Docs
Perp vault shares
Shares of EtherFamily vaults that hold a leveraged BTC or ETH perpetual position on a hybrid venue. Disabled today.
Design · not deployedValues on this page come from the design. Deployed addresses and settings: Contract addresses; live state: Status.
Perps are disabled
Perp markets are disabled until a live proof of trading and withdrawal on the venue passes.
The venue integration is designed, and its on-chain half works on a mainnet fork. No order, fill, reconciliation or withdrawal through the venue's API has been executed: the venue has no test network, and the proof of concept needs the owner's authorization, capital, keys and acceptance of the venue's terms. Until it passes, no vault exists, no share exists, and no market can pair with one. This page describes the design.
What a share is
What a perp share is
A perp share is a share of an EtherFamily vault that holds a long or short BTC or ETH perpetual position targeting a fixed leverage on Synthetix, a hybrid venue: collateral is on Ethereum but matching, margin and liquidations happen off-chain. The share's value is an attested net asset value, not an on-chain proof.
- One vault per market, direction and target leverage (for example BTC, long, 2x). Its share is an ordinary ERC-20 token whose count never changes with profit or loss; its value per share does.
- A launched token paired with a share moves in USD with the share's value, even when nobody trades it. This is the property EtherFamily borrows from alt.fun, without its bonding curve and migration.
- Only 2x vaults may open after the proof of concept. 3x and 5x need an economics review approved by the owner, and the contract itself refuses sizes the venue's margin tiers cannot carry.
Not a hedge
Holding this token is not a hedge. The share's direction changes this token's USD value, but pool prices depend on trading.
No claim on the pool's assets
Holding this token gives no right to a share of the pool's assets. Its price is set by trading in the pool, with slippage.
The venue: a hybrid, not on-chain execution
The candidate venue is Synthetix Mainnet. Its collateral sits in a contract on Ethereum, but orders are matched, and margin, profit and loss, funding and liquidations are computed, off-chain by the venue Observed on-chain Vendor-documented. The chain sees deposits and withdrawal requests; positions and fills exist only in the venue's API. EtherFamily never describes it as on-chain execution.
It was chosen because it is the only venue found that keeps custody of collateral on Ethereum without a bridge, and because no existing Ethereum token offers directional perp exposure settled on Ethereum Observed on-chain. Venues on other chains, rollups and appchains were excluded.
Constant leverage
Constant leverage loses value in choppy markets (volatility decay), pays or receives funding every hour, and can still be liquidated in a fast move. Rebalancing does not prevent liquidation.
Custody
Venue custody
Collateral is held by the venue's deposit contract, which the venue's operators can pause, upgrade or pay out without a timelock, and whose withdrawals have been paused for up to 15 days at a time. The venue's terms let it suspend accounts at its discretion and say that assets may then be lost. Exits can be delayed.
What the research found in the venue's contracts and history:
- Users have no withdrawal function of their own. One hot operator key can create, validate and pay out withdrawals to any address; on a fork it paid 100,000 USDT to an address that had never deposited Test-proven.
- A Safe needing 4 of 7 signers can upgrade the deposit contract at once, with no timelock Observed on-chain.
- Guardian keys paused withdrawals five times in about ten and a half months, about 26.8 days in total, the longest for 15 days. In normal times a withdrawal took a median of 108 seconds Observed on-chain.
- The vault would own its venue account; its managers can withdraw only to the vault, but that is the venue's API rule, not an on-chain check. Trading keys cannot be limited by market, size or leverage Vendor-documented.
| Value | Held by | Who can move it |
|---|---|---|
| USDT waiting to be invested or paid out, and the vault's free USDT | The vault contract: no admin transfer function, no upgrade, no arbitrary calls | Only the vault's rules: claims to the entitled holder, venue deposits by the operator within limits, emergency and terminal redemptions |
| Collateral at the venue, in flight to it or on its way back | Synthetix's deposit contract (pooled with every other user) and its off-chain ledger | Synthetix's operators: one hot key can pay out to any address, a 4-of-7 Safe can upgrade the contract without delay, guardians can pause withdrawals |
| Shares | Their holders; the vault for queued and unclaimed shares | Holders; the vault only under its request and claim rules |
A manager unable to withdraw elsewhere can still lose money by trading badly, and the venue can refuse, dispute or delay any withdrawal. That is why the product is never called trustless, non-custodial, fully on-chain or risk-free.
