Whitepaper · v1.0 · October 2026
H10X: a fully backed index of the Hedera ecosystem
One token for the ten most relevant tokens on Hedera. Every H10X is backed by the tokens themselves, held by an immutable vault on Hedera mainnet and redeemable in kind at any time.
H10X is a basket of volatile crypto assets. This paper describes how the system works; it is not investment advice and promises no return. The vault contract has had a self-review by the team, not an independent audit.
01Abstract
H10X is a token on the Hedera Token Service (HTS) that represents a weighted basket of ten tokens from the Hedera ecosystem: HBAR, Bitcoin and Ether bridged to Hedera, and seven native projects covering trading, lending, liquid staking, carbon credits, real-world assets, wallets and community.
Every H10X is backed by the basket itself. The tokens are held by H10XVault, an immutable smart contract with no proxy and no admin key. Anyone can issue H10X by depositing the basket in the vault's current proportions, and any holder can redeem H10X for their share of every token, at any time. Issue and redeem need no price oracle and no custodian, and redemptions can never be paused.
Day to day, people buy and sell H10X with HBAR on SaucerSwap. A keeper keeps the pool price close to the net asset value (NAV) by arbitraging between the pools and the vault, so buying pressure turns into new deposits in the vault. A 2-of-3 multisig reviews the basket every quarter under published rules. It can change weights and rebalance within limits set in the contract, but the contract has no function to withdraw the basket.
02The problem
Hedera has a growing ecosystem of tokens, but holding a broad, balanced position in it is hard work:
- Many tokens, many steps. Each token needs its own association, its own swap and its own price impact. Ten positions mean ten trades to enter, ten to exit and constant manual rebalancing.
- Thin markets. Many ecosystem tokens have shallow pools. A small buyer can lose more to slippage than to fees, and a single position can move far from its target weight.
- Issuer controls. On Hedera, a token can carry keys that let its issuer freeze accounts, pause transfers, require KYC or charge custom fees. A basket that ignores these keys can be blocked by any one of its issuers.
- Trust in custodians. An index held off-chain by a company asks holders to trust that company's books. An on-chain index that cannot be redeemed is only a price tracker.
H10X answers each point: one token and one association, a basket that follows published rules, admission checks enforced by the contract itself, and backing that anyone can verify on-chain and take out in kind.
03How H10X works
Properties
- Fully backed. The vault is the H10X token's treasury and its only supply key. H10X can only be minted when the proportional basket goes in, and it is burned when the basket comes out.
- Redeemable in kind. Any holder can burn H10X and receive their share of each token directly from the contract. Redemptions cannot be paused by anyone.
- No oracle in issue and redeem. Both use the vault's actual balances. Prices only matter off-chain: for the NAV shown in the dapp, the keeper and rebalancing.
- Immutable. No proxy and no admin key: the code on mainnet can't be changed or replaced. The source is verified on Sourcify (exact match).
- Bounded governance. Every power of the multisig is limited in the code: at most ten components, fees capped at 1%, swaps only between components through fixed routers, a cap per trade and a mandatory minimum output.
04The basket and its methodology
The official basket (version 3, October 2026) and its target weights:
| Token | Weight | Category | Why it is in the index |
|---|---|---|---|
| HBAR Hedera | 20% | Network | The network's own token: it pays for every transaction and secures Hedera through staking. The base of the ecosystem and its most liquid asset. Held as WHBAR, SaucerSwap's wrapped HBAR. |
| WBTC HTS-WBTC | 15% | Bitcoin | Bitcoin bridged to Hedera through LayerZero. Adds the largest asset in the market and steadies the basket. |
| SAUCE SaucerSwap | 10% | DEX | The token of Hedera's main exchange, where almost every token on the network trades. Live since 2022, with fee revenue and SAUCE buybacks. |
| WETH HTS-WETH | 10% | Ether | Ether bridged to Hedera through LayerZero. Brings Ethereum exposure into the index with solid liquidity on SaucerSwap. |
| BONZO Bonzo Finance | 10% | Lending | Lending, vaults and staking on Hedera. Its lending market was attacked through an external price oracle in July 2026; it is followed closely at every review. |
| DOVU DOVU | 10% | Carbon credits | A carbon-credit marketplace, one of Hedera's best-known sustainability use cases. Trading on SaucerSwap since 2023. |
| GIB gib | 10% | Community | One of Hedera's most liquid community tokens. It represents the cultural side of the ecosystem, which also brings users and volume. |
| PACK HashPack | 5% | Wallet | The token of HashPack, Hedera's most used wallet, and one of the network's highest daily-volume tokens. |
| HBARX Stader | 5% | Liquid staking | Stader's liquid-staked HBAR. It tracks HBAR and adds staking rewards to the basket. |
| GC GCoin | 5% | Real-world assets | GCoin, from Gilmore Estates, a real-estate tokenization project on Hedera. Brings the RWA sector into the basket; weighted at 5% because of its liquidity. |
4.1 Selection rules
- A Hedera (HTS) token with a SaucerSwap pool against HBAR.
