THE TOKEN HONEST

Bonding more $HOOKR can raise a market's ceiling only up to what its liquidity, its liquidation depth and the protocol limit already allow. It can never push the ceiling past them: behind a thin market, more bond buys nothing at all, because the liquidity term is the one still binding. The bond can be the constraint that binds; it can never be the one that overrules the others.

As utilisation climbs, borrowing gets more expensive, and past a threshold new leverage is refused outright — the ceiling is reached by pricing before it is reached by breakage.

The market prices itself

The canonical market for a token is the place to ask what that token is worth, so the module reads the pool it is lending against rather than an unrelated venue that may have no depth in the same asset.

Spot priceShort-window time-weighted averageLong-window time-weighted averageLiquidity depthRealised volatilityDeviation between spot and the averagesTrade size against the liquidity actually active
THE SHARP EDGE

This is the design's sharpest trade, and it cuts both ways. A pool that prices itself can be pushed by whoever can move that pool, and a borrower has every reason to try. The averages, the depth check and the deviation check exist because spot alone is not safe to lend against — they raise the cost of moving the price, and they do not reduce it to zero. A market too thin to price is a market too thin to lend against.

Risk can leave; new risk cannot enter

When a market stops trusting its own price, it does not freeze. Freezing would trap borrowers inside the positions they are trying to escape, which turns a risk control into a cause of loss. Every exit stays open; every entrance closes.

BLOCKED

Open new leverage

BLOCKED

Increase an existing position

STAYS OPEN

Repay debt

STAYS OPEN

Reduce a position

STAYS OPEN

Close a position

BLOCKED

Withdraw collateral from a position

STAYS OPEN

Add collateral to a position

STAYS OPEN

Liquidate an unhealthy position

Risk can leave; new risk cannot enter. A market in this state is not frozen and not settled — it is refusing to write anything new while it is unsure of its own price. Liquidation is on the open side deliberately: a market that stopped liquidating while it doubted its price would be choosing to accumulate exactly the positions it can least afford. The unresolved part, stated rather than glossed: every action still open is a sell into a pool the market has just judged too thin or too volatile to lend against, so exits compete with liquidations for the same depth.

WHAT TRIPS IT
Price deviating sharply from the market's own averagesDepth thinning below what a liquidation would needVolatility past the point where a position can be closed in timeThe market's price signal becoming unreliable

An existing token gets a new market, not a new hook

A pool's hook is chosen at creation and cannot be changed afterwards, so leverage cannot be attached to a market that is already trading. The route for a token that already exists is a new leverage-enabled pool for it, initialised at the price the token already trades at and seeded with liquidity from there.

THE SHARP EDGE

That means two markets for one token, and for a while the new one is the thinner of the two. Liquidity has to choose to move, price has to be kept honest across both, and until the new market has real depth it is exactly the kind of market this design refuses to extend much credit against.

Bond by what it can touch

A metrics widget and a liquidation engine have nothing in common except the word hook, so they should not post the same bond. The bands below are opening numbers, under review: the intent is a bond weighted by reach and by the value standing behind it, rather than four rungs anyone can memorise.

TIER 0
Read-only

Reads pool state and emits. Touches no balance, changes no parameter.

Analytics · Oracle display · Market metrics

0 – 10,000 $HOOKR
TIER 1
Economic parameters

Sets numbers the pool already applies — fees, shares, routing weights.

Dynamic fees · Reward calculation · Fee routing

25,000 – 100,000 $HOOKR
TIER 2
Asset movement

Moves value that already exists — treasury, LP position, buyback flow.

Buybacks · Treasury routing · LP management

100,000 – 250,000 $HOOKR
TIER 3
Credit and leverage

Creates obligations that did not exist — borrowing, collateral, liquidation.

Leveraged Hooks · Fee-backed credit · Liquidation auctions

250,000+ $HOOKR

A record earns relief, never a pass

A track record is the second thing a developer posts behind a module, and the only one they cannot buy. It reduces what has to be locked — and it buys less of that the more a module can cost someone. The bands are coarse on purpose: a score out of a hundred would be exactly the fake precision this page refuses everywhere else.

TIER 2 · ASSETS
TIER 3 · CREDIT
NEW
0% NOMINAL

No published history on Hookr. Posts the full band for the tier.

100,000
250,000
ESTABLISHED
25% NOMINAL

Modules live across more than one market, through at least one full version migration, with no slashable finding against them.

75,000
218,750
TRUSTED
50% NOMINAL

A long published record, disclosures handled in the open, and incidents — if any — reported by the developer before anyone else found them.

