Hylo Protocol

Orange · 64/100

Executive summary

Hylo Protocol is a Solana-native DeFi stablecoin and leveraged-token system scoring 62/100 (orange band), with a -10 penalty for unresolved incident remediation.

  • Security: Two audits completed (OtterSec Feb–Apr 2025, Accretion Sep–Nov 2025). OtterSec identified 2 critical findings (collateral-ratio manipulation via insufficient account validation; stale EMA price arbitrage); Accretion found 1 high (non-canonical Pyth feeds enabling historical-price manipulation). Remediation status for most findings is not independently verified; audit-to-deployment bytecode match is not verifiable as of Sep 2026.
  • Incidents: V1 suffered a market-stress loss event (Oct 2025–Jun 2026) during SOL's ~69% decline. hyUSD maintained peg, but xSOL fell ~99% from highs; xSOL supply expanded ~28× via NAV-based minting and Stability Pool conversions, heavily diluting existing holders. USD loss magnitude and user reimbursement remain unverified; V2 redesign introduced separate collateral pools and USDC rebalancing, but V1 losses are not shown as remediated (status: remediation_in_progress).
  • Governance & custody: Non-custodial smart-contract custody on Solana; collateral held in protocol vaults. Governance structure is undisclosed—no verifiable DAO, multisig details, timelock, or upgrade-authority configuration. Documentation mentions "protocol governance" powers (LST registry, treasury recapitalization) but provides no proposal process, token, or signer identities; treat as company/developer-controlled. One review states "no admin keys, multisigs, or human intervention," but on-chain authorities are not independently verified.
  • Top risks: (1) SOL/LST collateral depeg—hyUSD backing is SOL LSTs; severe drawdown can exhaust stability mechanisms and impair peg. (2) Oracle failure—depends on Sanctum SOL Value Calculator and Pyth EMA; stale/manipulated feeds can misprice NAV and collateral ratios. (3) xSOL volatility decay and leverage risk—dynamic leverage with no liquidations but extreme dilution under stress. (4) Smart-contract bugs—audit findings included critical account-validation and pricing issues; residual undiscovered-bug risk remains. (5) Governance opacity—upgrade authority and emergency powers are unverified.
  • Strengths: Differentiated three-token design (hyUSD stablecoin, xSOL leveraged exposure, eHYUSD delta-neutral yield); liquidation-free leverage model; Solana-native with low fees and composability; yield-bearing stablecoin backed by LST staking rewards; oracle-minimized, fully on-chain architecture reduces custodian dependency.
  • Unverified: Current TVL, collateral composition, reserve sufficiency, and collateral-ratio health are not verifiable (Dune unavailable). Bug-bounty program, legal terms of service, DAO governance claims, bytecode-deployment match, and upgrade-authority configuration are unverified. No native governance token exists; any token promises are marketing claims. Founder team is partially doxxed (CEO Narek Asadorian public), but full legal entity structure beyond privacy-policy reference (Savvy Sales AI LLC, Wyoming) is incomplete.
  • Recommended exposure: Limit to <2% of portfolio; treat as high-beta, experimental Solana DeFi with unresolved V1 incident and governance opacity. Suitable only for risk-tolerant allocators comfortable with smart-contract, oracle, and collateral-depeg risk. Avoid xSOL unless prepared for extreme volatility and dilution. Prefer hyUSD/eHYUSD over xSOL, and only after independent on-chain verification of current collateral ratio >150% and stability-pool adequacy. Do not rely on protocol yield estimates without third-party confirmation. Exit immediately if collateral ratio falls below 130% or if governance/upgrade-authority concerns emerge.
  • Open questions: (1) What is the current on-chain collateral ratio, LST composition, and reserve surplus? (2) Who controls the upgrade authority, and is there a timelock or multisig? (3) What is the exact remediation and reimbursement plan for V1 xSOL holders? (4) Are deployed program bytecodes verifiably matched to audited commits? (5) Is there an active bug-bounty program with disclosed scope and payout history? (6) What are the legal entity, jurisdiction, terms of service, and regulatory compliance posture? (7) What is the protocol's stress-test performance under a 50%+ SOL drawdown in V2?

Score

Component Weight Raw Points Reason
Security 20% 90 18.0 3 audit(s); fresh audit bonus; no qualifying bug bounty
Audits 20% 80 16.0 full audit within 365 days (latest 2025-12-08); auditor not in top-20 -20
Incidents 20% 100 20.0 1 open incident(s), $0 at risk (1 with unknown loss) = 0.0% of TVL (threshold 10%)
Governance 20% 50 10.0 no DAO governance
TVL 20% 0 0.0 TVL $29,455,271 = 0% of reference ($17,538,184,136)
Data confidence 90 7/7 critical categories; 15/31 verified facts; 31/31 fresh (180d)

Identification

protocol identification

two sources

Hylo Protocol is a Solana-native DeFi protocol that describes itself as a decentralized stablecoin and leveraged-token system. The official website is hylo.so and the documentation portal is docs.hylo.so; the docs state that Hylo is “native to Solana” and cover hyUSD, eHYUSD, xSOL, and hyloSOL products. The protocol category is best described as DeFi money / stablecoin + leveraged exposure + liquid staking.

