Leverage
Leveraged Hooks is a credit module for hooked pools — and the first Hookr block Hookr does not intend to write itself. This is the marketplace it arrives through: who is allowed to publish a module that can lose your money, what they have to put behind it, and what $HOOKR does about it.
The module
Leveraged Hooks
Credit extended by the market itself, rather than by a lending pot parked beside it. A trader posts equity in the pool's quote asset and the market sells them the token on margin: the tokens they acquire are the collateral, locked in the position, and the market records what they owe back to it. One pool, one liquidity base, spot and credit on the same balance sheet — the LPs who provide depth for trading are the same LPs financing the position. Opening, closing and liquidating all execute through that pool.
Leverage multiplies losses at exactly the rate it multiplies gains, and a liquidation is the system working rather than failing. The part a liquidity provider has to read twice: the same liquidity now carries credit risk it did not carry before. When a position cannot be closed for enough to cover what it owes, the shortfall is bad debt against that market — the reserve absorbs the first of it, and past the reserve it is the pool's own balance sheet, which means the LPs. Providing liquidity to a leverage-enabled market is underwriting, not just market making.
Leveraged Hooks turn a market's trading liquidity into lending liquidity as well.
The primitive underneath it: A hook-controlled AMM with an expanded balance sheet. A hook sits where liquidity, price discovery, execution, settlement and LP accounting meet. It can inspect a swap before it runs, apply the market's own policy, reconcile what actually happened afterwards, and keep state between transactions. That is enough to turn an ordinary swap into a balance-sheet transaction with rules attached.
It does not create capital, and nothing here is free. The hook's power is narrower and more useful than that: it can refuse a trade the market cannot afford, and it can remember what the trade left behind.
The five blocks that exist today are ours, and they are immutable once a pool graduates. A marketplace changes that in one specific way: code Hookr did not write starts running next to other people’s money. Everything below is the answer to that — not a review process, which is a person’s opinion, but a bond, which is a balance.
One pool, one liquidity base
The question a credit module has to answer first is where the money comes from. The familiar answer is a second pot of lenders beside the market. This design takes the other one, and the option it rejected is written down beside the option it took.
Lenders deposit the quote asset into a second pot, borrowers draw from it, and the pool is only where the trade executes. It is the familiar arrangement and it works.
It splits one market into two liquidity bases that have to be bootstrapped, incentivised and balanced separately, and it leaves the pool's own depth idle while a vault beside it does the financing.
No second pot. The pool sells the token on margin out of the liquidity that is already there, and books what the trader owes back to it. Same market, same liquidity, same LPs, financing and trading against one balance sheet.
Liquidity is provided once and does more than one job, and there is no second market to bootstrap before a token can have credit at all.
The trade is concentration. One balance sheet doing both jobs means a credit loss and a trading loss land in the same place, on the same providers, at the same time — which is exactly when a market is least able to absorb either.
What the market owns, and what it is owed
Credit extended by the market is only sound if the market can still say what it is worth. The identity below is the whole of it, and the error it rules out is the one that would let a market believe it is solvent while it is not.
The tokens locked as a borrower's collateral and the debt that borrower owes are two sides of one position, not two assets. Counting both would inflate the market by the size of its own lending book.
Nothing is minted to make a position. The market hands over exposure it already had and takes back cash plus a claim — the claim is why the sheet still balances, and the claim is also the part that can go bad.
Every open, close and liquidation is a swap against the pool, and every one of them settles in full inside its own transaction. Nothing is left owing at the v4 layer.
The position that outlives the transaction is recorded by the module: collateral held, debt in the quote asset, interest accrued, health, and the price at which the position is liquidated.
One position, in arithmetic
An invented token and round numbers, to show how the accounting moves. Nothing here is a measurement, a quote, or a projection.
Their own capital — the equity in the position.
Extended out of the pool's own liquidity.
Bought through the pool and locked as collateral.
Plus interest, owed back to the market.
Closing sells the collateral back through the same pool. The proceeds repay the market's principal first, then interest and fees, and whatever is left is the trader's.
If the position is closed for less than it owes, the trader's equity goes first and in full. Only what is missing after that is the market's problem.
The tokens bought on margin, locked in the position.
What is owed back to the market, denominated in the quote asset.
