# Etesia Research documentation, in full Etesia Research runs systematic quantitative strategies onchain. This file contains every page of https://docs.etesiar.com in reading order, for assistants and agents that prefer a single document. A shorter index with descriptions is at https://docs.etesiar.com/llms.txt. Generated from the published documentation. ============================================================================== # Introduction https://docs.etesiar.com/ ============================================================================== Etesia Research is a systematic asset management firm. We run institutional quantitative strategies onchain, in non-custodial vaults, so that the strategy is executed by software and your shares stay in your own wallet. The flagship strategy is a systematic CTA: a trend-following program that goes long what is rising and short what is falling, across crypto perpetuals and tokenized real-world assets. The signal is derived from price. No human approves a trade. ### Where to start **Depositing.** [Etesia Multistrat](multistrat.md) is the flagship vault. It runs on HyperEVM, executes on Hyperliquid, and takes USDC. Deposit at [app.etesiar.com](https://app.etesiar.com). **Understanding the mechanics.** [How They Work](how-they-work.md) covers deposits, redemptions and what happens to your capital in between. **Sizing a position.** [Our Thesis](thesis.md), then [Risk Overview](risk.md). **Allocating institutionally.** [Separately Managed Accounts](sma.md). ### Live figures Current NAV, share price, TVL and open positions are on [app.etesiar.com](https://app.etesiar.com) and readable onchain. We do not reproduce them here: the documentation describes mechanics, the app carries the state. Fee rates and vault parameters are the exception: they are set in the contract and listed under [Fees + Redemption Period](fees.md), with the address to verify them against. ============================================================================== # Our Thesis https://docs.etesiar.com/thesis ============================================================================== Traditional finance solved risk management decades ago. Systematic trend-following, risk parity and volatility targeting are well understood and evidence-backed. None of them existed in digital-asset markets in a serious, accessible form. Etesia was founded to close that gap. ### What crypto investors are usually offered An index is a long-only bet on the market. It falls when the market falls, which is the exposure most crypto holders already have. A yield strategy generates a rate. The rate compresses as capital arrives, and there is no directional upside. Etesia is neither. It is a systematic CTA: it can be long or short, it targets a level of volatility rather than a level of return, and its position in any market depends on that market's own trend rather than on a view about the asset class. ### Why uncorrelated matters more than another token A typical crypto portfolio holds assets whose daily returns correlate at 0.7 to 0.9 with each other. Adding another token to that portfolio barely reduces its risk, because the new position moves with everything already in it. An uncorrelated return stream lowers portfolio variance without lowering expected return. That is the argument for holding a CTA sleeve next to a directional crypto book. ### Why trends persist Four mechanisms, documented across more than 100 markets and 50 years of data (Moskowitz, Ooi and Pedersen, 2012): - **Information diffuses slowly.** Not every participant reprices at once, so a repricing plays out over days and weeks. - **Investors herd.** Participants chase moves that have already started, which extends them. - **Risk is transferred.** Hedgers pay speculators to take the other side, and that payment shows up as a persistent drift. - **Anchoring.** Participants adjust from a previous price rather than to a new fair value, so adjustment is gradual. These effects are stronger in young, retail-driven, fragmented markets than in mature ones. Crypto adds a fifth: forced flows from liquidations, token unlocks and index rebalances move price in a direction predictable from price and calendar alone. The strategy does not forecast. It harvests the moves that happen and pays for them with many small losses on the trends that fail. ### Why onchain **Custody.** Assets sit in a vault contract rather than on our balance sheet. See [Vault Protections](vault-protections.md). **Verifiability.** Holdings, share price and history are readable by anyone with an RPC endpoint. There is no monthly letter to wait for. **Access.** A fund wrapper has minimums, subscription windows and a jurisdictional perimeter. A vault contract has a deposit function. ### What we do not claim Trend-following has bad decades. The 2010s were largely range-bound and the strategy family did poorly through them. A single year lands far from the long-run average in both directions. The strategy went live on 27 May 2026. Everything before that date is simulated. [Risk Warnings and Disclaimers](disclaimers.md) sets out the rest. ============================================================================== # Etesia Multistrat https://docs.etesiar.com/multistrat ============================================================================== Systematic trend-following across ten sectors of crypto perpetuals and tokenized real-world assets, executed on Hyperliquid. Deposit USDC, receive `etesiaUSDC` shares. | | | |---|---| | Curator | Etesia Research | | Chain | HyperEVM, chain 999 | | Execution venue | Hyperliquid, perpetuals and spot | | Deposit asset | USDC | | Vault standard | Lagoon ERC-7540 | | Fees | 1% management, 20% performance above high-water mark | | Redemption cooldown | 7 days | | Live since | 27 May 2026 | | Deposit | [app.etesiar.com](https://app.etesiar.com) | Full fee mechanics are on [Fees + Redemption Period](fees.md). Live NAV, share price and TVL cap are in the app and onchain. ### Return profile Return comes from directional positions in perpetual futures, long and short, sized to a volatility target. There is no rate and no yield source. The payoff shape is many small losses funded by a few large gains. The losing periods come in choppy, trendless markets; that is the cost of the shape, not a malfunction. ### What it trades Ten sectors. Seven crypto-native, three tokenized real-world assets whose drivers are macro rather than crypto. | Sector | Type | |---|---| | DeFi | Crypto | | Layer-1 | Crypto | | Infrastructure | Crypto | | Meme | Crypto | | Payment | Crypto | | Store of value | Crypto | | AI | Crypto | | Energy | Tokenized RWA | | Equity indices | Tokenized RWA | | Metals | Tokenized RWA | The RWA sleeves are why correlation to crypto is low rather than merely moderate. ### How the strategy works **Signal.** Fast and slow moving averages of price are compared. When the fast average sits above the slow one the target position is long, below it short. Several comparisons run at different speeds, so the program captures both multi-day and multi-month moves. **Sizing.** Position size scales with signal strength, not just its sign. Every instrument is scaled to a common risk unit first, so dollar size follows risk. **Portfolio construction.