50,000
187,500

The two columns are the same three records against two tiers. The nominal relief on the left of each row is what a lower tier grants in full; a credit module scales the whole ladder to half of it, so the longest record still posts three quarters of a credit bond and every rung stays worth climbing. The floor is never zero for a tier that asks for a bond at all — the module that has never failed is also the module that has never been attacked.

Four categories, one of them empty

The five blocks that exist today are a rail Hookr wrote and cannot change once a pool graduates. A marketplace turns each category into a slot with competing implementations behind it. Credit opens first because it is the category Hookr is not writing — which is also the category where being wrong costs the most.

TRADING
HOOKR STANDARD

What a swap costs and who is allowed to make it.

Anti-Snipe and Surge Fees hold this today, and both stay the standard.

LIQUIDITY
HOOKR STANDARD

Who is paid for providing depth, and on what terms.

LP Rewards holds this today.

CREDIT
OPENS FIRST

Borrowing against a pool, collateral, and liquidation.

Empty today. Leveraged Hooks is the first module proposed into it.

TREASURY
HOOKR STANDARD

What a market does with its own take once it has been collected.

Auto Burn and Nth-buy Pot hold this today.

What a creator actually chooses

The difference between a marketplace and a checkbox list is that the standard is always present, always included, and always costs no module fee. A creator who never opens the marketplace still gets a working market — that is the property that keeps all of this optional.

NO CREDIT MODULE
DEFAULT · NO MODULE FEE

The default. The pool trades spot only, nothing can be borrowed against it, and there is no liquidation path to get wrong.

LEVERAGED HOOKS
THIRD-PARTY · BONDED

Lets this market lend against its own liquidity. Carries the module's own fee, its developer's bond, and its own reserve against bad debt.

A third-party module prices its own fee beneath a published ceiling of 5 bps. A module's fee is disclosed at install and fixed for the version installed. A new version may price differently, which is one more reason a live market never migrates on its own.

THE SHARP EDGE

Installing a credit module is not a setting a creator can quietly reverse. Positions opened against the pool have to be closed or liquidated before it can be removed, so the choice outlives the launch screen it was made on.

What the registry pins

Every field here is something a creator would otherwise take on trust from a developer's own README. A field the registry does not hold is a field nobody can be held to later.

MODULE AND VERSION

Names the exact code a market installed, so a pool can say what it is running.

PUBLISHING WALLET

The address the bond is posted from and the track record accrues to.

RISK TIER AND BOND

What the module may reach, and what is locked behind it while it is live.

PERMISSION MANIFEST

The declared reach the runtime enforces — the boundary, not a description of it.

REVENUE SPLIT

Where this module's fees go, fixed at publication rather than set per invoice.

REVIEW STATE

What review it has had, by whom, and what that review did not cover.

DEPENDENCIES

What else must be installed for it to work, so a missing piece fails at install.

LIFECYCLE STATE

Live, closed to new installs, or withdrawn — and the cooldown clock if it is exiting.

Declare the reach, enforce the boundary

Every module declares what it can touch before it publishes, and the boundary is enforced rather than documented: a module reaching past its manifest fails the call. This is the cheapest safety property in the design, because it turns we reviewed the code into the code cannot do that — and reviewers are fallible in a way a revert is not.

LEVERAGED HOOKS CAN
  • Read the pool's own price signals — spot, both averages, depth, volatility and their deviation
  • Read the pool's in-range liquidity
  • Open, settle and liquidate against the pool it is installed on
  • Refuse new leverage when its risk conditions are not met
LEVERAGED HOOKS CANNOT
  • Move a user's assets outside a position it opened
  • Change the creator's fee routing
  • Change any $HOOKR balance
  • Reach the liquidity or the positions of any other market

What it stacks with

Composability here is constrained rather than arbitrary. The builder already surfaces the guard-versus-pot conflict before a launch ships; a credit module extends that idea to a stack it knows breaks.

REQUIRES · POOL ORACLE

Spot, both time-weighted averages, depth and the deviation between them, read from the market being lent against. A single spot reading is not a price to lend on: it is the number a borrower can move hardest and most cheaply.

REQUIRES · LIQUIDATION ROUTING

A path that can actually sell collateral back through the pool under stress. Credit a market cannot liquidate is credit it should never have written.

REQUIRES · CREDIT CEILING

A live bound on how much the market may lend, recomputed from its own liquidity. Without a ceiling, a thin market will happily write debt it cannot cover.

Surge FeesCONDITIONAL

Surge Fees scales with how much of the pool a trade consumes and consults no oracle, so it raises the cost of exactly the trades that would move a leveraged pool against its own positions. The condition is that a liquidation is also a large trade: charged at surge, the fee comes out of the recovery, so the market pays a premium precisely when it is trying to make itself whole. Liquidation swaps have to be exempted from the surge computation, or charged at a floor, or the fee lands on first loss.