Accrues against the debt at a rate that moves with utilisation.
How far the position sits from the point where it is closed for it.
Derived from the pool's own price and the risk parameters.
Reconciled against what happened, not what was quoted
The purchase executes through the real market, so the trader receives whatever that market actually gave them — after depth, fees, slippage and their own price impact. The position is then written from that figure rather than from the estimate that preceded it, and the whole operation either completes or reverts.
Leveraged demand is real demand. The buy moves the price like any other buy, and a larger position moves it more, so the leverage a trader asks for is partly paid for in the price they get. There is no separate venue where the position is filled more kindly.
Liquidation starts early, on purpose
A position is closed for it well before its collateral merely equals what it owes. The gap has to cover the swap fee on the way out, the liquidator's incentive, the price impact of the sale itself, interest still accruing, any lag in the price signal, and whatever the market does while the unwind is executing.
Collateral is sold back through the same market
Principal and interest are repaid
The liquidator takes a bounded incentive
Anything left over goes back to the trader
Any shortfall is written down as bad debt against the market
Early is not safe, only earlier. Selling collateral into the market that priced it pushes that price down as it goes, which is the same reflexive move that made the position unhealthy — so capacity is set against the depth a sale could actually clear, not against a headline liquidity figure that no liquidation could ever use.
The same liquidity, doing more than one job
Liquidity is provided once. With credit running against it, that one position can be paid from more than one place — which is also the point at which providing it stops being only market making.
Swap fees, as before
Interest on the credit the market extends
Liquidation fees when a position is closed for it
Three fee streams are three fee streams, not a rate and not a forecast — a market with no borrowers pays exactly the first one. The module's own fee is not among them: that one is carved out of the take the market already charges and splits to the developer, the backers, Hookr.fun and the reserve, so running a module costs an LP something before it pays them anything. And the same liquidity that earns the other two is the liquidity standing behind the debt: an LP here is underwriting positions, and bad debt past the reserve is theirs.
Borrow interest is the price of carrying that list, not a bonus on top of market making. The aim is not to advertise a bigger number to liquidity providers — it is a market where the extra revenue is matched by exposure that is named, measurable and bounded.
How much credit a market may write
A market with shallow liquidity should never be able to write deep debt. The ceiling is recomputed from the market's own condition, and the way its inputs combine matters more than the list of them.
How much depth actually stands behind the token.
Not what the pool holds — what a liquidation could actually sell into without gapping.
How far the price can travel before a liquidation can be executed.
How much of the ceiling this market has already lent against.
How trustworthy the market's own price signal currently is.
Per market, and not double-pledged across markets. Distinct from the publisher's bond behind the module itself and from module backers' delegated bond, which answer for the code rather than for this market's credit line.
A ceiling the protocol keeps regardless of what any single market's own numbers say.
Bonding more $HOOKR can raise a market's ceiling only up to what its liquidity, its liquidation depth and the protocol limit already allow. It can never push the ceiling past them: behind a thin market, more bond buys nothing at all, because the liquidity term is the one still binding. The bond can be the constraint that binds; it can never be the one that overrules the others.
As utilisation climbs, borrowing gets more expensive, and past a threshold new leverage is refused outright — the ceiling is reached by pricing before it is reached by breakage.
The market prices itself
The canonical market for a token is the place to ask what that token is worth, so the module reads the pool it is lending against rather than an unrelated venue that may have no depth in the same asset.
This is the design's sharpest trade, and it cuts both ways. A pool that prices itself can be pushed by whoever can move that pool, and a borrower has every reason to try. The averages, the depth check and the deviation check exist because spot alone is not safe to lend against — they raise the cost of moving the price, and they do not reduce it to zero. A market too thin to price is a market too thin to lend against.
Risk can leave; new risk cannot enter
When a market stops trusting its own price, it does not freeze. Freezing would trap borrowers inside the positions they are trying to escape, which turns a risk control into a cause of loss. Every exit stays open; every entrance closes.
Open new leverage
Increase an existing position
Repay debt
Reduce a position
Close a position
Withdraw collateral from a position
Add collateral to a position
Liquidate an unhealthy position
Risk can leave; new risk cannot enter. A market in this state is not frozen and not settled — it is refusing to write anything new while it is unsure of its own price. Liquidation is on the open side deliberately: a market that stopped liquidating while it doubted its price would be choosing to accumulate exactly the positions it can least afford. The unresolved part, stated rather than glossed: every action still open is a sell into a pool the market has just judged too thin or too volatile to lend against, so exits compete with liquidations for the same depth.
