Risks
Read this section before you trade. It describes how hashpad.fun works today, and nothing in it is softened.
Mining coins are synthetic and unbacked
A mining coin is a token whose price is set by a feed. It is not a claim on anything. HASH is not backed by hashrate, S21 is not backed by machines, MWH is not backed by electricity, and BTC on hashpad.fun is not backed by bitcoin. No contract holds any asset that a coin can be redeemed for. Holding a mining coin is holding a number the protocol has agreed to quote.
The ask is minted from nothing
When a coin is registered, the PegManager mints coin worth $100,000 at the feed price and places it as the ask. When buyers take more than half of that, it mints more. There is no cost of production and no reserve behind the mint. Every coin a buyer receives from the ask was created at the moment the seed or refill happened, against nothing.
The bid holds only dollars buyers paid in
The only dollars in the system are the ones buyers paid to take coin from the ask. Those dollars are placed one tick spacing below the feed as the bid. That is the entire pool of money available to pay sellers. The protocol contributes nothing to it.
The protocol is short every coin outstanding
Every coin outstanding was sold by the protocol and is owed a bid. Every dollar in the bid was received at an earlier, possibly lower, price. If the feed rises after coin has been sold, the manager re-places the same dollars at the new higher price, where they buy back fewer coins. There is no mechanism that adds dollars to a bid when the price rises. The protocol's liability grows with the price of the coin; its assets do not.
The bid pays first-come, first-served
The bid is a Uniswap range. Sellers take from it in the order their transactions land, until it is empty. If more coin is offered than the bid can absorb, later sellers' transactions revert and they hold coin nobody is obligated to buy. There is no queue, no pro-rata haircut, and no obligation to refill the bid. The keeper refills the ask with newly minted coin; it has no equivalent for the bid, because it has no dollars to put there.
Hashprice and BLOCK are BTC-correlated and the short is unhedged
HASH, BLOCK, BTC, and SATVB all move with the price of bitcoin. A bitcoin rally raises the protocol's liability on all four at once. Nothing offsets that exposure. The protocol does not hold bitcoin, does not hold hashrate, and does not hold any derivative. If bitcoin doubles, the dollars in every BTC-correlated bid buy back half as much coin as was sold.
Protocol fee sweeps sell coin into the bid ahead of users
Every 15 minutes the keeper sweeps the buyback and protocol shares of fees, which are held in mining coin, and sells them for USDG against the peg bid. Those sales consume bid depth. They happen on a schedule, before any user sells in the same cycle, and they are the protocol selling its own coin into its own bid for dollars that users paid in. If the bid is thin, a sweep can leave it empty.
Halvings cut HASH and BLOCK by roughly half, by design
At the next Bitcoin halving, at block height 1,050,000, the subsidy goes from 3.125 BTC to 1.5625 BTC in one block. HASH and BLOCK are computed from the subsidy, so their reference prices fall by roughly half in the same minute, and the keeper reprices their pegs at the next tick. A holder of HASH at the halving loses about half the coin's dollar value. This is not a failure; it is what the unit measures. Markets paired with HASH or BLOCK do not reprice in coin terms, but their dollar value falls with the coin.
Stale-price windows
If the keeper stops pushing a price for 6 hours (HASH, BTC, BLOCK, SATVB) or 72 hours (TH, S21, MWH), the feed is stale. The peg pool does not stop. It keeps trading at the last placed level, which can be arbitrarily far from the real reference. A trader who takes coin during a stale window at a stale price has no recourse. Coins marked manual are curated by hand and may be days old even when not formally stale.
The keeper is a single operator with mint authority and no timelock
One address runs the keeper. It pushes every price, and prices drive minting into the ask and repricing of the bid. A wrong price, whether by bug, by a bad upstream source, or by a compromised key, mints coin at the wrong level and moves every bid with it. The keeper address is set by a single owner. There is no timelock, no multisig requirement, no second signer, and no on-chain circuit breaker. The only circuit breaker is the keeper's own two-source BTC/USD divergence halt, which runs off-chain and can be disabled by the operator. Every keeper action is a public transaction, so it is auditable after the fact, but not before.
Market tokens
Every market token opens at a $5,000 market cap with its entire supply in a pool nobody can withdraw. That does not make it worth anything. Its price in coin is set only by what buyers pay. Its price in dollars also moves with the pair coin, so a token can lose dollar value with no trade at all.