** Weights are set by Equal Risk Contribution: each asset contributes the same share of total portfolio variance. This is the framework behind Bridgewater's All Weather and RPAR. A volatile meme sleeve therefore carries a smaller dollar position than a metals sleeve, sized so both can hurt the portfolio by the same amount. **Volatility targeting.** The portfolio targets a fixed annualised volatility. Positions scale down as realised volatility rises and back up as it falls, so the risk profile stays stable across regimes. The program targets roughly 25% annualised, with a variant scaled to 20%. **Reversal and exit.** The target position is a continuous function of the signal, so a trend that turns produces a reversal automatically. There is no separate exit rule and no discretionary override. **Cost control.** Spread, market impact and funding are modelled per trade. Signals whose expected value sits below their expected cost are trimmed. We do not publish lookback windows, the number of horizons, the smoothing method or the weights applied to each signal. ### How the vault operates A curator service runs a cycle every 5 minutes: compute NAV from Hyperliquid and HyperEVM state, run sanity guards, and settle if a deposit or redemption is pending or if the daily settlement is due. See [How They Work](how-they-work.md). The curator reads canonical venue and chain state only. It does not read the trading bot, so a bug in the bot cannot corrupt the vault's NAV. ### Performance Live figures are in the app. Published statistics, with their windows: | Window | Net return | Sharpe | Notes | |---|---|---|---| | Apr 2025 to Apr 2026, simulated | 35.3% | 1.26 | 25% annualised volatility | | Apr 2025 to Jun 2026, simulated | 35.3% | 1.41 | 9.3% max drawdown over 92 days | Correlation to BTC is approximately -0.22 and to the S&P 500 approximately -0.39 to -0.40 over those windows. > ⚠️ **The two Sharpe figures cover different windows.** A Sharpe quoted without > its window should not be used. Sector attribution over the Apr 2025 to Apr 2026 simulated window: Metals 37% of PnL at 1.10 Sharpe, Layer-1 25% at 0.90, DeFi 17% at 0.76. Energy detracted. Some sleeves losing while the portfolio gains is the construction working. > ⚠️ **Everything before 27 May 2026 is a backtest**, run on historical execution > data net of modelled commission, slippage and funding. Modelled frictions are > not real frictions. Live execution has tracked the backtest within > approximately 7 basis points per day since inception, on a sample of weeks. ### Risk factors Trend-following loses in choppy, mean-reverting markets: the signal flips, the program pays the spread each time, and no position runs long enough to pay for the ones that did not. Extended flat-to-negative periods are the normal cost of the strategy. Execution is concentrated on one venue. A halt, exploit, socialised loss event or insolvency at Hyperliquid would affect the portfolio directly. Full breakdown: [Market & Strategy Risk](risk-market.md) and [Venue, Counterparty & Curator Risk](risk-venue.md). ### Trust and security Assets sit in a Gnosis Safe and a Lagoon ERC-7540 vault, not on our servers. The vault framework is audited by Nethermind Security and Trail of Bits; our own curator code is not audited. See [Vault Protections](vault-protections.md) and [Security](security.md). Addresses are on [Contract Addresses](addresses.md). ============================================================================== # Risk Overview https://docs.etesiar.com/risk ============================================================================== Risk sits upstream of every strategy decision we make. The first number we look at is not what the strategy made, but what it could have lost. ### The categories | Category | What it is | Covered in | |---|---|---| | Market and strategy | The strategy loses money because trends fail or reverse | [Market & Strategy Risk](risk-market.md) | | Venue and counterparty | An exchange the strategy trades on fails, halts or becomes insolvent | [Venue, Counterparty & Curator Risk](risk-venue.md) | | Liquidity and redemption | You cannot exit at the price or on the timeline you expected | [Venue, Counterparty & Curator Risk](risk-venue.md) | | Platform and smart contract | A bug in the vault, or a compromised operational key | [Security](security.md), [Vault Protections](vault-protections.md) | | Regulatory and external | Law, sanctions or jurisdictional access changes | [Regional Availability](regional-availability.md) | ### What the controls do | Control | Addresses | Mechanism | |---|---|---| | Volatility targeting | Market | Positions scale down as realised volatility rises | | Equal risk contribution | Market | No sector can dominate portfolio variance | | Sector and instrument caps | Market | Hard limits on idiosyncratic exposure | | Gross notional cap | Market, venue | Total exposure bounded as a fraction of NAV | | Separated signing keys | Platform | Valuation and settlement are different permissions | | NAV sanity guards | Platform | A valuation that fails a check is never settled | | Reduce-only closes, per-cycle locks | Venue | Bounds the damage from a malfunctioning cycle | | Signal staleness rule | Venue | Stale signal means hold the book, never flatten it | ### What the controls do not do They cannot make a losing strategy profitable, keep an external venue solvent, guarantee liquidity when the portfolio needs to exit, or protect against a bug in code that has not been audited. Specifically: - The strategy is expected to have losing years. Trend-following is a multi-year proposition. - Our own curator and executor code has not been through a third-party audit. Only the Lagoon vault framework has. - Settlement depends on our backend. Redemption is onchain, but pricing shares requires a NAV push, so an extended outage queues redemptions. - The strategy went live on 27 May 2026. There is not yet a long live track record. ### Sizing A CTA sleeve is a diversifier. Its value comes from being uncorrelated with the rest of a portfolio, which is an argument for holding some and against holding a lot. We do not publish a recommended allocation and do not give investment advice. The formal statement is at [Risk Warnings and Disclaimers](disclaimers.md). ============================================================================== # Market & Strategy Risk https://docs.etesiar.com/risk-market ============================================================================== ### The main failure mode Trend-following loses in choppy, mean-reverting markets. When price oscillates around a level rather than moving in a direction, the signal flips repeatedly. The program buys after each move up and sells after each move down, paying the spread and the impact each time, and none of the positions run long enough to pay for the ones that did not. This is the ordinary cost of the strategy, not an edge case. The payoff shape is many small losses funded by a few large gains. The 2010s were largely range-bound and the CTA category performed poorly across the decade. Expect extended flat-to-negative periods. They are not evidence that something has broken. ### Drawdown The deepest drawdown in the simulated period from April 2025 to June 2026 was 9.3%, over 92 days. > ⚠️ **That is one simulated window, not a limit.