A dollar that compounds with a real-asset portfolio, with equity beneath it and a launchpad above it.
USD++ is soft-pegged, positively rebasing money backed by a diversified treasury of stable reserves, gold, equities, and other approved real-world assets. PLUS is the junior equity layer that governs the treasury, absorbs first loss, and lets the protocol convert speculative demand into additional assets. A USD++-native token launchpad creates the utility and attention required to bootstrap both.
What the protocol is trying to accomplish
Build productive money
USD++ should be more compelling to hold than a conventional reserve stablecoin because eligible treasury profits become Monetary Dividends that increase holder balances while the unit remains targeted near one dollar.
Turn speculation into capital
PLUS can float above hard NAV. When it does, finite PLUS issuance can buy RWA, retire USD++, or acquire strategic liquidity at a hard economic cost below the market value paid to bonders.
Create native demand
Every launchpad token is quoted against USD++. Token creation, speculation, liquidity, routing, and fees therefore increase USD++ demand instead of treating the stable asset as an isolated financial product.
The three economic claims
Decisions, rationale, and explicit non-goals
The protocol is easiest to reason about when settled choices are separated from optimization questions. The following decisions are the current canonical direction.
Decision registerFull rationale and status for each settled directionOpen for the complete design record.
| Decision | Current direction | Why | Status |
|---|---|---|---|
| USD++ redemption | No contractual $1 redemption | Hard redemption would force the treasury toward cash-like assets and weaken the differentiated gold/equity thesis. Peg support is policy-driven, with an explicit loss waterfall. | Settled for V1 |
| Holder yield | Positive share/index rebases; wUSD++ for v4 markets and fixed-balance integrations | Users hold one roughly $1 token whose balance compounds. Canonical AMMs use wUSD++ internally to avoid rebasing-balance risk while routers present ordinary USD++ pairs. | Settled |
| Negative rebases | Never routine; available only as final resolution | PLUS and treasury reserves must absorb loss first. A negative rebase is the honest final tool if the system is actually insolvent. | Settled |
| ESD-like Coupons | Not included | Coupons exchange liquid USD++ for an interest-bearing future liability rather than adding capital, while complicating creditor priority and recovery. | Not included |
| Two-token model | Keep USD++ and PLUS separate | USD++ needs a price anchor; PLUS needs the freedom to carry speculative premium, absorb first loss, and act as a capital-raising asset. | Settled |
| Bond payouts | User chooses among protocol-priced USD++/vPLUS modes | Different bonders want liquidity, balanced exposure, or maximum PLUS. The protocol controls reward and capacity rather than forcing a single demand profile. | Three-mode baseline |
| Launchpad rewards | No PLUS subsidies to creators | Creator token allocation and fee share are sufficient. PLUS incentives would create wash-trading and low-quality launch pressure. | Settled |
| Platform fee use | Protocol capitalization + sustainable builder funding | External usage revenue strengthens the monetary system while funding continued development. The exact allocation is specified later under Fees & monetization. | Settled |
| RWA profit use | Split between USD++ dividends and protected PLUS capital | USD++ needs differentiated portfolio yield; PLUS needs superior percentage upside for first-loss risk. | m = 2 baseline |
| USDC/USD++ liquidity | Treasury-managed predetermined ranges | The protocol should allocate bonded USDC directly, rather than acquire arbitrary user LP positions or subsidize ranges it does not control. | Settled direction |
| Canonical AMM | Uniswap v4 USDC/wUSD++ pool with a normalized oracle and policy hook | Fixed-balance wUSD++ limits initial AMM risk. Routers wrap and unwrap automatically, and the UI reports the normalized USD++/USDC price. | Settled direction; hook proof required |
| Capitalization | Risk-responsive target derived from portfolio stress retention | A fixed ratio ignores portfolio composition. Safer diversification should support more USD++; concentrated or risky assets should require more junior capital. | 150% baseline |
Technical detailNon-goals and failure boundariesWhat the protocol deliberately refuses to promise or optimize for.
Non-goals
Not a conventional reserve stablecoin
USD++ is not intended to be a fully redeemable wrapper around USDC or Treasury bills. Stable reserves are defensive liquidity, not the full product thesis.
