Split-collateral
protocol guide
Levy is the working name for a Hylo-style stablecoin and leveraged-token protocol designed for Robinhood’s EVM chain. Levy, hyUSD, eHYUSD, xETH, xBTC, hyETH, and internal vUSD labels are all renameable working tokens—not final brand copy.
PREMISE
One deposit becomes two claims.
Deposits of supported ETH liquid-staking tokens, BTC collateral, or USDC are separated into a system-wide stable claim and a pool-specific residual claim.
SUPPORTED COLLATERAL
wstETH · weETH · cbBTC · USDC
│
▼
PER-ASSET POOL
┌────┴────┐
▼ ▼
hyUSD xETH / xBTC
stable claim residual claim
│
▼
deposit to Earn → eHYUSDEach pool may use an internal USD-denominated liability unit for accounting. The product interface calls this stable liability; the internal name vUSD does not normally appear in user flows.
INFORMATION ARCHITECTURE
Six v1 product surfaces.
- Landing explains the split in roughly 15 seconds and exposes live protocol headline stats when sources exist.
- Stable mints and redeems the aggregate hyUSD claim with route health visible.
- Earn moves between hyUSD and the auto-compounding eHYUSD receipt.
- Leverage trades the residual xETH and xBTC claims with effective leverage and CR in context.
- Pools exposes protocol health, fee zones, liability, NAV, yield, and rebalances.
- Portfolio separates holdings, P&L, and realized yield.
PRODUCT / STABLE
hyUSD
hyUSD is one aggregate stablecoin backed by all eligible Levy pools. Users mint it with wstETH, weETH, cbBTC, or USDC and redeem it through the lowest-cost eligible route. Idle hyUSD has no yield. Its peg is at risk only if aggregate collateralization breaks and Earn Pool capital is exhausted.
A mint quote shows output, effective fee, routed pool, collateral ratio before and after, and resulting zone. A mint is gated if it would leave the Neutral zone; the interface asks the quote source for a suggested maximum.
PRODUCT / EARN
eHYUSD
Deposit hyUSD to receive eHYUSD, the receipt for a proportional share of the Earn Pool. All liquid-staking yield and rebalance profits compound into the wrapper as a variable APY.
PRODUCT / LEVERAGE
xASSET market coverage
xASSET is the residual claim after the stable liability is separated. xETH targets roughly 2–3× ETH exposure as pool conditions move; xBTC applies the same residual model but also includes a small per-epoch borrow-drag parameter because BTC has no native yield.
There is no individual debt position, recurring funding payment, or liquidation engine. Effective leverage is path-dependent and must never be presented as a fixed multiplier. ETH liquid-staking yield remains embedded in xETH-side economics. Both assets can experience volatility decay, and NAV goes to zero if their pool destabilizes.
OPTIONAL SURFACE
hyETH
A yield-bearing ETH wrapper is described as optional v1.x collateral. The intended flow wraps native ETH, makes staking APY prominent, and discloses validator and slashing risk. It is not exposed in v1 navigation until issuance, accounting, and product priority are decided.
CORE MECHANIC
Collateral ratio and leverage
collateral ratio = pool collateral value / stable liability × 100 effective leverage = pool TVL / xASSET market capitalization
The working target CR is 150%. Minting hyUSD increases stable liability, lowers CR, and increases residual leverage. Minting xASSET adds collateral against the same stable liability, raises CR, and lowers residual leverage.
PROTOCOL DEFENSE
Zones and fees
Fees change directionally to push each pool back toward its operating band. Red is reserved for actual protocol danger; regular input validation uses amber.
| CR | Zone | Stable mint | x mint | x redeem |
|---|---|---|---|---|
| ≥175% | Buy 2 | High | 1.00% | 1.00% |
| 165–175% | Buy 1 | Rising | 1.00% | 1.00% |
| 135–165% | Neutral | Low | 1.00% | 1.00% |
| 120–135% | Sell 1 | 0 bps | 0.50% | 4.00% |
| 100–120% | Sell 2 | 0 bps | 0.00% | 8.00% |
| <100% | Destabilized | Blocked | Blocked | Blocked |
FAILURE MODE
Destabilized means visible and frozen.
Below 100% CR, minting and redemption freeze for the affected pool, its xASSET NAV is displayed as zero, and a site-wide red banner identifies the event. Earn exposes the backstop loss, recovery progress, eHYUSD burned, and xASSET held. Withdrawals can include xASSET dust while loss remains unresolved.
