Whitepaper · v1.1
Five metrics move underneath every DeFi position you hold: funding, pool utilization, positioning, exchange flows and book depth. Throb lets you take an offsetting position on where they go next, settled on-chain with nobody in the middle.
Every position in DeFi carries risk that has nothing to do with the asset's price. Funding rates swing, venue pool utilization climbs and falls, order books crowd onto one side, tokens flow onto exchanges ahead of sell pressure, and liquidity thins or deepens. All independent of whether the underlying asset goes up or down. These are the metrics that quietly cost liquidity providers, perpetual traders, and treasuries real money, and until now there has been no direct, on-chain way to offset them.
Throb Market exists to let anyone with real, verifiable exposure to one of these metrics take an on-chain position that offsets it. Settled automatically, with no operator, no custodian, and no one on the other side of the trade except another account with the mirrored real exposure.
A liquidity provider cannot hedge funding-rate risk without leaving the pool. A perpetual desk running a book too large to unwind quickly has no on-chain instrument for the metrics that move against it hour to hour. A treasury holding a large position has no direct way to offset the risk that exchange inflows signal ahead of price moves. These risks are real, they are already priced into the returns these participants realize, and none of them are speculation on price. They are structural costs of doing business on-chain.
Existing venues that offer directional products require choosing a side and are open to anyone regardless of whether they hold the underlying risk. That structure is speculation by design. Throb's constraint is the opposite: no verified exposure, no position. Full stop.
Five on-chain metrics are readable, unforgeable, and economically meaningful: perpetual funding rate, perp pool utilization, the long/short ratio, net exchange flow, and order book imbalance. Each one is a real cost or benefit to a real class of on-chain participant. Throb reads them directly from the venues that already produce them, no oracle committee, no price feed to manipulate, no team deciding an outcome.
What makes this a hedging protocol rather than a betting market is not marketing language. It is four enforced constraints, described below, that apply to every position on every symbol with no exception and no configuration path around them.
Throb is a risk management protocol for on-chain metrics. It is not a casino, sportsbook or betting service, is not operated as one, and offers no game of chance. The trade-off this makes on purpose: both sides of a market need mirrored real exposure, so liquidity is thinner than an open venue and more markets go one-sided and void. That is the cost of the constraint, disclosed rather than hidden.
Opening a position runs through the same gate every time: the exposure verifier for the chosen symbol answers how much verifiable exposure your account holds and which direction offsets it. If you hold none, the transaction reverts before anything else happens. If you do, your position opens sized to (and capped by) that exposure, on the direction the verifier returned, never one you chose.
From there the market runs itself. It settles the moment its term expires and anyone at all calls to collect, which triggers settlement inline and that caller simply pays the gas as part of collecting. If the underlying metric moved enough to clear a deadband, the market resolves and fees split 50/25/25 between eligible THROB holders, protocol-owned liquidity, and treasury. If the data was unreadable, stale, or the move never cleared the deadband, the market voids and every position is returned in full with no fee taken.
An exposure verifier is a small, read-only contract that answers one question for a given account and symbol: how much real exposure do you hold, and which direction reduces your risk? Verifiers read on-chain state directly. A perpetual venue's position records, an LP token's share of a pool's notional, never an API, never a value a team can push.
This is the protocol's entire trust boundary. A verifier that reports honestly is what makes every position here a real risk transfer, which is why exposure re-verification, adapter integrity, and fail-closed behavior on every external read are treated as the highest-priority engineering concerns in the project's own threat model.
Not every venue a participant carries risk on publishes that risk to the chain Throb settles on. Where a venue's state is not directly readable, coverage is extended through an attested verifier, and it is deliberately the weaker instrument of the two. Attested exposure is bounded by a per-venue ceiling fixed at deployment, so the worst case of a compromised attestation is capped rather than open-ended, and the ceiling clamps an overstated figure instead of rejecting it outright. Directly-read exposure carries no such cap because it needs none. The distinction between the two is preserved rather than blended: a wallet is never shown a single number that silently mixes what was measured with what was asserted.