- Its issuer cannot block the vault: no freeze, pause, KYC or fee-schedule key and no custom fees. The contract checks this itself when a token is added (section 4.3).
- SaucerSwap liquidity in line with its weight: at least $50k for a 5% weight, $250k for 10% and $1M for 15–20%, plus at least $500 of average daily volume.
- An active project with at least 12 months of history. For BTC and ETH, the original asset's history counts.
- Reviewed every quarter. Changes are signed by the 2-of-3 multisig and announced beforehand.
4.2 Weighting
Weights are fixed tiers, not market-cap weights: market caps on Hedera are dominated by HBAR, and a cap-weighted basket would be little more than HBAR. The tiers give the network token the largest single weight (20%), anchor the basket with Bitcoin (15%) and Ether (10%), and give each ecosystem sector a meaningful share. The 5% tier is for tokens that meet every rule but whose liquidity does not yet support 10%. The largest single weight is 20%.
Weights are targets. Between rebalances the actual weights drift with prices; the dapp shows both the target and the live weight of every token in the vault.
4.3 Admission checks in the contract
When the multisig adds a token, the vault reads its keys and custom fees from the Hedera Token Service and rejects it if it has a KYC, freeze, fee-schedule or pause key, or any custom fee. On Hedera such keys cannot be added to a token after it is created, so a token that passes once stays safe from them. Other keys are allowed but disclosed:
| Token | Token ID | Issuer keys (none of the blocking kind) |
|---|---|---|
| HBAR | 0.0.1456986 | Held as WHBAR, wrapped 1:1 by SaucerSwap's WHBAR contract |
| WBTC | 0.0.10082597 | Supply and wipe keys: LayerZero connector 0.0.9675688 |
| SAUCE | 0.0.731861 | Admin and supply keys: SaucerSwap team |
| WETH | 0.0.9770617 | Supply and wipe keys: LayerZero connector 0.0.9675688 |
| BONZO | 0.0.8279134 | No keys and no custom fees |
| DOVU | 0.0.3716059 | No keys and no custom fees |
| GIB | 0.0.7893707 | Supply key only |
| PACK | 0.0.4794920 | Admin key only |
| HBARX | 0.0.834116 | Admin and supply keys: Stader |
| GC | 0.0.3241481 | Supply key only; the maximum supply of 100M is already minted |
An admin key can delete its token. The vault handles that case: a deleted component can be removed by the multisig, and redemptions can skip it so holders always get the rest of the basket. A wipe key, held here only by the LayerZero bridge connector for WBTC and WETH, is part of the bridge's trust model and is listed as a risk in section 12.
4.4 How a basket change is made
- Exit: the multisig sets the leaving token's target weight to 0, then sells its whole balance in a single swap. The swap that empties the token also removes it from the basket, in the same transaction.
- Entry: the multisig adds the new token together with the new target weights (the new token's weight must be above 0), and buys it through rebalancing swaps.
- Weights: the exact target weights are set, and the remaining differences are rebalanced.
Each step is a separate multisig transaction signed by two of the three members, and each one is visible on HashScan. Holders can redeem at any point during a change.
4.5 Changes to the basket
| Date | Change |
|---|---|
| Oct 2026 | HBARX and GCoin join (5% each). GRELF and DAVINCI leave: their SaucerSwap liquidity and daily volume no longer met the rules for a 5% weight. GRELF is sold for HBAR; DAVINCI is sold directly for GC. |
| 6 Oct 2026 | Mainnet launch. HBAR 20%, WBTC 15%, SAUCE, WETH, BONZO, DOVU and GIB 10% each, PACK, DAVINCI and GRELF 5% each. |
4.6 Backtest of the launch basket
Before launch, the launch basket was simulated over three years of real prices (October 2023 to September 2026, weekly data from Binance and SaucerSwap, monthly rebalancing, 0.3% cost on every rebalancing trade). Tokens that did not exist yet were left out and their weight was shared among the rest until they appeared.