OPERATIONS
Rebalances are readable events.
When the system executes a subsidized swap, the event log describes asset movement, subsidy, and Earn Pool cost in one sentence.
Example: Swapped 12 ETH → 41,200 USDC at 1.5% subsidy, Earn Pool cost $618.
TRANSACTIONS
Six complete flows.
- Mint hyUSD: choose collateral, enter amount, inspect route and CR, approve, confirm.
- Redeem hyUSD: choose payout asset, inspect the lowest-cost eligible source pool, approve, confirm.
- Deposit to Earn: enter hyUSD, review eHYUSD share output, approve, confirm.
- Withdraw from Earn: enter eHYUSD, review hyUSD plus any xASSET dust, approve, confirm.
- Mint xASSET: choose a listed reference, verify that its Levy pool is configured, inspect leverage, CR, zone, and fee, approve, confirm.
- Redeem xASSET: inspect elevated Sell-zone fees and collateral output, approve, confirm.
TRANSACTION SAFETY
Quotes, allowances, and routing.
The shared quote shape includes input, output, fee, price impact, gas, current NAV where relevant, CR before and after, and zone. Contract quotes are cross-checked against locally calculated CR, zone, and fee values. Advanced disclosure explains why a pool was selected. Permit2 is preferred; otherwise the user chooses an exact or infinite ERC-20 allowance. The transaction stepper is Approve → Send → Confirm, with one loading state for each action.
Confirmation surfaces retain significant digits instead of rounding away information that changes the transaction.
COMPLETION
Every flow ends with proof.
The success sheet names the completed action, received assets, updated balances, transaction hash, and explorer link. When the explorer is not configured, the link remains unavailable rather than pointing somewhere plausible.
WALLET & NETWORK
Robinhood EVM, configuration pending.
The recommended frontend stack is wagmi, viem, and RainbowKit. On connection, Levy should request an add-network flow when necessary. Chain ID, RPC endpoints, block explorer, native gas token, and contract addresses remain open inputs.
If a primary RPC fails, the app falls back to an alternate RPC and then read-only mode. Every completed transaction links to the configured explorer.
DATA
Four data layers.
- Static configuration
- Token symbols, addresses, decimals, chain details, collateral eligibility, feature flags.
- Live, every 4–8 seconds
- ETH/USD, BTC/USD, and USDC/USD from the protocol oracle; pool TVL, stable and xASSET supplies, CR, zones, fee quotes, and Earn APY from contracts and harvest events. Oracle choice and staleness rules remain open.
- Per-user
- All token and collateral balances, router allowances, eHYUSD position, and realized yield calculated from mint price versus current NAV.
- Historical indexer
- xASSET NAV, pool CR, harvested yield, transaction history, and rebalance events via a subgraph or custom indexer.
IMPLEMENTATION
Frontend modules.
app/ landing · stable · earn · leverage · pools · portfolio · docs
components/ ZoneChip · CRMeter · LeverageGauge · FeeCurve
QuotePanel · PoolCard · RiskBanner · TxStepper
config/ chains · tokens · protocol parameters
lib/ pure TypeScript CR · zone · fee · leverage helpers
future/ contract bindings · quotes · oracle freshness · indexerThe build ships static wireframes with labeled scenarios, reusable primitives ready for a Storybook harness, the wallet/add-network boundary, pure TypeScript reference math for a future Solidity port, and explicit copy for the split and destabilization before protocol addresses exist.
V1 BOUNDARY
Deliberately out of scope.
- Governance UI
- Cross-chain bridge
- Advanced orders
- Native mobile application
- XP or points unless the product explicitly ships them
UNRESOLVED INPUTS
Decisions that must stay visible.
- Levy as the final product name
- Final collateral set, actual Robinhood-chain liquidity, and deposit caps
- Robinhood chain ID, RPCs, explorer, and native gas token
- Contract addresses and oracle choice: Chainlink, Redstone, Pyth Pull, or another design
- Whether hyETH ships
- Whether XP or a governance token ships—and who controls parameters if governance does not
- Final 150% target, 135–165% Neutral band, and all fee curves
- Fee split between Earn Pool and treasury, required for APY projections
- Earn withdrawal fee and whether it appears during deposit
- Final brand tokens and production asset system