fx Protocol
Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.
f(x) Protocol splits ETH and WBTC collateral into two tokens: leveraged long or short exposure on one side, and fxUSD, a stablecoin backed by wstETH and WBTC, on the other. At the 2026-08-14 survey, DefiLlama records about $95.8M of protocol TVL and separately reports pool2 liquidity. That near-threshold record does not support the former $72M size-only disposition. The leverage side would fail our rules on its own terms; the stablecoin side needs its own examination. Rejected individually because the slug combines stable fxUSD with leveraged xPOSITION and sPOSITION products whose loss paths are materially different.
- Reopen only after fxUSD, xPOSITION and sPOSITION each have a separate record pinning every proposed chain, token, implementation, oracle, pool manager and privileged role to a current deployment manifest and applicable audit
- A proposed-size fxUSD redemption must complete into the named collateral or stablecoin route within 50 basis points and the written time limit without an unpriced CreditNote or unresolved recapitalization claim
- Each xPOSITION and sPOSITION record must bound maximum leverage, rebalance and liquidation loss under at least a 30% one-day collateral move and identify which product absorbs any resulting bad debt
The research file
Mechanism
fxUSD is minted against stETH and WBTC exposure created alongside leveraged xPOSITIONs; sPOSITIONs add lending-based short or yield exposure. Stability-pool capital and automated rebalancing absorb pressure as collateral prices move. The aggregate is a two-sided structured market, not one stablecoin claim.
Control and operating evidence
Governance sets collateral, leverage, fee and peg-defense parameters and can amplify funding costs or halt new leveraged positions during stress. The protocol publishes a detailed risk framework and on-chain redemption design. This memo does not treat those controls as proof that every product side has the same suitability.
Deployment and assurance boundary
The official deployment page points to the Ethereum V2 address manifest and separately lists V1 and ancillary contracts. The audit index includes Secbit V2 and V2.1 reviews, an OpenZeppelin V2 review, oracle updates, fxSAVE and the January 2026 omnichain fxUSD review. That is meaningful assurance evidence, but an audit-list claim is not enough: each proposed fxUSD, xPOSITION or sPOSITION exposure must pin its live chain, contract, implementation, oracle, pool manager and privileged roles to the report that actually covered them.
Exact V2 identity, authority and incident boundary
The Ethereum V2 manifest identifies fxUSD proxy `0x085780639CC2cACd35E474e71f4d000e2405d8f6`, PoolManager proxy `0x250893CA4Ba5d05626C785e8da758026928FCD24`, wstETH long pool `0x6Ecfa38FeE8a5277B91eFdA204c235814F0122E8`, FxProxyAdmin `0x9B54B7703551D9d0ced177A78367560a8B2eDDA4`, and CustomProxyAdmin `0xd41d29fc53fE5Ce9f0fB2328E54d35A2a03a324B`. The keeper guide separately identifies ShortPoolManager `0xaCDc0AB51178d0Ae8F70c1EAd7d3cF5421FDd66D`, wstETH short pool `0x25707b9e6690B52C60aE6744d711cf9C1dFC1876`, and WBTC short pool `0xA0cC8162c523998856D59065fAa254F87D20A5b0`. xPOSITION and sPOSITION are non-fungible, pool-specific leveraged positions, not fungible aliases of fxUSD. The audit index maps reviews to V2, V2.1 sPOSITION, oracle, fxSAVE and omnichain components, but neither it nor the deployment manifest is an incident ledger. No claim of a clean incident history is made; an allocation record must search governance, upgrade and loss events for its exact pool and implementation rather than transfer V1 history or one audit to every V2 product.
Exit consequences
fxUSD can redeem at oracle value into stETH or WBTC subject to a fee and position deleveraging. If system collateralization falls below 100%, openings halt and recapitalization begins; extreme bad debt can be redistributed across active positions and operations can stop. Leveraged holders can be rebalanced or liquidated.
Product-level comparison and decision
fxUSD is the low-volatility side of the invariant and must be compared with stablecoin or stable-yield claims on collateral quality, peg defense, redemption and bad-debt allocation. xPOSITION is directional leveraged exposure and must be compared with transparent perpetual or margin positions on leverage, rebalance and liquidation loss. sPOSITION borrows collateral through Aave-linked short pools and must be compared with both short exposure and lending-dependent structured yield. None of those comparisons supports applying one aggregate approval: a control or exit that protects fxUSD may transfer risk to a leveraged side, while a leverage feature has no place in a stable sleeve. Keep the combined slug rejected until each named product has a contract-specific record and independent allocation decision.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- f(x) Docs — system risk framework · primary · accessed 2026-08-14
Supports: loss waterfall, recapitalization, operation halt, bad-debt redistribution - f(x) Docs — peg and redemption mechanisms · primary · accessed 2026-08-14
Supports: oracle redemption, collateral assets, stability pool, peg controls - f(x) Docs — funding and governance controls · primary · accessed 2026-08-14
Supports: funding fee, governance amplification, sPOSITION exposure, Aave dependency - f(x) Docs — audit reports and reviewed components · primary · accessed 2026-08-15
Supports: V2 audit, V2.1 sPOSITION audit, oracle reviews, fxSAVE audit, omnichain fxUSD review - f(x) Docs — live contracts and deployment manifests · primary · accessed 2026-08-15
Supports: V2 Ethereum deployment manifest, governance contracts, oracle addresses, pool and token addresses, deprecated contracts - f(x) V2 Ethereum deployed-address manifest · primary · accessed 2026-08-15
Supports: fxUSD proxy, PoolManager proxy, long pool, proxy-admin addresses, implementation mapping - f(x) Docs — keeper contract identifiers for long and short positions · primary · accessed 2026-08-15
Supports: ShortPoolManager, wstETH and WBTC short pools, long pools, keeper dependency - DefiLlama — f(x) Protocol survey record · secondary · accessed 2026-08-14
Supports: survey TVL, Ethereum deployment, dual-token stablecoin category
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Ethereum | Approved | sovereign | No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus. |