DevnetFortunissimo Testnet·

Risks

What can go wrong, stated plainly, including the things the protocol cannot protect you from.

Start here

Who is exposed to what

If youYou can loseBecause
Hold the tokenmost of its valuenothing supports the price but demand
Trade with leverageyour entire margina 4% adverse move is enough at high leverage
Shortmore than your margina token debt grows without limit as the price rises
Supply USDTpart of your deposita collapse can outrun liquidation
Lend your tokensvalue, not quantityyou are owed the same number back, not the same worth
The big one

These pools are small

A token graduates with about $12,000 behind it. At that size your own trade moves the price noticeably — buying a few thousand dollars can shift it by tens of percent, and you pay that on the way in and again on the way out.

This is also why the leverage on offer is usually far below the headline maximum. The number shown is what the pool could genuinely absorb, and on a thin market that is a few times, not twenty.

A 20× position is liquidated by a 1% move
With a 4% maintenance margin, high leverage leaves almost no room. On a small pool the price impact of opening the position can be larger than that on its own, which is why the protocol will simply refuse the trade.
The obvious temptation

Borrowing against your own token

It looks like a machine for free money: buy your token, borrow against it, buy more, repeat. Each loop is smaller than the last, because borrowing power is capped by what the collateral could actually be sold for into the pool — and your own buying adds price, not liquidity to sell into.

Measured on a $12,000 pool, $1,000 produced about $2,000 of buying and stopped after two cycles. When it unwinds, the losses land on whoever built the position: the collateral is sold into the market it inflated.

A real trade-off

Liquidation reads an average price

Positions are valued at a 10-second average, not the last trade, so that nobody can manufacture a price for one block and liquidate you with it. The cost is that in a genuine collapse the trigger lags the market by a few seconds.

If the price falls far enough in that window, the collateral no longer covers the debt and the shortfall becomes a loss for suppliers. Shortening the window would react faster and make manipulation cheaper; there is no setting that avoids both.

Asymmetric by nature

A short's losses are not capped

A long can lose what it put in. A short owes a number of tokens, and that debt grows without limit as the price rises — so a sharp rally can leave a short owing more than it can pay, whatever the maintenance margin says.

Covering pushes the price further against you
Buying the token back is itself a purchase into the pool, so a large short being closed drives the price up as it closes. On a thin market this can cost noticeably more than the screen suggested.
What the design does guarantee

Tokens cannot infect each other

Every pool, oracle, lending pool and insurance account is separate. A token can fail completely — collapse, exhaust its insurance, leave bad debt — without touching any other market. There is one shared fund that can cover tail losses, and it only pays out when it is comfortably ahead.

Plainly

Things no protocol can fix

Most tokens launched here will go to approximately zero, as they do everywhere. Nothing in this design changes that, and none of the mechanics above are a reason to expect otherwise. What the protocol can promise is narrower: that the price you see is the price you trade, that limits are tied to real liquidity rather than invented numbers, and that when something goes wrong the loss is recorded rather than hidden.

This is unaudited software on devnet. Treat everything in it as experimental.