Skip to content
Protocol

FYBER internals

A cap written in the token, ten and a half million in existence at deployment and every other unit minted at the moment somebody claims it, a staking weight that does five jobs, an exit grid that prices impatience, and an invariant that keeps all of it out of the risk layer.

Spec v0.15, reviewed 2026-09-09

FYBER exists at deployment as contracts nobody owns. A cap of 100,000,000 FYBER is written into the token itself and two immutable contracts may mint under it. There is no sale, no auction, no entity, no allocation to the authors and no vesting anywhere. Distribution is by seasons of counters written on chain, converted by a curve fixed in the constructor, with no human act at any point in the process.

The one thing to hold on to while reading: no regime, threshold, cap, rate or activation criterion reads FYBER, and the Stability Pool's own return contains no emission.

Rule R-12.10.1, Rule R-19.12.1, principle P10

What exists on day one

10,500,000 FYBER, and nothing else, until the first claim.

At deploymentAmountWhere it is
The initial liquidity10,000,000 FYBERinert inside FYBERLiquidity, which has no withdrawal function, until the launch
The launch lot500,000 FYBERstaked in sFYBER as one lot dated the deployment, for the launch address
Everything elsenothingit does not exist yet

Nothing is minted before it is earned

Neither the opening of the liquidity position nor the settlement of a season mints anything. A unit of FYBER comes into existence at the moment a user calls claim or claimStaked and takes what their counters entitle them to, plus the protocol lot's proportional share of it. What no user claims is never minted, in that season or in any later one. There is no carry-forward and no burn of an unclaimed share, because the token was never created.


Rule R-19.7.1, decisions D229 and D233

The launch lot is the one exception, and it is named rather than blurred. It is 500,000 FYBER — under one per cent of the cap — staked for the launch address, taken out of the protocol lot rather than added to the total. It carries no privilege of any kind: it leaves through the same exit grid as every other lot, it is seizable pro rata like every other lot, and it weighs in every sum from the deployment onward. Its declared use is outside the protocol: discretionary rewards to pools and to users. It is the only FYBER ever attributed to a person's address, and the only address of a person in the immutable fields of the whole protocol.

The allocation, which sums to the cap

DestinationShare of the capHow it comes into existence
Initial liquidity10,000,000 FYBERminted at deployment, into a position nobody can withdraw
The launch lot500,000 FYBERminted at deployment, staked
Season zero4,000,000 FYBERa ceiling, minted at each claim, streamed over 90 days
Twenty seasons65,000,000 FYBERa ceiling, minted at each claim
The protocol's own stake20,500,000 FYBERminted at each claim, at 0.315385 per unit claimed, and staked on the spot
The authors0%
A second version's endowment10,000,000 FYBERminted only by an election, and above the cap

The first five sum to exactly 100,000,000 FYBER, and that identity is asserted in both constructors that hold the constants and checked across them at the end of the deployment sequence. A second assertion bounds what claims can actually mint, including the protocol lot's share, under the same cap.

There is no vesting on a reward and no cliff anywhere. The stream and the exit grid do that work, and a locked reward nobody can reach is a known failure of other protocols.

Rule R-19.7.1

Seasons, and the four counters

A season is 90 days long, counted from the first one, which opens 180 days after deployment. Season zero is everything before that. There are 20 seasons and then nothing: past the last one no counter is written and no budget exists. A season closes automatically the moment the next begins, and any write to a closed season reverts — absorbed by a try/catch on the core side, so no protocol operation can ever fail because of the ledger.

ClassUnitShare of a season
DepositorsfyUSD-days in a pool or its wrapper35%
BorrowersfyUSD of interest accrued, at a rate capped by tier20%
Pool liquidityin-range liquidity times time, on the reference pool15%
Vault liquidityin-range value times time times the lock multiplier, per branch30%

Season zero used 55% and 45% on the first two and nothing on the others, because neither pool existed yet.

The borrower class counts interest actually accrued and nothing else. Origination fees and rate-change fees earn no counters at all, and the rate that counts is capped at 3% on tier 1, 5% on tier 2 and 8% on tier 3, which is twice each tier's floor. Choosing a rate above that cap pays more to the Stability Pool and adds nothing here.

Staked FYBER multiplies the first two counters by up to 1.5×, saturating at the same weight per unit as the pool boost. It does not multiply the vault class, where the lock is already the multiplier.

The counters are non-transferable, are converted alone, and are not written at all while a branch has no price.