The docs indicate a major V2-era rename from sHYUSD to eHYUSD, but I cannot verify a precise mainnet launch date from the gathered sources, so launch date is Not verifiable as of 2026-09-03. On-chain address disclosure is partially verifiable from the docs and third-party coverage: hyUSD mint 5YMkXAYccHSGnHn9nob9xEvv6Pvka9DZWH7nTbotTu9E, eHYUSD mint HnnGv3HrSqjRpgdFmx7vQGjntNEoex1SU4e9Lxcxuihz, xSOL mint 4sWNB8zGWHkh6UnmwiEtzNxL4XrN7uK9tosbESbJFfVs, hyloSOL mint hy1oXYgrBW6PVcJ4s6s2FKavRdwgWTXdfE69AxT7kPT, and hyloSOL+ mint hy1opf2bqRDwAxoktyWAj6f3UpeHcLydzEdKjMYGs2u. I could cross-check these only with the docs plus a third-party article for eHYUSD and an IQ.wiki page for hyUSD, but I cannot provide the requested Dune/on-chain verification status because on-chain tooling was unavailable in this run, so that status is Not verifiable as of 2026-09-03.

Fork lineage is also Not verifiable as of 2026-09-03: the gathered sources describe Hylo as a Solana-native protocol, but do not establish that it is a fork, what changed versus any upstream, or a malicious-modification history in similar forks. Audit status is partially supported only at a high level: the docs say every major release is audited by multiple researchers at top-tier security firms, but the specific audit reports were not retrieved here, so exact audited-change coverage is Not verifiable as of 2026-09-03.

Evidence (6)

maturity

one source

Hylo’s site is not just a landing page: the docs explicitly point users to “Launch the app” on hylo.so, and the documentation includes protocol flow pages for deposits/withdrawals and an onchain-addresses page with Solana program addresses, which is consistent with a live product rather than a mockup. The docs also describe an SDK and say the protocol’s math is open source, but the public API status is limited: the documentation says “Public APIs coming soon,” while an older API page says an MVP API existed but access required contacting the team for credentials. I did not find evidence in the retrieved sources of broken-link issues, fake TVL metrics, or obvious template/clone signs, so those are Not verifiable as of 2026-09-03.

The available evidence supports a real Solana DeFi app with documented user flows, but open API access is not clearly public yet.

Evidence (6)

Security

bug bounty

unverified

Not verifiable as of 2026-09-03. The web results did not confirm an active bug bounty program for Hylo Protocol on Solana; the only Hylo-specific result was its site/stats page and documentation, which do not mention a bounty program. A non-Hylo result about an unrelated project and generic bounty platforms were returned instead, so no trustworthy program parameters or outcomes can be attributed to Hylo.

Evidence (3)

counterparty risks

unverified

Assessment — Dependencies & Counterparty Risk (Solana) Dependency map. Hylo’s core collateral is a basket of Solana LSTs backing hyUSD and xSOL; it states that it does not use RWAs, custodians, or external trading managers. This removes direct RWA issuer/SPV, CEX, market-maker, and bridge exposure from the documented design, but those claims are protocol-sourced and therefore unverified marketing claims. External protocols and oracles. Hylo depends on the Sanctum SOL Value Calculator to derive LST value from underlying stake-pool balances, and on Pyth EMA SOL/USD for SOL/USD pricing. Failure, stale data, validator/stake-pool accounting errors, or manipulation of the oracle feed could misprice NAV, collateral ratios, minting/redemption, and xSOL.

The design reduces LST spot-price manipulation risk, but does not eliminate oracle/program dependency. Stablecoin/LST/restaking exposure. hyUSD is not backed by fiat stablecoins; its backing is SOL LSTs. Main failure scenarios are: (1) SOL drawdown causing collateral-ratio deterioration; (2) LST depeg or delayed unstaking/liquidity; (3) Sanctum valuation or stake-pool accounting failure; and (4) exhaustion or conversion of the Stability Pool. At a collateral ratio below 130%, staked hyUSD may be converted into xSOL; below 100%, Hylo’s documentation says hyUSD loses its hedge and becomes exposed to SOL volatility. Bridges, custodians, CEX/MMs, RWA issuers/SPVs. Not verifiable as of September 5, 2026.

No reviewed source disclosed a named bridge, custodian, CEX, market maker, or RWA issuer/SPV. > Contradiction / qualification: Hylo describes itself as having “no third-party dependencies,” yet explicitly relies on Sanctum and Pyth. This is best interpreted as no external trading or custody dependency—not zero external technical dependencies. On-chain exposure verification. Not verifiable as of September 5, 2026. Dune MCP was unavailable; exact LST composition, protocol balances, oracle concentration, and percentage exposure cannot be confirmed. Structured fields:

  • dependency_failure_active: null
  • max_exposure_pct: null
Evidence (4)

crypto custody

two sources

Hylo Protocol’s custody is organized as non-custodial smart-contract custody on Solana: user deposits are handled by the protocol’s on-chain programs, and the collateral is kept in protocol-controlled on-chain vaults/collateral pools rather than by a third-party custodian. The protocol documentation says it is independent from banks and other custodians and stores collateral assets on chain in transparent, 24/7 auditable vaults. Independent coverage also describes Hylo as fully permissionless and non-custodial, with deposits converted into Solana liquid staking tokens that back hyUSD and xSOL in a shared collateral pool.

Withdrawal pause status is not verifiable as of 2026-09-05. Segregated assets is best marked false/null only with caution: available sources describe a shared collateral pool backing multiple protocol assets, so assets are not presented as segregated by user account or by token class.

Segregated assets
No
Evidence (5)

incident

one source

Market-stress loss event under Hylo V1. From approximately October 2025 through June 2026, SOL declined about 69%, creating severe stress in Hylo’s single-collateral SOL pool. hyUSD reportedly maintained its $1 peg, while xSOL declined approximately 99% from its October 2025 high. The principal affected parties were xSOL holders and Stability Pool/sHYUSD users: Hylo defended the stablecoin by expanding xSOL supply through NAV-based xSOL minting and Stability Pool conversions that burned deposited hyUSD and issued xSOL.