Not an unbacked algorithmic peg
Supply expansion is bounded by external treasury value. Recovery cannot rely on an unlimited fixed-price USD++-to-PLUS conversion.
Not perpetual liquidity mining
Genesis PLUS emissions acquire treasury assets and strategic liquidity. Post-Genesis operation must be sustainable without permanent reward emissions.
Not a promise of lossless dollars
PLUS takes first loss, but severe insolvency can ultimately reach USD++ through an emergency negative rebase. The design specifies that outcome rather than hiding it.
System architecture and balance-sheet model
The protocol is a monetary balance sheet, a floating equity layer, a treasury manager, a canonical market maker, and a consumer launchpad. Each component has a distinct claim and must be accounted for separately.
USD++
Senior soft-pegged monetary claim. It targets ~$1, receives explicitly allocated portfolio profit through positive rebases, and has no hard redemption right.
PLUS
Junior residual equity. It governs risk, absorbs treasury losses first, owns protected capital and platform economics, and can be issued to acquire assets when accretive.
Launchpad
Demand and distribution layer. Every canonical launch market quotes against USD++, turning speculative activity into stable-asset demand, fee burns, and treasury expansion.
Consolidated accounting
| Item | External treasury NAV? | Free peg reserve? | USD++ backing / capitalization? | PLUS hard NAV? |
|---|---|---|---|---|
| USDC held freely | Yes | Yes | Yes | Yes, net of USD++ |
| Tokenized Treasuries | Yes | Only if operationally liquid | Yes | Yes, net of USD++ |
| Gold / equities | Yes | No | Yes at MTM for capitalization; constrained by risk rules | Yes |
| USDC inside protocol-owned POL | Yes | No, while committed | Yes | Yes |
| Protocol-owned USD++ | No external asset | No | Exclude if treasury stock; reserve capacity if committed for sale | No |
| Treasury-owned PLUS | No | No | No | No; it is treasury stock |
| USD++/PLUS LP | External assets only; not endogenous token face value | No | Strategic, not free reserve | External component + realized external fees only |
| Launch-token LP | Not core RWA backing | No | No | Only explicit protocol fee rights, conservatively |
Economic ownership compact
USD++ holders receive
- Explicit share of eligible RWA portfolio profit
- Positive Monetary Dividends when release conditions permit
- Stronger protection from permanent fee burns and PLUS capital
- Native launchpad utility and settlement demand
PLUS holders receive
- Protected bond capital
- Permanent protocol share of platform-fee economics
- Residual portfolio-profit share: eligible RWA profit not credited to USD++, retained as protected junior equity (50% at the 150% / m = 2 baseline)
- First-loss risk and leveraged hard-NAV exposure
- Governance and accretive issuance optionality
Builders receive
- A defined minority share of genuine external platform and trading fee revenue
- Long-vested PLUS allocation
- No skim from RWA principal, monetary operations, or treasury returns
(3,3) is the protocol-wide coordination strategy, not merely a bond setting
Olympus used “(3,3)” to communicate that participants created more collective value by staking, bonding, and avoiding reflexive selling. This protocol expands that idea into a complete user playbook: capitalize the treasury, preserve PLUS’s financing power, grow USD++ usage, and recycle value through the system.
The multiplication is intentional: treasury capitalization, low reflexive sell pressure, monetary usage, and reinvestment reinforce one another. Weakness in any leg limits the value created by the others.
What the original meme captured
“(3,3)” was not a solvency guarantee. It was a coordination shorthand: bonding gave the treasury assets, staking or holding reduced liquid sell pressure, and a durable OHM premium let the protocol acquire more assets with less dilution.
The Surplus (3,3) doctrine
Default to the capital-balanced bond when it fits. This expands the treasury and the USD++ economy together.
Lower liquid sell pressure helps preserve the premium the protocol can exchange for more RWA and strategic liquidity.
USD++ usage creates demand, external fees, paid issuance, and deeper canonical markets.
Reuse USD++, rebond external assets, or maintain long-term PLUS exposure instead of immediately extracting all value.
An action is protocol-positive only when it raises net accrued value, respects the capitalization floor, and reflects outside demand rather than self-trading. “Hold” is coordination guidance, not a promise of price appreciation or a restriction on exit.
