How Hourglass works.
Fixed-rate, fixed-term USDG loans against tokenized stocks on Robinhood Chain. A loan ends when it is repaid, rolled over, or, if the date is missed, sold at auction with the surplus returned to the borrower. Price alone never ends a loan.
Last updated · October 2026
Overview
Hourglass has three sides:
- Borrowers lock a listed stock token and receive USDG. The rate and the due date are fixed when the loan opens.
- Lenders deposit USDG into a 7-day or a 30-day vault. Each vault is the lender of every loan in its term.
- $GLASS stakers back lenders against bad debt and receive 40% of protocol fees in USDG.
Every term a loan depends on (rate, due date, fee, minimum interest, protocol cut) is recorded on the loan when it opens. Governance changes never apply to loans that are already open.
Status. The contracts passed an internal security review on 3 October 2026. An external audit is pending. Read the Risks page before using the protocol.
Borrowing
Opening a loan
Choose a stock token, the amount of collateral, a term (7 or 30 days) and the USDG you want. A loan opens only if all of these hold:
- The asset is listed and its price is usable (see Prices & market hours).
- Loan-to-value is within the asset's limit for that term. While the US market is closed the limit is 10 points lower.
- The loan is at least 100 USDG.
- Total debt against that asset stays within 20% of the vault, and vault utilization after the loan stays at or below 80%.
- The rate and fee are no higher than the maximums you signed, so a parameter change can't be slipped in front of your transaction.
You receive the loan amount minus the origination fee. Your collateral is held by LoanManager.
The rate
The rate is set by the vault's utilization after your loan, inside the asset's band, and then fixed until the due date:
Utilization is measured against the lower of the vault's current assets and its once-a-day snapshot, so a deposit made a minute before your loan can't make your rate cheaper (or anyone else's).
The due date
The due date is the open date plus the term, moved to the nearest Tuesday, Wednesday or Thursday at 18:30 UTC (14:30 ET in summer, 13:30 ET in winter). US market holidays are skipped. A 7-day loan therefore runs 5 to 9 days, and interest is charged for the actual time.
Repaying
- Repay any time. You pay principal plus interest for the time used, with a minimum of 3 days on 7-day loans and 10 days on 30-day loans.
- Anyone may repay a loan, but the collateral always goes to the address the borrower chose. You can set that address in advance, which matters if your own wallet is ever restricted by the token issuer.
- Repaying, adding collateral and claiming a surplus can never be paused.
Adding collateral
You can add collateral to an open loan at any time, including weekends. It lowers the risk of a shortfall if your loan ever goes to auction, and it is needed if you roll over at a lower price.
Rolling over
From 3 days before the due date until the end of grace, the borrower can roll a loan into a new one in a single transaction. Interest owed so far is settled, the collateral is valued again at today's price, and a new rate, fee and due date are set as for a new loan. If the new amount is smaller than what is owed you pay the difference; if larger, you receive it.
Example
94.20 NVDA at $236 is worth $22,231. You borrow 10,000 USDG for 7 days (45% LTV) at 12.00%.
| Origination fee (0.06%) | 6.00 USDG |
| You receive | 9,994.00 USDG |
| Interest for 7 days | 23.01 USDG |
| Repay by the due date | 10,023.01 USDG |
Overdue loans & auctions
Grace
After the due date there is a 24-hour grace period with no penalty. Repaying or rolling over still works as normal.
Auction
When grace ends, anyone can start the auction (the protocol's keeper does it automatically). The whole collateral lot is offered in a Dutch auction priced from the oracle, not from the debt, so the price tracks what the shares are worth:
The clock only runs while the US market is open and the price is usable. Weekends, holidays, a stale feed or an issuer pause stop it. Auctions can only start, and lots can only be bought, while the market is open. After 8 active hours with no buyer, the safety module may buy the lot at 70% with its reserve.
Where the money goes
- The vault receives principal, its share of the interest, and a 1% late fee on principal.
- The protocol receives its 10% share of the interest.
- Everything above that is the borrower's, claimable in the app under Certificates.
- If the sale doesn't cover the vault, the safety module pays the gap (see Safety module).
Continuing the example: NVDA falls to $200 and the loan is missed. The lot is worth $18,840 and sells at a 95% multiplier for 17,898 USDG. The vault receives 10,120.71, the protocol 2.30, and 7,774.99 USDG goes back to the borrower.
Lending
Vaults
There are two ERC-4626 vaults in USDG: hgUSDG-7D and hgUSDG-30D. Deposits receive vault shares. The share price rises as interest accrues on open loans, second by second, so it does not jump when a loan is repaid.
Withdrawing
- If the vault has enough idle USDG, you withdraw immediately.
- Otherwise you join a first-in, first-out queue. Repayments fill the queue before anything else. Because every loan has a due date, the wait is at most about one term (7 or 30 days).
- Withdrawals never push utilization above 80%. The part that would is kept in the queue until more loans repay.
- Requests can be cancelled while they wait.
Protections built into the vault
- Shares received from a deposit or transfer are locked for 5 minutes, so nobody can deposit, borrow cheaply and withdraw in one go. Amounts under 1 USDG don't lock the receiver.
- Deposits are paused while the vault has a loan in auction, so nobody can buy shares just before a settlement and sell just after.
- Anyone can mark a loan whose collateral is worth less than its debt ÷ 85%, even before its due date. The expected loss is then taken out of the share price straight away and put back if the price recovers or the loan is repaid.