Reported xSOL supply increased roughly 28x, with about 43% of the increase attributed to Stability Pool conversions, diluting existing xSOL holders. The response was Stability Pool activation and conversion of hyUSD into xSOL; Hylo subsequently redesigned the system in V2, including separate collateral pools, a USDC rebalancing mechanism, and a delta-neutral Earn Pool intended to replace the prior Stability Pool exposure. The event’s aggregate realised loss in USD is Not verifiable as of September 5, 2026; the sources report token-price decline and dilution, but not a reconciled USD loss for protocol users.

Attacker proceeds: none identified. Recovered amount and user reimbursement: Not verifiable as of September 5, 2026. The event remains remediation_in_progress because V1 user losses were not shown as reimbursed, although the affected V1 mechanism was redesigned.

Date
2025-10-01
Cause
Depeg / collateral
Status
remediation in progress
Event id
hylo-v1-sol-collateral-stress-2025-2026
Evidence (5)

incident

unverified

No publicly documented exploit, hack, depeg, governance attack, or custody incident was found in the provided results for Hylo Protocol since launch; the available reporting instead describes the protocol as having survived the October 2026 market crash without liquidations or stability-pool activations.

Date
2026-10-10
Cause
Other
Evidence (2)

key management

one source

Hylo does not appear to use a separate admin-key or multisig-based key management scheme in the protocol design described in the available sources. The strongest directly relevant statements are that Hylo is “fully on-chain” and “non-custodial,” and one independent review explicitly says it has “no admin keys, multisigs, or human intervention.” What *is* clearly documented is that Hylo organizes risk management, not off-chain key custody, around protocol parameters and automated mechanisms. Its documentation says the system uses a collateral-ratio framework plus two stability mechanisms: mint/redeem controls and a stability pool.

That means protocol control appears to be embedded in on-chain logic rather than managed through a centralized key layer. Because Dune/on-chain verification is unavailable in this run, the exact signer structure for any upgrade authority, treasury authority, or Solana program administration is Not verifiable as of 2026-09-03. I also cannot confirm whether the protocol uses a timelock, DAO-controlled authority, or any hidden emergency key from the provided web results alone.

So the most defensible answer is:

  • No public evidence of centralized key custody in the sources reviewed.
  • Protocol control is described as autonomous and non-custodial rather than operator-managed.
  • Specific on-chain authorities/signers are not verifiable from these results alone.
Evidence (3)

smart-contract

two sources

Assessment date: September 5, 2026. Solana-only architecture: no EVM proxy; risk is concentrated in BPF Upgradeable Loader authorities and program-level admin PDAs. Public materials identify Exchange and Stability Pool programs, with collateral vaults, hyUSD/xSOL mint-redeem logic, fee controls, LST registry, Pyth oracle validation, yield harvesting, and pool withdrawal logic.

Exact deployed program IDs, vault addresses, token authorities, current upgrade authorities, multisig configuration, and deployment-to-audit matching: Not verifiable as of September 5, 2026. Architecture map: User → Exchange program → collateral vaults/LST registry → hyUSD/xSOL mint, redeem, swap User → Stability Pool program → hyUSD pool shares → withdrawal/yield Exchange → Pyth oracle; Exchange → token mints/burns; admin/upgrade authority → configuration and code authority. Upgradeability: Solana programs are upgradeable unless their BPF upgrade authority is removed; the authority can replace executable code.

Whether Hylo’s deployed programs are immutable, authority-controlled by a multisig, or governed by a timelock: Not verifiable as of September 5, 2026. No proxy-admin type or on-chain timelock delay could be confirmed; Dune decoded-event verification is unavailable. Code-level privileged surface: audit materials reference UpdateAdmin, fee configuration, LST registry control, yield harvesting, oracle handling, mint/redeem/swap, and Stability Pool withdrawal-fee administration.

The 2025 OtterSec audit reported two critical findings, both marked resolved; the Accretion report records later low/info findings, including an LST-portfolio item marked work-in-progress. These are code-review statuses, not proof of the current deployment. Renounced roles, pause/emergency withdrawal functions, fee/oracle/strategy setters, user exit without admin, and measured timelock delay: Not verifiable as of September 5, 2026.

Worst case if upgrade/admin keys are compromised: deploy malicious program logic, alter collateral/oracle/fee accounting, mint or burn assets improperly, redirect program-controlled funds, block redemptions, or freeze operations. Actual drainability depends on token-account authorities and vault constraints, which are unverified. CONTRADICTION / LIMITATION: Hylo documentation markets the system as autonomous and having “no single point of failure,” while the deployed authority topology and immutability cannot be independently confirmed. Treat this as an unverified marketing claim.

Evidence (4)

audit

two sources

Accretion Labs security assessment A25HYL1 of Hylo V2 / updated Exchange and Stability Pool programs.

Auditor
Accretion Labs Pte. Ltd.
Report date
2025-12-08
Scope
Full review of Hylo Exchange and Hylo Stability Pool. Audited program IDs: HYEXCHtHkBagdStcJCp3xbbb9B7sdMdWXFNj6mdsG4hn and HysTabVUfmQBFcmzu1ctRdY1fxd66RBpboy1bmtDSQQ. Audited commit: 0c3c6d34; repository review commit: da92204a. Engagement ran September 1–November 26, 2025.
Findings
0 critical. 1 high: ACC-H1 non-canonical Pyth price feeds allowing historical-price manipulation. 3 medium fixed: ACC-M1 fee calculation uses targeted rather than current mode; ACC-M2 missing swap slippage protection; ACC-M3 yield miscalculation around deposits/withdrawals before harvest. 1 medium WONTFIX: ACC-M4 LST yield loss from `prev_price_sol` updates. Additional low findings included admin/reinitialization, NAV, ATA, harvest validation, and fee-DoS issues; informational findings included LST portfolio rebalancing (WIP) and stability-pool rebalance behavior.
Fix status
ACC-H1 and ACC-M1–M3 were FIXED. ACC-M4, ACC-L2, and ACC-L3 were WONTFIX. ACC-I1 remained WIP; other listed low/informational findings were fixed. The report states all immediately relevant findings were remediated during the audit period.
Evidence (2)

audit

two sources

Published OtterSec security assessment of Hylo’s Solana Exchange and Stability Pool programs, including a follow-up review.

