Skip to content
User guide

FYBER and sFYBER

A token that does not exist until somebody has earned it, what staking it does and what it costs to stop, what the treasury does with the protocol's revenue, and the four ways it divides a flow between users without creating one.

Spec v0.15, reviewed 2026-09-09

FYBER is Fyber's token. Its base supply can never exceed 100,000,000 FYBER, a number written into the token contract itself, and only two immutable contracts may ever mint against it. It is not sold: no offering, no auction, no company. It goes to the people who use the protocol, by seasons, on a curve written into the code.

Guarantee

No regime, threshold, ceiling, rate or activation criterion anywhere in the protocol reads FYBER. The yield of sfyUSD contains no emission. If FYBER went to zero tonight, a borrower's threshold, a depositor's interest and the peg would be exactly where they are.


Rules R-19.12.1, invariant 52

Nothing exists before it is earned

This is the first thing to understand, because it is unusual and it changes what every other number on this page means.

At deployment, 10,500,000 FYBER exist and nothing else. There is no treasury holding tokens, no distributor holding tokens, no vesting contract, no allocation waiting to be unlocked. When a season closes, nothing is minted. Tokens come into existence one at a time, at the moment the person who accrued them calls claim — and a share of a season that nobody accrued toward is never minted at all, not carried to the next season, not swept anywhere.

What exists at deploymentAmountWhere it sitsWhat it does
The one-way liquidity position10,000,000 FYBERA contract with no owner and no withdrawal functionInert until the launch, then a standing offer of FYBER against ETH between two known prices
The launch lot500,000 FYBERStaked in sFYBER for one published addressThe only FYBER ever attributed to a person's address. It leaves through the same exit grid as any stake, it is seizable like any stake, and its declared use is discretionary rewards outside the protocol

Everything else is a ceiling, not a holding: 4,000,000 FYBER for what was done before the first season, 65,000,000 FYBER across twenty seasons, and 20,500,000 FYBER for the protocol's own staked lot, which is minted at the rate of 0.315385 FYBER per FYBER any user claims, and never on season zero. A further 10,000,000 FYBER exists only as a possibility: it is minted above the cap, once, if and only if an election names an address allowed to deploy a version 2.

There is no allocation to the authors. There are no vesting contracts, because there is nothing to vest.

Rules R-19.7.1, R-19.8.4, D229, D233, D234

The launch position

At the launch — 180 days after deployment — anyone may call openLiquidity() once. It places all 10,000,000 FYBER into a single-sided position in the FYBER/ETH pool, between a starting price of $0.005 and 10× that price, converted into ETH once from a fresh price round at that moment. That puts the capitalisation of the position alone at $50,000 and the fully diluted value at $500,000 on the base cap.

It sells FYBER for ETH as the price rises through the range, and buys it back with that ETH if the price falls. It is not a sale: nobody receives the proceeds, because the ETH stays in the position, and the pool's 1% fee in ETH goes to a contract with no key. The FYBER side of those fees is burned. There is no withdrawal function of any kind; the one exit is at the very top of the range, where the position is entirely ETH and can be swept to the treasury, which ends it for good.

Risk

It is not a price floor and not an issue price. The market can trade under $0.005, in which case the position is inert — it sells nothing and supports nothing — and the price is whatever third-party providers make it. The only mechanical floor under FYBER is the ETH this position has actually accumulated, which is nothing until it has sold something.


Rules R-19.18.3, R-15.4.1 (14)

Rules R-19.18.1 to R-19.18.4, D203, D235

The seasons

The first season opens 180 days after deployment. Each lasts 90 days, and there are 20 of them, so the whole emission is finished five years after the launch. Anyone may close a finished season; nobody can open one early, skip one, or extend past the last one.

Four things accrue a share of a season's ceiling:

ClassWhat it countsShare
DepositorsfyUSD-days in a Stability Pool or in sfyUSD35%
BorrowersfyUSD of interest actually accrued, at a rate capped by tier20%
FYBER liquidityIn-range liquidity-time in the FYBER/ETH reference pool15%
Vault liquidityIn-range value × time × lock multiplier, per branch30%

Season zero uses a different split — 55% depositors, 45% borrowers — because the other two classes do not exist before the launch.

A staker's counters are multiplied by up to 1.5×, which divides the same ceiling between users and adds nothing to it. The vault class is the exception: its multiplier is the lock, not the stake. A class with nobody in it, or a branch with nobody in its vault, simply mints nothing.

The borrower class counts accrued interest only, and only up to 3% on tier 1, 5% on tier 2 and 8% on tier 3. Origination and rate-change fees count nothing at all — a fee never accrues anything.

