Protocol
Mechanism
The five steps from a USDG deposit to a premium paid at the bell.
Blotter does one thing in five steps: take deposits, absorb liquidations, warehouse the collateral, unwind it during market hours, and distribute the net premium. This page walks through each step, the parties involved, and where assets move.
The actors
- Depositors supply USDG to the pool and hold its ERC-4626 shares.
- Borrowers hold loans on a lending market, with Stock Tokens as collateral and USDG as debt. They never interact with Blotter.
- The lending market holds the loans and exposes a liquidation function. Blotter targets Morpho Blue-style markets, where that function is permissionless.
- The oracle publishes the price of each Stock Token. The lending market uses it to decide which loans are liquidatable. The pool uses the same price to value its inventory.
- The pool is the Blotter Pool contract. It holds free USDG and the warehouse of seized Stock Tokens.
- The AMM is the on-chain venue where inventory is sold for USDG. This documentation always calls it the AMM, to keep it distinct from the pool.
- Stakers lock $BLOT as first-loss capital.
- Ordinary liquidators keep operating as they do today. Blotter does not replace them.
Who may submit the transactions that trigger a seizure or a tranche is a contract-level detail, not published yet. The checks below apply whoever the caller is.
The five steps
- 1
Deposit
A depositor sends USDG to the pool and receives shares. The shares follow the ERC-4626 standard and are transferable ERC-20 tokens. Their price is the pool's total assets divided by the share supply. See Pool shares.
- 2
Absorb
When a Stock Token-backed loan becomes liquidatable on an integrated lending market, the pool calls the market's liquidation function. It repays debt in USDG and receives collateral worth the repaid amount plus the liquidation bonus, at the oracle price. The pool acts only if its own checks pass: the feed is fresh, inventory caps have room, and the withdrawal reserve is untouched. See Liquidation flow.
- 3
Warehouse
The seized Stock Tokens are not sold. They stay in the pool, valued at the oracle price. Because the pool paid the oracle price less the bonus, the inventory enters the books above its cost. That difference is the gross premium. It is not realized yet: it depends on what the inventory later sells for.
- 4
Unwind
Inventory is sold for USDG on the AMM only during the regular session of the underlying stock market. Each sale is a tranche capped as a percentage of the AMM's volume and reserve. No tranche is sent during a halt or on a stale feed. Whatever is not sold by the close is carried to the next session. See Warehouse and unwinding.
- 5
Distribute
Once inventory is sold, the result is known: bonus collected, minus slippage paid, plus or minus the move in the oracle price while the inventory was held. A positive net premium is split 70% to depositors, 20% to $BLOT stakers and 10% to buy and burn. A negative result is a loss. It burns staked $BLOT first, then reduces the share price. See $BLOT.
Asset flows
USDG
USDG enters the pool from depositors. It leaves as debt repayment to a lending market, as withdrawals to depositors, and as the part of a positive net premium owed to stakers and to buy and burn. It returns as proceeds of each unwind tranche.
A set share of the pool's assets always stays in free USDG and cannot be spent on liquidations, so that ordinary withdrawals do not depend on the pace of unwinding. Withdrawals beyond the free USDG wait in a queue.
Stock Tokens
Stock Tokens enter the pool only through liquidations. The pool never buys them on the market. They leave only through unwind tranches on the AMM. There is no discretionary trading in either direction, and no lending of the inventory.
$BLOT
Staked $BLOT sits in the staking contract. It moves in three cases: a staker unstakes, a loss burns part of the stake, or the buy and burn removes tokens from the market. The token is not launched. See the warning on the $BLOT page.
Why each step is built this way
Why repay with pooled capital. An atomic liquidator needs the AMM to pay for the liquidation in the same transaction. A pool with its own USDG does not. It can liquidate at the oracle price even when the AMM is dislocated, which is when liquidations stall. See The Monday problem.
Why warehouse instead of sell. The bonus is the same for every liquidator. What differs is the exit price. Selling at the print means selling into the thinnest, most crowded minute of the week.
Why market hours only. During the regular session, arbitrageurs can hedge on the underlying market, so the AMM price is pulled back toward the oracle price after each sale. Outside the session, a tranche moves a price that nobody corrects.
Why caps everywhere. Every rule that slows the pool reduces what it can absorb. That is the cost. The benefit is that no single ticker, sector, stale price or rush of withdrawals decides the fate of the pool. See Guardrails and parameters.
What the mechanism does not do
The pool has finite capacity. Liquidations beyond it go to ordinary liquidators. The pool does not make lenders whole: if collateral is worth less than debt at the print, the shortfall stays with the lending market. And the pool takes price risk on everything it holds across a close. See Risks.