Logo
My Crypto News AI

Hyperliquid's HIP-4 Goes Permissionless: What Validators Still Control

Hyperliquid's HIP-4 outcome contracts are shifting to permissionless deployment, allowing third-party builders to launch markets without individual validator approval. However, this move does not mean validators are stepping back entirely. Instead, the network is implementing a template-based system where validators approve market structures once, and deployers can then create individual markets within those approved frameworks.

What Does Permissionless Deployment Actually Change?

Before the shift, Hyperliquid validators controlled every aspect of HIP-4 market creation. They decided which individual markets could exist on the network. Now, the responsibility is split. Validators govern the overall market structure through approved templates, while third-party deployers handle the creation of specific markets that fit those templates.

HIP-4 outcome contracts are fully collateralized contracts that settle between 0 and 1 based on event results. Since launching in May, these contracts have cleared roughly $283 million in cumulative volume with close to 19,000 unique traders. The first week of September alone saw $16.2 million in trading volume and 351,000 trades, showing clear demand for this type of outcome trading.

The permissionless model addresses a bottleneck: validators no longer need to individually approve each market. Instead, they focus on approving the templates that define what kinds of markets can exist. This separation makes the system scalable. Approve the structure once, deploy many individual markets from it.

What Do Validators Still Control in Permissionless HIP-4?

Validators retain three critical functions in the permissionless system:

  • Template Governance: Validators vote on the templates that deployers can use to create markets. An approved template defines a market structure that can support many individual markets.
  • Stake Slashing: Every permissionless deployer must stake 500,000 HYPE tokens on mainnet. Validators can vote to slash that stake for violations such as incorrectly settling a market or leaving it unresolved.
  • Direct Market Creation: Validators can still create markets directly. Hyperliquid reserves this route for rare canonical outcomes that should exist independently of third-party deployers.

This structure means permissionless deployment does not remove validators from HIP-4. It redistributes their workload. They move away from approving individual markets and toward governing the rules that deployers must follow.

How Do HIP-4 Templates Work?

Templates are validator-approved contract specifications for a class of outcome markets. For example, a template could establish how a binary outcome works and settles. Deployers can then use that structure for different questions without asking validators to approve each question separately.

A new market structure does not become permissionlessly available just because a deployer wants it. Validators must first approve the template. Once approved, eligible deployers can create markets that conform to the template without another validator vote for each deployment.

Potential HIP-4 builders have two possible paths: if their market idea fits an approved template, they can deploy permissionlessly. If they need a new market structure, they must first seek template approval from validators before deploying the market.

Steps to Deploy a Permissionless HIP-4 Market

The deployment process for a permissionless HIP-4 outcome market follows five stages:

  • Template Selection: The deployer checks the live catalog through outcomeTemplates and selects a template that fits the market. If none supports the intended structure, a new template must first receive validator approval.
  • Stake Activation: On mainnet, deployers must stake 500,000 HYPE for at least six months and activate through activateOutcomeDeployer. On testnet, the requirement is only 100 HYPE, allowing the full flow to be tested before committing mainnet capital.
  • Parameter Setting: Deployers set the parameters permitted by the template, such as the question, settlement date, and outcome criteria. Forge is a live example on testnet where builders pick a validator-approved format, fill in the question, and sign with their wallet to deploy the market.
  • Market Launch: Markets run as native HyperCore assets, using Hyperliquid's existing matching and trading infrastructure. Deployers can receive up to 50 percent of trading fees generated by their markets.
  • Settlement and Closure: Once resolved, HyperCore settles the market at its final value. Validators can vote to slash the deployer's stake if the market settles contrary to the template's criteria or is left incorrectly unsettled.

What Are the Economic Incentives for Deployers?

For permissionless HIP-4 to work, three parties need economic reasons to participate: deployers to operate markets, market makers to supply liquidity, and traders to create flow.

Deployers face capital requirements and operating costs. They must stake 500,000 HYPE on mainnet, which locks capital for at least six months. In return, they can capture up to 50 percent of trading fees from their markets. This fee structure incentivizes deployers to create markets that attract traders and generate volume.

Market makers provide liquidity to these outcome contracts, similar to how they operate in traditional financial markets. Traders then create the flow that generates fees. The system works only if all three parties see a path to profit or value.

Where Do Risks Sit in Permissionless HIP-4?

The shift to permissionless deployment introduces new risks, particularly around market resolution. Deployers must choose between price-threshold markets, which settle based on whether a price crosses a set threshold, and event-based markets, which run through the deployer's authorized oracle or other resolution source.

For event-based markets, wording matters significantly. Ambiguous definitions or incorrect resolution can put the deployer's 500,000 HYPE stake at risk. Validators can vote to slash that stake if the market settles contrary to the template's criteria. This mechanism creates an economic incentive for deployers to resolve markets correctly, but it also means deployers bear the risk of interpretation disputes.

The permissionless model does not remove validators from HIP-4. Instead, it shifts their role from individual market gatekeepers to template governors and stake enforcers. This approach allows Hyperliquid to scale outcome trading while maintaining network-level oversight through template approval and slashing mechanisms.