The ceiling of each season is a geometric curve: 8,816,000 FYBER for the first, then multiplied by 0.873423559829 each time, which is a fall of 12.66% per season with no larger step anywhere in the twenty.

SeasonCeiling
18,816,000 FYBER
27,700,102 FYBER
36,725,451 FYBER
45,874,167 FYBER
55,130,636 FYBER
20673,821 FYBER

By year, and these are the numbers that matter: 33,120,000 FYBER in the first year including season zero, which is 33.1% of the base cap; then 16,940,000 FYBER, 9,860,000 FYBER, 5,740,000 FYBER and 3,340,000 FYBER. The minted supply reaches at most 52,800,000 FYBER twelve months after the launch and at most 100,000,000 FYBER at sixty, and both are ceilings that require everybody to claim everything.

Nobody computes any of this by hand. There is no list, no root, no conversion rate and no human act anywhere in the path from using the protocol to holding FYBER.

Rules R-19.8.1 to R-19.8.5

Claiming

claim(k) mints and releases a season's allocation as a straight line over 90 days, liquid, for the depositor, borrower and FYBER-liquidity classes. The stream is a speed limit on what is claimable, not a schedule that runs on its own: a user who never claims never brings their FYBER into existence, and nothing obliges them to.

claimStaked(k) takes the whole of it — every class — straight into the stake instead.

The vault class has no liquid path at all: it is delivered staked, and it leaves through the exit grid, which makes it free to withdraw 7 days after you claim it. claim(k) mints the liquid classes and leaves that part waiting for claimStaked(k).

Rules R-19.8.4, R-19.8.5, D249

Staking

Staking creates a dated lot. A lot counts for 25% of its size on the day it is staked and rises to the whole of it over 365 days. A lot a year old therefore weighs four times a lot staked today, per token.

That single weight does five things, and there is no second notion anywhere:

  1. A share of the protocol's revenue, once the treasury's cascade reaches the buy-back and once the burn period is over. See below — this one is smaller and later than it sounds.
  2. A larger share of a Stability Pool's yield, up to 1.50×, saturating at 0.25× of weight per fyUSD deposited.
  3. A better place in the redemption queue: the position is sorted as though its rate were up to 2% higher, without paying it, saturating at 0.10× of weight per fyUSD of debt.
  4. A multiplier on what you accrue toward a season, up to 1.5×.
  5. First loss. Staked FYBER is what covers bad debt after the fyUSD reserve, from the first day you stake.

The second, third and fourth divide a flow between users. They create nothing, and a user who holds no FYBER receives a smaller share of the same total.

Rules R-19.2.1, R-19.4.1, R-19.10.1, R-19.11.1

What the protocol does with its revenue

The protocol's revenue goes to a contract with no key, no owner and a spending order nobody can change. Anyone may call its settle(), at most once an hour, and it spends what came in since the last call in exactly this order:

  1. A quarter of every fyUSD that came in buys FYBER, before anything else. 25%, from the first settlement, at any level of debt.
  2. The gas of the permissionless work the protocol depends on — settling borrowing epochs, observing the pools, running the liquidations that pay for themselves. Paid in ETH first, from the launch position's fees, then in fyUSD up to 50% of the rolling intake.
  3. The reserve that stands in front of bad debt, in slices: 60% of what is left, until it holds 2% of the debt. The other 40% goes to the buy-back. Once the reserve is full, everything does.
  4. The rest buys FYBER.

Guarantee

Every FYBER the treasury buys is burned through season 8 inclusive — 100% of it, for two years. Only afterwards is the part corresponding to the protocol's own staking weight burned and the remainder credited to stakers. Nothing about the buy-back reads a target, and no target is published.


Rules R-19.5.1, R-19.5.2, D227, D232

The buy-back is deliberately slow. Each tranche the treasury sends is released linearly until the next settlement, and never faster than over 3,600 seconds; a permissionless buy() takes what is released and never more than what moves the reference pool by 0.2%, under a 30-minute average price with a tolerance of 2%. Capturing that 0.2% would cost a sandwicher the pool's 1% fee twice — a net loss — which is why there is no auction and no schedule to front-run.

What it is actually worth, and when

Risk

For the first two years the buy-back is small and everything it buys is destroyed rather than credited to anybody. Against what the seasons distribute, a model at $0.10 puts it at most at 5.5% in the second year, 20% in the third, 47% to 57% in the fourth, and 113% to 123% in the fifth, which is where it crosses. Meanwhile the first year distributes up to 33,120,000 FYBER. The only mechanical floor under the price of FYBER is the ETH the launch position has accumulated, and that is zero until it has sold something.