LP RewardsSTACKS

LP Rewards pays in-range liquidity, and in-range depth is precisely what a liquidation needs in order to close a position without gapping through it.

Anti-SnipeCONDITIONAL

Anti-Snipe caps buy size and blocks exact-output buys for its window. A liquidation that has to trade through the pool inside that window would be capped alongside the bots. Leverage must stay closed until the guard window has elapsed.

Nth-buy PotCONDITIONAL

The pot's counter advances on qualifying buys, and a liquidation is a swap the trader did not choose to make. Allowed only where liquidation swaps are excluded from the counter, or a position being closed starts paying out its own liquidation.

Auto BurnBLOCKED

Auto Burn takes its share out of the buyer's received output inside the swap. A position sized on pre-swap output would be collateralised against tokens that never arrive, so the collateral is short by the burn share from the moment it is posted.

Versions never mutate under a live market

Publishing v1.1 does not change the markets running v1.0. The new version becomes available and every creator decides for themselves whether to migrate. Deployed pools keep the rules they graduated with — the same property the five hook blocks already hold, extended to third-party code.

The cost is fragmentation: a popular module will have several live versions at once, each with its own bond and its own reserve, and a fix in v1.1 does not reach anyone still on v1.0. Silent upgrades would be tidier and strictly more dangerous.

What $HOOKR does here

Beyond the 11 utilities already specified on the token page, this gives $HOOKR one more job, and it is the cleanest one: the token buys the right to put capital at risk behind software, and is paid out of that software being used.

Developer bondLock $HOOKR behind the module you publish

The bond scales with what the module can touch, and stays locked for as long as the module has live exposure. It is what turns a developer from an uploader into a participant with something to lose.

EDGE · A bond is collateral against defined misconduct, not a quality rating and not a refund. A well-bonded module can still be badly designed, and the bond does not pay a trader back.

Module backingPost $HOOKR behind someone else's module

A developer who cannot cover the bond alone can open the remainder to holders. Backers cover the gap, take a share of that module's fee stream while it is posted, and stand behind the same slashing conditions the developer does.

EDGE · Backing is at risk. A slashable failure takes the backers' $HOOKR with the developer's, a module nobody installs pays its backers nothing at all, and the backing stays locked through the cooldown after exposure ends.

Allocation as curationChoose which modules deserve distribution

Where backing goes is a public statement about which software is worth running. It is one input into ranking rather than the whole of it, so allocation informs the marketplace without buying the front page.

EDGE · A crowd allocating capital can be confidently wrong, and backing concentrated on a module is a measure of belief, never of correctness.

Market backingBond $HOOKR behind the market you switch credit on for

A creator turning on leverage posts existing $HOOKR behind that market. No new token is minted for it and nothing migrates — the $HOOKR already in circulation is what does the job. The bond is one input into that market's credit ceiling.

EDGE · It is one input, and it enters as a minimum rather than a sum. A large bond behind a thin market buys no extra credit at all, because the liquidity limit is still the one binding. Backing can only ever tighten the ceiling, never lift it.

Fee compoundingLet a market strengthen its own backing out of its own activity

A separate module can route part of a market's fees into buying $HOOKR and bonding it behind that market, so activity compounds into economic backing without anyone topping it up by hand.

EDGE · A loop that compounds upward compounds downward on the same track: activity falling away unwinds the backing it built. And because backing enters the ceiling as a minimum, a market that compounds a great deal of it still gets no more credit than its liquidity supports.

Fee routingBe paid out of usage, or not at all

Module fees are split at source between the developer, the backers, the protocol, and that module's own reserve. Nothing is minted to pay any of it.

EDGE · Usage is the only source. A module with no installs routes nothing, and no part of this pays anyone for holding $HOOKR without putting it behind something.

DELEGATION, AS ARITHMETIC
TIER 3 BOND
250,000
DEVELOPER POSTS
100,000
HOLDERS COVER
150,000

A developer who cannot cover a credit-tier bond alone posts what they have and opens the rest. Holders who cover the gap take a share of that module’s fee stream while it is posted, and stand behind the same slashing conditions the developer does. The requirement and the holders’ share are both derived from the tier floor above; only the developer’s side is a chosen round number, so the example cannot drift away from the band it is quoting.

Where module fees go

A module's fee stream splits at source, four ways. Developers pick a configuration inside these bounds, so modules compete on economics as well as on quality. The protocol share and the reserve share are floors, not knobs — and nothing is minted to pay any of it.