** A strategy targeting 25% > annualised volatility can draw down well beyond 9.3% without anything having > gone wrong. ### Model risk The strategy is calibrated on historical data. Trend persistence is documented over 50 years and 100+ markets, but crypto microstructure is young and evolving. The effects being harvested could weaken as these markets mature and as more capital chases them. ### Simulated performance flatters All performance before 27 May 2026 is simulated on historical execution data, net of modelled commission, slippage and funding. Modelled frictions are not real frictions. Live trading reveals costs a backtest does not contain: queue position, adverse selection, and the price impact of being the marginal participant in a thin market. Live execution has tracked the backtest within approximately 7 basis points per day since inception. That is a sample of weeks. ### Concentration of outcome The portfolio is diversified by risk contribution, not by outcome. In the simulated window one sector, Metals, produced 37% of the return while Energy detracted. That is the construction working as designed. It also means a given year's result may be dominated by a small number of sleeves, so twelve months of data is not evidence that the diversification is delivering, in either direction. ### Volatility targeting cuts both ways Scaling positions down as volatility rises bounds the risk profile. It also means the program is smallest exactly when a violent move is underway, so in a sharp sustained rally it participates less than a static-weight portfolio would. ### Leverage The public vault is fully collateralised. The strategy does not gear the portfolio to manufacture return. Perpetual positions still carry margin mechanics, covered in [Venue, Counterparty & Curator Risk](risk-venue.md). ### What would make the thesis wrong - Trends stop persisting in crypto as the market matures and the flow that created them is arbitraged away. - Correlations between sectors rise toward the levels seen inside crypto-only portfolios, removing the diversification the construction depends on. - Tokenized RWA markets stay too thin to carry a meaningful risk allocation, removing the three sleeves that supply most of the low correlation. - Live execution costs come in materially above modelled costs. ============================================================================== # Venue, Counterparty & Curator Risk https://docs.etesiar.com/risk-venue ============================================================================== The strategy trades on venues we do not control, prices itself from data we do not produce, and settles through infrastructure we operate. Each is a dependency. ### Venue risk Execution happens on Hyperliquid. A failure, exploit, halt or insolvency there affects the strategy's ability to trade or withdraw. Concretely, a venue can halt trading or withdrawals, socialise losses across users after a large liquidation event, suffer an exploit that removes collateral, or change margin and funding rules in a way that forces a position change at a bad moment. > ⚠️ **Execution is concentrated on one venue.** The live strategy trades > overwhelmingly on Hyperliquid, and there is currently little venue > diversification to absorb an event there. ### Liquidation Perpetual positions are margined. If margin requirements are breached the venue can liquidate at a price the strategy does not choose. The gross notional cap, full collateralisation and volatility targeting keep the portfolio well inside its margin requirement in normal conditions. A large gap move against a concentrated position is where they are not enough. ### Liquidity Large positions can be difficult to exit at modelled prices in thin conditions. The strategy models impact per trade, but conditions change faster than a model recalibrates. Meme markets are liquid in normal conditions and can become one-sided quickly. Tokenized RWA markets are structurally thinner than the major crypto perpetuals, which is the trade-off that comes with the low correlation they supply. ### Redemption Redemption is onchain and does not require our permission. Two things still delay it: the 7 day cooldown, and settlement, which needs a NAV push from the valuation manager. If our backend is down, requests queue. The position is not lost and the assets stay in the vault, but the exit is not immediate. > ⚠️ **If you need same-day liquidity, this is not the product.** ### Oracle and pricing NAV is computed off-chain from venue state and pushed onchain. If that computation is wrong, shares are minted or burned at the wrong price, transferring value between whoever transacts in that window and everyone else. The guards on [Vault Protections](vault-protections.md) bound the size of that error. They do not eliminate it. ### Curator and operational risk The signal engine, orchestrator, data pipelines and curator service can fail. We run monitoring with SMS escalation for a small set of critical conditions. That monitoring exists because of a real incident: in June 2026 a signing key ran out of gas and settlements froze for 34.7 hours while a single muted alert was deduplicated silently. A backend outage results in a missed rebalance and delayed settlement. A process that is dead sends no alerts. Custody configurations differ between deployments and determine what a compromised operational key can reach. See [Security](security.md), and read the Safe configuration onchain rather than relying on a documentation page. ============================================================================== # Other Deployments https://docs.etesiar.com/other-deployments ============================================================================== The flagship vault is [Etesia Multistrat](multistrat.md). The deployment below is listed for status and address verification. ### Hyperliquid Native Vault The strategy running on Hyperliquid's own vault primitive rather than through an ERC-7540 contract on HyperEVM. | | | |---|---| | Venue | Hyperliquid L1 | | Collateral | USDC | | Page | [app.hyperliquid.xyz vault `0x4b8916…d7a6`](https://app.hyperliquid.xyz/vaults/0x4b891614af47c62fe740c72811893b0a5ae6d7a6) | Share price updates from the venue's own accounting rather than at one of our settlements. > ⚠️ **Terms for this vault are set by Hyperliquid's vault mechanics**, not by > the schedule on [Fees + Redemption Period](fees.md). Read them on the vault > page before depositing. ============================================================================== # How They Work https://docs.etesiar.com/how-they-work ============================================================================== Etesia Strategy Vaults are the layer that connects your deposit to the strategy. This page explains how deposits and redemptions work, and what happens to your capital between the two. ### What the curator can and cannot do You deposit on HyperEVM. Behind the vault, capital is deployed to Hyperliquid, where the strategy trades perpetuals and spot. The trading key is registered as an agent of the Safe. It can place and cancel orders on the Safe's venue account. It cannot withdraw from the venue. Proposing a valuation and acting on it are two separate permissions held by two separate keys: the valuation manager proposes a NAV and cannot settle, the curator settles a NAV that was already proposed. For the full breakdown, see [Vault Protections](vault-protections.md). ### Depositing **1. Connect your wallet** Connect a wallet holding USDC on HyperEVM, plus a small balance of the chain's gas token. Use the canonical USDC contract listed on [Contract Addresses](addresses.md); bridged USDC from another contract is not accepted. **2. Submit a deposit request** Your USDC leaves your wallet and is held by the vault's silo contract until the next settlement. > ⚠️ **Between the request and settlement your capital is not in the strategy.