| Oct 2023 – Sep 2026 | Total return | Volatility (yearly) | Max. drawdown |
|---|---|---|---|
| H10X launch basket | +375% | 84% | −66% |
| HBAR alone | +89% | 102% | −81% |
| BTC alone | +202% | 45% | −53% |
A backtest is a simulation, not a track record, and the past says nothing reliable about the future. The basket fell 66% from its peak in September 2025 to July 2026. The backtest will be regenerated with the current basket; the full study is at h10xindex.xyz/backtest.
05Vault mechanics
5.1 The H10X token
H10X (0.0.10907484, 8 decimals) is a native HTS token. The vault is its treasury and its only supply key. It has no admin, freeze, wipe, KYC or pause key and no custom fees, so nobody can mint, block or confiscate H10X outside the vault's rules. Its only other key is a metadata key, used for the token's logo.
5.2 Seed
The first issuance (the seed) sets how much of each token stands behind one H10X, and with it the starting NAV. It can only happen once, while the supply is zero, and must issue at least 1 H10X. The vault was seeded on 6 October 2026 at a NAV of about $1.03 per H10X.
5.3 Issue and redeem
With S the H10X supply before the operation, s the H10X issued or redeemed, and balancei the vault's balance of component i:
Because amounts follow the vault's actual balances, issuing and redeeming never change the backing of the H10X already in circulation, and no price is needed. Callers pass a maximum deposit (issue) or a minimum output (redeem) for every component, so a rebalance between quoting and signing cannot hurt them.
5.4 Net asset value
The NAV is computed off-chain from SaucerSwap pool prices against HBAR, only from pools deep enough to be meaningful, and published with the vault's composition in the dapp and in a public API. The contract itself never uses it.
5.5 Redemptions that cannot be blocked
- No role can pause redemptions. The multisig and the guardian can only pause new issuance.
- A redeemer can give up a component (a skip mask), for example if its issuer has deleted or frozen it: the rest of the basket still comes out, and the skipped share stays with the other holders.
- Every change to the component list or the fees bumps a configuration version. Issue and redeem check it, so arrays built for an old basket are rejected rather than misread. A holder can also skip this check (with no skip mask) and always leave, whatever governance does.
5.6 Hedera limits
Hedera allows at most 50 child records per transaction, and every call from the vault to the token service creates one. With the maximum of ten components, measured on live transactions, issue needs 43, the seed 33 and redeem 25. This is why the basket is capped at ten tokens, and why buying H10X with HBAR goes through the pools, with the keeper handling the basket side, instead of a single transaction at the vault.
5.7 Housekeeping
Anyone can call claimFees to send accrued fees to the fee recipient, and burnStrayShares to burn H10X sent to the vault by mistake, which raises every holder's backing. Ownership changes take two steps and ownership can never be renounced, so the vault is never left without governance by accident.
06Governance
The vault's owner, guardian and rebalancer are the same account: a Hedera multisig, 0.0.10907480, that needs two of its three members' signatures for every action. Members' keys are never stored on the servers that run the keeper and the website.
| The multisig can | Nobody can |
|---|---|
| Add and remove components (at most 10) and set target weights | Mint H10X without the basket going into the vault |
| Set the issue and redeem fees, never above the 1% cap in the code | Withdraw basket tokens: there is no withdrawal function |
| Pause and resume new issuance (the guardian can pause too) and set a supply cap | Pause redemptions |
| Rebalance: swap one component for another through SaucerSwap, within limits | Upgrade or replace the contract, or renounce its ownership |
6.1 Limits on rebalancing
- Both ends of a swap must be basket components; value can only move between components.
- Only through the SaucerSwap V1 and V2 routers fixed when the vault was deployed.
- At most 20% of the sold token's balance per swap. The exception is a token whose weight is already 0, which can be sold in full so it can leave.
- Every swap needs a non-zero minimum output and a deadline, and the vault measures the balances before and after to check what was really spent and received.
6.2 Process
Proposals are created as Hedera scheduled transactions and signed one at a time from the governance panel of the dapp; each one must execute before the next is built, because it is tied to the configuration version. The team's tooling quotes every swap against on-chain prices before proposing it, and the minimum output is set from that quote. Before signing, the panel decodes the real transaction from the network and warns if it does not target the official vault, if a swap routes through tokens outside the basket, or if its minimum output is more than 5% below the current price. Basket changes are announced before they are signed.
