Hyperliquid
KLEAR3 ResearchPublished 2026-08-25Updated
Hyperliquid closes this list at tenth by capitalisation, and it is the entry where reading the repository name would mislead you most. hyperliquid-dex/node holds 7 entries and 163 kilobytes, none of them protocol source. Only 22.2 % of the supply circulates.
What does Hyperliquid actually do?
It runs a trading venue on its own chain, with the order book and matching handled by the chain itself rather than by a contract sitting on someone else’s. That design is what makes it fast, and it is also what makes the missing source code consequential.
Building the venue into the chain is the interesting choice here. Everything a trader depends on, matching, liquidation, pricing, is protocol rather than application, so the usual separation between a chain you can audit and an application you take on trust collapses into one object.
The arrangement invites comparison with a chain launched by a trading venue, and the two are not the same. There, the venue and the chain are separate things run by the same company. Here, the venue is the chain.
Source GitHub https://api.github.com/repos/hyperliquid-dex/node, read 2026-08-25
Is the code actually open?
No, and the repository name says otherwise. hyperliquid-dex/node contains a Dockerfile, a licence, two readmes, a compose file, a pruner directory and a public key. GitHub reports its language as Dockerfile. There is no protocol source in it, nor in the organisation’s other ten repositories.
We measured the contents rather than the name, and that is the whole point of this section. Reading hyperliquid-dex/node and concluding that the code is public is the exact error this measurement prevents, and it is an easy one to make: the repository is real, active and correctly named for what it does, which is to distribute a binary.
The licence compounds it. Apache-2.0 appears on the repository, which reads as open source at a glance, and it covers this distribution image rather than the protocol it ships. A free licence on a container file grants you nothing about the software inside.
The nearest case on this list is an entry with no repository at all. That one at least does not look open.
Source GitHub API https://api.github.com/repos/hyperliquid-dex/node/contents/, read 2026-08-25
No audit report is published, and there is a structural reason why one would be hard to act on: without published code, an audit of the protocol could not be verified by anyone outside. The reader would be trusting the auditor’s summary rather than checking the object.
Source Zellic et Cyfrin https://api.github.com/repos/{Zellic/publications,Cyfrin/cyfrin-audit-reports}/git/trees/HEAD?recursive=1, read 2026-08-26
Is anyone still working on it?
On the distribution image, barely: 4 commits from 3 identities in the 90 days to 25 August 2026, and no published releases at all, none since it opened. On the protocol itself we cannot say, because there is nothing at all to measure.
This is the distinction that matters, and it is easy to blur. Those four commits are real work on a real repository, and they tell you nothing about the software that actually runs the venue.
Set against the most actively developed client on this list, where 1 215 commits landed over the same window, the contrast is not between a busy project and a quiet one. It is between a project you can observe and one you cannot.
Source GitHub https://api.github.com/repos/hyperliquid-dex/node/commits?since=2026-05-27T00:00:00Z&per_page=100, read 2026-08-25
- The distribution repository opens
Where does it actually run?
On its own chain, according to the aggregator. We did not reach a public node for it, so unlike most entries on this list we cannot confirm from our own measurement that the network responds to anyone at all today.
The gap is worth naming rather than papering over. A chain that is also a trading venue is exactly the kind of system a reader would want to verify independently, and the two things we could not do here, read the code and query the chain, are the two that would have made that possible.
Source Hyperliquid Docs https://hyperliquid.gitbook.io/hyperliquid-docs, read 2026-08-25
Network verified by reading its current block height on a public node.
What the token actually does
HYPE is the venue’s own token, and it is the least circulated on this list: 222 million out of 955 million issued, against a cap of one billion. Roughly a fifth of what exists is in the market, and four fifths of it are not.
222,445,714 circulating against 955,307,079 issued means about four fifths of the supply sits outside the market, on a schedule we did not examine. Every price and capitalisation quoted for it rests on the fifth that trades.
The other end of that spectrum is on this list too: a chain whose entire issued supply circulates. Between the two, the difference in how much future supply can arrive is the single largest on these ten pages.
- What the token is forThird-party supported
- How many existThird-party supported
- How new ones appearNot verified
- Who can change the rulesNot verified
KLEAR3 rating
- Open code4
public repository · Apache-2.0 licence · 4 commits in 90 days
What holds it back no published release
- Audits3
2 firms on the core · 1 audited scope · report opened: 0 critical, 1 high, 3 medium · 1 critical or high finding found and fixed
What holds it back 1 low findings not fully fixed · audit stops at 2023-11-27: the code has moved since
- Business modelnot measured
What holds it back business model not established from a primary source
- Governance2
decided by decision-de-l-emetteur, with no vote
What holds it back no public proposal process among its 11 open repositories
- Token alignment2
supply capped at 1 billion · 22% already in circulation
What holds it back emission schedule unknown
- Maturity1
2 years of public code
What holds it back no deployment verified at the source
We rate the protocol: how it is built, how much of it can be checked, how its token lines up. Never an investment. A high score is not advice to buy, and a low one is not advice to sell.
What we could not establish
The protocol source, the audits, the governance, the emission schedule for the four fifths not circulating, and whether the chain responds to us. What we did establish is narrow and precise: what the published repository contains, and what it does not.
It is worth separating two claims that get conflated. We are not reporting that this venue is unsafe; we are reporting that its safety cannot be checked from outside, which is a statement about what is knowable rather than about what is true.
Frequently asked questions
The repository is called node and has an open licence. Is that not open source?
No. We opened it: seven entries, 163 kilobytes, and GitHub reports the language as Dockerfile. It packages and distributes a binary. The Apache-2.0 licence covers that packaging, not the protocol the binary contains.
This is the cleanest example on the site of why we measure contents rather than labels. A name, a star count and a licence badge are three signals that all point at openness here, and none of them is the thing.
The organisation’s other ten repositories do not change the answer: they are SDKs, tools and peripheral contracts. Useful software, and none of it the protocol that matches orders. A name is a claim; contents are a measurement, and only one of the two can be checked by a reader without asking anyone for access. That asymmetry is the whole reason this profile scores the axis the way it does.
Does closed source mean the venue is unsafe?
It does not, and this page does not say so. It means the safety cannot be verified independently: nobody outside can read what happens during a liquidation, how prices are formed, or under what conditions the system stops.
Plenty of financial infrastructure runs on closed software and works. The difference here is what the surrounding market expects: a chain is normally something you can inspect, and this one is presented alongside chains that can be.
For a reader, the practical question is what you are relying on instead of the code. That usually means the operator’s reputation and the venue’s track record, both of which are real inputs, and neither of which is what the word verifiable is meant to describe. Both sit outside anything this page can measure. We name them rather than score them, because a reputation is not a measurement.
Why does only a fifth of the supply circulate?
We measured the ratio, not its cause. 222 million tokens circulate out of 955 million issued, against a cap of one billion. The release schedule for the rest, and who holds it, we did not examine here, and nobody publishes it in a form we could read.
The consequence is arithmetic that gets quoted without qualification. A capitalisation computed on circulating supply is roughly a fifth of one computed on issued supply, and headlines rarely say which they used.
It also means the supply that could arrive in the market over time is larger than the supply currently in it. Whether that matters depends entirely on a schedule this page does not have, and which nobody publishes in a form we could read or verify ourselves. Until it is published, the ratio is a fact and its consequence is a guess.
Next: our Ethereum profile shows what a fully readable protocol looks like, and our XRP profile another entry where a large share of the supply sits outside circulation.
Ask an assistant to summarise it and check what it claims.