What is measured before launch
Sixteen measurements that have to come back before any constant is frozen, what each one is worth, and what changes in the design if it comes back badly.
Spec v0.9.1, reviewed 2026-09-08
Every number in the contracts is final at deployment. A value calibrated on a guess is a guess that lasts for the life of the protocol, so the design record carries a register of things that must be measured first. Each entry says what is measured, over what window, and what the design does if the measurement disappoints.
Risk
Every one of these is blocking. Not "preferable to check" and not "to be revisited": a measurement that comes back badly changes a constant, changes a branch's tier, or removes a branch from the registry, and all three have to happen before the deployment transaction. Afterwards, none of them can.
The full register runs from the first hypothesis about the collateral token to the last about gas. What follows is the part added or reopened by the current specification, which is where the unmeasured surface is concentrated.
Are the price sources actually alive when the exchange is not
The single most load-bearing claim in the protocol is that several markets trade the same exposure at three in the morning on a Sunday. It has been measured once, on one long weekend, and that is not enough.
| Measured | Over | If it comes back badly |
|---|---|---|
| For all twenty branches, every five minutes: each source's value and freshness, the number of live sources, the dispersion between families, and the resulting regime | Four weekends, read-only | The dispersion thresholds, the source quality weights and the confidence reference are recalibrated. A branch that is not in the full regime for at least 80% of the weekend hours is not activated at deployment, and stays dormant |
| Whether the signed round-the-clock feeds, the exchange feeds and the twin-token feeds are retrievable by any subscriber, in the current message format, and verifiable by a fixed verifier | The same four weekends, plus a fork test | Without them the only non-reporter group is the on-chain pools. The index branch survives; the branch with no deep pool and no signed feed is frozen at the weekend and cannot be activated. The gold branch has no exchange price at all and is not deployed |
| Whether five independent reporters exist, publish their keys and a proof of source, and will sign every minute without being paid by the protocol | Signed agreements, four weekends of test signatures | Without them the perpetual and twin venues do not enter at all, and the signed path reduces to one infrastructure |
| Whether the measured pool depths hold against an on-chain quoter rather than an in-range estimate | A quote per pool | The depth reference and every source weight derived from it are recalibrated |
| Whether the pool hooks on three named pools only take a fee, and touch neither the swap nor the balance | Bytecode review | Those pools are excluded from the price family. Two branches lose their on-chain source entirely |
| For the sixteen branches never measured: whether an exchange feed, a pool, a perpetual and a twin market exist at all, and how deep | Registry and venue reads | A branch with fewer than two independent sources is not deployed. Its registry slot stays empty in this version |
Whether the chain and its infrastructure behave
| Measured | If it comes back badly |
|---|---|
| Whether a sequencer uptime feed exists on this chain | No uptime feed means no cause to detect an outage. The residual risk is documented and carried |
| Whether the Uniswap state-reading contracts are readable inside the gas budget, and whether the manager and its state view are fixed at the published addresses | This is blocking for the index branch. Without it there is no on-chain price family and no depth measurement |
| Whether the exchange feeds behave as assumed: the age at which a print stops counting, the missed-heartbeat window, the first print of a Sunday evening, and the behaviour on a long holiday weekend | The freshness constants are replaced at construction. The stake is smaller than it was: the exchange print is one source among several, not the price |
| Whether the historical round data of a feed is readable at least ten rounds back | The pre-pause snapshot falls back to the last round seen, and recovering from a halt needs one refresh per round |
| What gas actually costs after the subsidy ends, for a price refresh, a signed update, a pool observation and a liquidation | The keeper share is raised at construction, and the freshness window is lengthened |
| Whether a corporate action really runs pause, multiplier, unpause, and whether the price per raw token is unchanged by a split | The conditions for leaving a pause, and the recalibration of the consistency bounds, are adjusted at construction |
| Whether the USDG price feed is a price feed rather than a reserve attestation, and whether it publishes during a depeg | The depeg guard is absent at deployment. The cap on the module is then the only line |
The liquidity vault ranges: measured, and settled
This one has been run, and its answer is in the constants rather than pending. Five years of history across all twenty names, with the 2022 decline, April 2025 and the individual earnings collapses as mandatory stress windows, against the criteria of at most five to ten days a year outside the range, at most six, twelve or eighteen recentrings a year by tier, and at least a quarter of the position still in fyUSD at a 20% fall.