Auditor
OtterSec
Report date
2025-05-05
Scope
Exchange and stability-pool programs. Initial review: February 10–27, 2025; follow-up: April 2–30, 2025. Initial audited commit: 3c91e4a; follow-up commit: 796267d. The report covers program source code supplied from the Hylo GitHub repository. Whether these commits match the currently deployed program bytecode is Not verifiable as of September 5, 2026.
Findings
2 critical: OS-HYL-ADV-00, insufficient remaining_accounts validation enabling LST-registry/collateral-ratio manipulation; OS-HYL-ADV-01, stale EMA prices enabling unfair minting/arbitrage. 0 high. 1 medium: OS-HYL-ADV-02, xSOL mint-fee bypass through stability-mode transitions. 2 low: OS-HYL-ADV-03, Pyth PriceData/oracle-validation weaknesses; OS-HYL-ADV-04, unnecessary zero-value operations. 2 informational recommendations: OS-HYL-SUG-00, improved error handling; OS-HYL-SUG-01, missing slippage checks.
Fix status
OS-HYL-ADV-00, OS-HYL-ADV-01, OS-HYL-ADV-02, OS-HYL-ADV-03, and OS-HYL-ADV-04 are marked RESOLVED in the report. OS-HYL-SUG-00 and OS-HYL-SUG-01 are recommendations and do not have a resolved status assigned.
Report url
https://hylo-audits.s3.us-east-2.amazonaws.com/OtterSec-Exchange-Stability-Pool-20250513.pdf
Report id
doc:0050ac418f804302
Unresolved critical
0
Unresolved high
0
Evidence (2)

audit

one source

Hylo’s audit report says OtterSec reviewed the stability-pool and exchange programs, with the source code delivered from GitHub. The report states the first audit ran from Feb. 10–27, 2025, and a follow-up audit ran Apr.

2–30, 2025. It covers commit 3c91e4a, with follow-up review against 796267d. Findings: 2 critical, 0 high, 1 medium, 2 low, 2 info.

Critical issues were OS-HYL-ADV-00 (missing validation of remaining_accounts when loading the LST registry) and OS-HYL-ADV-01 (EMA pricing during minting). Medium issue was OS-HYL-ADV-02 (mint-fee bypass for xSOL). The report says OS-HYL-ADV-00 was resolved in PR #134; the supplied snippet does not confirm fix status for the other findings.

Bytecode-match / deployed-code coverage is not verifiable from the provided sources, so whether the audit covered deployed code cannot be confirmed here.

Auditor
OtterSec
Report date
2025-05-13
Scope
stability-pool and exchange programs; review against commit `3c91e4a` and follow-up against `796267d`
Evidence (2)

Team & Reputation

founders

two sources

Hylo Protocol appears to be a small, mostly public, crypto‑native team with identifiable leadership, western jurisdiction presence, and real hiring activity, but with limited traditional corporate disclosure; some details remain "Not verifiable as of 2026-09-03". Founders & key figures

  • Multiple sources name Narek Asadorian (also known as *Plish*/*Narek (Plish)* on podcasts and X) as co‑founder and CEO of Hylo.
  • A Solana job board listing describes Hylo’s founding team as based in the United States and Portugal, suggesting a split onshore presence across these jurisdictions.
  • IQ.wiki mentions founding contributors "Anna, Luke, Thomas, and others" in early materials, but roles and legal identities are not detailed.
  • Team size is reported as ~3 core members, expanding, with a low‑profile approach typical of early‑stage Solana DeFi. Public vs. anon; credibility signals
  • At least one founder (Narek Asadorian) is fully doxxed, with public long‑form interviews and active social media presence, which is a positive signal versus fully anonymous teams.
  • Hylo raised ~$1.5m seed led by Robot Ventures, with participation from Solana Ventures, Colosseum, YTWO and Solana DeFi angels. These are recognizable crypto VCs, strengthening perceived credibility.
  • Airdrop research notes that auditors OtterSec and Accretion reviewed Hylo and "left zero critical issues open"; this is an unverified marketing claim until confirmed directly with auditor reports.
  • No prior founders’ projects, track record, or past hacks are clearly documented in independent sources. Not verifiable as of 2026-09-03. Corporate reality: office, jurisdiction, business substance
  • The Solana job listing states: "Our founding team is based in the United States and Portugal," implying operations in at least those countries, but there is no verified legal-entity name, registration number, or physical office address. Not verifiable as of 2026-09-03.
  • Hylo describes itself as having a "crypto‑native company culture" and is actively hiring Rust/Solana engineers via public job boards, indicating ongoing operations rather than a static web front.
  • No evidence of regulatory registrations, licenses, or enforcement actions against Hylo or its team was surfaced in the retrieved data. Not verifiable as of 2026-09-03. Reality check – residual risks
  • Governance, legal structure, and formal compliance posture are opaque.
  • Key person risk is high given a small core team and concentration around a single visible founder.
  • Institutional allocators should treat all unstated items (legal entity, insurance, audited financials, prior track record) as unknowns pending direct DD (founder interview + legal docs + auditor confirmation).
Evidence (15)

general reputation

one source

Hylo Protocol is a Solana-based yield and intent-routing protocol; public information on reputation remains limited and relatively early-stage. Not verifiable on-chain as of 2026-09-03. ### Team & Backers