Rule R-19.8.1, Rule R-19.8.2

The curve, and the year it front-loads

The season budget

B_0 = 4,000,000 FYBER


B_1 = 8,816,000 FYBER, then B_k = B_1 × 0.873423559829 ^ (k − 1) for k up to 20


which is −12.66% per season, and zero past the last one


season 1 8,816,000 FYBER · 2 7,700,102 FYBER · 3 6,725,451 FYBER · 4 5,874,167 FYBER · 5 5,130,636 FYBER · … · 20 673,821 FYBER


and they sum to 65,000,000 FYBER

The decay is a geometric ratio carried to twelve decimal places, and that precision is not cosmetic: at six places the twenty budgets summed to a hundred and seventy-nine units more than the total, which is 2.8 millionths — past the tolerance the constructor asserts, so the deployment would simply have reverted. At twelve places the error is a hundred-thousandth of a millionth.

Geometric rather than piecewise, so that the step between any two consecutive seasons is the same −12.7% and there is no cliff anywhere except the end. A linear decay to the same total would have meant a drop of 39% between the first season and the second, which is the step this curve exists to remove.

WindowEmitted, at most
Seasons 1 to 429,120,000 FYBER
The first year, season zero included33,120,000 FYBER
Second year16,940,000 FYBER
Third year9,860,000 FYBER
Fourth year5,740,000 FYBER
Fifth year3,340,000 FYBER

The whole of the farming and of the protocol lot is minted inside five years. The first year is 33,120,000 FYBER, which is a third of the cap, and the ceilings some other protocols hold to are not held to here: they were removed rather than quietly missed, and the comparison is published.

The ceiling on the minted supply, by date

deployment 10,500,000 FYBER · twelve months 52,800,000 FYBER · sixty months 100,000,000 FYBER


circulating outside the protocol lot, the liquidity position and the launch lot, at twelve months: 33,100,000 FYBER


every one of those is a ceiling, reached only if everything is claimed, and reduced by whatever has been burned

Weekly, as a ceiling and not as a plan: season zero releases at most 311,000 a week over ninety days; the first season at most 686,000 a week during its stream, plus the protocol lot's share of what is claimed, which is staked and not circulating; the second season 599,000; the eighth 266,000; the twentieth 52,000.

Rule R-19.8.3, decisions D209, D211, D246

Conversion and delivery

settleSeason(k) is permissionless, runs once, and only after the season has ended. It freezes the totals and, for the vault class, the weights the branches carried at that instant — a dormant or shut branch weighs zero. It mints nothing.

claim(k) releases a stream over 90 days for the three liquid classes and mints, at that moment, what has vested and not yet been taken, plus 0.315385 of it to the protocol's own stake. Season zero is streamed like every other and is the one season that mints no protocol share, because adding it would have pushed the last claims of the last season past the written cap.

claimStaked(k) takes everything acquired, all classes, and stakes it directly.

The vault class has no liquid path. claim leaves it alone, and claimStaked is the only way out — which, with the exit grid, makes it liquid after 7 days, or worth 70% less straight away. Delivering it liquid would have put a third of a season's emission on the market inside the stream, and those same tokens are what absorbs the first loss on the liquidity they reward.

No Merkle root, no whitelist and no conversion rate set by anybody: there is no human act in this path at all.

Rule R-19.8.4, Rule R-19.8.5

The staking weight, which does five jobs

Weight of one lot

weight = stake × growth × (W0 + (1 − W0) × min(age, AGE_CAP) ÷ AGE_CAP) × slash index


W0 = 25%, AGE_CAP = 365 days

A fresh lot counts a quarter; a lot older than a year counts fully, so a one-year staker is worth four times a same-day one per token. Lots on their way out are excluded from the weight entirely.

The same weight is used for the credited share of the buy-back, the Stability Pool boost, the redemption shield, the season multiplier and the seizure base. There is one notion of weight and no second accounting.

The exit grid

The fee is a continuous line, not a set of steps. Four points are fixed and straight lines join them, so every hour of waiting is worth something and no minute is worth more than the one beside it.

Leaving costs what you refuse to wait

request, then withdraw after Δ. The fee falls along the line through


0 → 70% · 24 hours → 50% · 3 days → 30% · 7 days → nothing


so 12 hours → 60% · 2 days → 40% · 5 days → 15%


and what is kept back is burned in full: 100% of it, to the zero address

The fee used to be credited to the stakers who stayed. It is now burned outright, which is simpler and which removes the protocol lot's share of it from the calculation entirely. What the stakers who stay give up is stated: on the order of 3.5% a year in units, at five per cent of stakes leaving instantly.

exitPreview returns the fee and the next step, so an interface shows what waiting another hour is worth rather than a table of four rows.

Requesting removes the amount from the weight immediately. A lot on its way out receives no share of the revenue, no boost, no shield, no multiplier and no vote, its age is frozen, and it remains seizable until it is actually withdrawn. Cancelling returns it to the stake, dated now.

