Field guide / Protocol · 4 min read

Risks and assumptions

Stated plainly: issuer powers, revenue uncertainty, software, privileged roles, markets.

Live, and clear about what is not.
A trade on the degen.zone curve pays about 4.19% all in. About 0.34% of that goes to degen.zone, about 0.84% to Meteora, and the rest, about 3.02% of volume, reaches the protocol. After graduation, at about 80 SOL raised, trading moves to a Meteora DAMM v2 pool that charges 1% regardless of the curve tier. Meteora keeps 20% of that, and the rest is split by liquidity share between the protocol's locked position and degen.zone's, so about 0.52% of volume reaches the protocol. The protocol's take per trade falls at graduation. It funds holder payouts in tokenized stocks, protocol-owned liquidity, a staking reserve and operations, in a fixed ratio the treasury program enforces. Staking itself is planned, phase 2: the allocation is set aside, but no staking program is deployed and nothing accepts a deposit. Values that have not been read from the chain render as a dash with the reason beside them.

Issuer and asset risk

  • The xStock issuer holds a permanent delegate over every xStock account, including yours. It can freeze or move balances under its terms. Redemption depends on the issuer and its custodian.
  • A tokenized stock is not a share held in a brokerage account. Corporate actions are handled as the issuer specifies.
  • A stock whose market becomes too thin to buy or sell at size can be retired from the allowlist; its outstanding epochs still pay.

Revenue is uncertain

  • Payouts are proportional to fee revenue, shared out by holding time. Low volume means low or zero payouts, however long you have held.
  • Trades outside the launch venue and the protocol pools pay nothing to the treasury. More $FLUX volume does not necessarily mean more revenue.
  • The protocol's take per trade falls at graduation, from about 3.02% of curve volume to about 0.52% of pool volume: the graduated pool charges 1% whatever the curve tier was, Meteora keeps 20% of that, and the protocol's locked position holds 65% of the pool's liquidity while degen.zone's holds the rest.
  • Protocol-owned liquidity in the protocol’s own token is a long position. It can lose value, and impermanent loss is real.

Holding time: what the weighting defends against, and what it does not

  • Your share of a payout is your average eligible balance over the last 48 epochs (24 hours at the 30-minute cadence), not your balance at the snapshot. It defeats renting supply for a payout: a position bought for the snapshot earns 1/48 of its balance-weight and has to be held for a day to earn the rest, and it decays at the same rate afterwards, so buying before and selling after leaves nothing to collect.
  • It is symmetric on purpose, so it does not penalise a wallet that genuinely held for the window and then sells: that wallet is paid, at a falling weight, for the following window, which is the same value it would have received had the payouts arrived on time.
  • It does not stop a wallet from holding for a day and then selling, and is not meant to. It cannot tell one wallet from many under one owner. It does not change who is eligible, only how much of the pot each eligible wallet is weighted for.
  • The window is counted in published epochs. A stretch with no revenue publishes no epoch and does not age anyone out of the window, and a lost proof file inside the window counts as zero for everyone, so a keeper outage also costs holding time. Both are stated in the epoch file rather than smoothed over.

Software and privileged roles

  • Bugs in the programs, the keeper, this site, Raydium, Meteora, Jupiter, Pyth or the token contracts can cause loss.
  • The keeper is trusted to compute allocations honestly. A compromised keeper can misallocate a future epoch; it cannot move funds out of program vaults or rewrite a published root.
  • The authority can withdraw liquidity from a pool at any time, immediately and even while the protocol is paused. The proceeds land only in protocol accounts and cannot be paid out as holder rewards, and moving value out of the protocol still takes seven days of continuous public pause. You are trusting the authority not to exit the protocol’s positions without cause.
  • The upgrade authority can change the programs. It is intended to be a multisig; until then it is a single key held by the operator.
  • An independent security review has not been completed.

Network and market conditions

  • RPC outages, congestion and fee spikes can delay epochs and claims. A delayed epoch is published late, not skipped.
  • Oracle staleness stops buys until fresh prices arrive; that is the guard working.
  • Wallet connection alone does not establish anyone’s eligibility for a particular asset in a particular jurisdiction.