The venue's terms
Each vault's venue account would be opened under Synthetix's Exchange Terms (last modified 19 December 2025, read 2026-09-30) Vendor-documented. The clauses that matter most for a vault, read by EtherFamily for the owner's legal review (this is not legal advice):
| Clause | The terms say | For a vault |
|---|---|---|
| Counterparty, law and disputes (preamble, §17, §18) | The contract is with Molon Labe Inc., a Panamanian corporation, under the laws of Panama. Disputes go to 60 days of informal resolution, then to individual, confidential arbitration under ICC rules; class actions and jury trials are waived. | Recovering a vault's collateral after a venue failure would be one confidential arbitration under Panamanian law. |
| Liability (§16) | Capped at the greater of $100 or the fees paid to the venue in the previous six months, with no liability for third-party fraud, exploits or vulnerabilities. | Losses the venue causes are practically unrecoverable. |
| Suspension and termination (§10, §19.2) | The venue may modify, suspend or discontinue its services at its sole discretion, with or without notice, and restrict or terminate access at any time. After a permanent suspension or termination, assets “may be lost”; open orders can be cancelled and amounts owed fall due at once. | Collateral can be held back or lost, and a position closed at a bad moment. The vault treats a stuck withdrawal as distress and, if it lasts, winds down. |
| Liquidation (§7.17, §7.19) | A liquidated account loses all its collateral and can end with a negative balance, owed to the venue with interest. | A vault can owe the venue more than it holds. The design winds down a vault whose venue equity reaches zero; who would owe the deficit needs the venue's answer and counsel. |
| Fees and funding (§13) | Fees, funding and fee schedules can change at any time without notice. | The costs on this page are dated estimates, and the venue can change the fees behind them at any time. |
| Automated access (§9.4, §4.5) | Accessing the services with “any robot, spider, or other automatic device” is prohibited, yet representatives may act “through API keys or apps you authorize”. | The executor trades automatically. Whether a vault may do so needs the venue's written answer (gate G-2). |
| Ownership of the assets (§9.6) | The account holder represents that it is “the legal and rightful owner” of the assets it uses. | A vault pools its holders' USDT in one account. Whether that is acceptable needs the venue's written answer (gate G-2). |
| Custody (§4.2, §4.3) | The venue says it does not custody, possess or control the assets in your wallet, and that you bear all risk of loss. | On-chain, one operator key can pay out the pooled collateral and a Safe can upgrade the deposit contract without a timelock. These pages describe what the contracts allow. |
| Names and marks (§9.5) | No use of the venue's name, marks or logo without consent, and nothing implying endorsement or affiliation. | These pages name the venue only to describe it, with no logo. Whether the venue consents is one of the written questions. |
Accepting these terms for a vault is the owner's decision. Before any live test, the venue has to answer in writing whether a contract-owned account may trade automatically, whether it may pool third-party capital, who the contracting party is and how a negative balance would be pursued (gate G-2 below). EtherFamily is not affiliated with Synthetix, and Synthetix does not endorse EtherFamily.
How a share is valued
How the share is valued
A perp share's value comes from reports signed by attestor count attestors, independent count of them independent of EtherFamily, checked on-chain against Chainlink prices and the venue's on-chain records. Without every attestor's signature, reports can overstate it by at most drift bound in total until all attestors sign again; if every attestor colludes there is no limit. Last report: report age ago.
Because positions exist only in the venue's API, a quorum of attestors signs what the API returned. The vault checks each report on-chain against Chainlink prices, its own deposit records, the venue's on-chain withdrawal records, arithmetic identities between the report's fields and continuity with the previous report. The design calls for at least three attestors, a quorum of at least two, and at least one run by a party independent of EtherFamily. No attestor key may be an operator, manager, guardian or deployment key.
What colluding attestors can and cannot do
- Can, without every attestor's signature: overstate the value by about 2.1% of it (plus 50 USDT) in one report at 2x, and by at most 4% in total until every attestor signs again; understate it by 4% plus 1.5% per day; stop reporting, which fails epochs and eventually lets anyone start a wind-down Model.
- Cannot: move USDT, mint shares without deposits, choose which report settles an epoch, change parameters or attestors, or stop redemption requests, claims, cancellations or the emergency exit.
- If every attestor colludes, there is no bound. That is the trust assumption of the product.
A report outside those bounds is stored as disputed and closes deposits. A later report within bounds clears it, or every attestor confirms it. The guardian or the admin can discard it, but that does not stop the clock: a dispute older than 24 hours puts the vault in distress (below).
Deposits and redemptions
Shares are created and redeemed in scheduled epochs, not instantly. The launch pools trade shares that already exist; minting and redeeming them is a separate, slower layer.
- A request made before an epoch's cutoff (every 24 hours by default) settles at the report the attestors observe within 300 seconds after the cutoff. Nobody chooses the price: the clock does, and a report submitted early or late within the deadline settles identically.