** > It is not earning and it is not exposed to the strategy's positions. There is no minimum deposit and no allowlist on the public vault. **3. Shares are issued at settlement** At settlement the vault fixes a share price from the NAV computed for that moment and mints your shares against it. You then claim them; some interfaces do this for you on your next interaction. Your share price moves with the strategy from that point forward. ### Why settlement is not instant The vault holds open perpetual positions. Its net asset value cannot be read in a single contract call the way an AMM pool balance can: it has to be computed from spot balances, unrealised PnL across every venue the strategy touches, and idle stablecoins on two layers. Minting or burning shares against a stale valuation would transfer value between the person transacting and everyone already in the vault. So the vault prices shares only at a settlement, from a NAV computed and checked for that moment. ### While your capital is deployed The curator service runs a cycle every 5 minutes. It computes NAV as spot balances plus unrealised PnL across every dex plus Safe and vault USDC on HyperEVM, runs the sanity guards, and bridges USDC between HyperEVM and HyperCore as the book requires. It settles when a deposit or redemption is pending, and otherwise once per UTC day. Settling more often would cost holders money: each settlement takes management and performance fees and ratchets the high-water mark upward. The vault is configured so that a proposed NAV never applies on its own. It only takes effect through an explicit settlement. ### Withdrawing **1. Submit a redemption request** For some or all of your shares. > ⚠️ **The Multistrat vault applies a 7 day redemption cooldown** before your > request can settle. **2. Redemption period** After the cooldown, the request waits for the next settlement, because shares are priced at settlement. In normal operation that is same-day. **3. Funds return to your wallet** You claim USDC and your shares are burned. Terms are in the vault's details in the app and on [Fees + Redemption Period](fees.md). ### If our backend is offline Your assets stay in the vault and nothing moves. Settlement stops, because pricing shares requires a NAV push, so redemption requests queue until service resumes. The redemption path is onchain. The pricing that makes it executable is not. ============================================================================== # Vault Protections https://docs.etesiar.com/vault-protections ============================================================================== The mechanisms that bound what can go wrong operationally, independent of whether the strategy makes money. ### Valuation and settlement are separate permissions The valuation manager can propose a NAV and nothing else. The curator can settle a NAV the valuation manager already proposed. Neither key can do the other's job, so a single compromised operational key cannot both invent a valuation and act on it. The vault is configured so a proposed NAV never applies by timeout. It applies only through an explicit settlement. ### A valuation that fails its checks is never used Every computed NAV passes a set of guards before it can be pushed or settled: - **First NAV zero.** On a fresh vault the first NAV must be zero, so the first depositor anchors the share price at par. - **Divergence cap.** A NAV moving more than a configured number of basis points against the previous one is rejected. The HyperEVM deployment has run this at 1000 bps. - **Negative NAV is fatal.** A negative computed value halts the cycle rather than being clamped. - **Per-cycle locks.** One cycle at a time, so a slow cycle cannot overlap the next. A NAV that fails a guard produces a missed settlement, not a mispriced one. The first-NAV-zero rule exists because of a real failure. On a test vault a curator pushed an inflated first valuation, and the resulting share price of roughly 27 times par was permanent: the framework has no in-band way to unwind it. ### The trading key cannot withdraw On Hyperliquid the trading key is registered as an agent of the Safe. It can trade the account and cannot move funds out of it. ### Venues and assets are allowlisted Every asset and venue adapter sits on an admin-maintained allowlist. An unlisted venue cannot be used by the execution layer. ### Execution bounds are enforced, not requested Slippage bounds are computed from onchain TWAP prices rather than supplied by the backend. A minimum cooldown enforces spacing between rebalances. Aggregate notional per rebalance is capped as a fraction of NAV. A proposal that violates any of these is rejected atomically; there is no partial execution. ### Stale signal means hold, never flatten If the signal is stale the strategy holds its current book rather than closing it. Flattening on stale data would turn an information outage into a realised loss, at the moment the system knows least about the market. ### Fee changes are delayed onchain Fee rates sit behind a 24 hour cooldown. A change is visible as pending before it takes effect. ### Emergency procedures The curator has an eject subsystem: an operator-triggered evacuation of the vault's Hyperliquid footprint back into the Safe. It is not a user-facing pause, and there is no Guardian role in the deployed contracts. ### Monitoring The curator pages a human on a signing key running low on gas, three consecutive failed cycles, and no successful NAV push within a watchdog window. Critical conditions escalate by SMS rather than chat alone. That design followed an incident: in June 2026 a signing key ran out of gas and settlements froze for 34.7 hours while a single muted chat alert was deduplicated silently. ============================================================================== # Security https://docs.etesiar.com/security ============================================================================== ### Smart contract audits Our EVM vaults are built on [Lagoon](https://lagoon.finance)'s ERC-7540 vault infrastructure. Lagoon, built by Hopper Labs, is our vault infrastructure partner. Lagoon publishes eleven reviews on [its audits page](https://docs.lagoon.finance/resources/audits), running from v0.1.0 in September 2024 to v0.6.0 in May 2026: | Firm | Coverage | |---|---| | Nethermind Security | Eight reports across the release history, plus the January 2026 bug disclosure | | Trail of Bits | Two reports, covering v0.5.0 and v0.6.0, the versions our vaults run | The audited source is public at [github.com/hopperlabsxyz/lagoon-v0](https://github.com/hopperlabsxyz/lagoon-v0) under the Business Source License 1.1, with `src/v0.5.1/` and `src/v0.6.0/` matching those versions. Nethermind has written up the engagement at [Securing Lagoon's Asynchronous ERC-7540 Vaults](https://www.nethermind.io/blog/securing-lagoons-asynchronous-erc-7540-vaults-as-the-protocol-scaled-from-v1-to-v5). ### Custody Working capital sits in a Gnosis Safe with three owners. Shares and accounting sit in the Lagoon vault contract. Neither is on our balance sheet or our