| Result | Over that history |
|---|---|
| Time a vault spent with no liquidity at the trading price | None |
| fyUSD still in the position at the worst episode | 26% |
| Ranges it settled on | 40% and 25%, 55% and 35%, 65% and 45% |
The ranges are therefore wider than the design first carried, and the width was bought with depth: 19 to 30% less at the centre of the range. That trade is the finding, not a residual doubt, and it is on Liquidity vaults.
Risk
What remains is that a measurement of five years is a measurement of five years. The constants are frozen at deployment like every other, so a name whose behaviour departs from its own history keeps the range that history gave it.
Still open beside it: a second simulation of the loop between the fyUSD the vaults release on a fall and the reserve behind the swap module, which is the exposure with no bound in the contracts.
Whether the volatility oracle reads what it is meant to read
| Measured | If it comes back badly |
|---|---|
| The cost of one daily volatility sample, in gas. The sample is the median of 3 readings taken in one fixed 24 hours slot, so the measurement covers three readings and not one | The sample ring is halved, which shortens the long window to a fortnight |
| How far the volatility computed from a round-the-clock composite sits above the volatility of exchange closes | The quantile constant is recalibrated. The historical borrowing limits published in this documentation are then slightly optimistic, and the real ones will sit below them |
| Whether the logarithm implementation is exact enough over the range the price can take | The implementation changes; the formula does not |
The three constants of the formula, 2.33×, 3 days and 2%, together with the floors 60%, 50% and 40% and the priors 25%, 50% and 80%, are estimates awaiting the founder's confirmation and a sensitivity run.
Two things this measurement no longer has to establish. A corporate action does not erase a branch's volatility history, so there is no longer a fall to the prior for a fortnight after each split or dividend. And a dormant branch builds that history from the hourly price readings it already needs for its activation criteria, so the requirement to have covered 15 days of the long window fills itself without anybody running a dedicated process for it.
The economic simulation that decides two tier assignments
Separate from the register, one simulation has authority over the branch list itself. Every branch is replayed on one-minute history since 2015, including the flash crash, the 2015 opening gap, March 2020 and every earnings release, with half the Stability Pool withdrawn at the start of each episode, a 90-second flag, a fifteen-minute lag on the on-chain family and its saturation on any fast move.
It publishes the anticipated annual loss to the pool and the anticipated bad debt for each branch, and it carries one rule with teeth:
Guarantee
A name placed in tier 2 whose simulated annual loss exceeds 0.5% of its debt moves to tier 3 before deployment. Never after.
The simulation is run again with the daily borrowing limit in place, opening positions at the limit of each day rather than at the tier ceiling, and to publish both results side by side.
What is still an open choice rather than a measurement
Some numbers are not waiting on data. They are waiting on a decision, and the record names them: the exact date the first season opens, the three constants of the volatility formula, the floors and priors, the nodes of the exit curve, the share of each season that goes to the vaults, and the pool requirement on tiers 2 and 3, which is still the provisional figure of 0.8× and will be frozen at deployment whether or not the simulation has revised it.
Those are on Parameters, marked as provisional in the same table as the measured ones, so that a reader can tell which is which.
One question that used to sit on this list has been settled, at zero. Nobody pays anything into the protocol at deployment, into any pool, the peg module, the reserve or a fyUSD pool; the sequence by which it gets off zero is on How it starts, and the risks that follow from starting empty are on Liquidation and bad debt and Peg and the swap module.
FBR
A token with no claim on anything, that can be seized to cover somebody else's bad debt, that costs to leave, and that can be worth nothing without a borrower or a depositor noticing.
Contracts overview
The modules an integrator meets, the call order for every user path, which functions anybody may call, who supplies the signed prices, and what reverts.