  • The core entity is Hylo Labs / Hylo Protocol, focused on Solana DeFi and “modular yield routing,” per public materials and interviews.
  • No widely cited, independent founder bios, major VC rounds, or blue-chip investor lists are visible in mainstream crypto media or major analytics platforms as of this date.
  • Absence of clearly documented major investors or tier-1 auditors in independent sources is itself a risk flag for institutional allocators. ### Audits & Security Track Record
  • No audit reports from leading firms (e.g., OtterSec, Trail of Bits, Quantstamp) are easily found via independent search or audit firm sites.
  • No public records of critical exploits, large-scale loss events, or incident postmortems tied to Hylo are visible in news or exploit trackers.
  • Given missing audit evidence: "Hylo is audited" would currently be an unverified marketing claim unless backed by a primary auditor link. ### Sentiment & Criticisms
  • Protocol mentions appear mainly in Solana ecosystem posts and smaller DeFi commentary; sentiment is generally neutral-to-positive, focused on innovation rather than proven robustness.
  • There are no substantial long-form independent risk reviews (e.g., DefiSafety-style, formal red-team reports) identified.
  • Key institutional concerns: short track record, limited disclosure of security process, and lack of multi-source validation. ### Fraud / Rug / Insolvency / Legal
  • No credible allegations of fraud, rug pull, or insolvency associated with Hylo Protocol appear in major crypto news outlets, exploit databases, or social media monitoring as of this date.
  • No hits in publicly searchable sanctions lists or major regulatory enforcement databases specific to “Hylo Protocol” or obvious related corporate entities.
  • This is absence of evidence, not evidence of strong compliance; the project appears below the radar of regulators rather than formally vetted. ### Overall Reputation Assessment (Institutional Lens)
  • Emerging, lightly documented Solana DeFi protocol with no major public scandals, but also no robust independent validation footprint.
  • Main unresolved concerns:
  • Lack of clearly documented audits from top firms.
  • Limited disclosure on team, governance, and risk framework.
  • No on-chain-verified metrics or formal ratings from leading risk platforms. For institutional use, Hylo currently screens as higher reputational and information risk, suitable only with strict position sizing and additional direct due diligence (founder calls, private audit confirmation, and contract review).
Evidence (1)

Economy

TVL: $29.5M

model

two sources

Economic model — Hylo Protocol (Solana)

  • Strategy/assets in: Users provide SOL liquid-staking assets (LSTs) and/or USDC/hyUSD. The core system issues hyUSD, an overcollateralized stablecoin, and xSOL, a dynamically leveraged SOL exposure token. V2 adds eHYUSD, which is designed to remain delta-neutral while accruing protocol-wide revenue.
  • Yield source: Primarily native SOL staking yield, plus mint/redeem fees, xAsset fees, borrow rates on non-yielding collateral, and P&L from protocol rebalancing. Yield and borrow income are split between Earn Pool depositors and treasury; mint/redeem fees go to treasury.
  • Organic vs subsidized: Predominantly organic/endogenous yield from staking, protocol fees, and rebalancing. Promotional XP/boost programs are subsidies and should not be treated as sustainable APY. The protocol previously described 8–11% reserve yield, but this is a protocol estimate, not independently verified.
  • Market exposure: eHYUSD is intended to be market-neutral; hyUSD is stablecoin exposure backed by SOL LSTs; xSOL is explicitly directional and leveraged long SOL. xSOL has volatility-decay risk.
  • Leverage/looping/external exposure: xSOL leverage is dynamic and protocol-managed, with no conventional liquidation. The protocol supports looping products such as eHYUSD/USDC and eHYUSD/hyUSD, creating additional smart-contract and liquidity risk. Restaking exposure was not identified. Effective leverage depends on collateral TVL and xSOL market capitalization; no current on-chain ratio is verifiable.
  • Lock-ups/withdrawals/fees: No fixed lock-up was identified. Minting/redemption are protocol-mediated; fees adjust with system health, increasing stress-period exit costs. Exact limits and current fee parameters: Not verifiable as of September 5, 2026.
  • TVL: Solana is the only supported chain. A current Dune total, product breakdown, trend, and Dune-vs-DeFiLlama comparison: Not verifiable as of September 5, 2026. DeFiLlama’s accessible page reports $90.46m Solana TVL, but the page is stale (crawled 10 months ago) and conflicts with more recent, much smaller product figures shown by Hylo; treat the DeFiLlama figure as stale, not current.
  • APY: eHYUSD was reported at 8.44% on July 14, 2026; DeFiLlama search data reported a 5.2% average pool APY, but historical APY volatility and sustainability are Not verifiable as of September 5, 2026. Structured fields: organic_yield_pct: null; leverage_ratio: null. Contradiction: DeFiLlama’s $90.46m TVL conflicts with newer Hylo product-level displays; no raw on-chain check was available, so the discrepancy remains unresolved.
Evidence (4)

reserves

two sources

As of September 5, 2026 — Solana only. Assessment: Hylo’s economically relevant “reserve” is the protocol collateral pool backing hyUSD and xSOL, not a conventional cash/T-bill treasury. Documentation describes a basket of Solana LSTs, with a variable reserve representing collateral value above hyUSD backing.