Two figures behind that: the gas of the permissionless work is structurally larger than 20% of the interest while the debt is under twenty to thirty million dollars, so the cascade spends most of what it receives on gas for the first years; and the reserve is therefore worth of the order of 0.2 to 0.5% of the debt over those two years rather than 2%.


Rules R-19.1.2, R-19.17.3, R-15.4.1 (14)

What is published, rather than promised, is the arithmetic after the fact: the net emission of each season — minted less burned — once the season has closed.

Rules R-19.1.2, R-19.5.1, D226, D231, D238

What leaving costs

requestUnstake removes the amount from your weight immediately and starts a clock. withdraw delivers what the grid leaves.

The fee is a straight line between four fixed points, so there is nothing to time and no hour at which waiting longer is worth nothing.

You waitKept back and burnedYou receive
Nothing70%30%
Twelve hours60%40%
A day50%50%
Two days40%60%
Three days30%70%
Five days15%85%
7 daysNothingAll of it

An hour of waiting is worth 0.83 of a point on the first day, 0.42 up to the third and 0.31 up to the seventh.

Everything kept back is burned. It used to be credited to the stakers who stayed; since the token was reworked it is destroyed instead, so an exit shrinks the supply rather than transferring value between holders. What the remaining stakers lose by that change, stated: about 3.5% a year in units, at an assumed 5% of stakes leaving immediately.

A stake on its way out has a weight of zero: no revenue share, no boost, no queue advantage, no season multiplier, no vote. Its age is frozen. And it can still be seized until you actually withdraw.

cancelUnstake puts it back at any time, dated today. Left more than 7 days past the last step, it returns to the stake through settleExpired, which anyone may call, at no cost. Splitting a withdrawal into a hundred small ones costs exactly the same, because each carries its own clock.

Taking part of your stake out does not reset the age of the rest. The age falls by the fraction withdrawn, so half a stake withdrawn leaves the other half at half its age. That is what makes the last row of the table true for a partial exit as well as a total one.

Rules R-19.2.4, R-19.2.5, R-19.2.6, D228

The seizure

When a branch carries bad debt that the fyUSD reserve did not cover, anyone may call for a seizure 24 hours later. It takes the same fraction of every staked lot, the protocol's own included, the launch lot included and exiting lots included, in no order at all, and puts it in a descending auction. The accepted price starts at 1.5× what FYBER is worth in fyUSD — the bounded average of the FYBER/ETH pool multiplied by the bounded average of the USDG/ETH pool, fixed when the auction opens — and falls linearly to 0.2× that over 24 hours. Bids may be for part of the amount, and no bid may pay more fyUSD than the bad debt still standing, so the auction stops taking money the moment the shortfall is covered. Whatever the auction does not sell is returned to every lot at the same index it was taken at.

If either average is unavailable, or USDG is outside its own guard, the seizure cannot be called at all: it reverts, and the bad debt waits. After 72 hours it is redistributed across the branch's borrowers instead, so a stake can be spared by a missing price rather than by anything a staker did.

Two ceilings bound it. A branch cannot be seized against twice inside 7 days, and across every branch together no more than 30% of the whole stake may be seized over any rolling 7 days.

Risk

Running from an announced seizure costs more than the seizure. Leaving immediately costs 70% of your stake and that cost is burned; the seizure takes at most 30%, and in practice a fraction of that. The ordering is deliberate and asserted at deployment: the fee still owed when a seizure may start is larger than the largest seizure.


Rules R-19.3.1, R-19.2.5

What FYBER is not

It is not a governance token for version 1: nothing in the protocol can be changed by anyone, so there is nothing to vote on. The one vote that exists names an address that would be allowed to deploy a version 2, and it releases nothing from version 1. In that vote one address carries at most 10% of the private weight, however much it holds.

Risk

A third party could stake on behalf of many users and issue a liquid receipt against it. That receipt would escape the exit grid, since the underlying stake never leaves, and its holders would hold none of the boost, the queue advantage or the season multiplier individually, because those are computed per address. Nothing in the protocol prevents such a contract from existing, and the exit fees would then fall on direct stakers alone.

It is not a source of yield for sfyUSD. It is not an asset whose price steers a risk parameter. It is not tail insurance: the dollar value of the staked layer is small against the debt it stands behind, and the specification calls it noise rather than cover. What a season accrues is a counter: not a promise, not an asset, not a debt.

FYBER can be worth nothing without anything breaking for a borrower or a depositor. That is the property the whole design is arranged around, and in the first year it is not a hypothetical: the emission is at its largest, the buy-back is at its smallest, and nothing in the contracts supports a price.

Rules R-19.14, R-15.4.1 (14)