MMashDiv

The Instant Convert house page - recovery that does not depend on the addon

The Instant Convert house page, reached from Finance → Transaction Management → Pool Backing - the core console that reads the Instant Convert house, holds its three kill switches, defunds it and settles its Sends, hedges and movements while the addon is disabled, unlicensed or even uninstalled - every action behind a mandatory second factor.

5 min readUpdated 1 October 2026admin, house, recovery, kill-switch, defund, licence, pool-backing, 2fa

The Instant Convert house page (/admin/finance/pool-backing/house), reached from Finance → Transaction Management → Pool Backing through the House inventory button at the top of that console. It is part of the core, not of the addon: /api/admin/finance/** is not gated by the Instant Convert licence or its enabled switch. Reading it needs view.pool.backing. Every action needs manage.pool.backing and a fresh two-factor code, and the three kill switches also need the Super Admin role.

Disable Instant Convert, or let its licence lapse, and /api/admin/convert answers 404 or 403. Switching it off under System → Extension Manager is refused while any Send, hedge order or house movement is still open (those in review included), or while the hedge cycle's last snapshot, if under ten minutes old, shows about $1 or more of the house's exposure unhedged; the refusal lists what is outstanding. To wind down, have a Super Admin set Mode to Drain (Convert → Settings → General), let the jobs finish, resolve whatever is in review in the Convert console, and switch the addon off once exposure is flat. The refusal mentions an acknowledgeInFlight override, which the Extension Manager screen cannot send; only a direct API call can. If the check itself cannot run, the switch-off goes through.

Sends, hedges and movements that were in flight are still being finished by their jobs, but anything that lands in review now needs a page that still opens. This is it.

What it shows

A banner says which of three states the addon is in, because that decides what the page can do:

Addon The page can
Installed (enabled or not, licensed or not) read everything, defund, change the kill switches, and confirm or reverse Sends and resolve hedges and movements, by calling the addon's own code
Files present but failing to load read, defund and change the switches; the resolve actions answer 503 and the backend log names the file
Not installed read, defund and change the switches; nothing to resolve

Then, each section read on its own so one failure never blanks the page:

  • House wallets: the house's Spot and Ecosystem balances, what open work holds on each (Sends · hedges · movements), and what may be defunded now.
  • On-chain inventory: the house's Ecosystem address on each chain, with the two balance trackers Sends and movements read, Key tracker and Address map (the lower one counts), and the band Instant Convert keeps there.
  • Open Sends: payouts whose reservation is still open, or in review.
  • Open hedges: planned, sent, or waiting for review. Only one in review can be resolved; the hedger finishes its own planned and sent orders.
  • Movements in flight.
  • Kill switches.

The kill switches

Switch Values Stops
Hedging mode (convertHedgeMode) Off, Monitor only, Automatic Off sends nothing; Monitor only records what it would send; Automatic places hedge orders on the exchange.
Pause hedging (convertHedgePause) on, off New hedge orders and new house movements, at once. What already started is finished and booked.
House movements (convertRebalanceEnabled) on, off New house movements. Movements already started are finished.

This page is their one editor. System → Settings refuses them by name, and the Convert console shows them read-only with a link here, so no two editors can validate them differently. Values are checked the way the addon reads them (an unknown mode is refused, never stored), then written and the settings cache is cleared. A change needs the Super Admin role on top of manage.pool.backing.

Two further switches are shown here read-only, with a link to where they are changed: Quoting paused (convertQuotingPaused, System → Settings) and the pool-backing global pause, which stops house movements too.

Defunding from here

Defund moves ledger inventory from the house to the Super Admin wallet of the same currency and wallet type, audited. It follows the addon's own rules, re-implemented in core so it works without the addon:

  • Spot, or Ecosystem of a single-chain pooled family only (UTXO coins, EVM tokens, TRC-20, TRX). Inventory at house addresses (native coins, SPL, multi-chain tokens) is never defunded by ledger: a Super Admin balance of it could not be paid out.
  • Never below what open work holds: Send holds, hedge holds (planned, sent or in review), and the holds of exchange-to-chain movements. The dialog says the most that can be defunded now.
  • Not limited by the floor. The floor is Convert's quoting band, and this is the wind-down path: emptying the house of a retired currency must be possible. The console's own defund still keeps the floor.
  • The Super Admin's Ecosystem wallet is opened through the ecosystem addon first, and the defund refuses if that cannot be done.

It shares the console's idempotency keys, so one request id retried on both pages (here and Admin → Convert → Inventory) is still one transfer: This defund had already been made; nothing new was moved.

Settling Sends, hedges and movements

With the addon installed, the same decisions as in the console, made by the addon's own code, which checks every one of them again before it moves anything:

  • Confirm a Send as sent: with the transaction ID from the explorer, booked only if it is the Send's own recorded hash and the chain confirms it.
  • Reverse a Send: with a reason of at least ten characters and the typed confirmation, as in the console. Refused unless nothing was ever signed for it, it has already failed, or the chain proves the payout can never land. See Sends for the proof on each chain. Cancel on chain and Approve are not on this page.
  • Resolve a hedge in review: the dialog shows Why in review, then offers Confirm fill, Mark failed (with a reason of at least ten characters, on proof the venue shows no such order), or Look it up again. See Hedging.
  • Resolve a movement: Confirm the exchange sent it, Confirm it arrived, Attach a transaction ID, Look it up again, or Mark failed on proof. See Movements.

The second factor

Every action asks for a code from the acting admin's own second factor, in a dialog on this page. The code authorises that change only: it is bound to the action and to its exact target (the currency, wallet type, amount and request id of a defund; the exact switch values; the Send, hedge or movement and the decision). A code confirmed for one payload does not exist for another.

This requirement is mandatory and does not fail open. If two-factor authentication is disabled platform-wide, or none of the accepted methods is available, every action here is refused until it is: house money is never moved on a password alone. An admin with no factor enrolled is asked to enable one in their profile security settings first.

In the pool-backing console

The house is inside the platform's totals, not beside them. The pool-backing reconciliation counts house balances in what the platform owes and shows them on their own line, so you can tell house inventory from customer money while the totals still add up. A convert moves no totals at all: it is double-entry against the house.