Skip to content
Risks

What is measured before launch

Sixteen measurements that have to come back before any constant is frozen, what each one is worth, and what changes in the design if it comes back badly.

Spec v0.9.1, reviewed 2026-09-08

Every number in the contracts is final at deployment. A value calibrated on a guess is a guess that lasts for the life of the protocol, so the design record carries a register of things that must be measured first. Each entry says what is measured, over what window, and what the design does if the measurement disappoints.

Risk

Every one of these is blocking. Not "preferable to check" and not "to be revisited": a measurement that comes back badly changes a constant, changes a branch's tier, or removes a branch from the registry, and all three have to happen before the deployment transaction. Afterwards, none of them can.

The full register runs from the first hypothesis about the collateral token to the last about gas. What follows is the part added or reopened by the current specification, which is where the unmeasured surface is concentrated.

Are the price sources actually alive when the exchange is not

The single most load-bearing claim in the protocol is that several markets trade the same exposure at three in the morning on a Sunday. It has been measured once, on one long weekend, and that is not enough.

MeasuredOverIf it comes back badly
For all twenty branches, every five minutes: each source's value and freshness, the number of live sources, the dispersion between families, and the resulting regimeFour weekends, read-onlyThe dispersion thresholds, the source quality weights and the confidence reference are recalibrated. A branch that is not in the full regime for at least 80% of the weekend hours is not activated at deployment, and stays dormant
Whether the signed round-the-clock feeds, the exchange feeds and the twin-token feeds are retrievable by any subscriber, in the current message format, and verifiable by a fixed verifierThe same four weekends, plus a fork testWithout them the only non-reporter group is the on-chain pools. The index branch survives; the branch with no deep pool and no signed feed is frozen at the weekend and cannot be activated. The gold branch has no exchange price at all and is not deployed
Whether five independent reporters exist, publish their keys and a proof of source, and will sign every minute without being paid by the protocolSigned agreements, four weekends of test signaturesWithout them the perpetual and twin venues do not enter at all, and the signed path reduces to one infrastructure
Whether the measured pool depths hold against an on-chain quoter rather than an in-range estimateA quote per poolThe depth reference and every source weight derived from it are recalibrated
Whether the pool hooks on three named pools only take a fee, and touch neither the swap nor the balanceBytecode reviewThose pools are excluded from the price family. Two branches lose their on-chain source entirely
For the sixteen branches never measured: whether an exchange feed, a pool, a perpetual and a twin market exist at all, and how deepRegistry and venue readsA branch with fewer than two independent sources is not deployed. Its registry slot stays empty in this version

Whether the chain and its infrastructure behave

MeasuredIf it comes back badly
Whether a sequencer uptime feed exists on this chainNo uptime feed means no cause to detect an outage. The residual risk is documented and carried
Whether the Uniswap state-reading contracts are readable inside the gas budget, and whether the manager and its state view are fixed at the published addressesThis is blocking for the index branch. Without it there is no on-chain price family and no depth measurement
Whether the exchange feeds behave as assumed: the age at which a print stops counting, the missed-heartbeat window, the first print of a Sunday evening, and the behaviour on a long holiday weekendThe freshness constants are replaced at construction. The stake is smaller than it was: the exchange print is one source among several, not the price
Whether the historical round data of a feed is readable at least ten rounds backThe pre-pause snapshot falls back to the last round seen, and recovering from a halt needs one refresh per round
What gas actually costs after the subsidy ends, for a price refresh, a signed update, a pool observation and a liquidationThe keeper share is raised at construction, and the freshness window is lengthened
Whether a corporate action really runs pause, multiplier, unpause, and whether the price per raw token is unchanged by a splitThe conditions for leaving a pause, and the recalibration of the consistency bounds, are adjusted at construction
Whether the USDG price feed is a price feed rather than a reserve attestation, and whether it publishes during a depegThe depeg guard is absent at deployment. The cap on the module is then the only line

The liquidity vault ranges: measured, and settled

This one has been run, and its answer is in the constants rather than pending. Five years of history across all twenty names, with the 2022 decline, April 2025 and the individual earnings collapses as mandatory stress windows, against the criteria of at most five to ten days a year outside the range, at most six, twelve or eighteen recentrings a year by tier, and at least a quarter of the position still in fyUSD at a 20% fall.

ResultOver that history
Time a vault spent with no liquidity at the trading priceNone
fyUSD still in the position at the worst episode26%
Ranges it settled on40% and 25%, 55% and 35%, 65% and 45%

The ranges are therefore wider than the design first carried, and the width was bought with depth: 19 to 30% less at the centre of the range. That trade is the finding, not a residual doubt, and it is on Liquidity vaults.

Risk

What remains is that a measurement of five years is a measurement of five years. The constants are frozen at deployment like every other, so a name whose behaviour departs from its own history keeps the range that history gave it.

Still open beside it: a second simulation of the loop between the fyUSD the vaults release on a fall and the reserve behind the swap module, which is the exposure with no bound in the contracts.

Whether the volatility oracle reads what it is meant to read

MeasuredIf it comes back badly
The cost of one daily volatility sample, in gas. The sample is the median of 3 readings taken in one fixed 24 hours slot, so the measurement covers three readings and not oneThe sample ring is halved, which shortens the long window to a fortnight
How far the volatility computed from a round-the-clock composite sits above the volatility of exchange closesThe quantile constant is recalibrated. The historical borrowing limits published in this documentation are then slightly optimistic, and the real ones will sit below them
Whether the logarithm implementation is exact enough over the range the price can takeThe implementation changes; the formula does not

The three constants of the formula, 2.33×, 3 days and 2%, together with the floors 60%, 50% and 40% and the priors 25%, 50% and 80%, are estimates awaiting the founder's confirmation and a sensitivity run.

Two things this measurement no longer has to establish. A corporate action does not erase a branch's volatility history, so there is no longer a fall to the prior for a fortnight after each split or dividend. And a dormant branch builds that history from the hourly price readings it already needs for its activation criteria, so the requirement to have covered 15 days of the long window fills itself without anybody running a dedicated process for it.

The economic simulation that decides two tier assignments

Separate from the register, one simulation has authority over the branch list itself. Every branch is replayed on one-minute history since 2015, including the flash crash, the 2015 opening gap, March 2020 and every earnings release, with half the Stability Pool withdrawn at the start of each episode, a 90-second flag, a fifteen-minute lag on the on-chain family and its saturation on any fast move.

It publishes the anticipated annual loss to the pool and the anticipated bad debt for each branch, and it carries one rule with teeth:

Guarantee

A name placed in tier 2 whose simulated annual loss exceeds 0.5% of its debt moves to tier 3 before deployment. Never after.

The simulation is run again with the daily borrowing limit in place, opening positions at the limit of each day rather than at the tier ceiling, and to publish both results side by side.

What is still an open choice rather than a measurement

Some numbers are not waiting on data. They are waiting on a decision, and the record names them: the exact date the first season opens, the three constants of the volatility formula, the floors and priors, the nodes of the exit curve, the share of each season that goes to the vaults, and the pool requirement on tiers 2 and 3, which is still the provisional figure of 0.8× and will be frozen at deployment whether or not the simulation has revised it.

Those are on Parameters, marked as provisional in the same table as the measured ones, so that a reader can tell which is which.

One question that used to sit on this list has been settled, at zero. Nobody pays anything into the protocol at deployment, into any pool, the peg module, the reserve or a fyUSD pool; the sequence by which it gets off zero is on How it starts, and the risks that follow from starting empty are on Liquidation and bad debt and Peg and the swap module.