Bulwark docs

How the guard works

Margin pools, the buffer, stages, retries, backstops, the guard's status, and when it holds off.

Margin pools and the buffer

Hyperliquid liquidates a pool, not a position:

Account modePools
StandardOne cross pool per dex (the main dex, xyz, …), plus one pool per isolated position
UnifiedOne pool per collateral token, shared across dexes, plus isolated positions
Portfolio marginShown read-only. The guard does not act on it

For each pool the guard computes equity and maintenance margin the way Hyperliquid does (margining, liquidations) and tracks the buffer:

buffer = pool equity ÷ maintenance margin. Liquidation happens at 1×.

The model was checked against Hyperliquid's own numbers on live accounts: over one hour and 15,621 comparisons it matched to floating-point rounding.

Stages

Your rules set lines on the buffer and what happens at each. Typical actions:

  • Alert you.
  • Move idle USDC in: the exact amount you set, from your own idle balances (spot, or another dex's free margin), once each time the line is crossed. It never takes another pool below your highest line.
  • Trim: cut a position by the share you set, or trim until the buffer is back at the line you set.
  • Close a position or everything.
  • Cancel your orders that would add to a position.

What a stage does after it has acted is your choice, for each stage. There is no default, and a stage can't be saved without one:

  • Once per fall: it acts once when its line is crossed, then leaves the rest of the fall to the backstop. It acts again only after the market recovers to where it was when the stage acted, or the positions it acted on are gone. Its own trim lifting your buffer back above the line does not count as a recovery.
  • Every time the line is crossed: it acts again each time your buffer comes back above the line and falls through it, including when the buffer only came back because of the guard's own trim.

You can also set a limit: at most N actions in H hours, both numbers yours. When the limit is reached, the stage holds and you get one alert; your backstop still stands. The replays show both choices on the same days.

Rules signed before this choice existed keep running as they did (every time the line is crossed) until you choose. The app and an alert ask you to choose, and the new version needs your signature.

If a stage's order does not fill, it is retried (see below). Orders are reduce-only IOC orders, priced no further from the mark than the slippage limit you set.

When an order does not fill

An IOC order fills at once or not at all. In a fast market it can miss: by the time it reaches the book, the price has moved past your slippage limit. Or it can fill only partly.

When that happens, the stage is not done. The guard sends the unfilled part again on the next price update, as long as the stage's line is still crossed:

  • Same checks: every retry is a new reduce-only IOC and passes all seven checks below, including the limit of 20 guard actions a minute.
  • Same slippage: each retry is priced from the mark at that moment and never further from it than your slippage limit. The limit is never widened.
  • Never more than needed: a retry is never larger than the unfilled part, or than the position.
  • No double sends: a retry waits for account data newer than the last attempt, so a fill that has not shown up yet is never sent twice.
  • After 3 attempts that did not fully fill, you get a critical alert saying the guard cannot fill within your slippage limit. It keeps trying while the line is crossed; you may want to act yourself.
  • It stops when the stage's line is no longer crossed, the position is closed, or you stop the guard.

Every attempt is in your audit log with its number, its limit price and how much filled.

Retries help when the price pauses or bounces between attempts. They cannot help when the account goes from its line to liquidation faster than an order can reach the exchange; the crash-day replays show both.

Rules can also watch account drawdown, a market's price move, or a position's leverage, and can be limited to fixed windows (weekend, overnight, US session).

Backstops on the exchange

For every guarded position, the guard keeps a reduce-only stop order resting on Hyperliquid at the price where the pool would reach your lowest line. It triggers on Hyperliquid's mark price even if Bulwark is down.

When a pool holds several positions, the stop is priced as if every position in that pool moves against you at once, by the same percentage: longs fall and shorts rise together. Each stop is placed at the earlier of that price and the price where that position alone would take the pool to the line. So it fires no later than the line would be crossed if they move together. Priced one position at a time, it could sit far too late. With two equal positions falling together, the pool reaches a 2× line after a 5.8% fall, but each single-position stop would sit about 11.5% down, where the pool is already gone.

The cost: if only one position falls, its stop fires earlier than strictly needed, and you exit sooner than the line alone would require. The replays show both.

The stop is re-priced whenever your positions, your margin (deposits, withdrawals, transfers, funding) or your rules change, and on the guard's regular sync once a minute. It is replaced when it drifts more than 0.5% from where it should be, and removed when the position is gone.

Measured in our replays: when two positions in a pool fell together, the accounts that were liquidated with the old pricing (each position on its own) survived with this one. When only one of them fell, the earlier stops kept less money. This pricing is on testnet; mainnet keeps the old pricing until it has been checked on funded testnet accounts.

Your own stop-loss and take-profit orders

  • Never touched by the guard: your reduce-only orders, including your stop-loss and take-profit, are never cancelled. The guard's only cancelling action, "cancel orders that would add to a position", leaves every reduce-only order alone. The kill switch and wipe cancel only the guard's own orders.
  • When your stop and the guard's backstop sit on the same position:
    • both rest on Hyperliquid and fire on the mark price, so whichever is reached first fires;
    • both are reduce-only, so together they never close more than the position or turn it around;
    • after either fires, the guard re-prices or removes its backstop for what is left.
  • Order limit: your orders and the guard's count toward Hyperliquid's limit of 1,000 open orders per account.

When the guard holds off

The guard acts only on fresh data: mark prices less than 10 seconds old and account state less than 30 seconds old. Otherwise it does nothing, records why in your audit log, and alerts you.

The guard's status

The app shows what the guard is doing right now, as the guard itself reports it:

StatusMeaning
ProtectedRules are active and no line is crossed
ActingThe guard has just acted, or is retrying an order that did not fill
At riskA line is crossed and that stage has already acted; the next line has not been reached
PausedThe guard cannot act right now. The reason is shown: data too old, Hyperliquid not answering, the signer could not use your guard key, or your guard key's approval on Hyperliquid has expired or been removed
StoppedYou turned on the kill switch
No rulesYou have not signed any rules yet
Alerts onlyAutomatic action is off in your region; the guard alerts you instead

With the status comes the time the guard last checked your rules on fresh data. If the guard has not reported for a minute, the app shows it as paused rather than assume all is well.

The checks before every signature

Every action passes seven checks twice: once when it is decided, and again in the signer just before signing.

Check
I1Every order is reduce-only, opposes the open position, and is no larger than it
I2Nothing raises leverage or changes margin mode; isolated margin can only be added
I3Funds move only between your own balances, only into a pool that needs margin, and never take a source pool below your highest line
I4Only under a policy whose hash matches your verified signature, with the kill switch off and automation allowed in your region
I5Every action traces to a rule in the policy you signed
I6At most 20 guard actions per minute; orders meet the $10 minimum unless closing
I7A builder code is attached only when enabled and approved; if the exchange rejects it, the order is retried without it

Your commands

  • Kill switch: stops the guard at once and cancels only the orders it placed. Your positions and your own orders are left alone.
  • Panic unwind: closes every position with reduce-only orders over the time you choose (5 minutes to 7 days): a TWAP for positions of $100 or more, an IOC below that.
  • Wipe guard key: stops the guard, cancels the orders it placed, and retires your guard key: a KMS key is disabled and scheduled for deletion; an encrypted key is destroyed. (Available through the API today; the button arrives with the app's next design update.)

Each command is signed in your wallet and must reach the server within 60 seconds of signing.

On this page