Risks & Security
A plain account of what perp.fun depends on and where it can fail. Some of it is inherent to leveraged exposure and won't change, because it's how the product works.
Leverage, decay, funding
A coin's backing is a 5× perp position on a real market, amplifying moves in both directions. At 5×, a −20% move in the underlying between two rebalances takes the backing to zero — arithmetically, not approximately. Rebalancing makes that survivable when the move arrives over hours; nothing makes an instant one survivable.
Constant-leverage exposure also loses value in choppy markets even when the underlying ends up exactly where it started. A ±5% round trip costs a 5× position 6.25%. This isn't a fee or a bug, it falls out of the compounding math, and it's continuous. On top of it the perp pays funding on notional rather than equity, whether or not anyone trades your coin. See NAV, decay & funding.
No backing floor and no redemption right
The hedge reaches you through the price — buybacks lifting it, depth supporting it. You cannot redeem a coin for a share of its hedge. You exit by selling on the pool like anyone else, at whatever price the pool offers.
The keeper is the trust point
The contracts never touch Lighter. They only know what a hedge is worth because the keeper computes that value, signs it, and posts it on-chain.
If the keeper stops, the affected LT's NAV goes stale and its vault freezes — mint and redeem revert rather than transacting on an old number. That's a deliberate fail-safe, and pool trading continues on existing depth, but the hedge stops growing, shrinking and paying out until the keeper is back.
A compromised keeper signer could post a false NAV. The oracle constrains it — signature auth, strictly-increasing timestamps, future-skew rejection, a minNav floor, a staleness bound, a rotatable signer — but those bound the damage rather than eliminate the trust. The keeper also decides when to harvest, expand and buy back, which are timing decisions with real economic consequences made off-chain.
This is the largest non-market risk in the system and it's inherent to hedging on a venue the chain cannot see.
External dependencies
Lighter downtime, socialized losses or venue failure hit every hedge. A Robinhood Chain halt stops every on-chain action. Uniswap V4 and V3 carry the pools and the WETH↔USDG conversion leg. Relay carries margin transport, so delays stall harvest and recall — though not trading. If the subgraph or front-end goes down, charts and prices go dark while the contracts keep working.
Smart-contract risk
The contracts have had a Slither pass and manual review, with checks-effects-interactions ordering and dust/precision hardening applied.
No professional audit has been performed yet, so this should be treated as unaudited software: a bug in the launcher, a vault or a hook could affect a coin's pool or its backing.
Owner powers
The protocol owner can tune parameters — the hedge activation floor, the creator fee share, range width, risk bands, buffer size — and can pause a vault. These are real powers over live coins. The owner cannot rename a coin, mint supply, change a coin's backing, or take a coin's pool.
Pool visibility and depth
Coins live in LP-gated pools on the protocol's own Uniswap V4 PoolManager. Third-party aggregators index the canonical deployment, so these pools do not appear on DexScreener-style trackers and the canonical SwapRouter02 cannot reach them. If the app is down, price discovery and history are harder to access, though the pool remains tradeable by any V4-aware router.
Liquidity also sits in a concentrated range rather than spread full-range. Depth within the range is thick; a trade large enough to run past it moves the price sharply.
Creator concentration
Nothing prevents a creator from taking a large seed buy at launch, and nothing prevents them from selling it. Creators receive fees but hold no authority over the coin.
What is not a risk here
You cannot be liquidated and cannot lose more than you put in. You hold an ERC-20 rather than a margin account: no liquidation price on your position, no margin call, no negative balance, and no way for anyone to force-close what you hold. The leverage sits inside the protocol's perp position, not as a liability attached to your wallet.
The perp itself is managed to stay away from liquidation — the keeper cuts notional as the position moves against it rather than letting it run into a liquidation price. That's a continuous mitigation rather than a guarantee: a large enough move arriving in a single gap can still close the position out, which is what the wipe arithmetic above describes.
One coin cannot drag down another. Every LT has its own vault, oracle and margin, and live coins hold isolated positions where slot capacity allows.
Liquidity is protocol-owned. The launcher contract owns every coin's LP position, so there's no third-party LP who can pull the rug out from under a pool — and by construction, no third party can even become one.
Regulatory
Several backing markets reference real-world securities and commodities. The venues involved apply their own jurisdictional restrictions, independently of this protocol or its front-end. Trading leveraged exposure to securities may be restricted or prohibited where you live, and you are responsible for your own compliance. Nothing here is investment, legal or tax advice.