- Deposits and redemptions of an epoch settle at the same price. Whichever side is larger pays a swing: the cost its net flow causes at the venue, so the holders who stay do not pay it.
- A deposit starts bearing profit and loss at its settlement report. A redemption keeps bearing it until the settlement that processes it. Processing pays out of the USDT the vault holds on-chain, so a large redemption can wait until the venue sends collateral back.
- The vault's size cap applies at settlement; deposits above it are refunded. A failed epoch refunds its deposits in full and carries its redemptions to the next.
- Requests can be cancelled except between a cutoff and its settlement (at most two hours by default). While the vault is active, nobody can block a redemption request or a claim.
Exits from a perp share
Selling this token gives you perp vault shares. Turning shares into USDT is instant only through the vault's buffer, when one is enabled and has capacity, at a live price minus a spread of about buffer spread. Otherwise you request a redemption: it settles at the next epoch's report and is paid once the venue has returned the collateral, which the venue can pause or dispute. While the vault is active an emergency exit is always available, but it pays only your share of the USDT the vault holds on-chain and gives up the rest.
Ways out
| Path | Price | Available | Cost |
|---|---|---|---|
| Instant buffer (shares ⇄ USDT) | The last report marked to Chainlink, ± a spread | Only where a provider funds one; off by default. Stops whenever the vault's data is stale, disputed or in distress. | The spread, about 2.1% or more at 2x |
| Redemption request | Net asset value at the epoch's cutoff report, minus the swing | Requests are always accepted while the vault is active; processing waits during distress. | The swing, and time: the next settlement plus the venue's withdrawal |
| Selling the launched token | The launch pool's price | Whenever the pool trades; it pays out in shares, not USDT | The launch fee and price impact |
| Emergency exit | Your share of the USDT the vault holds on-chain only | Always while the vault is active; nobody can pause it | You give up your part of the value held at the venue |
| Terminal redemption | Your share of what the vault has recovered | After wind-down, with no deadline; later recoveries are paid too | None |
The emergency exit
While a vault is active, any holder can burn shares for their pro-rata part of the vault's free USDT on-chain (not the USDT waiting for pending deposits or owed to processed redemptions), at once, without the venue and without the attestors. It gives up the rest: the part of the value held at the venue stays with the holders who remain, so the exit can never hurt them. During distress the on-chain part can be small. No guardian or admin action can pause it.
Distress and wind-down
A vault is in distress while the venue's withdrawals are paused, its own withdrawal is disputed or stuck, a deposit was not credited, a payment arrived short, the venue's permission registry is paused, the guardian has frozen it, or a dispute is older than 24 hours. Distress has one set of effects, whatever the cause: the epoch's deposits are refunded, redemptions wait (and keep bearing profit and loss), the instant buffer stops and nothing more is sent to the venue. Redemption requests, cancellations, claims and the emergency exit keep working.
A vault winds down on any of these triggers:
| Trigger | Who | Condition |
|---|---|---|
| Scheduled | EtherFamily's timelock schedules it; anyone executes it | Announced at least 7 days ahead; can be cancelled before it takes effect. |
| Impaired | Automatic | A report shows the venue account's equity at or below zero with a position open. |
| Value floor | Automatic | Net asset value per share below the vault's floor (default 0.10 USDT). |
| Distress timeout | Anyone | Continuous distress for the vault's limit (default 30 days; between 7 and 60). |
| Stale timeout | Anyone | No accepted report for 14 days (default). |
| Market delisted | Anyone | Reports show the venue market inactive for 3 days. |
| Queue starved | Anyone | For 14 days, every settlement outside distress left redemptions waiting: nobody brought the collateral back. |
In wind-down the executor closes the positions and asks the venue for all the collateral. Every share, including those in launch pools and in the fee escrow, can be redeemed for its part of what has been recovered, with no deadline, and receives later recoveries too. Markets paired with the share keep trading, but their quote no longer tracks a position:
Wind-down
This vault wind-down time or reason. From then on the perp share no longer tracks a leveraged position: it is a claim on the USDT the vault recovers. Any holder of shares, including shares later bought out of this pool, can redeem them at any time for their part of what has been recovered so far, and receives later recoveries as well.
Costs and funding
Costs of the exposure
At recent rates (as of date of the rates) holding this exposure costs about funding rate a year in funding (negative: the vault receives it) and rebalancing drag in rebalancing drag of the vault's value; neither goes to EtherFamily. Deposits and redemptions settle once per epoch and pay a swing of up to maximum swing for the trading their net flow causes; on small net outflows part of the venue's fixed withdrawal fee is paid by the vault.
