Demo on a mainnet fork: the real Upside program, the real Voltr and Phoenix programs, live Phoenix prices; only the USDC is test money. Nothing here is real money. What that means
upside

This demo runs on a mainnet fork

Demo on a mainnet fork: the real Upside program, the real Voltr and Phoenix programs, live Phoenix prices; only the USDC is test money. Nothing here is real money.

The site you are looking at is wired to a Surfpool fork of Solana mainnet, not to mainnet itself. A fork is a private copy of the chain: the real programs and the real accounts are snapshotted from mainnet, but every transaction you send lands only on the copy. Your wallet sees the fork because the site tells it to sign for solana:localnet and submits to the fork's RPC; balances shown here are read from the fork, and the explorer links open with ?cluster=custom so they resolve against it too.

  • The programs are real. Our Upside adaptor is deployed on the fork at its real program id, and Voltr and Phoenix Perpetuals are the actual mainnet programs, byte for byte. Minting really deposits into a Voltr vault and the keeper really trades on Phoenix.
  • Prices are real. The keeper reads Phoenix's live marks, so NAV moves with the actual market and every rebalance you see was priced off a real print.
  • The order book is not. Phoenix's book on the fork is a snapshot refreshed from mainnet; fills on the fork do not touch real liquidity and depth can look stale between refreshes.
  • Only the USDC is test money. The Get test funds button asks the fork to write 2 SOL and 10,000 USDC into your wallet (surfpool cheatcodes; once per wallet every 10 minutes). It exists only on the fork; your mainnet balances are untouched and are not what this site shows.
  • Wallets. Recommended: Backpack or Solflare with the wallet's custom RPC set to https://rpc.upside.cx, so your wallet shows fork balances and simulates correctly. Phantom works for signing but displays mainnet balances and warns that the transaction may fail; approve anyway. The site only ever asks the wallet to sign; it submits the signed transaction to the fork itself and confirms it there.
  • The fork can be reset. Balances, positions and tokens you minted may disappear when the demo is redeployed or the fork is rolled back to mainnet state.

Everything else on this page describes the mechanism as it will run on mainnet.

How it works

Each token is an ordinary SPL token. Holding it gives you a fixed multiple of an underlying’s daily return: u-tokens are long, d-tokens are short. You never open a margin account and you are never liquidated. The protocol runs the position for everyone at once.

  1. 1Vault

    A Voltr vault holds USDC and mints the token as its LP share. Voltr does the share accounting, the fees and the withdrawal queue. Audited by Sec3, FYEO and Certora.

  2. 2Adaptor

    Our adaptor program is the only thing allowed to move vault funds, and only into one place: a Phoenix Perpetuals trader account owned by the vault's strategy authority. No human key holds the position.

  3. 3Phoenix

    The adaptor keeps a perpetual position sized to the target leverage. Collateral is posted from the vault; the rest stays idle in USDC so redemptions and Jupiter sells are instant.

A keeper cranks the vault’s NAV every 20–30 seconds during exchange hours, keeps the leverage inside its band, keeps the margin between floor and ceiling, and refreshes an on-chain stop so the position is protected even if every keeper is down. Everything it does is written to a database that this site reads directly; see any token’s Transparency page.

Token price (NAV per token) = (vault idle USDC + collateral at Phoenix + unrealised PnL − accrued fees) ÷ token supply. Tokens launch at 1.00 USDC and there are no reverse splits, so the price drifts away from 1.00 in both directions over time. You mint by depositing USDC at the token price and redeem by burning tokens at the token price, instantly from idle USDC or through a short request when the amount exceeds it.

Issuance
0.05%
Redemption
0.05%
Management
1.00% / yr
Performance
0%

Issuance and redemption fees cover the position change your mint or redeem forces on Phoenix; they may rise to 15–25 bps once organic volume exists. Profit from a crank is released over 24 hours (Voltr’s locked-profit decay) so a stale NAV cannot be arbitraged. Jupiter quotes the last cranked NAV; anyone can crank.

Rebalancing policy

Target leverage is 3x on US500 and US100, 2x on everything else (how we choose it). Realised leverage (notional ÷ NAV) drifts as the price moves; the keeper only trades when it leaves the band. The ruler below is uGOLD at 2x; each token page shows its own.

Leverage policy
1.80x2.00x2.30x2.60x
Band 1.8x2.3x
Inside: nothing happens. Above the top: reduce to target at any hour. Below the bottom: add exposure, but only while the external index is live.
Hard delever 2.6x
Market order back to target whatever the session. Slices are capped at 20% of visible depth within 0.5%.
Margin 17.932.1% of notional
Venue equity (collateral plus unrealised PnL) is held at 25.0% of the position's notional, which is 50.0% of NAV at 2x. Lower tiers post more collateral (D27): the target is about half of NAV at every leverage, so a 2x token can absorb a larger unattended move than a 3x one. Below the floor the keeper tops up from idle; above the ceiling it withdraws to idle. A Phoenix conditional stop sits at the floor price as a keeper-independent backstop.

Tokens carry their own policy; the numbers above are from uGOLD. Each token page shows its own band.

How we choose leverage

3x on US500 and US100, 2x on everything else. There is no 1.5x tier. That is decision D26: 1.5x is not a product people want, demand is concentrated in the volatile single names, and the answer to decay is disclosure at the point of trade rather than refusal. So every token page carries a plain-language decay disclosure under the mint panel, with that token's measured cost over 24-hour, 7-day and 30-day holds from the last year and a link to the simulator. Gold at 2x was accepted knowingly. The decision would be revisited if live data showed holders systematically burnt despite the disclosure.