servers. Settlement and bridging are signed by the curator as Safe transactions. The [Hyperliquid Native Vault](other-deployments.md) is custodied by the venue's own vault mechanics and does not use this structure. ### Verify it yourself Owner sets, thresholds and enabled modules are public. Verify directly: ```bash RPC=https://rpc.hyperliquid.xyz/evm SAFE=0x33b7C2cE82784d79E7d658961fC74E0838b23a93 cast call --rpc-url $RPC $SAFE 'getOwners()(address[])' cast call --rpc-url $RPC $SAFE 'getThreshold()(uint256)' cast call --rpc-url $RPC $SAFE 'getModulesPaginated(address,uint256)(address[],address)' \ 0x0000000000000000000000000000000000000001 10 ``` ### Scoped signing keys Zodiac Roles Modifier v2 is the mechanism we use to restrict a curator key to a fixed set of calls. Under that configuration the key becomes the sole member of a role permitted to make exactly these calls: | Call | Constraint | |---|---| | `USDC.approve(spender, amount)` | Spender pinned to the canonical core deposit wallet | | `CoreDepositWallet.deposit(amount, dex)` | Target pinned, destination dex pinned to spot | | `CoreWriter.sendRawAction(spotSend(...))` | Destination pinned to the Safe, token pinned to USDC | | `CoreWriter.sendRawAction(addApiWallet(...))` | API wallet address pinned | | `settleDeposit` / `settleRedeem` | On the vault | The pinning uses bitmask conditions on the raw action bytes, which are the security boundary: five conditions pin the version byte, the action id, the destination address and the token id. Before a role is applied onchain, a sample payload is decoded byte by byte and each masked region compared against the definition, and a ten-case suite then exercises the deployed role, including cases that must revert. A flaw in Zodiac Roles Modifier v2.1.0 was disclosed in June 2026 and patched in the audited v2.1.1. ### Operational security Admin authority, meaning role reassignment and fee changes, is held on a Ledger and is not used day to day. Fee changes are additionally delayed 24 hours onchain. Vault-level protections are covered separately on [Vault Protections](vault-protections.md). ### Reporting a vulnerability Write to [contact@etesiar.com](mailto:contact@etesiar.com). Please do not open a public issue. There is no bug bounty and no published disclosure policy or response-time commitment. ============================================================================== # Separately Managed Accounts https://docs.etesiar.com/sma ============================================================================== For allocators who need a mandate rather than a public vault: foundations, treasuries, funds of funds, family offices. **Contact: [contact@etesiar.com](mailto:contact@etesiar.com).** ### Why not the public vault [Etesia Multistrat](multistrat.md) is permissionless. Anyone can deposit. That carries consequences an institutional allocator usually cannot accept: - No mandate. You get the strategy as run for everyone, with no ability to restrict the universe, cap leverage, exclude a venue or set your own volatility target. - No segregation. Your capital is commingled with every other depositor's. - No side letter, no reporting agreement, no MFN. Terms are whatever the contract says on the day. - Fees are the contract's: 1% management and 20% performance, as published on [Fees + Redemption Period](fees.md). - Onboarding is a wallet. There is no counterparty relationship and no KYB. ### What is negotiated | | | |---|---| | Trading universe | Which sectors and instruments are in scope, and which are excluded | | Volatility target | The public program runs near 25% annualised. An SMA sets its own. | | Leverage | Available under a defined mandate. Not applied to the public vault. | | Fees | Negotiated on size and complexity. Not the schedule on [Fees](fees.md). | | Reporting | Format, frequency and content | | Custody | Connection via an exchange account or an institutional custodian you already use | We can connect through OKX, Binance, Hyperliquid, or institutional custody providers such as Copper and Hidden Road. Confirm the current list when we talk. ### What we can show you today The mechanical description of the strategy in this documentation. Onchain verifiability of the live vault, down to its fee rates and custody configuration. The vault framework's audits by Nethermind Security and Trail of Bits. A live track record from 27 May 2026, and a simulated one before it, with every figure carrying its window. Some of what a full due diligence process asks for does not exist yet, and we would rather say so here than in week three of a process: | Item | Status | |---|---| | Administrator-verified or audited performance | None. Figures are our own. | | Third-party audit of our own curator and executor code | None | | Fund administrator, auditor, independent valuation agent | None appointed | | Regulatory status | Etesia Research Inc. is not a regulated asset manager | We are early. Ask for dates rather than assuming, in either direction. ### Questions worth putting in the first email 1. What is the legal entity, where is it domiciled, and what is its regulatory status in your jurisdiction and ours? 2. Who are the principals, what did they run before, and how much of their own capital is in the strategy? 3. What is current AUM, and what is the stated capacity of the program? 4. What is the custody configuration of the account you would run for us, who holds each key, and where? 5. Is the 1% management fee the long-term schedule, and if it changes, what happens to fees already accrued? 6. Which Sharpe figure is the reference one, and may we see the underlying return series rather than summary statistics? 7. Who else has allocated, and may we speak to them? 8. What does a monthly report contain, and may we see a sample? ### Process There is no published onboarding flow, no minimum and no standard timeline. Write to [contact@etesiar.com](mailto:contact@etesiar.com) and expect a conversation rather than a data room. A mutual NDA is available. ============================================================================== # Distributors https://docs.etesiar.com/distributors ============================================================================== For platforms, wallets and aggregators listing an Etesia vault in front of their own users. ### What you are listing A Lagoon ERC-7540 vault. If your platform already supports ERC-4626 and can handle an asynchronous request-and-claim flow, you already support these. See [API & SDK](api-sdk.md) for the call surface. ### What must be carried across These are the terms a user cannot discover from a share price, and a listing that omits them misleads: - The **7 day redemption cooldown** on the Multistrat vault, and that redemption additionally waits for the next settlement. - The **1% management fee and 20% performance fee**, read live from `feeRates()` rather than hardcoded. - That deposits and redemptions **settle asynchronously**, so a deposit is not immediately in the strategy. - That the strategy is **directional and can lose money**. This is not the profile of a lending or basis vault your users may be used to. - A link to [Risk Warnings and Disclaimers](disclaimers.md). ### Displaying returns Compute return from the change in share price over a stated period. There is no published rate and the vault has no fixed yield. Do not annualise a short window. See [APY and