Every symbol's signal is read through a time-weighted observation window, not a single instantaneous read. A design chosen specifically so a single transaction cannot move the number a market settles against. A manipulator would need to sustain a distortion across the whole window, which costs real capital held at real risk for the duration, rather than one flash-loaned block.
Settlement compares the value at market open to the time-weighted value as of expiry. The reading is anchored to the expiry timestamp rather than to whenever somebody calls settle, so two settlements at different moments produce the same outcome. If the move clears the symbol's deadband, the market resolves in the direction the metric actually moved, and the losing side's pool funds the payout to the winning side. If it doesn't clear the deadband, or the read is stale, reverting, or one-sided, the market voids and refunds everyone in full.
How much the losing side forfeits is bounded by the move itself, not by the size of its pool. Each adapter accumulates the signal it watches over time, so a market knows what its metric actually cost a hedger across the term. The winning side is paid that accrued cost. The losing side's stake after the fee is the ceiling on it, and whichever of the two is smaller is what changes hands. Everything above it is returned to the losing side rather than paid across. A small move therefore returns most of the losing collateral to the wallets that staked it, and only a large, sustained move claims the whole pool. That is the property that makes a hedge on Throb a cost-offset rather than a bet. It pays what the move cost, when the move cost something.
Market is a reader and a routing layer, not a second venue. It takes the exposure a wallet has already had verified on-chain, and assembles named protection products against it. Sized, directed and priced for the risk it actually found. A product exists only where a position justifies it. Nothing is listed, curated or approved.
What matters architecturally is what Market cannot do. It holds no collateral, keeps no book, and grants no capacity. Accepting a product routes into the same entry and the same settlement path as a hedge opened by hand, subject to the same verification gate and the same per-position ceilings. Removing Market entirely would change what the interface offers and nothing about what the protocol permits.
When both sides of a signal are populated, hedgers transfer risk to each other and the protocol stays out entirely. What remains is the residue: demand on one side that found no counterparty. A quarter of every protocol fee accumulates into a balance sheet whose only purpose is to stand against that residue, so a hedge does not simply fail for want of someone to take the other side.
It is self-managing in the strict sense. There is no switch, and no operator decides what it takes. Every capacity ceiling is expressed as a fraction of capital held, so on deployment day the balance is zero, every ceiling evaluates to zero, and markets settle exactly peer-to-peer. As revenue accrues the same unchanged expression yields a larger number, and capacity grows with it. Nothing directs where it is deployed: allocation is arithmetic, and the only contract that can move it into a market is immutable ThrobMarkets.
One disclosed exception, because the protocol runs on two chains and capital cannot bridge itself. A common operations Safe, the same address on both chains and fingerprinted on-chain before launch, can move idle capital between them. That release is announced 24 hours in advance. It is capped at 25% of free capital per request, and at 25% of window-start capital per rolling 30 days so it cannot compound. It is re-checked against the solvency reserve at execution. It can pay only that Safe, never a caller-selected wallet and never the treasury, and it can never reach capital allocated to a live market or the reserve. That is a rate limit rather than a lifetime ceiling. It is a real trust dependency, and we would rather state it than have you discover it.
It also only ever takes the thin side, the one users under-filled, which is the side that is cheap to enter and least likely to be crowded against. Risk limits are arithmetic, evaluated per market, and a market it declines settles as though it were not there.
Hedging is a maintenance task, and maintenance is what software is for. An owner can deploy a vault, fund it, and delegate hedging to an automated strategy, without handing over custody. The vault holds the capital. The agent holds only permission to act within it.
That permission is a grant: an explicit, bounded authority stating what an agent may do and up to what size, revocable by the owner at any time and enforced by the vault rather than by the agent's good behaviour. Withdrawal remains the owner's alone. An emergency stop blocks every agent at once while leaving the owner's own controls untouched, so the failure mode of a misbehaving strategy is that it stops acting, never that it drains anything.
Agents receive no privileged access to the protocol. They open positions through the same function, against the same verified exposure, under the same ceilings as any wallet.