Module developer20–60%Paid to the wallet that published the version in use, while it is in use.
$HOOKR backers10–40%Split pro-rata across the wallets whose $HOOKR is posted behind this module, for as long as it is posted.
Hookr.fun15% fixedA fixed floor for running the marketplace the module is distributed through.
Module safety reserve10% fixedA fixed minimum, held per module rather than pooled across the marketplace.
DEVELOPER-WEIGHTED
Module developer60%
$HOOKR backers15%
Hookr.fun15%
Module safety reserve10%
BACKER-WEIGHTED
Module developer35%
$HOOKR backers40%
Hookr.fun15%
Module safety reserve10%

Two corners of the same box, not a recommendation and not a forecast. The second is what a developer chasing adoption offers; the first is what a developer with a queue keeps.

Usage ranks a module, capital does not

If bonded $HOOKR drove the ranking, the front page would simply be for sale and the marketplace would sort by who is richest. Backing is a signal worth reading, so it is not zero — it is capped.

Fee revenue generated30%What markets actually paid to use it.
Active markets25%How many live pools have it installed right now.
Ninety-day retention15%Whether markets keep it after the novelty wears off.
Security history15%Incidents, disclosures, and how the developer handled them.
$HOOKR backing10%How much economic backing is posted behind it. Capped on purpose.
Developer reputation5%The publishing wallet's track record across its other modules.

GREEN is earned through use and totals 90% of the score. ORANGE can be bought and totals 10%. The tests hold that ratio: a change letting capital outweigh usage fails the suite rather than the review.

The bond outlives the developer's interest in it

One specific move has to be impossible: publish, win adoption, pull the bond, disappear. Everything after the exit request exists to close that door.

1PublishThe version is registered with its manifest, its tier, and its split.
2Bond locksThe developer's $HOOKR and any delegated backing are locked behind that version.
3Markets install itCreators opt in at launch. Each install is a live exposure the bond stands behind.
4Fees routeUsage pays the split — developer, backers, protocol, reserve.
5Exit requestedThe developer gives notice. Nothing is released yet.
6Installs closeNo new market can install the version. Existing markets are untouched.
7Live markets migrate or closeExposure has to reach zero on its own schedule, not the developer's.
8CooldownA waiting period after the last exposure ends, so late failures still have a bond.
9Bond releasesDeveloper and backers can withdraw.

Slashable, and not

Slashing is narrow on purpose. A bond that can be taken because a market lost money is not a bond, it is a fine for building something risky — and it would price every careful developer out of the credit tier while doing nothing about the malicious ones.

SLASHABLE
  • Hidden malicious code
  • Moving assets the manifest denies
  • Reaching past a declared permission boundary
  • Deliberate oracle manipulation
  • An undisclosed upgrade path
  • A critical invariant broken by the module's own logic
NEVER SLASHABLE
  • The token's price fell
  • A trader was liquidated
  • The module was unpopular
  • The fee stream dried up
  • A market the module was installed in went to zero
ISOLATED FAILURE DOMAINS

Each module accumulates its own reserve out of its own fee stream, and a credit module's bad debt hits that reserve first. Isolation is per module: a shortfall never reaches a module that was not part of the position.

Isolation stops at the module, not at the market. One reserve covers every market running that module, so a blow-up in one market drains the cover standing in front of another market's liquidity providers — they fund a common pot and they draw on a common pot. The reserve is also a first loss rather than a backstop, and smaller than a pooled one by construction: past it the shortfall is bad debt against that market's own balance sheet, which is its liquidity providers. It is written down where anyone can see it, because a market that hides insolvency prices everything after it wrongly.

What this is not

  • None of this is deployed. There is no module registry, no bond vault, and no fee router on chain today — this is a published design, open for review before it is built.
  • No figures on this page are measurements. There are no volumes, no install counts, and no scores here, because there is nothing running yet to measure.
  • The bond bands, the split bounds, and the score weights are opening parameters under review. They are here to be argued with.
  • A bond is not an audit and not an endorsement. Hookr's own contracts are adversarially reviewed and unaudited, and a third-party module carries strictly more risk than that, not less.
  • Backing a module puts $HOOKR at risk of slashing and pays only out of that module's usage. It is not a yield product.
  • Providing liquidity to a leverage-enabled market means underwriting its credit. Past the module's reserve, bad debt is the pool's, which is the liquidity providers'. The extra fee streams are the payment for taking that on, not a reason it is absent.
  • The market prices itself. Averages, depth and deviation checks raise the cost of pushing that price and do not remove it, and a market too thin to price is one this design refuses to lend against.
  • $HOOKR bonded behind a market cannot raise its credit ceiling. Capacity is the minimum of its inputs, so backing can only ever be the binding constraint.
  • Leverage can lose you everything you post as equity, faster than spot can. Not financial advice.
The $HOOKR utilitiesThe blocks that exist todayHow Hookr works