Withdrawing part of a stake does not reset the age of the rest. The age falls by the fraction taken out, age' = age × (1 − share withdrawn), so somebody who waits the full 7 days for a quarter of their stake keeps three quarters of their standing on the rest. The formula is path-independent — splitting a withdrawal into two changes nothing — so it opens no game of slicing.

A request left past 7 days plus 7 days returns to the stake through settleExpired, which anybody may call, with no fee and dated now.

Running from a seizure costs more than the seizure

Bad debt must sit uncovered for 24 hours before staked FYBER can be seized. Somebody who requests an exit the moment they see it and withdraws at that same delay pays 50%, where staying and being seized costs at most 30%. The assertion checked at deployment is on the fee itself: the fee at the seizure delay exceeds the seizure ceiling. The race to the exit is arithmetically irrational at every point on the curve.


Rule R-19.2.5

Rule R-19.2.4, Rule R-19.2.6

Crediting, without creating a lot

After the eighth season, the part of a buy-back that is not burned is credited by an index rather than paid out.

How a credit lands

credit index += amount ÷ Σ of the weights frozen at each staker's last touch


at a staker's next touch: E = their frozen weight × (index − their snapshot), then growth ← growth × (1 + E ÷ stake), then the snapshot and the frozen weight are refreshed

The frozen weight is what makes the sum exact. Divided by the current weights instead, a staker who let a year of age accrue without touching the contract would have been credited at four times their share, and the contract would have promised more FYBER than it held — the sum of the credits would not have equalled the amount received. What a staker gives up for not touching is stated: the age they gain between two touches counts for their weight but not for their credits until the next touch. A permissionless call refreshes anybody's snapshot, for free.

The credit joins the lots that already exist, in proportion to their stake. No new lot is created, every lot keeps its own age, and the weighted average age is exactly unchanged. It is never liquid: it leaves only through the exit grid, and it is seizable in the meantime.

The two alternatives were worse. A new lot per credit would be thousands of lots a year per staker. One aggregated lot dated at the credit would lower a one-year staker's average weight by nearly 4% on a 5% credit.

Rule R-19.5.2, decisions D157 and D245

What the buy-back is, in one paragraph

A quarter of every dollar of revenue buys FYBER from the first settlement of the treasury, and everything bought is burned through the eighth season — two years — after which the protocol lot's share is burned and the rest is credited. The buy-back releases slowly, moves the reference pool by at most 0.2% per call, and reads a bounded average for its price. It is closed while any branch carries bad debt and in the terminal mode. No target is published and none exists. The whole mechanism, its bounds and what it is worth are on the treasury and the buy-back.

Risk

The only mechanical floor under the price of FYBER in the first year is zero. Nothing in the protocol supports a price, and nothing is meant to. What is published, after the fact, is the net emission of each season — minted less burned — as a measurement. Read FYBER risk.

Seizure and auction

Bad debt is covered in three layers: the fyUSD reserve, then staked FYBER, then redistribution across the branch's own positions.

The middle layer opens when bad debt has been uncovered for 24 hours, the reserve is empty, and at least 7 days have passed since the last seizure on that branch. It takes the lesser of five times the shortfall, converted into FYBER at the price described below, and what the ceiling allows, as the same fraction of every staked lot: private lots, exiting lots, the launch lot and the protocol's own lot alike, in no order at all. A staker is in that base from their first day.

That was the alternative to taking the protocol's own lot first, and the reason for choosing it is stated: with the protocol lot as a first loss, no private staker would have been touched before the third year, and four sentences elsewhere in this documentation would have described an exposure that did not exist. A disclaimer that describes nothing is worse than none.

The ceiling is 30% of the whole stake over a rolling 7 days, counted across every branch together rather than branch by branch — otherwise three bad debts on three branches in one week could have taken 30% three times over.

The seized tokens go to a descending auction. The accepted price starts at 1.5× the price of FYBER in fyUSD, fixed at the opening, and falls linearly to 0.2× that price over 24 hours. That opening price is the bounded average of the FYBER/ETH pool multiplied by the bounded average of the USDG/ETH pool, so both sides of the auction are counted in the unit the debt is denominated in.

A bid names an amount of FYBER and the fyUSD it pays; it is accepted if the fyUSD is at least the amount times the price of that moment, if the amount is no more than what is left, and if the fyUSD is no more than the outstanding bad debt. Partial bids are the normal case. The fyUSD is burned against the debt. The auction closes as soon as nothing is left or the debt is covered, and otherwise at the end of the 24 hours, when anyone may close it: whatever did not sell goes back to every staked lot at the same index it was taken at, the protocol's own lot included.

The floor is the price of FYBER divided by the same multiple the seizure sizes itself with, so that at the floor the whole seized amount covers exactly the shortfall it was taken for. Nobody sets the price: the first buyer to accept pays the highest price of the auction, in competition with everybody else. The cost of that, said plainly: the first hours may sell nothing, and if the market is under the floor when the auction closes, the unsold tokens go back and the claim falls to redistribution instead.

