Documentation

How Hourglass works.

Fixed-rate, fixed-term USDG loans against tokenized stocks on Robinhood Chain. A loan ends when it is repaid, rolled over, or, if the date is missed, sold at auction with the surplus returned to the borrower. Price alone never ends a loan.

Last updated · October 2026

Overview

Hourglass has three sides:

  • Borrowers lock a listed stock token and receive USDG. The rate and the due date are fixed when the loan opens.
  • Lenders deposit USDG into a 7-day or a 30-day vault. Each vault is the lender of every loan in its term.
  • $GLASS stakers back lenders against bad debt and receive 40% of protocol fees in USDG.

Every term a loan depends on (rate, due date, fee, minimum interest, protocol cut) is recorded on the loan when it opens. Governance changes never apply to loans that are already open.

Status. The contracts passed an internal security review on 3 October 2026. An external audit is pending. Read the Risks page before using the protocol.

Borrowing

Opening a loan

Choose a stock token, the amount of collateral, a term (7 or 30 days) and the USDG you want. A loan opens only if all of these hold:

  • The asset is listed and its price is usable (see Prices & market hours).
  • Loan-to-value is within the asset's limit for that term. While the US market is closed the limit is 10 points lower.
  • The loan is at least 100 USDG.
  • Total debt against that asset stays within 20% of the vault, and vault utilization after the loan stays at or below 80%.
  • The rate and fee are no higher than the maximums you signed, so a parameter change can't be slipped in front of your transaction.

You receive the loan amount minus the origination fee. Your collateral is held by LoanManager.

The rate

The rate is set by the vault's utilization after your loan, inside the asset's band, and then fixed until the due date:

rate = bandMin + (bandMax − bandMin) × utilizationAfter / 80%

Utilization is measured against the lower of the vault's current assets and its once-a-day snapshot, so a deposit made a minute before your loan can't make your rate cheaper (or anyone else's).

The due date

The due date is the open date plus the term, moved to the nearest Tuesday, Wednesday or Thursday at 18:30 UTC (14:30 ET in summer, 13:30 ET in winter). US market holidays are skipped. A 7-day loan therefore runs 5 to 9 days, and interest is charged for the actual time.

Repaying

  • Repay any time. You pay principal plus interest for the time used, with a minimum of 3 days on 7-day loans and 10 days on 30-day loans.
  • Anyone may repay a loan, but the collateral always goes to the address the borrower chose. You can set that address in advance, which matters if your own wallet is ever restricted by the token issuer.
  • Repaying, adding collateral and claiming a surplus can never be paused.

Adding collateral

You can add collateral to an open loan at any time, including weekends. It lowers the risk of a shortfall if your loan ever goes to auction, and it is needed if you roll over at a lower price.

Rolling over

From 3 days before the due date until the end of grace, the borrower can roll a loan into a new one in a single transaction. Interest owed so far is settled, the collateral is valued again at today's price, and a new rate, fee and due date are set as for a new loan. If the new amount is smaller than what is owed you pay the difference; if larger, you receive it.

Example

94.20 NVDA at $236 is worth $22,231. You borrow 10,000 USDG for 7 days (45% LTV) at 12.00%.

Origination fee (0.06%)6.00 USDG
You receive9,994.00 USDG
Interest for 7 days23.01 USDG
Repay by the due date10,023.01 USDG

Overdue loans & auctions

Grace

After the due date there is a 24-hour grace period with no penalty. Repaying or rolling over still works as normal.

Auction

When grace ends, anyone can start the auction (the protocol's keeper does it automatically). The whole collateral lot is offered in a Dutch auction priced from the oracle, not from the debt, so the price tracks what the shares are worth:

lot price = oracle value of the lot × multiplier multiplier: 102% → 85% over the first 4 active hours 85% → 70% over the next 4 active hours

The clock only runs while the US market is open and the price is usable. Weekends, holidays, a stale feed or an issuer pause stop it. Auctions can only start, and lots can only be bought, while the market is open. After 8 active hours with no buyer, the safety module may buy the lot at 70% with its reserve.

Where the money goes

  1. The vault receives principal, its share of the interest, and a 1% late fee on principal.
  2. The protocol receives its 10% share of the interest.
  3. Everything above that is the borrower's, claimable in the app under Certificates.
  4. If the sale doesn't cover the vault, the safety module pays the gap (see Safety module).

Continuing the example: NVDA falls to $200 and the loan is missed. The lot is worth $18,840 and sells at a 95% multiplier for 17,898 USDG. The vault receives 10,120.71, the protocol 2.30, and 7,774.99 USDG goes back to the borrower.

Lending

Vaults

There are two ERC-4626 vaults in USDG: hgUSDG-7D and hgUSDG-30D. Deposits receive vault shares. The share price rises as interest accrues on open loans, second by second, so it does not jump when a loan is repaid.

vault assets = idle USDG + principal lent out + interest accrued on open loans − provisions for loans at risk

Withdrawing

  • If the vault has enough idle USDG, you withdraw immediately.
  • Otherwise you join a first-in, first-out queue. Repayments fill the queue before anything else. Because every loan has a due date, the wait is at most about one term (7 or 30 days).
  • Withdrawals never push utilization above 80%. The part that would is kept in the queue until more loans repay.
  • Requests can be cancelled while they wait.