Trust assumption (finding F-1 of the security review). The rebalancer chooses each swap's route and minimum output, and the contract has no on-chain price limit or cooldown. A malicious or compromised multisig could therefore move value out of the basket through bad swaps, a little at a time. This is the main trust placed in the team. It is limited by the 2-of-3 threshold, the per-trade cap, routes restricted to SaucerSwap, and every action being public on-chain.
07Market and keeper
7.1 Where H10X trades
Holders buy and sell H10X with HBAR on SaucerSwap, in one swap, from any Hedera wallet or from the H10X dapp. Two pools are planned: an H10X/HBAR pool on SaucerSwap V2 (concentrated liquidity, 0.3% fee tier), which has been proposed to the SaucerSwap DAO because V2 pools are approved by its vote, and optionally a SaucerSwap V1 pool, which is permissionless. Buying and selling in the dapp opens when the pools are live.
7.2 The keeper
The keeper is a service run by the team with its own operating account, which has no role in the vault. In every cycle it computes the NAV, reads both pools and picks the most profitable correction:
- Premium (pool price above NAV): issue H10X with basket tokens from its inventory and sell them in the pool.
- Discount (pool price below NAV): buy H10X in the pool and redeem it for the basket.
- Between pools: buy in the cheaper pool and sell in the dearer one, without touching the vault.
Each trade is sized up to the point where the next H10X stops being profitable. After arbitrage the price settles within about ±0.8% of the NAV: the 0.3% pool fee plus the 0.5% vault fee.
7.3 How the vault grows
Buying H10X in the pool only moves existing H10X from the pool to the buyer. When buying pushes the price above the NAV, the keeper issues new H10X, which means depositing the basket in the vault, and sells them into the pool. The vault therefore grows with net demand, while the NAV per H10X only moves with the prices of the ten tokens. When holders sell, the keeper buys and redeems, and the vault shrinks. Issue and redeem are open to anyone, so any other arbitrageur can do the same.
7.4 Liquidity that follows the NAV
The protocol's own V2 liquidity is a concentrated position of ±20% around the NAV. When the NAV enters the outer 20% of the range, or leaves it, and stays there for 10 minutes, the keeper recentres the position on the NAV in a single transaction, keeping its value. It decides by the NAV and never by the pool price, so a large trade cannot force a recentring. Recentring is limited to once every 6 hours and three times a day.
These defaults come from a range laboratory that replays three years of real NAV moves and stress paths (double volatility, a 35% drop in an hour, swings at the range edge) through the same code the keeper runs.
7.5 Keeper safety limits
- Caps on the size of every trade, a minimum profit per trade, and an automatic stop if it loses more than a set amount in 24 hours.
- It does nothing while a price source is in dispute, or while a pool is more than 20% away from the NAV: a jump that large is reviewed by a person.
- Token allowances are always revoked after use, and the account keeps an HBAR reserve for fees.
- If the keeper stops, nothing is at risk in the vault: the pool price may drift from the NAV until it is back, and holders can always redeem directly.
08Security
- Tests: 124 Foundry tests, including unit, fuzz and invariant tests and economic simulations. Adversarial campaigns of millions of random calls found no violation, and mutation testing caught 35 of 36 deliberately planted bugs (the survivor changes nothing).
- Static analysis: Slither 0.11.6 and Aderyn 0.6.8; every result was checked by hand and none was exploitable.
- Manual review: two rounds with proofs of concept. Version 1.3.0 fixes every finding except F-1 (trust in the multisig, by design; section 6) and F-5 (dust sent to a token that never held a balance can block its removal; buying some and exiting works around it, and nothing is at risk).
- Testnet rehearsal: the full life cycle of 1.3.0 ran on Hedera testnet, including a basket token deleted by its issuer.
- Off-chain tools: the keeper, rebalancing and basket changes are rehearsed in a simulator of the vault and SaucerSwap before any mainnet action.
This is a self-review by the H10X team, not an independent audit. An independent professional audit is the first thing external funding will pay for. The full review is published at h10xindex.xyz/security.
To report a vulnerability, email h10xindex@gmail.com with the details and, if possible, a proof of concept, and please don't disclose it publicly until we have answered.
