Every fund deck has a risk section. Almost none of them are meant to be read.
They're written by lawyers, in the smallest font on the page, in sentences engineered to be technically complete and practically unreadable. The purpose isn't to inform you - it's to be able to say, later, that it was disclosed. The risk section is the part of the document that exists so that when something breaks, the answer can be "you were told."
This is the opposite of that.
The belief this piece is here to break: a fund that doesn't dwell on what can go wrong is a safe one. It's backwards. The danger was never the risk written down - it's the one nobody named until it arrived. So here is the whole list, in plain language, ordered not alphabetically but by how much it should actually worry you. For each one, four questions - and the fourth is the one almost no one answers out loud.
How to read this list
Every failure below gets the same four questions:
- What happens? - the mechanism, in plain terms.
- How bad can it get? - the honest worst case, not the comfortable one.
- What protects you? - the structure that absorbs or limits it.
- What doesn't? - the part the protection can't reach.
That last question is the one that matters, and the one you will almost never see in a fund document. Anyone can list a risk and then immediately reassure you. Telling you where the reassurance stops is the actual disclosure. We'll answer it every time.
And the order isn't random. Risks aren't equal - a likely-but-mild problem and a rare-but-ruinous one deserve different amounts of your attention. Here's the whole list plotted by both, so you can see where ours actually concentrates. The list itself then runs roughly from the risks you'd feel first, closest to your money, to the ones you'd feel rarely.
1. Basis risk
What happens? We protect SOL-denominated capital using BTC options, because BTC has the deepest, cheapest, most liquid options market in crypto. When the whole market falls together - the usual shape of a crisis - that hedge works well. But when SOL falls on its own while BTC holds, the BTC puts sit near their strike and pay little. You're left holding the SOL drop with thin cover.
How bad can it get? In a sharp, Solana-specific shock - a chain outage, an ecosystem blow-up, a single-name de-rating - the hedge could pay a fraction of the loss. This is the single most likely way the protection underperforms in practice.
What protects you? Most large drawdowns in crypto are broadly correlated - when fear hits, it hits everything - so the hedge fires in the majority of real stress events. And the first-loss capital absorbs the early damage before a senior investor is touched.
What doesn't? Nothing fully closes a SOL-specific gap while we hedge with BTC. We accept basis risk deliberately, as the price of using a liquid options market instead of an illiquid one. It is a stated weakness, not a hidden one - and it's first on this list because it's the one most likely to actually bite.
2. Liquidity mismatch
What happens? The book holds positions - options especially - that cannot be unwound continuously at size without paying a punishing spread. But redemption requests can arrive in a cluster, all at once, usually in the same stressed moment when exits are most expensive. The assets are slower to sell than the promises to return cash.
How bad can it get? In a crowded-exit scenario, honouring every redemption immediately would mean dumping positions into a thin market and crystallising losses for everyone who stayed. Left ungoverned, a liquidity mismatch is how a sound book gets force-liquidated at the worst possible price. It's second on this list because it's the failure an investor feels soonest - it sits right next to your ability to get your own money back.
What protects you? Redemption runs through a monthly window with a gate and a floor, not an instant button. The gate caps how much can leave in any one window and pro-rates the rest; the structure exists specifically so a rush for the door can't trample the people behind it. Redeemable value is fixed at the window for the same reason - the mark is fair, the exit isn't frictionless.
What doesn't? The flip side of that protection is that you cannot always get 100% of your capital out the instant you want it. The gate protects the pool by constraining you. That's an honest trade, and you should know it before you need the money, not after.
3. Counterparty failure
What happens? A hedge is a promise from someone else to pay you in a crisis. The options venue, the clearing layer, the custodian holding collateral - each is a counterparty that could fail, freeze withdrawals, or get hacked at precisely the moment you need it. Crypto has buried more than one fund this exact way.
How bad can it get? This is the lowest-probability item near the top of the list and the highest-severity. A counterparty failure at the wrong moment can turn a working hedge into an unpaid IOU - the protection is "in the money" and uncollectable. Worst case, it's not a drawdown, it's a loss of principal that no payoff diagram predicts.
What protects you? Using the most liquid, most established venues rather than the highest-yielding obscure ones; not concentrating everything behind a single name; and a ledger that records exactly where exposure sits so concentration is visible, not buried.
What doesn't? No amount of diligence makes a counterparty risk-free. If a major venue fails catastrophically and instantly, diversification softens the blow but does not erase it. This is the residual tail we watch hardest and can least fully neutralise - which is exactly why it sits where it does on the matrix.