APR](apy.md). ### Assets We have not published a brand kit. Ask at [contact@etesiar.com](mailto:contact@etesiar.com). ### Getting in touch [contact@etesiar.com](mailto:contact@etesiar.com). There is no self-serve listing process. ============================================================================== # API & SDK https://docs.etesiar.com/api-sdk ============================================================================== ### What exists We publish no API, no SDK, no subgraph and no price feed. Read the vault contract directly with viem, ethers or your existing ERC-4626 tooling. Lagoon publishes a TypeScript SDK (`sdk-v0`) and a `vault-computation-cli` at [github.com/hopperlabsxyz](https://github.com/hopperlabsxyz), which may save you writing the accounting. If you need something that does not exist, ask at [contact@etesiar.com](mailto:contact@etesiar.com). It is a question of demand, not policy. ### The async flow ```mermaid sequenceDiagram participant U as User participant V as Vault participant S as Silo participant C as Curator U->>V: requestDeposit(assets, controller, owner) V->>S: assets held pending C->>V: settleDeposit(...) Note over U,S: claimable U->>V: deposit(assets, receiver) V->>U: shares ``` Redemption mirrors this with `requestRedeem`, then `settleRedeem`, then `redeem` or `withdraw`, with the cooldown applying before the request can be settled. ### Calls **Requesting** | Call | Notes | |---|---| | `requestDeposit(uint256 assets, address controller, address owner)` | Pulls assets to the silo. Requires prior ERC-20 approval. | | `requestRedeem(uint256 shares, address controller, address owner)` | Shares are escrowed, not yet burned. | **Checking state** | Call | Notes | |---|---| | `pendingDepositRequest(uint256 requestId, address controller)` | Assets awaiting settlement | | `claimableDepositRequest(uint256 requestId, address controller)` | Settled, awaiting claim | | `pendingRedeemRequest(...)` / `claimableRedeemRequest(...)` | Redemption equivalents | **Claiming** | Call | Notes | |---|---| | `deposit(uint256 assets, address receiver)` | Claims settled shares | | `redeem(uint256 shares, address receiver, address owner)` | Claims settled assets | **Reading** | Call | Notes | |---|---| | `totalAssets()` | Asset decimals, 6 for USDC | | `totalSupply()` | Share decimals, 18 | | `asset()` | The underlying token | | `feeRates()` | `(managementRate, performanceRate)` in bps | | `safe()` | The address holding working capital | ### Gotchas **Decimals.** Shares are 18 decimals, USDC is 6. Share price is `totalAssets * 1e18 / totalSupply`, interpreted in asset decimals. Getting this wrong by a factor of 10^12 is the most common integration bug on these vaults. **`convertToShares` and `convertToAssets` are indicative.** They use the last settled `totalAssets`. Between settlements they do not reflect the live portfolio. **`previewDeposit` may revert.** ERC-7540 vaults are permitted to revert on the ERC-4626 preview functions, because a synchronous preview would be a lie. Handle it. **No fresh price between settlements.** A proposed NAV never auto-applies, so polling for one outside a settlement will not find it. **Requests are per controller.** The `controller` and `owner` parameters let a contract request on a user's behalf. Read the ERC-7540 spec on operator approval before assuming your address can claim. ### ABI Take it from [github.com/hopperlabsxyz/lagoon-v0](https://github.com/hopperlabsxyz/lagoon-v0) (`src/v0.6.0/` for Multistrat), from [Lagoon's documentation](https://docs.lagoon.finance), or from a verified contract on the explorer. ### Machine-readable documentation | File | Contents | |---|---| | [`/llms.txt`](https://docs.etesiar.com/llms.txt) | Curated index, per the llmstxt.org convention | | [`/llms-full.txt`](https://docs.etesiar.com/llms-full.txt) | Every page concatenated in sidebar order | | `/md/.md` | Any page as raw markdown | ============================================================================== # Fees + Redemption Period https://docs.etesiar.com/fees ============================================================================== Rates below are read from the vault contract, which is authoritative. Last verified 2026-08-12. | | Rate | |---|---| | Management fee | 1.00%, 100 bps annual | | Performance fee | 20%, 2000 bps, above the high-water mark | | Deposit fee | None | | Withdrawal fee | None | | Redemption cooldown | 7 days | | Fee-change cooldown, onchain | 24 hours | Verify: ```bash cast call --rpc-url https://rpc.hyperliquid.xyz/evm \ 0xe6b30da13c2c97aacd8ba3df4e97977725847fca "feeRates()(uint16,uint16)" # 100 2000 ``` A rate change requires an owner transaction and takes effect after the 24 hour onchain cooldown, so a pending change is visible before it applies. ### How fees are taken Fees are not deducted from a balance. They are minted as new shares to the fee receiver at settlement, which dilutes every existing holder in proportion. **Management fee.** Accrues on assets under management, pro-rated by the time since the last settlement. A vault settling once a day takes it once a day. **Performance fee.** Charged on gains above the high-water mark, so the same gain is never charged twice. If the share price falls and recovers, no performance fee is taken until it passes its previous peak. Lagoon takes a protocol cut of 1000 bps on the performance fee. That comes out of our 20%, not on top of it. Because each settlement takes fees and ratchets the high-water mark upward, the curator settles once per UTC day rather than on every cycle. See [How They Work](how-they-work.md). ### Redemption period > ⚠️ **Redemptions carry a 7 day cooldown.** After the cooldown, the redemption waits for the next settlement before it can be claimed, because shares are priced at settlement. In normal operation that is same-day. The 7 day redemption cooldown and the 24 hour fee-change cooldown are unrelated parameters. ### Separately managed accounts SMA fee terms are negotiated per mandate and are not the schedule above. See [Separately Managed Accounts](sma.md). ============================================================================== # APY and APR Calculations https://docs.etesiar.com/apy ============================================================================== We do not quote an APY. APY is meaningful for a product with a rate: a lending market, a basis trade, a staking position. Those earn a spread that is roughly stable over short windows, so annualising a recent window estimates the next one. A trend-following program has no rate. Its return is directional and its distribution is wide: many small losses funded by a few large gains. A strong month annualises to a figure the strategy will not repeat; a flat month annualises to zero. Either would mislead. ### What to compute instead Return over a stated period, from the change in share price: ``` return = (sharePrice_end / sharePrice_start) - 1 sharePrice = totalAssets / totalSupply ``` adjusted for the difference between the 6-decimal asset and the 18-decimal share token. Always show the period next to the number. ### If you must annualise Use a window of at least a year and label it a realised return over that window, not a forward-looking yield. For anything shorter, show the raw period return. The formula relating a simple rate to a compounded one: ``` APY = (1 + APR/365)^365 - 1 ``` It does not turn a two-week return into