An existing token gets a new market, not a new hook
A pool's hook is chosen at creation and cannot be changed afterwards, so leverage cannot be attached to a market that is already trading. The route for a token that already exists is a new leverage-enabled pool for it, initialised at the price the token already trades at and seeded with liquidity from there.
That means two markets for one token, and for a while the new one is the thinner of the two. Liquidity has to choose to move, price has to be kept honest across both, and until the new market has real depth it is exactly the kind of market this design refuses to extend much credit against.
Bond by what it can touch
A metrics widget and a liquidation engine have nothing in common except the word hook, so they should not post the same bond. The bands below are opening numbers, under review: the intent is a bond weighted by reach and by the value standing behind it, rather than four rungs anyone can memorise.
Reads pool state and emits. Touches no balance, changes no parameter.
Analytics · Oracle display · Market metrics
Sets numbers the pool already applies — fees, shares, routing weights.
Dynamic fees · Reward calculation · Fee routing
Moves value that already exists — treasury, LP position, buyback flow.
Buybacks · Treasury routing · LP management
Creates obligations that did not exist — borrowing, collateral, liquidation.
Leveraged Hooks · Fee-backed credit · Liquidation auctions
A record earns relief, never a pass
A track record is the second thing a developer posts behind a module, and the only one they cannot buy. It reduces what has to be locked — and it buys less of that the more a module can cost someone. The bands are coarse on purpose: a score out of a hundred would be exactly the fake precision this page refuses everywhere else.
No published history on Hookr. Posts the full band for the tier.
Modules live across more than one market, through at least one full version migration, with no slashable finding against them.
A long published record, disclosures handled in the open, and incidents — if any — reported by the developer before anyone else found them.
The two columns are the same three records against two tiers. The nominal relief on the left of each row is what a lower tier grants in full; a credit module scales the whole ladder to half of it, so the longest record still posts three quarters of a credit bond and every rung stays worth climbing. The floor is never zero for a tier that asks for a bond at all — the module that has never failed is also the module that has never been attacked.
Four categories, one of them empty
The five blocks that exist today are a rail Hookr wrote and cannot change once a pool graduates. A marketplace turns each category into a slot with competing implementations behind it. Credit opens first because it is the category Hookr is not writing — which is also the category where being wrong costs the most.
What a swap costs and who is allowed to make it.
Anti-Snipe and Surge Fees hold this today, and both stay the standard.
Who is paid for providing depth, and on what terms.
LP Rewards holds this today.
Borrowing against a pool, collateral, and liquidation.
Empty today. Leveraged Hooks is the first module proposed into it.
What a market does with its own take once it has been collected.
Auto Burn and Nth-buy Pot hold this today.
What a creator actually chooses
The difference between a marketplace and a checkbox list is that the standard is always present, always included, and always costs no module fee. A creator who never opens the marketplace still gets a working market — that is the property that keeps all of this optional.
The default. The pool trades spot only, nothing can be borrowed against it, and there is no liquidation path to get wrong.
Lets this market lend against its own liquidity. Carries the module's own fee, its developer's bond, and its own reserve against bad debt.
A third-party module prices its own fee beneath a published ceiling of 5 bps. A module's fee is disclosed at install and fixed for the version installed. A new version may price differently, which is one more reason a live market never migrates on its own.
Installing a credit module is not a setting a creator can quietly reverse. Positions opened against the pool have to be closed or liquidated before it can be removed, so the choice outlives the launch screen it was made on.
What the registry pins
Every field here is something a creator would otherwise take on trust from a developer's own README. A field the registry does not hold is a field nobody can be held to later.
Names the exact code a market installed, so a pool can say what it is running.
The address the bond is posted from and the track record accrues to.
What the module may reach, and what is locked behind it while it is live.
The declared reach the runtime enforces — the boundary, not a description of it.
Where this module's fees go, fixed at publication rather than set per invoice.
What review it has had, by whom, and what that review did not cover.
What else must be installed for it to work, so a missing piece fails at install.