Protections built into the vault

  • Shares received from a deposit or transfer are locked for 5 minutes, so nobody can deposit, borrow cheaply and withdraw in one go. Amounts under 1 USDG don't lock the receiver.
  • Deposits are paused while the vault has a loan in auction, so nobody can buy shares just before a settlement and sell just after.
  • Anyone can mark a loan whose collateral is worth less than its debt ÷ 85%, even before its due date. The expected loss is then taken out of the share price straight away and put back if the price recovers or the loan is repaid.
  • Each vault has a deposit cap: 250,000 USDG at mainnet launch, raised over time by governance.

Prices & market hours

Prices come from Chainlink feeds, one per stock token. Spot prices from on-chain pools are never used anywhere.

CheckRule
Market openPrice must be no older than 25 hours.
Market closedFriday 21:00 UTC to Monday 01:00 UTC, plus US market holidays. Price may be up to 72 hours old; new loans get 10 points less LTV; auctions don't run.
Issuer flagsIf the stock token reports paused or oraclePaused (for example during a corporate action), no loan can open, roll over or go to auction on that asset. Repaying and adding collateral still work.
SanityAnswer above zero, complete round, 8 decimals.

Feed prices already include the issuer's corporate-action multiplier. USDG is valued at $1.

Safety module & $GLASS

Staking

  • Stake GLASS to receive stkGLASS. Stakers earn 40% of protocol fees in USDG, streamed over 7 days after each distribution.
  • To unstake, start a 10-day cooldown, then withdraw within the following 2-day window. The cooldown means nobody can leave just ahead of a loss.

If an auction falls short

  1. The USDG reserve in the safety module pays the vault automatically, in the same transaction.
  2. Anything the reserve can't cover opens a slash budget of 30% of the GLASS staked at that moment. The guardian can slash within that budget, at most once a day. Slashed GLASS goes only to the recovery address, is sold, and the USDG is paid to the vault.
  3. Anything left is a loss shared by the vault's depositors in proportion to their shares.

Fees & revenue

FeeRatePaid to
Origination, 7-day loan0.06%Protocol
Origination, 30-day loan0.25%Protocol
Share of interest10%Protocol (90% to lenders)
Late fee, only if a loan goes to auction1% of principalLenders

Rollovers pay the origination fee of the new term. Hard limits in the contracts: origination ≤ 1%, interest share ≤ 20%.

Protocol fees collect in FeeSplitter. Anyone can trigger a distribution:

  • 40% to stakers, in USDG.
  • 30% to the buyback operator, who buys GLASS on the open market (USDG → ETH → GLASS). Half is burned, half is added to the safety module.
  • 30% to the USDG reserve until it reaches its target (25,000 USDG at launch), then to the treasury.

Every distribution is listed on the public ledger.

Governance

RoleCanCannot
Timelock (48 h delay). Admin proposes, anyone executesList or delist assets; change LTV, rate bands, caps and fees within hard limits; set addressesChange the terms of an open loan
Guardian (no delay)Pause new loans and rollovers; cancel queued timelock proposals; add future holidays; push back the earliest auction start (up to 7 days, forward only); slash within an open budgetPause repayment, adding collateral, withdrawals or surplus claims

The deployer keeps no role. Every change goes through the timelock and is visible on-chain for 48 hours before it can take effect.

Keepers

Some actions have to be triggered by a transaction. The protocol runs a keeper bot for them, but none needs a special role: anyone can call every one of them.

  • startAuction once a loan's grace has ended.
  • pokeAuction every few minutes during an auction, so pauses are kept off the auction clock.
  • markLoan when collateral value falls, so vault share prices reflect expected losses.
  • processQueue to pay waiting withdrawals.
  • distribute on FeeSplitter.

Parameters

First listings planned for mainnet. The contracts are always the source of truth; today's rates are on the Markets table.

GroupAssetsLTV 7DLTV 30DRate band
Index & ETFSPY, QQQ60%55%8–12%
Mega-capNVDA, AAPL, MSFT, GOOGL, META, AMZN45%40%10–16%
High volatilityTSLA40%35%12–20%
T-billsSGOV80%80%6–8%
Minimum loan100 USDG
Max debt per asset20% of vault
Max utilization80%
Weekend LTV reduction10 points
Grace24 hours
Rollover window3 days before due
Minimum interest (7D / 30D)3 / 10 days
Auction102% → 85% → 70%, 8 active hours
Unstake cooldown / window10 days / 2 days
Slash budget per shortfall30% of stake

Contracts

Network: Robinhood Chain Testnet (chain ID 46630).

ContractAddress
LoanManager
Loans, auctions, oracle checks
0x40aC092233166a1Dc20196fd7142E6787145E7Cf
HourglassVault · 7D
hgUSDG-7D
0x6D49A7769A672f353d9E3f21A8daDd296652c716
HourglassVault · 30D
hgUSDG-30D
0x4897D59b274D45982C6571e22d688De9dAb8Fcc3
SafetyModule
stkGLASS, USDG reserve
0x8C9c43E7c0b5aF02BCe69240FA06Ab223eEcAB46
FeeSplitter
40 / 30 / 30
0x9ff9437871b415937C27638ab25b57400b924b74
TimelockController
Owner of every contract, 48h delay
0xEe3CDC6929dF4716A39A5347D6986Ee04400A534

$GLASS has not launched yet. Its address will be published here and on @hourglasslend at launch, and nowhere else.