09Transparency
- Verified source: exact match on Sourcify, and the public GitHub repository rebuilds the same bytecode (solc 0.8.28, Cancun, 200 runs) with its tests running in CI.
- Everything on-chain: every issue, redeem, swap, weight change and fee claim is an event of the vault, visible on HashScan.
- Live composition: the dapp shows the vault's balances, the live weight of each token, the NAV and its history. The same data is served as a public JSON API.
- Public metrics: value in the vault, holders, active accounts, transactions and pool liquidity, with their daily history, for grant programmes and anyone else who wants to follow the project.
- Published rules: the selection rules, the basket and its change history are on the website and in this paper.
10Fees and economics
- No pre-mine, no team allocation, no sale of H10X. Every H10X in existence was issued against the basket, including the team's own seed. There is no separate governance token.
- Vault fees: 0.5% on issue and 0.5% on redeem, paid in fully backed H10X to the fee recipient
0.0.10353916. The code caps each fee at 1%, and there are no management or performance fees. - Pool fees: SaucerSwap's 0.3% swap fee goes to liquidity providers, including the protocol when it provides liquidity.
- Keeper: its arbitrage margin stays in its operating account as inventory to keep the price at the NAV.
Holding H10X earns nothing by itself beyond the performance of the basket (and the staking rewards built into HBARX). The project makes no promise of returns.
Use of external funding
- An independent audit of the vault.
- A legal review, including the EU's MiCA regulation.
- More protocol-owned liquidity in the H10X pools.
- A supply cap during the early phase, raised as liquidity and the audit allow.
11Roadmap
- Vault 1.3.0 and H10X on mainnet
- 2-of-3 multisig governance
- Security review and backtest published
- Keeper for V1 and V2 pools
- Basket v3 and this whitepaper
- H10X/HBAR pools on SaucerSwap
- Buy and sell with HBAR in the dapp
- Keeper live on both pools
- Automatic V2 recentring
- Independent audit
- Legal review (MiCA)
- More protocol-owned liquidity
- Early-phase supply cap
- Liquidity aggregators
- Wallet and DeFi integrations
12Risks
- Market risk. All ten tokens are volatile and closely correlated with HBAR. The value of H10X can fall sharply; the launch basket's backtest lost 66% from peak to trough.
- Smart-contract risk. The vault has had a self-review, not an independent audit, and is immutable: a bug could not be patched, only worked around by migrating to a new vault.
- Governance risk. The multisig is trusted with the quality of rebalancing (F-1). If two of three member keys were compromised, value could be lost through bad swaps, a little at a time within the per-trade cap.
- Component risk. A component can lose its value, be exploited (as Bonzo's lending market was in July 2026) or be deleted by its issuer. WBTC and WETH depend on the LayerZero bridge, whose connector holds their supply and wipe keys.
- Liquidity risk. Pools for some components are small, and the H10X pools will be small at first. Large trades move prices, rebalancing costs grow, and the H10X price can drift from the NAV if the keeper is stopped or short of inventory.
- Price-data risk. The NAV, the keeper and rebalancing quotes use on-chain SaucerSwap prices, which can be moved in thin pools. Guards exist, but no price source is perfect.
- Platform risk. H10X depends on Hedera, the Hedera Token Service and SaucerSwap working as they do today.
- Regulatory risk. Rules for crypto-asset products, including MiCA in the EU, may affect how H10X can be offered in some places.
13Team and contact
| Álvaro Montes | Founder and developer |
| Virginnis | Graphic design and marketing |
| Jose | Developer and engineer |
Website h10xindex.xyz · X @H10Xtoken · email h10xindex@gmail.com · code github.com/burnbytes26/H10X-index
14Appendix: addresses
| What | Hedera ID | Notes |
|---|---|---|
| H10XVault 1.3.0 | 0.0.10907483 | EVM 0x…a66f5b; verified on Sourcify |
| H10X token | 0.0.10907484 | HTS, 8 decimals; treasury and supply key: the vault |
| Governance multisig | 0.0.10907480 | 2 of 3; owner, guardian and rebalancer |
| Fee recipient | 0.0.10353916 | Receives the vault fees; holds the H10X metadata key (logo) |
| WHBAR | 0.0.1456986 | SaucerSwap's wrapped HBAR, held for the HBAR weight |
| SaucerSwap V1 router | 0.0.3045981 | Fixed in the vault at deployment |
| SaucerSwap V2 router | 0.0.3949434 | Fixed in the vault at deployment |