Trust

Risks and trust

What can go wrong with a Crest position, and which parts of the system you rely on someone else for.

Market risks#

The crest moves against you. Long crest loses every epoch the crest comes in under the fixed rate; short crest loses every epoch it comes in above. Your worst epoch is set when you open the position, and you can see it in the ticket.

Early close. After each settlement, a side that can no longer cover one more worst epoch plus the reserve closes the position. Deposits can't be topped up, so a run of bad epochs ends a hedge before its market does, and the side that fell short pays the reserve.

The rules change. Changes to consensus, block building or fee rules can move the crest for good. Markets run ten epochs at most and each one caps the crest it pays, which limits how far one change reaches.

Thin books. Orders match whole, one maker to one taker. An order may wait, or never be taken. An order nobody takes can be cancelled in full at any time.

Prices are in SOL. Deposits and payments are SOL. Their value in other currencies moves with SOL's price.

Index risks#

A checkpoint can be late. An epoch's number exists only once every cohort validator's tip root is final and a checkpoint passes its challenge window. Until then, settlement on that epoch waits.

A stalled epoch cancels legs. If an epoch has no final checkpoint by the delay limit, positions waiting on it can be ended. Legs already settled stand; the rest are cancelled, not estimated. A counterparty who expects to lose the remaining legs could try to bring this about with a challenge the dispute authority never rules on.

The index is a sample. It measures the gross Jito tip distributions of a named cohort of up to eight validators. It doesn't include priority fees, other validators, or what any one staker nets after commission.

Gross distributions aren't proven to be tips. max_total_claim is what a tip account declares it will pay out. Anyone can send SOL to a tip distribution account, and the uploader's distribution tree is trusted as published. The program checks that the account holds what it declares, not where that SOL came from.

Trust assumptions#

You rely onForIf it fails
The oracle and the reviewerAttesting each epoch's stake honestlyA wrong stake makes a wrong rate unless someone challenges it within the window.
ChallengersRecomputing checkpoints and challenging wrong onesA wrong checkpoint that nobody challenges becomes final.
The dispute authorityRuling on challenges, and ruling correctlyUnruled challenges stall epochs until the delay limit; wrong rulings stand.
Jito's tip distribution program and uploadersPublishing each validator's distributionThe program is upgradeable; a change to its accounts halts collection until reviewed.
Crest's serversShowing chain state and building transactionsYour wallet still signs only what it shows you, and the chain stays the record: any RPC can confirm it.
The Crest programHolding deposits and paying them correctlyA bug could lose deposits. The accounts and instructions are documented in full here.

The bonds give each checkpoint a cost for being wrong, but they are fixed amounts and don't grow with the notional that depends on an epoch.

What Crest doesn't do#

  • It never holds your keys or signs for you.
  • It doesn't pool deposits: each position's SOL sits in its own account.
  • It doesn't lend, borrow or carry debt: when a position closes, nothing more is owed.
  • It doesn't charge a fee of its own.