  • Size / liquid reserves: Not verifiable as of September 5, 2026. Dune on-chain verification is unavailable in this run, and public analytics are not equivalent to reserve balances. DeFiLlama currently reports $48.65m for the broader Hylo parent protocol, including Hylo Protocol and Hylo LST products; this should not be treated as treasury or collateral-pool cash. RWA.xyz reports approximately $17.01m on-chain market capitalization for hyUSD, which is a token metric, not proof of total collateral reserves.
  • Liabilities: Not verifiable as of September 5, 2026. hyUSD supply is publicly reported by RWA.xyz at approximately $16.42m, but total system liabilities—including xSOL-related claims, stability-pool obligations, fees, and any other protocol liabilities—cannot be established from the available evidence.
  • Addresses: Public documentation identifies Hylo programs and token mints, including Exchange v0.1 (HYEXCHtHkBagdStcJCp3xbbb9B7sdMdWXFNj6mdsG4hn), Stability Pool v0.1 (HysTabVUfmQBFcmzu1ctRd1Y1fxd66RBpboy1bmtDSQQ), hyUSD, xSOL, hyloSOL, and hyloSOL+. It does not establish a complete, independently verified list of reserve vaults or treasury wallets.
  • Composition / policy: LST collateral, protocol fees, and a treasury-revenue reserve may support stability-mode incentives. These mechanisms are documented by Hylo but remain unverified marketing/protocol claims absent independent balance verification.
  • Custody / control: Hylo claims autonomous, permissionless operation without a fund manager. RWA.xyz lists no crypto custodian or auditor for hyUSD, and reports 0 confirmed attestations. Contradiction / data-quality callout: DeFiLlama’s broader $48.65m figure and RWA.xyz’s $17.01m/$16.42m hyUSD figures measure different scopes; neither proves reserve solvency. On-chain reserve balances, treasury control authority, and attestations remain unresolved.
Evidence (5)

tokenomics

two sources

Hylo Protocol currently has no launched native token on Solana or elsewhere. All token-related details are therefore either absent or speculative and must not be treated as live tokenomics. ### 1. Existence of a native token

  • Public sources (site, docs, analytics, explorers, media) show no deployed SPL token contract corresponding to a Hylo governance or utility token on Solana.
  • No listing appears on major aggregators (CoinGecko, CoinMarketCap, DeFiLlama) under “Hylo Protocol” or “HYLO” tied to the hylo.so domain.
  • Therefore, Hylo has no tradable native token as of the latest available data. Because there is no verifiable live token, all items below are Not verifiable as of 2026-09-03 unless explicitly stated. ### 2. Token identifiers & supply
  • Name/ticker/contract address: Not verifiable as of 2026-09-03.
  • Total vs circulating supply: Not verifiable as of 2026-09-03.
  • Market cap / FDV: Not verifiable as of 2026-09-03. ### 3. Utility, governance, and value accrual
  • Any references to future tokens in marketing or roadmap materials (e.g., “points”, “future governance token”, “rewards token”) are unverified marketing claims unless backed by deployed contracts or independent filings.
  • Governance role, revenue share, buybacks, burns, staking rewards: Not verifiable as of 2026-09-03. ### 4. Emissions & unlocks
  • Emissions schedule and unlock schedule: No independently verifiable schedule, TGE date, or vesting contracts for a Hylo token are available from non-protocol sources.
  • Whether unlocks happened on-chain: Not verifiable as of 2026-09-03. ### 5. Allocations & holder concentration
  • Team/investor/treasury/community allocations: Not verifiable as of 2026-09-03.
  • Top-holder concentration/insider wallets: Not verifiable as of 2026-09-03. ### 6. Contract controls & risk knobs
  • Mint/burn/blacklist/fee-switch functions and controllers: Not verifiable as of 2026-09-03, since no token contract is confirmed. ### 7. DEX liquidity and listings
  • No Hylo-native token pool or listing is visible on major Solana DEXs (Jupiter router, Raydium, Orca) under a confirmed Hylo contract.
  • DEX liquidity depth and main listings: Not verifiable as of 2026-09-03. Risk takeaway: For institutional analysis, Hylo should currently be treated as a protocol without a live native token. Any investment thesis based on a “Hylo token” is contingent on future launches and carries high uncertainty until on-chain contracts and third-party listings exist and can be independently verified.
Evidence (6)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

Hylo’s BTC-specific stress impact is not directly verifiable from the provided sources because the protocol documentation and third-party analyses describe Hylo primarily as a SOL/LST-backed system with hyUSD and xSOL, not a BTC-collateralized design. On the documented mechanism, a severe drop in the underlying collateral would first push the collateral ratio down, which can trigger dynamic fee increases below 150% and then Stability Pool intervention below 130% to reallocate risk and restore solvency. If the shock is deep enough that the collateral ratio cannot be restored, the docs and analyses indicate the downside is concentrated on xSOL and, in an extreme case, hyUSD peg stability could be impaired.

For the specific scenario of Bitcoin falling below $10,000, the effect on Hylo is Not verifiable as of 2026-09-03 because no provided source establishes that BTC is an active collateral input on Solana for this protocol, nor do the sources give a BTC-specific stress simulation or a mapped exposure path. The only BTC mention in the results is a general market-price article, not a protocol risk analysis. So the defensible risk reading is: if Hylo were exposed to BTC indirectly or via a BTC-linked collateral pool, a sub-$10,000 BTC shock would likely be treated like a severe collateral drawdown, activating Hylo’s rebalancing and stability mechanisms; but the actual protocol impact for Hylo itself is Not verifiable as of 2026-09-03 from the supplied evidence.

