Skip to content
Temporal Docs← Back to the app

08 · Testnet venue & testing

Testnet venue & testing

One shared venue#

This is one shared venue, not a copy per browser. The chain holds the accounts of record and the service reads it; a screen is a client, reading the view over a live stream and calling an API to act. Two browsers are two wallets on the same book, with the same front, and neither sees the other's positions.

The chain: where everything computes#

The venue computes in contracts on the Elysium testnet (an Arbitrum Orbit chain settling to HyperEVM). The ledger holds every account, deposit, position, fee and funding charge. The front contract picks the best quote on each side from the makers' posted curves, and the margin contract applies the closed-form margin for sold options. What the contracts cannot see, a keeper on the service pushes in: the oracle's fitted surfaces, the roster of makers standing, the marks, and the perp mark. The keeper does not set a price and clears no trade.

Money and the perps stay on HyperCore. Deposits and withdrawals move USDC between your HyperCore account and the ledger, and perps settle on HyperCore. You sign an intent for each act; the venue's signer submits it and pays the gas. The chip in the header names the ledger version and the last block the service has read, and says so when the service is behind the chain.

Only the latest minimal core lives on chain: each deploy deletes retired code at the root and is checked against a size budget, so the contracts carry nothing they do not use.

Testnet and mainnet#

The venue has two phases on the identical engine. Testnet is running now: every wallet is a real testnet wallet, deposits and payouts settle on HyperCore testnet, and no real money moves. A wallet's own accounts may fill each other, so one person can exercise both sides of a test. Mainnet starts when Elysium ships mainnet: the same venue on real funds, where a taker is never filled against a curve owned by its own wallet.

The event log#

The service keeps an append-only event log of everything it sees: every request, fill slice, requote, settlement, oracle tick and account creation is written down with its wallet, its timestamp and its before and after numbers. A restart loses nothing, and replaying the log from event one reproduces the state hash exactly — which is what makes an independent audit possible at all.

Two test harnesses, plus a population run#

An agent swarm runs N scripted actors — takers, makers and an oracle actor, each with its own key and wallet — concurrently against one venue, then checks the venue's own export: unit conservation per asset over every wallet, cash, anonymity, and an event log that replays to the same state hash. A format gate measures the interface itself, reading every table's alignment, row height and number format out of the live page at four widths. After each deploy that touches the interface, a population run drives ten actors as profit maximisers, one per traded role, against the live testnet venue — the same run doubles as the interaction-surface QC, filing what is shown against what actually happened. A closing RETIRE step then stops quoting and closes out any account left with no actor still behind it, so a batch does not leave junk curves standing on the live book for the next one to trip over. Every harness must be green before anything ships.

The audit protocol#

The protocol an auditor follows — trace every printed number to the operator's own spreadsheet or to a closed-form invariant, then force the states that prove the mechanism rather than waiting for them — is the audit protocol.

What to expect while testing#

No real money: this is a TESTNET venue. Connecting gives you a real testnet wallet (no mainnet funds; margin comes from the USDC in your own HyperCore account when an act needs it) and nothing else — accounts appear as you open them. The oracle mark is the live Hyperliquid mark, so the book moves under you exactly as the real market does, and everything you do persists on the venue until the log is cleared.

Everything above is the short form. The canon — every ruling, every rejected alternative with the reason it was rejected, and the measurements behind each number — is the design spec, and the corroboration procedure is the audit protocol. Both live in the repository this venue is built from.