Parameters
Every protocol parameter in the Tuo contracts, what it means in plain language, and whether it can ever change.
All protocol parameters live in one library, TuoConstants, and are compiled into the contracts.
They cannot be changed after deployment. A handful of settings are stored on the vault and can be
adjusted by the treasury Safe; those are listed separately at the bottom.
Compiled constants
Fees and deposits
| Constant | Value | Meaning |
|---|---|---|
PERFORMANCE_FEE_BPS | 3,000 (30%) | Share of the withdrawn portion of profit taken as a fee. Never charged on principal. No setter |
MIN_DEPOSIT_USDC | 2,500 USDC | Minimum USDC credited per deposit or top-up |
BPS_DENOMINATOR | 10,000 | Basis-point denominator shared by every ratio |
Keeper budgets
| Constant | Value | Meaning |
|---|---|---|
MAX_KEEPER_ACTIONS_PER_WINDOW | 10 | Metered keeper actions (swapIdle, mintLp, burnLp, bridgeToHl) per position per window |
KEEPER_ACTION_WINDOW | 24 hours | Window over which the action allowance fully regenerates (leaky bucket) |
MAX_KEEPER_LOSS_BPS_PER_WINDOW | 150 bps | Cumulative TWAP-measured value loss the keeper may cause one position inside the window, as a share of that position's basis |
KEEPER_LOSS_WINDOW | 24 hours | Window for the loss budget |
The loss budget is a rate limiter. 150 bps per day compounds to roughly 36% of a position in a month. The real bound on a compromised keeper is detection plus the treasury Safe revoking the keeper role.
Pricing and slippage
| Constant | Value | Meaning |
|---|---|---|
TWAP_WINDOW | 30 minutes | Window for every pool TWAP the vault reads, for valuation and for gates |
MIN_OBSERVATION_CARDINALITY | 2,000 | Oracle observation slots a pool must have provisioned before the vault will price against it. Checked at deployment; the deployment aborts otherwise |
MAX_TWAP_DEVIATION_TICKS | 200 (about 2%) | Largest allowed distance between spot and TWAP before keeper pool operations revert |
DEFAULT_SLIPPAGE_BPS | 50 bps | Slippage floor the vault derives for keeper idle swaps, on top of the keeper's own minimum |
LP_PRICE_BAND_TICKS | 100 (about 1%) | Price move an LP mint must survive between the vault's quote and inclusion |
LP_BURN_VALUE_FLOOR_BPS | 9,950 (99.5%) | Minimum share of a position's TWAP value a burn must return, measured on both legs combined |
MIN_LP_TICK_WIDTH | 200 ticks (about 2%) | Narrowest range the keeper may mint |
Hedge and exit
| Constant | Value | Meaning |
|---|---|---|
MIN_HL_BRIDGE_USDC | 100 USDC | Smallest margin transfer to a Hyperliquid operator |
EMERGENCY_WITHDRAW_DELAY | 24 hours | Wait after requestWithdraw before emergencyWithdraw unlocks |
USD accounting is USDC with 6 decimals throughout. The vault prices against pool TWAPs only, so no external oracle decimal convention applies.
Product policies
Products are registered in the vault at deployment. The registry is add-only: a code can never be overwritten, and retiring a product only blocks new positions.
| Product | Code | Hedge cap (maxHedgeBps) | Max open LPs (maxLpCount) |
|---|---|---|---|
| Basis Plus Core | 1 | 5,000 bps (50% of basis) | 3 |
| Delta Hedge Standalone | 2 | 9,000 bps (90% of basis) | 1 |
The hedge cap bounds how much of a position's basis may sit on Hyperliquid at once. It is the only on-chain bound on the leg the vault cannot measure.
Treasury-settable values
These live in vault storage and can be changed by the treasury Safe. Every change emits an event.
| Setting | Launch value | Setter | Event |
|---|---|---|---|
| Per-position cap | 25,000 USDC | setPerNftCap | PerNftCapUpdated |
| Fee recipient | Treasury Safe | setFeeRecipient | FeeRecipientUpdated |
| Hyperliquid operator allowlist | Seeded at deployment | setHlOperator | HlOperatorUpdated |
| Aggregator allowlist | 0x AllowanceHolder, 1inch v6 | addAggregator, removeAggregator | AggregatorAdded, AggregatorRemoved |
| Product registry | The two products above | registerProduct, setProductOpen | ProductRegistered, ProductOpenUpdated |
| Deposits paused | No | pauseDeposits, unpauseDeposits (pauser role) | DepositsPauseUpdated |
Frozen at deployment
| Setting | Why it cannot change |
|---|---|
| Pool allowlist | No setter. Every pool must pair its token with USDC and pass the cardinality check |
| Valuation pools | No setter |
| Deposit token set | No setter |
| USDC, WETH, position manager addresses | Immutable |
| Fee percentage | Compiled constant |
Changing any of these means deploying a new vault and migrating every position.
Related
- Roles and admin controls for who may call each setter.
- Performance fee for how the fee constant is applied.