Evidence (8)

stress scenario - largest collateral depegs 20%,

one source

Hylo’s documented risk logic says a collateral ratio (CR) above 150% is healthy, CR below 150% triggers fee-based tightening, and CR below 130% activates the stability pool, which converts staked hyUSD into xSOL to restore coverage. Under a 20% depeg of the largest collateral, the impact cannot be quantified from the available sources because the current on-chain collateral mix for Hylo was not independently verified in this run; therefore the protocol-level loss, post-shock CR, and whether the system would enter Stability Mode 1 or 2 are Not verifiable as of 2026-09-03. If the largest collateral is truly the dominant LST in a basket, a 20% depeg would reduce backing value materially, but the exact effect depends on that asset’s share of total collateral and the starting CR, neither of which is reliably established here.

Evidence (5)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

Hylo does not appear to have a *traditional external counterparty* (for example, a lender or OTC borrower) whose insolvency would create a clean credit-loss waterfall. Based on the sources I found, Hylo is an on-chain Solana protocol backed by Liquid Staking Tokens, with loss exposure concentrated in the protocol’s own collateral pool and stability mechanisms rather than in an off-chain counterparty. If the *top counterparty* means the largest underlying LST issuer/validator set or a major collateral component becoming impaired, the expected loss path is: collateral value falls first, then Hylo’s collateral ratio compresses, then the protocol shifts from normal operation into fee-adjustment or stability-pool mode, and finally the system may need rebalancing via its own on-chain mechanism.

In that path, the loss is borne first by the protocol’s surplus collateral and then by hyUSD holders and/or xSOL holders through reduced backing or a reallocation of value inside the system; the exact allocation is not fully verifiable from the available web sources. The stated compensation/backstop is the stability pool: users deposit hyUSD to earn yield while supporting rebalancing of the collateral ratio, and one source describes an insurance-vault style backstop that earns yield from staking rewards, protocol fees, and rebalancing premiums. That implies compensation, if any, is internal and on-chain, funded by protocol-owned buffers and stability-pool participants rather than an external insurer.

The smart-contract impact path is therefore: collateral impairment -> ratio deterioration -> contract-level fee changes / rebalancing logic -> stability-pool involvement -> possible conversion or redistribution between hyUSD and xSOL. The audited codebase described an exchange program minting hyUSD and xSOL from LST collateral and a stability pool that supports collateral-ratio rebalancing, but the precise insolvency waterfall is not fully documented in the sources I found. Not verifiable as of 2026-09-04: the exact loss waterfall, seniority between hyUSD and xSOL, and whether any specific external counterparty insolvency is explicitly covered by the contracts or audits.

Evidence (4)

stress scenario - committed fraud by the DAO or owners

two sources

No public evidence in the provided sources shows that Hylo Protocol’s DAO or owners committed fraud. The only Hylo-specific materials here are documentation about protocol mechanics and a third-party risk note; neither alleges misconduct, theft, misrepresentation, or governance abuse by the DAO/owners. For a stress scenario, the relevant fraud modes for a DAO-controlled DeFi protocol are generic and include: a deceptive treasury proposal, insiders draining funds, or a fake/project clone used to mislead users.

Those are recognized DAO/crypto fraud patterns, but they are not evidence that Hylo has done this. Because on-chain verification is unavailable in this run, any claim about treasury movements, governance capture, or owner-controlled drain is Not verifiable as of 2026-09-03. On the record available here, the correct risk statement is: no verified fraud finding, only a hypothetical insider/DAO-fraud scenario consistent with broader DAO fraud typologies.

Evidence (7)

stress scenario - primary yield source negative 30d,

unverified

Hylo’s primary yield source is negative under the stress scenario if the 30-day SOL/LST carry turns negative, because the protocol’s yield for hyUSD/sHYUSD is built from LST staking rewards and related collateral-pool yield; if that underlying yield is negative, the primary yield leg is negative as well. Hylo’s documentation says the Earn/Stability pool yield is derived from collateral pools, with SOL-pool yield coming from native staking rewards and the overall yield harvested each epoch. For a stress analysis, the key issue is that negative primary yield would pressure the yield-bearing side first, while Hylo’s design still routes value through the stability mechanism and fee adjustments rather than relying on external revenue.

The protocol also states that, during stress, the stability pool can activate when collateral ratios weaken, and sHYUSD can become more volatile if that pool is activated. What is not verifiable as of 2026-09-03 from the provided sources is the actual 30-day signed yield figure, the live chain-level yield contribution, or whether the negative yield is currently offset by fees or other revenue streams. The documentation confirms the yield sources, but not the present on-chain magnitude.

So the risk conclusion is: yes, a negative 30d primary yield is a credible stress condition for Hylo, and it would directly impair the protocol’s main user-facing yield product; however, the exact size of the impairment is Not verifiable as of 2026-09-03 without on-chain data.

Evidence (4)

Governance & Legal

governance

two sources

Assessment as of September 13, 2026: Hylo’s public frontend is operated at hylo.so and development artifacts are maintained under the hylo-so GitHub organization. The organization has no public members, so individual developer/control identities are not disclosed. The documentation describes “protocol governance” as able to modify the collateral/LST registry and states that treasury revenue may be used for recapitalization.

These are material powers, but the governing account, proposal venue, voting token, execution authority, signer set, and constraints are not identified; treat this as an unverified marketing claim. No public, verifiable proposal process or live token-holder DAO was identified. The available Hylo GitHub repositories include forks of Squads V4 and its public client, but this does not establish that Hylo’s deployed programs or treasury are controlled by a particular Squads multisig.

Voting concentration, top holders, upgrade authorities, treasury ownership, timelock settings, multisig signers/threshold, and emergency powers require on-chain inspection. Dune was unavailable in this run; therefore: Not verifiable as of September 13, 2026. The audit confirms the deployed program scope and source repository, but does not identify operational authorities.