A seizure needs both of those averages and the USDG peg guard. If any of them is unavailable, seizeFYBER reverts and the claim simply waits: nothing is seized at a price the protocol cannot compute. The layer behind it is unaffected — after 72 hours of uncovered bad debt, redistribution takes over whether a seizure happened or not.

Risk

The dollar thickness of this layer is 30% of a stake whose price nobody controls. At a low price it is a few hundred thousand dollars for the whole protocol. It is noise, not insurance, and it is junior to the fyUSD reserve. Read liquidation and bad debt.

Rule R-19.3.1, decisions D168 and D260

Boost, shield, multiplier

All three divide something that already exists between users. None of them creates a unit of anything.

MechanismSaturates atWorth at mostPaid by
Pool boost0.25× of weight per fyUSD deposited1.50× of the average sharethe other depositors, up to a third less
Redemption shield0.10× per fyUSD of debt2% on the sort keythe borrowers behind you in the queue
Season multiplierthe same as the boost1.5×the other holders of counters in that class

Every read of the staking weight from the core is a bounded static call. A revert gives zero, or one for a multiplier, and the core operation goes through regardless.

Liquidity mining

One canonical pool, FYBER against ether, fee 1%, whose identifier is known at deployment. It is the same pool the initial liquidity position opens at 0.005 dollars, the same pool the buy-back reads to bound itself, and the only pool the seasons reward. The alternative — a reference pool against fyUSD and a separate one against ether — was presented with its cost, two pools sharing the depth that one class of counters rewards, and refused.

A staked position must sit on that exact pool key, be at least about a hundred per cent wide, and stay locked seven days. There is also a floor on the liquidity a position may carry — not fixed yet — under which staking is refused outright, so dust cannot lengthen the list of positions for nothing.

Counting happens in tours. A tour opens once the interval has elapsed, and anyone advances it page by page — checkpoint(maxPositions) visits that many positions and stops, the caller choosing the page under the block limit. The tour closes when the cursor comes back to the start, and its interval is the time between two openings. A position counts for a tour only if it was in range at the previous visit and at this one. That rules out just-in-time liquidity, narrow positions, pool hopping and leaving at the first sign of trouble. unstake waits for a tour in progress to finish. The protocol's own position never counts: it is single-asset, above the price, and held directly rather than as a staked token.

The tours are paid for by whoever runs them, and nothing refunds that gas — the providers are the only ones who benefit, so they are the ones with the reason to turn the crank. A position staked between two tours is first counted in the next one.

If nobody provides liquidity at all, that class's share of the season is never minted. The first provider to arrive takes the whole class alone, which is up to 1.3 million FYBER in the first season, so the empty outcome is not a stable one.

Other FYBER pools may exist and may be rewarded from the launch lot, outside the protocol. Never from a season.

Rule R-19.9.1, decision D236

The second version's endowment

FYBERVote carries three objects. Two are signals with no execution: a closer address and a parameter set that a published deployment script reads. The third elects a deployer, once, no earlier than a year after the first season, in a 30-day window, with a quorum of 25% and a two-thirds majority. Election mints 10,000,000 FYBER above the written cap and streams it over two years. With no election, those tokens never exist at all. The protocol's own stake does not vote, and one address counts for at most 10% of the private weight.

Risk

A third-party contract that staked on users' behalf and issued a liquid receipt against it would escape the exit grid entirely: its holders would sell the receipt instead of paying 70% to leave, and the burned exit fees would become a charge on direct stakers alone. It would also deprive them of the boost and the shield, which are computed per address. What such a contract could not do is escape a seizure — it never exits, so it is seized like everybody — and the vote cap is what stops it reaching a quorum alone. Nothing in the protocol prevents it from existing.

Rule R-19.6.1, decision D167

The independence invariant

The risk layer cannot see the token

Any sequence of interactions with any FYBER, vault or treasury contract leaves the reference price, the liquidation price, the regime, the branch ceiling, the activation test, the mint freeze, the rate floor, the redemption fee, the pool cap and the total flow to the pools unchanged. No path in the core reads a price of FYBER, and the only price of ether the token layer reads is the single reading taken when the liquidity position opens. A revert inside the staking contract or the ledger fails no core operation. The treasury's share is zero while the pools are thin, the buy-back is closed under bad debt, and both are zero in the terminal mode.


Rule R-19.12.1

What FYBER is not

Not a governance token for version 1. Not a source of return for the pool wrapper. Not an asset whose price steers a parameter. Not tail insurance. Not a discretionary treasury — the treasury is a contract with a frozen order of spending that nobody commands. Not an entity. The season counters are neither a promise, nor an asset, nor a debt.

Rule R-19.14

What follows from this page