- Each vault has a deposit cap: 250,000 USDG at mainnet launch, raised over time by governance.
Prices & market hours
Prices come from Chainlink feeds, one per stock token. Spot prices from on-chain pools are never used anywhere.
| Check | Rule |
|---|---|
| Market open | Price must be no older than 25 hours. |
| Market closed | Friday 21:00 UTC to Monday 01:00 UTC, plus US market holidays. Price may be up to 72 hours old; new loans get 10 points less LTV; auctions don't run. |
| Issuer flags | If the stock token reports paused or oraclePaused (for example during a corporate action), no loan can open, roll over or go to auction on that asset. Repaying and adding collateral still work. |
| Sanity | Answer above zero, complete round, 8 decimals. |
Feed prices already include the issuer's corporate-action multiplier. USDG is valued at $1.
Safety module & $GLASS
Staking
- Stake GLASS to receive stkGLASS. Stakers earn 40% of protocol fees in USDG, streamed over 7 days after each distribution.
- To unstake, start a 10-day cooldown, then withdraw within the following 2-day window. The cooldown means nobody can leave just ahead of a loss.
If an auction falls short
- The USDG reserve in the safety module pays the vault automatically, in the same transaction.
- Anything the reserve can't cover opens a slash budget of 30% of the GLASS staked at that moment. The guardian can slash within that budget, at most once a day. Slashed GLASS goes only to the recovery address, is sold, and the USDG is paid to the vault.
- Anything left is a loss shared by the vault's depositors in proportion to their shares.
Fees & revenue
| Fee | Rate | Paid to |
|---|---|---|
| Origination, 7-day loan | 0.06% | Protocol |
| Origination, 30-day loan | 0.25% | Protocol |
| Share of interest | 10% | Protocol (90% to lenders) |
| Late fee, only if a loan goes to auction | 1% of principal | Lenders |
Rollovers pay the origination fee of the new term. Hard limits in the contracts: origination ≤ 1%, interest share ≤ 20%.
Protocol fees collect in FeeSplitter. Anyone can trigger a distribution:
- 40% to stakers, in USDG.
- 30% to the buyback operator, who buys GLASS on the open market (USDG → ETH → GLASS). Half is burned, half is added to the safety module.
- 30% to the USDG reserve until it reaches its target (25,000 USDG at launch), then to the treasury.
Every distribution is listed on the public ledger.
Governance
| Role | Can | Cannot |
|---|---|---|
| Timelock (48 h delay). Admin proposes, anyone executes | List or delist assets; change LTV, rate bands, caps and fees within hard limits; set addresses | Change the terms of an open loan |
| Guardian (no delay) | Pause new loans and rollovers; cancel queued timelock proposals; add future holidays; push back the earliest auction start (up to 7 days, forward only); slash within an open budget | Pause repayment, adding collateral, withdrawals or surplus claims |
The deployer keeps no role. Every change goes through the timelock and is visible on-chain for 48 hours before it can take effect.
Keepers
Some actions have to be triggered by a transaction. The protocol runs a keeper bot for them, but none needs a special role: anyone can call every one of them.
startAuctiononce a loan's grace has ended.pokeAuctionevery few minutes during an auction, so pauses are kept off the auction clock.markLoanwhen collateral value falls, so vault share prices reflect expected losses.processQueueto pay waiting withdrawals.distributeonFeeSplitter.
Parameters
First listings planned for mainnet. The contracts are always the source of truth; today's rates are on the Markets table.
| Group | Assets | LTV 7D | LTV 30D | Rate band |
|---|---|---|---|---|
| Index & ETF | SPY, QQQ | 60% | 55% | 8–12% |
| Mega-cap | NVDA, AAPL, MSFT, GOOGL, META, AMZN | 45% | 40% | 10–16% |
| High volatility | TSLA | 40% | 35% | 12–20% |
| T-bills | SGOV | 80% | 80% | 6–8% |
| Minimum loan | 100 USDG |
| Max debt per asset | 20% of vault |
| Max utilization | 80% |
| Weekend LTV reduction | 10 points |
| Grace | 24 hours |
| Rollover window | 3 days before due |
| Minimum interest (7D / 30D) | 3 / 10 days |
| Auction | 102% → 85% → 70%, 8 active hours |
| Unstake cooldown / window | 10 days / 2 days |
| Slash budget per shortfall | 30% of stake |
Contracts
Network: Robinhood Chain Testnet (chain ID 46630).
| Contract | Address |
|---|---|
| LoanManager Loans, auctions, oracle checks | 0x40aC092233166a1Dc20196fd7142E6787145E7Cf |
| HourglassVault · 7D hgUSDG-7D | 0x6D49A7769A672f353d9E3f21A8daDd296652c716 |
| HourglassVault · 30D hgUSDG-30D | 0x4897D59b274D45982C6571e22d688De9dAb8Fcc3 |
| SafetyModule stkGLASS, USDG reserve | 0x8C9c43E7c0b5aF02BCe69240FA06Ab223eEcAB46 |
| FeeSplitter 40 / 30 / 30 | 0x9ff9437871b415937C27638ab25b57400b924b74 |
| TimelockController Owner of every contract, 48h delay | 0xEe3CDC6929dF4716A39A5347D6986Ee04400A534 |
$GLASS has not launched yet. Its address will be published here and on @hourglasslend at launch, and nowhere else.