Separately, a published rule grades every Phoenix market on four caps — a decay budget no worse than the US 500 at 3x, the worst overnight gap the keeper could not act inside, the venue's own leverage cap, and how much history exists — and awards a tier of 3x, 2.5x, 2x, 1.5x or not listed. Applied to the 17 of the 17 markets we list that it has graded so far, the rule would put 1 at 3x, 1 at 2.5x, 2 at 2x, 2 at 1.5x and would not list 11 of them at all. That grade is shown on each token page as a risk grade; it drives the disclosure, not the listing. The full table, with the rule written out, is the listing grades.

Collateral scales with the tier. Decision D27: the venue-equity target is about half of NAV at every leverage — 17.5% of notional at 3x, 20% at 2.5x, 25% at 2x — with the floor and ceiling in the same proportions to the target as before. With a flat share of notional, lowering a market's leverage bought it no protection against a gap at all; posting more at lower tiers means a 2x token survives an unattended move of about 19% and a 3x one about 11%. Idle USDC at lower tiers is plentiful, so the extra collateral costs holders nothing. It would change if Phoenix changed its maintenance margin.

TierAssetsBandHard deleverVenue equity targetSurvives unattended
3xUS500 US1002.7x3.3x4.0x17.5% of notional · 52.5% of NAV11% (hard delever first)
2xGOLD SILVER WTIOIL TSLA NVDA AAPL MSTR COIN HOOD SPCX SNDK MU PLTR LLY MRNA1.8x2.3x2.6x25.0% of notional · 50.0% of NAV19% (hard delever first)

From the product registry. "Survives unattended" is the smaller of the move to the hard-delever line and the move from the margin target to Phoenix's 3.5% maintenance margin with no top-up in between, which is what an overnight gap is. Grades as of 2026-09-12 are the rule's answer, labelled 3x / 2.5x / 2x / 1.5x / not listed; leverage is D26's.

Weekends and impact pricing

Stocks and metals have exchange hours; the tokens do not. While the underlying’s exchange is open (external), Phoenix marks track the external index and everything runs normally. When it is closed (impact), Phoenix prices the market from its own order flow, bounded to 1/max-leverage away from the last external print. NAV marks to that price, the keeper cranks less often, and only defensive rebalances run, so a weekend gap can move the token before the exchange reopens. The session is shown on every token page.

Decay

Try the simulator: replay any token over any window since 2006 and roll the same hold across every start date.

A constant-leverage product compounds daily. In a trending market it beats 2× the period return; in a choppy market it loses to it, because every rebalance buys after a rise and sells after a fall. Add fees and funding and the token bleeds relative to the underlying when the price goes nowhere. This is a trading instrument, not a long-term holding.

TokenLevDecay 1 wk4 wks1 yrWorst yrFunding ±10%/yr, per wk
uGOLD2x0.08%4.2%±0.38%
dGOLD2x0.23%12.1%±0.38%
uMSTR2x0.79%41.2%±0.38%
dMSTR2x2.50%130.2%±0.38%
uUS1003x0.31%1.2%16.2%55%±0.58%
dUS1003x0.68%2.7%35.3%123%±0.58%
uUS5003x0.25%1.0%13.1%60%±0.58%
dUS5003x0.50%2.0%26.0%121%±0.58%
uWTIOIL2x0.33%17.0%±0.38%
dWTIOIL2x0.92%47.6%±0.38%

Decay is the simulated cost of holding for an average week, four weeks and a year (volatility drag plus fees, slippage and management), with the worst simulated year alongside, from the risk sheet §3b. Funding is not in those numbers: at ±10%/yr it costs the paying side about 0.38% a week at 2x (rate × leverage ÷ 52), paid by longs when the rate is positive and by shorts when it is negative. For index and gold holders at a days-to-weeks horizon, funding is the larger cost, and direction dwarfs both. The live rate is shown per token from the keeper's snapshots.

Tracking error, turnover, gap history and drawdown-to-trigger for 2x, 2.5x and 3x are in the risk sheet (docs/RISK_SHEET.md). Leverage is set per asset when its vault is created and cannot change on a live token; which tier each asset gets, and why, is under How we choose leverage.

Risks

  • Venue risk. Phoenix Perpetuals is in beta. Parameters can change, books can thin out, and auto-deleveraging or backstop mechanisms can act on our position. Caps are tied to open-interest headroom and depth, and a second venue adaptor is planned.
  • Gap risk. A move past the hard-delever line before the keeper acts, or across a weekend, can push realised leverage far from target. The margin floor and the on-chain stop are sized to survive an unattended adverse move of about 11% at 3x and 19% at 2x (D27), not more.
  • Stale NAV. Jupiter quotes the last cranked NAV. A stale crank is a free option to minters; the issuance fee and crank cadence are set together, and the cap can be set to zero during anomalies.
  • Keeper risk. Two keepers on different RPC providers are the target; when both are down the Phoenix conditional stop is the only protection. Keeper liveness is public on every Transparency page.
  • Smart-contract risk. Voltr is audited; our adaptor is new. The adaptor can only move funds between the vault and its own Phoenix account, never to any other address, and every invariant has a negative test.
  • Liquidity risk. Secondary pools are small and re-centred on NAV by a bot; mint and redeem at NAV are the primary market. Pools can be pulled when the keeper is down or depth is thin.

Eligibility

These tokens are not offered to US persons or to residents of restricted jurisdictions. Connections from restricted countries are redirected to a notice page; using a VPN does not change your eligibility. Names such as US500 are generic descriptions of the underlying market and imply no affiliation with any index provider or issuer.

Questions about the mechanism? Every number on this site comes from the keeper’s own records; start at Protocol status.