Live, closed to new installs, or withdrawn — and the cooldown clock if it is exiting.
Declare the reach, enforce the boundary
Every module declares what it can touch before it publishes, and the boundary is enforced rather than documented: a module reaching past its manifest fails the call. This is the cheapest safety property in the design, because it turns we reviewed the code into the code cannot do that — and reviewers are fallible in a way a revert is not.
- Read the pool's own price signals — spot, both averages, depth, volatility and their deviation
- Read the pool's in-range liquidity
- Open, settle and liquidate against the pool it is installed on
- Refuse new leverage when its risk conditions are not met
- Move a user's assets outside a position it opened
- Change the creator's fee routing
- Change any $HOOKR balance
- Reach the liquidity or the positions of any other market
What it stacks with
Composability here is constrained rather than arbitrary. The builder already surfaces the guard-versus-pot conflict before a launch ships; a credit module extends that idea to a stack it knows breaks.
Spot, both time-weighted averages, depth and the deviation between them, read from the market being lent against. A single spot reading is not a price to lend on: it is the number a borrower can move hardest and most cheaply.
A path that can actually sell collateral back through the pool under stress. Credit a market cannot liquidate is credit it should never have written.
A live bound on how much the market may lend, recomputed from its own liquidity. Without a ceiling, a thin market will happily write debt it cannot cover.
Surge Fees scales with how much of the pool a trade consumes and consults no oracle, so it raises the cost of exactly the trades that would move a leveraged pool against its own positions. The condition is that a liquidation is also a large trade: charged at surge, the fee comes out of the recovery, so the market pays a premium precisely when it is trying to make itself whole. Liquidation swaps have to be exempted from the surge computation, or charged at a floor, or the fee lands on first loss.
LP Rewards pays in-range liquidity, and in-range depth is precisely what a liquidation needs in order to close a position without gapping through it.
Anti-Snipe caps buy size and blocks exact-output buys for its window. A liquidation that has to trade through the pool inside that window would be capped alongside the bots. Leverage must stay closed until the guard window has elapsed.
The pot's counter advances on qualifying buys, and a liquidation is a swap the trader did not choose to make. Allowed only where liquidation swaps are excluded from the counter, or a position being closed starts paying out its own liquidation.
Auto Burn takes its share out of the buyer's received output inside the swap. A position sized on pre-swap output would be collateralised against tokens that never arrive, so the collateral is short by the burn share from the moment it is posted.
Versions never mutate under a live market
Publishing v1.1 does not change the markets running v1.0. The new version becomes available and every creator decides for themselves whether to migrate. Deployed pools keep the rules they graduated with — the same property the five hook blocks already hold, extended to third-party code.
The cost is fragmentation: a popular module will have several live versions at once, each with its own bond and its own reserve, and a fix in v1.1 does not reach anyone still on v1.0. Silent upgrades would be tidier and strictly more dangerous.
What $HOOKR does here
Beyond the 11 utilities already specified on the token page, this gives $HOOKR one more job, and it is the cleanest one: the token buys the right to put capital at risk behind software, and is paid out of that software being used.
The bond scales with what the module can touch, and stays locked for as long as the module has live exposure. It is what turns a developer from an uploader into a participant with something to lose.
EDGE · A bond is collateral against defined misconduct, not a quality rating and not a refund. A well-bonded module can still be badly designed, and the bond does not pay a trader back.
A developer who cannot cover the bond alone can open the remainder to holders. Backers cover the gap, take a share of that module's fee stream while it is posted, and stand behind the same slashing conditions the developer does.
EDGE · Backing is at risk. A slashable failure takes the backers' $HOOKR with the developer's, a module nobody installs pays its backers nothing at all, and the backing stays locked through the cooldown after exposure ends.
Where backing goes is a public statement about which software is worth running. It is one input into ranking rather than the whole of it, so allocation informs the marketplace without buying the front page.
EDGE · A crowd allocating capital can be confidently wrong, and backing concentrated on a module is a measure of belief, never of correctness.
A creator turning on leverage posts existing $HOOKR behind that market. No new token is minted for it and nothing migrates — the $HOOKR already in circulation is what does the job. The bond is one input into that market's credit ceiling.