a yield. ### Fees are already in the number Both the management and performance fee are minted as shares at settlement, which dilutes the share price. A return computed from share price is therefore net. Do not subtract fees again on top of a share-price return. ============================================================================== # Contract Addresses https://docs.etesiar.com/addresses ============================================================================== Verify anything on this page against the chain before you rely on it. Addresses change when a vault is redeployed, and a documentation page is not a source of truth. ## HyperEVM, chain 999 Etesia Multistrat, the current production vault. Read onchain 2026-08-09. | Role | Address | |---|---| | Vault | `0xe6b30da13c2c97aacd8ba3df4e97977725847fca` | | Silo | `0xc1A7c99bff40314Fa1CD046eCa14872743b2E287` | | Safe, also `vault.owner()` | `0x33b7C2cE82784d79E7d658961fC74E0838b23a93` | | Curator EOA, a Safe owner | `0x678820c67B7a98F72C21b38c53217C23b13fb454` | | Ledger admin, a Safe owner | `0x9F2F3f48aE7563096452a0573DD6e774321f3D11` | | Third Safe owner | `0x145706E76746a2A5752860ABc2322e505bF92782` | | API wallet, Hyperliquid agent | `0xbeaF8bC9d08Af2232e1E249e964d42cFFfD6d3c9` | | USDC | `0xb88339CB7199b77E23DB6E890353E22632Ba630f` | | Core deposit wallet, USDC bridge | `0x6b9e773128f453f5c2c60935ee2de2cbc5390a24` | | CoreWriter | `0x3333333333333333333333333333333333333333` | See [Security](security.md) for the authority model and the commands to read the Safe's current configuration. ### Retired: the v0.5 HyperEVM deployment Kept here so the address is identifiable rather than mysterious. **Do not deposit.** | Role | Address | |---|---| | Vault | `0xb718bdaa857d5ab82c09c7f0c75bfba2f831090a` | | Safe | `0xF99aC94E1630a28D4Cb8d340efE16303933db63b` | | Silo | `0x07FD359821013BD48EEF7EF46475A90e0f429B2f` | | Roles modifier | `0x1b62fc543e0F391ff25B271909939635D4f45a1e` | | Valuation oracle | `0x27C65382243F5eB63AFb10808A6130b9Df362eDc` | | API wallet | `0xf4948c13746b508ca1143d8FD25B0A4c460117f9` | ## Hyperliquid L1 The native vault is addressed by its Hyperliquid vault page rather than by an EVM contract. See [Other Deployments](other-deployments.md). ## Verifying ```bash RPC=https://rpc.hyperliquid.xyz/evm V=0xe6b30da13c2c97aacd8ba3df4e97977725847fca cast call --rpc-url $RPC $V "name()(string)" cast call --rpc-url $RPC $V "asset()(address)" cast call --rpc-url $RPC $V "feeRates()(uint16,uint16)" cast call --rpc-url $RPC $V "safe()(address)" ``` Explorer: [hyperscan.com](https://www.hyperscan.com) for HyperEVM. ============================================================================== # Glossary https://docs.etesiar.com/glossary ============================================================================== Terms as this documentation uses them. ### Strategy **Systematic CTA.** A manager running trend-following and related strategies on a mechanical, price-derived signal, with no discretionary override. The managed-futures model institutional funds have run since the 1970s. **Trend following.** Long what is rising, short what is falling. The payoff is many small losses funded by a few large gains. See [Etesia Multistrat](multistrat.md). **Equal risk contribution.** Portfolio weights chosen so every asset contributes the same share of total portfolio variance, rather than weighting by market capitalisation. **Volatility targeting.** Scaling positions so realised portfolio volatility stays near a fixed level across market regimes. **Sharpe ratio.** Return per unit of volatility. Meaningless without the window it was measured over, which is why every Sharpe on this site carries one. **Drawdown.** The fall from a peak in the equity curve to the subsequent trough. **High-water mark.** The highest share price at which a performance fee has been charged. Gains below it are never charged twice. **Perpetual.** A futures contract with no expiry, held in line with spot by a periodic funding payment between longs and shorts. **Funding.** That periodic payment. A cost or a revenue depending on the side of the position. **Tokenized RWA.** A real-world asset represented onchain. In our universe: the metals, energy and equity-index sectors. ### Vault mechanics **ERC-4626.** The standard interface for a tokenized vault with synchronous deposits and redemptions. **ERC-7540.** An asynchronous extension of ERC-4626: you request, the vault settles at a valuation computed for that moment, then you claim. Necessary when a vault's value cannot be read in one call. See [How They Work](how-they-work.md). **Lagoon.** The vault framework our EVM vaults are built on, by Hopper Labs. Audited; see [Security](security.md). **Silo.** The contract holding assets between a deposit request and its settlement. **Settlement.** The moment the vault fixes a share price from a proposed NAV and mints or burns shares against it. We settle when a deposit or redemption is pending, otherwise once per UTC day. **NAV.** Net asset value: what the vault's portfolio is worth, computed from venue and chain state. **Share price.** `totalAssets / totalSupply`, restated at each settlement. Mind the decimals: shares carry 18, USDC carries 6. **Redemption cooldown.** The 7 day wait between a redemption request and its settlement on the Multistrat vault. ### Roles and infrastructure **Curator.** On this site, our own settlement role: the authority that settles deposits and redemptions and bridges between layers. Elsewhere in DeFi the word can mean a third-party risk manager selecting markets for a vault. **Valuation manager.** The key permitted to propose a NAV, and nothing else. Proposing and applying are separate permissions. **Safe.** A Gnosis Safe multisig holding the vault's working capital. **Zodiac Roles Modifier.** A Safe module that restricts a key to specific calls with specific parameters, so it can act without holding full Safe authority. **API wallet, agent.** On Hyperliquid, a delegated key registered to trade an account without being able to withdraw from it. **Eject.** Our operator-triggered evacuation of the vault's Hyperliquid footprint back into the Safe. ### Venue **Hyperliquid.** The perpetuals exchange the strategy executes on, with its own L1 and an EVM layer. **HyperEVM.** Hyperliquid's EVM chain, id 999, where the Multistrat vault lives. **HyperCore.