Estimates from research snapshots of the venue's funding and order books Vendor-documented and design arithmetic, to be replaced by measured data. None of these costs goes to EtherFamily.
| Cost | 2x | 3x | 5x | Borne by |
|---|---|---|---|---|
| Funding at the 29-day mean (+10.5% a year on notional; longs paid, shorts received) | ≈ 21% of NAV a year | ≈ 31% | ≈ 52% | Holders (it is the product) |
| Rebalancing drag (keeping leverage constant) | ≈ 1.2% of NAV a year | ≈ 3.7% | ≈ 12% | Holders |
| Execution cost of net deposits or redemptions, plus 5 USDT per venue withdrawal | Swing on the net side | Same | Same | The deposits or redemptions that cause it |
| Ethereum gas for reports, settlement and venue deposits | ≈ 0.001-0.008 ETH a day per vault (a hypothesis until measured) | Same | Same | Proposed: EtherFamily (owner decision pending) |
At those rates a 2x BTC long costs about 22% of its value a year before any price move. Funding changes every hour and can turn either way.
USDT accounting
The vault accounts in USDT. USD values assume USDT's market price from Chainlink; a USDT depeg changes them.
Administration
Vault administration
EtherFamily administers the vault behind the perp share through a 48-hour timelock: it can change the vault's bounded parameters, its operator and venue managers and, with 7 more days, its attestors, and it can wind the vault down after at least 7 days' notice. A guardian can pause deposits, and can halt redemption processing, the instant buffer and new venue deposits for up to 72 hours once a week. None of them can send the vault's on-chain USDT anywhere except into its own venue account, or stop redemption requests, claims or the emergency exit. These powers change what the perp share is worth and what it tracks, although this market itself cannot be changed.
The full table of roles, delays and revocation paths is on Admin powers and timelocks.
Vault parameters
| Parameter | Value | Status |
|---|---|---|
| Epoch | 24 hoursBounded to 1 hour-7 days. Deposits and redemptions settle once per epoch. | Default · not deployed |
| Settlement report | Observed within 300 s of the cutoff, accepted within 2 hoursA missed deadline fails the epoch: deposits are refunded and redemptions carried over. | Default · not deployed |
| Maximum NAV age | 1 hourAlso the upper bound. Older NAV marks the vault stale: new launches and the instant buffer stop. | Default · not deployed |
| Vault size cap | 25,000 USDT (proof of concept: 500 USDT)Under an immutable ceiling derived from the venue's margin tiers. | Default · not deployed |
| Maximum swing | 1% at 2xImmutable ceilings 1.5%, 2.5% and 4% at 2x, 3x and 5x. | Default · not deployed |
| Venue withdrawal fee | 5 USDT per withdrawal | Vendor-documented |
| Attestors | At least 3, a quorum of at least 2, at least 1 independentAdditions and quorum changes take 7 days on top of the 48-hour timelock; deposits close meanwhile. | Bound · not deployed |
| Unexplained gain without every attestor | At most 4% of NAV in totalUntil a report signed by every attestor. Downward: 4% plus 1.5% per day since that report. | Default · not deployed |
| Wind-down notice | At least 7 days | Bound · not deployed |
| Guardian freeze | At most 72 hours, once per 7 days | Bound · not deployed |
What must happen first
Production perps need every one of these gates. All are open.
| Gate | Requirement | Owner | Status |
|---|---|---|---|
| G-1 | Written authorization for a capped mainnet proof of concept and, later, for production. | Owner | Open |
| G-2 | The owner's acceptance of the venue's terms, and Synthetix's written confirmation that a contract-owned account may trade automatically through a manager key with pooled third-party capital, of who the contracting party is and how a negative balance would be pursued, of its per-owner caps, and of how its discretionary suspension terms apply. | Owner (legal) | Open |
| G-3 | The mainnet proof of concept passes every step: deposit, long and short orders, fills, reconciliation, close, and withdrawal back to the vault. | Engineering, owner funds | Open |
| G-4 | At least one attestor run by a party independent of EtherFamily. | Owner | Open |
| G-5 | Keys and custody: hot and standby venue managers, operator, attestors, guardian and timelock Safes, in hardware or managed key stores. | Owner | Open |
| G-6 | Disclosures and a legal review of offering the product: venue custody, account suspension, funding costs, no forced exit. | Owner (legal) | Open |
| G-7 | Vault size caps within the venue's capacity; 3x and 5x vaults only after an economics review. | Owner | Open |
Sources: perp feasibility §1-§10, perp vault NAV and redemption §2-§9, vault specification §2, §8-§10, executor §9 (design); research on Synthetix Mainnet (on-chain reads at block 26,085,700, fork tests, vendor documents); the clause review of Synthetix's Exchange Terms (2026-09-30); reference model model/perp_vault.py.