Roadmap
ksUSD: deposit USDC, hold one share token, earn carry from perp funding, jitoSOL staking, and USDC lending. v1 hedges on Phoenix Perps (USDC margin via Ember), holds jitoSOL unlevered as the spot leg, and switches between normal basis and parked automatically: the on-chain smoothed funding signal decides the mode and a keeper bot executes the switch, with no manual intervention. Reverse basis is built but dormant in v1.
This roadmap runs as parallel pipelines: each advances on its own clock, and the launch gate is where they converge. Status: ✅ done · 🟡 in progress · ⬜ planned · ⏸ dormant.
Pipeline 1 — Integrations (the v1 stack)
The four on-chain primitives ksUSD composes. Three are live and wired; the perp hedge is the gating dependency.
Jito (staking) ─┐
Kamino (lending)├─→ vault plumbing wired ─→ Phoenix basis live ─→ full v1
Jupiter (swaps)─┘ (devnet) (when available)Staking
jitoSOL held unlevered, the spot leg; ~5.8% APR
Jito
✅ wired (devnet)
Lending
USDC lending for parked NAV, liquidity buffer, and reserve fund
Kamino
✅ wired (devnet)
Swaps
USDC ↔ jitoSOL on mode entry/exit, slippage-bounded on-chain
Jupiter V6
✅ wired (devnet)
Perp basis
Short SOL-PERP at 1×, USDC margin via Ember, the hedge
Phoenix Perps
🟡 pending, see below
Phoenix, "when available." The basis trade turns on when Phoenix Perps is reachable by CPI from the vault: it needs the perp integration ported to Phoenix + Ember and a builder-access grant for the vault's trader account. Until the hedge is live, the vault runs parked (USDC lending on Kamino). The swap, lending, and staking plumbing is already in place, so switching the hedge on is additive, not a rewrite.
Pipeline 2 — Protocol (to mainnet)
The program work that turns the stack into a deployable vault.
Phoenix/Ember CPI ─→ automated keeper transitions ─→ devnet round-trip ─→ audit ─→ mainnetSingle-program vault
One Anchor program, one PDA vault, one share mint
✅ done (devnet)
Automated transitions
On-chain funding signal + guardrails (threshold, 12h dwell, EMA staleness, OI cap, depeg auto-pause); keeper bot executes
✅ logic on-chain
Phoenix/Ember CPI
The perp leg on Phoenix with USDC margin via Ember
⬜ next
Devnet round-trip
deposit → normal basis → parked → withdraw, end to end
⬜ gated on Phoenix access
Audit
Single-program audit, top-tier Solana firm
⬜ planned
Mainnet
Deploy with a hard TVL cap
⬜ planned
Pipeline 3 — Venue & capacity
The external caps and grants that gate how much TVL the vault can hold.
Builder-access grant
Ellipsis Labs
Vault trader account on Phoenix Perps
The hedge at all
SOL-PERP OI headroom
Phoenix
Confirm the short fits at $50M+ TVL
Per-vault size ceiling
jitoSOL borrow cap (~$26.8M)
Kamino governance
Cap-raise as dormant-reverse demand approaches it
Reverse leg if/when activated
Multi-LST collateral
Jito / Kamino
jupSOL, mSOL alongside jitoSOL
Removes single-LST binding
Critical path: the Phoenix builder-access grant. This is the one dependency that gates the whole launch. The pre-mainnet posture is to be ready to go live the moment access lands; the venue doesn't change. ksUSD is built for Phoenix.
Pipeline 4 — Composability (the collateral flywheel)
Once ksUSD is accepted collateral elsewhere, holding it earns carry and unlocks borrow, which is what makes TVL sticky. The sUSDe playbook.
Kamino Lend
List ksUSD as a collateral asset, the first and highest-leverage listing
🟡 in conversation; listing post-beta
Marginfi
Second lending venue
⬜ later
Jupiter routing
Default USDC↔ksUSD routing pair; one-click deposit/redeem from any token
⬜ later
DAO treasuries
Direct integrations for sticky allocations
⬜ later
Each is a governance proposal plus a risk-parameter negotiation. Conversations open now (🟡); listings close post-beta (⬜), once there's a live track record to cite.
Pipeline 5 — Growth (TVL)
Private beta
$1M, invite-only: builds the on-chain track record
⬜ gated on audit
Public launch
$5M → $25M ramp on real-data confidence
⬜ planned
Scale
$20M+ TVL; first composability listing converts beta record to TVL
⬜ planned
Where deposits come from: caps set the ceiling; these fill it: yield marketplaces (Exponent, RateX), collateral acceptance across Solana (Pipeline 4), and DAO-treasury allocations. Day-one liquidity: instant buffer redemption covers normal size, and a USDC↔ksUSD pool at launch plus Jupiter routing give allocators a secondary exit on day one, not just the queue.
Pipeline 6 — Ops & security
The pipeline a DAO treasury risk committee asks about first.
Admin / guardian authority
End-state is a multisig; keeper-key custody and pause authority defined before beta
⬜ before beta
Monitoring
NAV, mode, Pyth oracle staleness, jitoSOL/SOL depeg, keeper liveness, drawdown counter
⬜ before beta
Incident runbook
Depeg auto-pause, oracle-divergence circuit breaker, emergency_close, keeper outage (permissionless cranks keep the vault safe + redeemable)
⬜ before beta
Bug bounty
Live post-audit
⬜ post-audit
Reserve fund
5% perf-fee skim, lent on Kamino; first-loss buffer
🟡 in design
Oracle: Pyth SOL/USD + jitoSOL/USD, gated by 5-min staleness + 2% confidence; the depeg trigger reads the jitoSOL/SOL ratio.
Pipeline 7 — Legal & compliance
Tracked before beta, not treated as an afterthought.
Entity
Operating / issuing entity
⬜ before beta
Regulatory posture
ksUSD is a non-pegged share, not a stablecoin (no peg defense), the framing counsel works from
🟡 framing set
Counsel
Engaged before beta for the yield-bearing-dollar review
⬜ before beta
Geo-fencing / access
App-level access controls; disclaimers in docs
⬜ before beta
Convergence — the launch gate
The pipelines run in parallel, but they gate each other in a specific order:
To mainnet: Phoenix builder access (Pipeline 3) → hedge live (1) + devnet round-trip (2) → audit complete (2).
To beta: audit complete and ops/security (6) and legal (7) all clear. A DAO treasury won't deposit without the last two.
To scale: composability + growth (4, 5): conversations open now, listings and TVL close after beta produces a live track record.
Indicative timeline
Now
Phoenix builder access · audit-firm shortlist · anchor conversations
Q3 2026
Phoenix/Ember CPI + devnet round-trip (gated on builder access)
Q3–Q4 2026
Audit complete · ops/security + legal ready · private beta ($1M cap, invite-only)
Q4 2026
Public launch ($5M → $25M ramp) · USDC↔ksUSD pool + Jupiter routing · first composability listing
Q1 2027
$20M TVL
The critical path is the Phoenix builder-access grant and the audit slot, not the engineering.
Dormant / past v1 (not in launch scope)
Reverse basis: ⏸ built but dormant. Activates only when the funding-minus-borrow spread clears a set hurdle; until then Parked covers negative funding.
Multi-LST collateral: jupSOL / mSOL / bSOL alongside jitoSOL.
Marginfi as a second lending venue (v1 is Kamino-only).
Related
Last updated