DAO conclusion: governance is not demonstrated as real protocol control; classify it as company/developer-controlled or undisclosed rather than DAO-controlled. Legal entity, jurisdiction, registration number, directors, and applicable ToS: Not verifiable as of September 13, 2026.

Dao governance
No
Evidence (5)

legal & regulatory

one source

Hylo Protocol’s legal/regulatory profile is not fully verifiable from the gathered web evidence. The strongest source tied to the protocol is its privacy policy, which identifies the service as operated by Savvy Sales AI LLC, a Wyoming, USA limited liability company, with privacy contact details and a Wyoming/US nexus. However, the protocol’s terms of use that surfaced are for a separate entity at hylo.com in Oakland, California, and should not be assumed to govern Hylo Protocol; that source is likely a name-collision and not reliable for this protocol.

For Hylo Protocol specifically, I could not verify a published terms-of-service/restrictions page, KYC/AML policy, formal legal structure beyond the privacy policy, or any disclosed regulator warnings, enforcement actions, court cases, or sanctions designations. Accordingly, the correct status for those items is Not verifiable as of 2026-09-03. The available material does not show that Hylo Protocol or its identified entity is under sanctions, and there is no verified evidence here of active regulator enforcement against the protocol or entity itself.

The privacy policy indicates data collection and user-rights handling, which is relevant for data protection, but it does not by itself establish a broader regulated financial-services structure. Based on the evidence gathered, the safest classification is that Hylo Protocol appears to be a US-linked software/service entity rather than a verified licensed financial intermediary; any stronger regulatory or compliance characterization would be an unverified marketing claim unless corroborated by independent legal or regulatory records.

Sanctioned
No
Entity
Savvy Sales AI LLC
Jurisdiction
Wyoming, USA
Evidence (3)

legal registries

two sources

No exact GLEIF LEI record for 'Savvy Sales AI LLC', 'Hylo Protocol'. OFAC SDN screening of 'Savvy Sales AI LLC', 'Hylo Protocol': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Savvy Sales AI LLC
  • Hylo Protocol
Sanctioned
No
Evidence (4)

Stability

stability

one source

Hylo issues its own stablecoin, hyUSD, so own_stablecoin is true. I found no verifiable evidence in the retrieved sources of any hyUSD depeg event, so stable is true and depeg_count, max_depeg_pct, and last_depeg_date are not verifiable as of 2026-09-05.

Own stablecoin
Yes
Stable
Yes
Stablecoin ids
  • hyUSD
Evidence (3)

Risks & Strengths

risks

one source

Hylo’s principal risks arise from its SOL/LST-backed stablecoin design, leveraged xSOL mechanics, oracle dependence, and reliance on a single Solana execution environment. Dune/on-chain verification was unavailable for this run; therefore current TVL, collateral composition, concentration, and reserve sufficiency are Not verifiable as of 2026-09-05. Risk ratings are qualitative and reflect documented mechanisms, audit history, and residual design exposure.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Smart-contract implementation failureA coding, account-validation, or upgrade defect could misprice assets, authorize improper minting, or impair withdrawals. OtterSec identified two critical findings in the audited version.HighMediumMultiple audits, remediation of reported findings, account checks, and documented slippage protections.Audit coverage reduces but does not eliminate undiscovered-bug and deployment-drift risk.
SOL/LST collateral depeghyUSD is backed by SOL liquid-staking assets, so SOL volatility, LST impairment, or staking-provider failure can reduce collateral value and threaten the peg.HighHighLST redemption-value pricing, overcollateralization, dynamic fees, and Stability Pool conversion.Collateral remains crypto-native and correlated; extreme losses can overwhelm safeguards.
Stability Pool exhaustionSustained SOL declines may consume Stability Pool hyUSD and treasury resources, leaving insufficient capacity to restore collateralization or the peg.HighMediumTwo stability modes, adjusted collateral-ratio monitoring, treasury bounties, and recapitalization procedures.Backstops depend on available liquidity, reserves, and orderly market participation.
Oracle and valuation-model riskStale or manipulated SOL/USD data, EMA lag, or errors in LST/NAV calculations can enable unfair minting, redemptions, or incorrect collateral ratios.HighMediumPyth EMA pricing, protocol equations, and audit recommendations for oracle validation and slippage checks.Oracle outages, latency, and model-boundary failures remain possible.
Solana and dependency concentrationA Solana outage, congestion event, validator/LST-provider issue, or dependency failure could halt minting, redemption, or risk rebalancing across the entire deployment.MediumMediumSolana-native programs and on-chain automated mechanisms; multi-chain fallback is not documented.Single-chain and external-dependency concentration remains material; current exposure is Not verifiable as of 2026-09-05.
Evidence (5)

strengths

unverified

Hylo Protocol’s top strengths are: (1) a differentiated three-token design that pairs hyUSD, xSOL, and sHYUSD to separate stability, leverage, and yield; (2) liquidation-free SOL leverage via xSOL, which is repeatedly described as avoiding forced liquidations; (3) a yield-bearing stablecoin model where hyUSD/sHYUSD are backed by Solana liquid staking tokens, letting users capture staking yield; (4) Solana-native architecture, which should benefit from Solana’s low fees, high throughput, and composability; and (5) an oracle-minimized, fully on-chain design that relies on internal protocol logic rather than off-chain custodians or RWAs, reducing dependency on centralized intermediaries.

Evidence (6)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 15 two independent sources, 11 one source, 5 unverified.
  • Oldest fact verification date: 2026-08-29.