EDGE · It is one input, and it enters as a minimum rather than a sum. A large bond behind a thin market buys no extra credit at all, because the liquidity limit is still the one binding. Backing can only ever tighten the ceiling, never lift it.
A separate module can route part of a market's fees into buying $HOOKR and bonding it behind that market, so activity compounds into economic backing without anyone topping it up by hand.
EDGE · A loop that compounds upward compounds downward on the same track: activity falling away unwinds the backing it built. And because backing enters the ceiling as a minimum, a market that compounds a great deal of it still gets no more credit than its liquidity supports.
Module fees are split at source between the developer, the backers, the protocol, and that module's own reserve. Nothing is minted to pay any of it.
EDGE · Usage is the only source. A module with no installs routes nothing, and no part of this pays anyone for holding $HOOKR without putting it behind something.
A developer who cannot cover a credit-tier bond alone posts what they have and opens the rest. Holders who cover the gap take a share of that module’s fee stream while it is posted, and stand behind the same slashing conditions the developer does. The requirement and the holders’ share are both derived from the tier floor above; only the developer’s side is a chosen round number, so the example cannot drift away from the band it is quoting.
Where module fees go
A module's fee stream splits at source, four ways. Developers pick a configuration inside these bounds, so modules compete on economics as well as on quality. The protocol share and the reserve share are floors, not knobs — and nothing is minted to pay any of it.
Two corners of the same box, not a recommendation and not a forecast. The second is what a developer chasing adoption offers; the first is what a developer with a queue keeps.
Usage ranks a module, capital does not
If bonded $HOOKR drove the ranking, the front page would simply be for sale and the marketplace would sort by who is richest. Backing is a signal worth reading, so it is not zero — it is capped.
GREEN is earned through use and totals 90% of the score. ORANGE can be bought and totals 10%. The tests hold that ratio: a change letting capital outweigh usage fails the suite rather than the review.
The bond outlives the developer's interest in it
One specific move has to be impossible: publish, win adoption, pull the bond, disappear. Everything after the exit request exists to close that door.
Slashable, and not
Slashing is narrow on purpose. A bond that can be taken because a market lost money is not a bond, it is a fine for building something risky — and it would price every careful developer out of the credit tier while doing nothing about the malicious ones.
- Hidden malicious code
- Moving assets the manifest denies
- Reaching past a declared permission boundary
- Deliberate oracle manipulation
- An undisclosed upgrade path
- A critical invariant broken by the module's own logic
- The token's price fell
- A trader was liquidated
- The module was unpopular
- The fee stream dried up
- A market the module was installed in went to zero
Each module accumulates its own reserve out of its own fee stream, and a credit module's bad debt hits that reserve first. Isolation is per module: a shortfall never reaches a module that was not part of the position.
Isolation stops at the module, not at the market. One reserve covers every market running that module, so a blow-up in one market drains the cover standing in front of another market's liquidity providers — they fund a common pot and they draw on a common pot. The reserve is also a first loss rather than a backstop, and smaller than a pooled one by construction: past it the shortfall is bad debt against that market's own balance sheet, which is its liquidity providers. It is written down where anyone can see it, because a market that hides insolvency prices everything after it wrongly.
What this is not
- None of this is deployed. There is no module registry, no bond vault, and no fee router on chain today — this is a published design, open for review before it is built.
- No figures on this page are measurements. There are no volumes, no install counts, and no scores here, because there is nothing running yet to measure.
- The bond bands, the split bounds, and the score weights are opening parameters under review. They are here to be argued with.
- A bond is not an audit and not an endorsement. Hookr's own contracts are adversarially reviewed and unaudited, and a third-party module carries strictly more risk than that, not less.
- Backing a module puts $HOOKR at risk of slashing and pays only out of that module's usage. It is not a yield product.
- Providing liquidity to a leverage-enabled market means underwriting its credit. Past the module's reserve, bad debt is the pool's, which is the liquidity providers'. The extra fee streams are the payment for taking that on, not a reason it is absent.
- The market prices itself. Averages, depth and deviation checks raise the cost of pushing that price and do not remove it, and a market too thin to price is one this design refuses to lend against.
- $HOOKR bonded behind a market cannot raise its credit ceiling. Capacity is the minimum of its inputs, so backing can only ever be the binding constraint.
- Leverage can lose you everything you post as equity, faster than spot can. Not financial advice.