Skip to content
Blotter

Protocol

Guardrails and parameters

Every limit the pool works under, what it prevents, and what it costs.

The pool buys assets in stressed markets and holds them. The guardrails below limit how much it can buy, of what, at which prices, and how fast it can sell. Each has a cost, stated next to its purpose. No value appears on this page: values are not set yet, and once set they are published on-chain.

Inventory limits

Cap per ticker

What it limits. The value of the warehouse held in a single Stock Token, relative to the pool's assets.

Why. Gaps are more often single-stock events than market events: results, litigation and halts hit one ticker at a time.

Failure it prevents. A pool that absorbs every liquidation of one falling stock ends up holding mostly that stock. One more bad print would then decide the result for everyone.

Cost. When the cap binds, the pool stops absorbing the ticker under the most stress. The overflow goes to ordinary liquidators and to the AMM.

Cap per sector

What it limits. The combined warehouse value across all tickers mapped to one sector.

Why. Stocks in a sector gap together. Ticker caps alone would allow many correlated names, each under its own cap.

Failure it prevents. A sector repricing turning a diversified-looking warehouse into one position.

Cost. If listed Stock Tokens are dominated by one sector, this cap binds early. Any sector mapping is a simplification of how stocks correlate.

Price integrity

No seizure past the heartbeat

What it limits. Liquidations by the pool when the oracle price is older than the feed's heartbeat, the maximum expected interval between updates.

Why. The seizure price is the oracle price. On a stale feed, the pool does not know what it is paying.

Failure it prevents. Buying collateral at a price that no longer exists, and booking a premium that is not there.

Cost. A feed outage in a fast market sidelines the pool when it is most wanted. The rule also depends on correct session information, to tell a closed market from a broken feed. See Integrations.

No unwinding on a stale feed or during a halt

What it limits. Sales of inventory when the price is stale, the ticker is halted or a market-wide circuit breaker is active.

Why. Without a live reference, arbitrageurs cannot hedge and the AMM price is not anchored.

Failure it prevents. Selling into an AMM where the pool's own tranche sets the price.

Cost. Inventory stays longer in the warehouse and may be carried across a close.

Execution limits

Market hours only

What it limits. Unwinding to the regular session of the underlying market.

Why. On-chain liquidity for Stock Tokens is deepest and best anchored when the stock itself trades.

Failure it prevents. Overnight and weekend sales at dislocated prices.

Cost. The pool cannot reduce risk outside the session, even when news arrives. It holds through the gap by design.

Tranche cap

What it limits. The size of each sale, as a percentage of the AMM's volume and reserve.

Why. Price impact depends on sale size relative to the reserve. See Warehouse and unwinding.

Failure it prevents. The pool becoming the cascade it was built to absorb.

Cost. Slower unwinding, more inventory carried across the close, and less USDG for the next wave.

Liquidity for depositors

Withdrawal reserve and queue

What it limits. The share of assets that liquidations may spend. A set share always stays in free USDG. Withdrawals beyond the free USDG exit through a queue, filled as unwinding returns USDG.

Why. Inventory cannot become USDG on demand without breaking the unwinding rules.

Failure it prevents. A rush of withdrawals forcing a fire sale, paid for by the depositors who stay.

Cost. The reserve is idle capital that absorbs nothing. In stress, a depositor may wait, exposed to the warehouse, until the queue reaches them. See Pool shares.

Parameters

ParameterScopeWhat it controls
Inventory cap per tickerPer Stock TokenMaximum warehouse value in one ticker, relative to pool assets
Inventory cap per sectorPer sectorMaximum combined warehouse value across one sector
Sector mappingPer Stock TokenWhich sector a ticker counts toward
Oracle heartbeatPer price feedMaximum age of a price for seizing or unwinding
Session and halt statusPer Stock TokenWhether the underlying market is open and the ticker is trading
Withdrawal reserve sharePoolShare of assets kept in free USDG, unavailable for liquidations
Tranche capPer Stock Token and AMMMaximum size of one sale, as a percentage of the AMM's volume and reserve
Integrated lending marketsPer lending marketWhere the pool may liquidate
Approved unwind venuesPer Stock TokenWhich AMMs inventory may be sold on
Premium splitProtocol70% depositors, 20% $BLOT stakers, 10% buy and burn

Reading and tracking parameters

Every parameter is stored in contract state and can be read directly, without relying on this site. A change is an on-chain transaction: visible when it happens, with a permanent record.

Visibility is not protection. A change can alter the risk of the pool, for example by raising a cap, and seeing it does not undo it. Who may change parameters, and with what delay, will be published with the contracts. See governance risk in Risks.