4. Model failure
What happens? A great deal of the system runs on models: how options are marked, how the hedge is sized, how Liquidity Weather reads market conditions and throttles risk. A model is a simplification of reality, and every simplification is wrong somewhere. A bad input, a regime the model never saw, an assumption that quietly stops holding - and the system acts confidently on a number that's off.
How bad can it get? A mis-sized hedge under-protects or over-pays; a marking model that drifts misstates NAV; a weather reading that misfires throttles risk at the wrong time. Most model errors are gradual and recoverable. The dangerous one is the confident error in a regime nobody back-tested.
What protects you? Marks are tied to real, observable prices rather than a model's opinion, which caps how far valuation can drift from reality. An hourly reconciliation invariant flags when the published number stops matching the ledger. And models advise the system - they throttle and shape - rather than silently overriding the hard accounting.
What doesn't? Reconciliation catches a number that doesn't add up; it does not catch a number that adds up but is built on a wrong assumption. A self-consistent model can still be self-consistently wrong. That residual is real, and it's why none of this is sold as certainty.
5. Founder / key-person risk
What happens? This is a small, founder-run operation. The same person makes the key calls, and a single point of human failure - illness, absence, error, or worse - is a real risk in a way it isn't at a 200-person institution.
How bad can it get? Honestly: high severity if it ever happened, because there's no deep bench today. We're not going to pretend otherwise to look bigger than we are.
What protects you? The thing that doesn't depend on any one person being present: an append-only ledger that records every flow, automated reconciliation and reporting, off-site encrypted backups, and a redemption process defined in code rather than living in someone's head. The truth of what you own survives the operator. And founder capital sits in first-loss - the incentive to keep the lights on is structural, not just goodwill.
What doesn't? Automation preserves the record and the rules; it does not replace human judgment in a genuine crisis. A small operation is a small operation. We'd rather you size your commitment knowing that than discover it later.
6. The plumbing: operational, settlement, infrastructure
What happens? The unglamorous failures. A software bug. A bad price feed. A settlement calculation that errors at month-end. A server, a database, or a service that falls over. None of these is exotic; all of them are real, and they cluster at the boring, mechanical layer.
How bad can it get? Usually contained - these are mild-severity by nature - but a silent bad mark or a botched settlement could misstate balances until caught. The danger isn't the failure; it's a failure that goes unnoticed.
What protects you? Layered, deliberately. The hourly treasury-equals-NAV invariant catches numbers that stop reconciling. Settlement logic is rehearsed against copies of real data before it runs live. Infrastructure is covered by Tier-1 disaster recovery: off-box encrypted backups, weekly full snapshots, and an off-site code mirror, so a lost server is an inconvenience, not an extinction.
What doesn't? Backups protect against loss, not against a wrong number that reconciles cleanly before anyone notices. Good plumbing shrinks the window between a failure and its detection - it does not make the window zero.
7. Market gaps and closure
What happens? Markets don't always move smoothly through a price - sometimes they gap, jumping over the level where a hedge was meant to engage. Expiries cluster risk on specific dates; venues can halt trading exactly when you most want to act.
How bad can it get? A violent gap through a strike, or a halt during a fast move, can mean the hedge engages later or worse than the clean payoff diagram suggests. Real fills in a crisis are rougher than a textbook line.
What protects you? The hedge is built around broad, BTC-led drawdowns - the scenario where deep, liquid markets keep functioning even under stress. Position sizing assumes imperfect fills rather than textbook ones.
What doesn't? No structure makes a discontinuous market continuous. If price teleports, execution is imperfect, full stop. We size for that reality instead of pretending it away.
The risk we can't write down
Here's the uncomfortable part. The most dangerous risk in any system is the one not on the list - the failure mode nobody imagined, which is precisely why it isn't disclosed anywhere, by anyone.
And here is the part that should keep you skeptical of every risk page, including this one: every risk on this list was once an unlisted risk. Before FTX failed, "FTX collapses" was on no one's disclosure. Before Terra unravelled, "Terra de-pegs" was in nobody's risk section. The catastrophic failures are, almost by definition, the ones not yet written down - which means a complete-looking list is itself a kind of illusion. Ours included.
We can't itemise the unknown. What we can do is build for it: keep the first-loss equity as a buffer that doesn't care what caused the loss, keep the ledger honest so a surprise is visible fast, keep leverage modest so a shock that's twice as bad as expected is survivable rather than terminal, and write down what we do know so the unlisted set is as small as we can honestly make it.
A surprise that finds you with a buffer and a clean record is a bad month. The same surprise that finds you over-extended and opaque is the end.
The one line to keep
The fund that tells you nothing can go wrong has already told you the one thing that has:
its honesty.