Arena asks one question: can a person build a better hedge than the protocol's mechanical default? Each round presents the on-chain signals and pre-fills the hedge the protocol would have constructed. A participant adjusts it. When the window closes, the result is scored against that default on the same realised market path, and ranked within the cohort that faced it.
Scoring is deterministic and on-chain, weighted across three axes: how much the hedge improved on the default, how well the participant's stated confidence matched reality, and how soundly the hedge was constructed judged before the market moved at all. The confidence axis uses a scoring rule under which overstating certainty lowers the expected score. Honesty is the optimal strategy rather than a request.
Entry requirements are checks, never charges: nothing is transferred, escrowed or staked to compete. Arena reads protocol state and never writes to it, so a deployment without Arena behaves identically. Ratings are published as a conservative lower bound shown with their uncertainty and sample size, because a single round contains luck and a figure that hides that would be dishonest.
Funding Rate
Positive funding means longs are paying to stay long.
Pool Utilization
Rising utilization means borrowing fees are rising. A real cost to anyone holding a position, a real yield gain to whoever supplied the pool.
Long/Short Ratio
Past 65% long, the book is crowded and carries squeeze fuel.
Exchange Flows
Coins moving onto venues are usually moving there to be sold.
Book Imbalance
Depth resting on the bid is real buy pressure, not sentiment.
Lite
Full protocol access, free forever.
Pro
Professional risk tooling and a reduced protocol fee.
Pro extends Lite, and never gates access to the core protocol. Every constraint described under Core Philosophy applies identically to both tiers.
THROB is a fixed-supply ERC-20 with a single utility: real wallets holding at least 10,000 THROB earn a pro-rata share of half of every protocol fee, paid in WETH, claimed on demand. Holding is the only requirement, no staking, no lock-up, no auto-transfer on trade. Contracts (pools, routers, smart accounts) never accrue, so pool liquidity never silently absorbs a slice of every distribution.
Distribution to holders needs no snapshot and no distribution round. Each release advances a single per-token accumulator, so crediting every eligible holder costs the same regardless of how many there are, and each wallet collects on its own schedule by pulling rather than waiting to be paid. No holder can block a release for anyone else, and nothing expires unclaimed.
The token reaches its first holders through a fixed-price genesis sale and a paired liquidity pool created from the proceeds. The same price, at the same moment, with no allowlist and no privileged early access. The sale contract has no owner, no pause and no setter of any kind: transferring the allocation into it is what opens it, opening and finalisation are calls anyone may make, and a sale that never reaches its target unlocks contribution recovery on a timer rather than on a decision.
Full allocation, vesting schedule, and contract addresses are on the THROB Token page.
Throb takes a protocol fee only on the losing side of a settled market, never on principal that resolves in a position's favour, and never on a voided market. That fee splits 50/25/25 between eligible THROB holders, protocol-owned liquidity, and the treasury when POL is wired, paid in WETH and computed by the contract with no discretion. Pro subscriptions (a flat, time-boxed access fee, not a revenue share) are the other source, escrowed for a statutory cooling-off period before reaching the treasury.
The protocol is immutable after deployment: a single configurator key can wire adapters and verifiers once each, then is permanently burned. No pause switch and no upgrade path exist anywhere in the system. A deliberate trade-off. Every settlement-path external call is wrapped and fails closed to a full refund rather than guessing on bad data.
A full threat model, findings tracker, and technical specification are maintained and published alongside every material change to the contracts, and a paid third-party audit is a hard prerequisite before any mainnet deployment, not a formality run in parallel with one.
Found a vulnerability? Report it privately to connect@kryptik.works rather than opening a public issue. The repository's SECURITY.md carries the full scope and process.
The symbol set grows autonomously: six permanent symbols and three rotating slots promoted purely on measured on-chain hedging volume, with no listing committee and no oracle. Additional exposure verifiers extend coverage to new venues over time. Always following the same rule as every verifier before it: read real on-chain state, report honestly, fail closed. The destination is the same one the protocol already points at: every metric that quietly costs a DeFi participant money, made directly hedgeable, on-chain, with nobody in the middle.