** Hyperliquid's trading layer, as distinct from HyperEVM. USDC is bridged between the two by the curator. ============================================================================== # Frequently Asked Questions https://docs.etesiar.com/faq ============================================================================== ### What am I depositing into? [Etesia Multistrat](multistrat.md), a Lagoon ERC-7540 vault on HyperEVM running a systematic trend-following program on Hyperliquid. You deposit USDC and receive `etesiaUSDC` shares that track the strategy's NAV. ### Is there a minimum deposit? No. There is no minimum and no allowlist on the public vault. ### What are the fees? 1% management and 20% performance above the high-water mark. No deposit fee, no withdrawal fee. Read them from the contract yourself: ```bash cast call --rpc-url https://rpc.hyperliquid.xyz/evm \ 0xe6b30da13c2c97aacd8ba3df4e97977725847fca "feeRates()(uint16,uint16)" ``` [Fees + Redemption Period](fees.md) has the mechanics. ### Is there a lock-up? Redemptions carry a 7 day cooldown, then settle at the next settlement. In normal operation that settlement is same-day. ### Why is my deposit still pending? Deposits settle when the curator next settles: when a deposit or redemption is pending, or otherwise once per UTC day. Between your request and settlement your USDC sits in the silo, not in the strategy. If it has been longer than a day, write to [contact@etesiar.com](mailto:contact@etesiar.com). ### Can I lose money? Yes. The strategy is directional, long and short, and it has extended losing periods by construction, particularly in choppy markets. This is not a yield product. Read [Risk Overview](risk.md) before depositing. ### Is the track record live or simulated? The strategy went live on 27 May 2026. Everything before that date is a backtest with modelled costs. Published figures carry their windows on [Etesia Multistrat](multistrat.md). ### Who holds custody? A Gnosis Safe and the Lagoon vault contract, not our servers. Owner sets, thresholds and modules are public; [Security](security.md) gives you the commands to read them. ### What happens if Etesia's backend goes down? Your assets stay in the vault and nothing moves. Settlement stops, because pricing shares requires a NAV push, so redemption requests queue until service resumes. ### Is the code audited? The Lagoon vault framework is, by Nethermind Security and Trail of Bits. Our own curator and executor code is not, and there is no public bug bounty. [Security](security.md) has the reports and the scope. ### How is this different from a crypto index or a yield vault? An index is long-only: it falls when the market falls. A yield vault earns a rate with no directional upside. We can be long or short, target a level of volatility rather than a rate, and are structurally uncorrelated to both crypto and equities. [Our Thesis](thesis.md) is the full argument. ### Is there an API? No. Read the vault contract directly; [API & SDK](api-sdk.md) covers the call surface and the gotchas. ### Can I get a separately managed account? Yes, for allocators who need a mandate: own universe, own volatility target, negotiated fees, agreed reporting. [Separately Managed Accounts](sma.md), then [contact@etesiar.com](mailto:contact@etesiar.com). ### How do I start? [app.etesiar.com](https://app.etesiar.com). Connect a wallet holding USDC on HyperEVM and submit a deposit request. [How They Work](how-they-work.md) walks through the flow. ============================================================================== # Risk Warnings and Disclaimers Statement https://docs.etesiar.com/disclaimers ============================================================================== Nothing on this site is an offer to sell, a solicitation to buy, or investment advice. This statement is provided for information and is not legal advice. Read it before depositing. ### You can lose money The strategy is directional. It takes long and short positions in perpetual futures and it can lose. Trend-following has extended losing periods by construction, particularly in choppy markets. The deepest drawdown in the simulated period was 9.3% over 92 days. That is one window's outcome, not a limit. ### Most of the track record is simulated The strategy went live on 27 May 2026. Everything before that is a backtest with modelled costs. Simulated results routinely overstate what follows. The live sample is weeks long. ### Audit scope Lagoon's vault framework has been reviewed by Nethermind Security across its release history and by Trail of Bits on the two versions our vaults run. Those reports are public. Our own curator services, NAV computation, executors and permission configuration have not been audited, and there is no public bug bounty. Lagoon published a low-level bug disclosure in January 2026, after those reviews. An audit is evidence of effort, not a guarantee. ### Redemption is not immediate A 7 day cooldown, then a wait for the next settlement, which depends on our backend being alive to push a NAV. An extended outage queues redemptions for as long as it lasts. ### Operational keys are a live risk surface The strategy is driven by hot keys that sign continuously: a valuation manager pushing NAV, a curator settling, a trading key sending orders. Custody models differ between deployments and the authority each key holds differs with them. Do not rely on a documentation page for this. Read the Safe's owner set, threshold and modules onchain before you deposit, and re-read them if you hold a position for any length of time. Commands are on [Security](security.md). ### Venue risk is concentrated The live strategy executes overwhelmingly on Hyperliquid. A halt, exploit, socialised loss event or insolvency there would affect the portfolio directly. ### Other risks **Oracle and pricing.** NAV is computed off-chain. An error inside the guard bounds still prices shares wrongly and transfers value between whoever transacts in that window and everyone else. **Liquidity.** Large positions can be hard to exit at modelled prices in thin conditions, particularly in the tokenized RWA sleeves. **Model risk.** The strategy is calibrated on history and the effects it harvests could weaken as these markets mature. **Regulatory.** See [Regional Availability](regional-availability.md). **Operational.** Off-chain infrastructure can fail. Redundancy and monitoring are in place; outages remain possible. ============================================================================== # Regional Availability https://docs.etesiar.com/regional-availability ============================================================================== **Etesia Research Inc.** is the operating entity. It is not a regulated asset manager, and depositing into the vaults gives you none of the protections that come with investing in a regulated fund. The public vault is a permissionless smart contract. There is no geographic gating and no KYC at the point of deposit. Whether you may lawfully use it is your own determination, and nothing on this site is an invitation directed at any particular jurisdiction. The regulatory position of digital assets and onchain asset management is evolving. Changes in law or regulatory action could affect the availability or operation of these products in some jurisdictions. ### Sanctions screening We operate our vaults with Lagoon's Access Manager in blacklist mode, wired to an onchain sanctions list. Screening is enforced by the vault contract, so it applies to every deposit regardless of the interface used to submit it, and we cannot waive it for an individual address. Lagoon documents the mechanism as follows: the Access Manager can "block specific addresses from interacting with the vault", can "integrate with a third-party on-chain sanctions list for automated compliance checks", and sanctioned addresses "are blocked regardless of the active access mode". Blacklist mode is set at vault creation rather than toggled afterwards. See [Access Manager](https://docs.lagoon.finance/vault/roles-and-capacities/whitelist-manager). This addresses sanctions screening at the point of deposit. It is not a KYC programme and not a restricted-jurisdictions policy. ### Policies Terms of use, a privacy policy and a formal jurisdictional policy have not yet been published. For a question about availability in your jurisdiction, write to [contact@etesiar.com](mailto:contact@etesiar.com).