The complete compounding system
How the platform generates and capitalizes on virality
Creators own meaningful upside
Initial token allocation and recurring creator fees motivate builders to recruit communities and sustain activity.
USD++ is the common quote asset
Every canonical launch, route, and graduated market turns attention into demand for the protocol’s monetary asset.
Routing removes acquisition friction
Users can enter with USDC, ETH, or another asset while the router acquires USD++ and settles through it automatically.
Usage becomes hard economic value
External fees burn USD++, paid issuance imports RWA, and portfolio returns strengthen both Monetary Dividends and PLUS.
Interactive: attention compounds into protocol value
A stylized 24-month model showing treasury NAV, USD++ supply, and PLUS hard equity in separate synchronized lanes so one fast-growing series cannot hide the others.
Treasury composition, asset factors, and the risk-responsive capital target
Stable reserves provide intervention capacity; growth assets provide the differentiated return. Asset-level USD++ Factors limit issuance against each RWA, while portfolio-wide stress determines how much junior capital the whole treasury must maintain.
Defensive assets
USDC, short-duration tokenized Treasuries, and other liquid dollar-like assets fund buybacks and operations. They are defensive ammunition, not the core debasement-protection thesis.
- Free reserve baseline: 25% of USD++ supply
- Used first in pool buybacks and Inverse Reserve Bonds
- Separated from USDC committed to AMM liquidity
Growth and debasement-sensitive assets
Gold, diversified equities, selected individual equities, and approved productive RWA drive long-term appreciation, Monetary Dividends, and PLUS residual value.
- Bounded by issuer, custodian, category, and single-name caps
- New bond terms steer allocation before treasury trades
- Never assumed instantly liquid during stress
A provisional USD++ Factor model
The USD++ Factor is the maximum USD++ a bond may create per dollar of an asset. It should be reproducible from observable risk inputs, then capped by governance and stress testing rather than selected as a narrative percentage.
Price-risk retention
Rσ = exp(−z·σ·√(h/365) − g), using annualized volatility, a stress horizon, confidence level, and explicit gap penalty.
Market capacity
Rliq compares 2% depth and trading capacity with the intended exposure; Rfloat and Rmcap are saturating free-float and market-cap scores.
Non-market risk
Rops scores oracle, custody, transfer, settlement, issuer, and legal enforceability. A class ceiling prevents superficially liquid assets from exceeding policy limits.
Default weights are a calibration prior, not a final risk model. Scenario simulation, issuer/custodian limits, and exposure caps may only reduce the resulting factor.
Technical detailFactor normalization, portfolio stress, reserve sizing, and rebalancingThe equations and safeguards behind the risk controls.
Normalized factor inputs
D2% is aggregate depth available before a 2% move, Qexit is the modeled emergency-sale amount, and F50/M50 are governance-set saturation constants. Final calibration should use log-scaled or empirical transforms if simulations show these simple curves misprice large assets.
Illustrative asset classes
| Asset class | Illustrative class ceiling | Illustrative exposure cap | Primary risk rationale |
|---|---|---|---|
| USDC / approved reserve stablecoin | 100% | 30% per issuer; 50% stable category | Issuer, blacklist, custody, and depeg risk |
| Short-duration tokenized Treasuries | 98% | 50% category; 25% per issuer/custodian | Settlement delay, custody, duration, and NAV reporting |
| Tokenized gold | 90% | 30% | Drawdown, custody, redemption logistics, oracle, and issuer risk |
| Diversified equity index | 80% | 50% equities total; 30% per index | Tail drawdown, market closure, gap risk, and correlation |
| Individual equity | 65% | 5% per name | Concentration, idiosyncratic gaps, tokenization, and market-hours mismatch |
Portfolio-level stress target
For scenario s, let r_i,s be the fraction of asset i retained after stress and w_i its current portfolio weight.
If a gold-only portfolio is modeled to retain 80% of value, 120% starting capitalization leaves only 96% after the shock. Exact 100% coverage requires 125%; preserving 110% coverage requires 137.5%.
Stable-reserve target
At a 20% contraction objective and a $0.95 maximum average purchase price, the mechanical requirement is 19% of supply. The 25% baseline adds operational and market-making separation.
Rebalancing policy
- Change bond capacity and reward: underweight assets receive better vPLUS terms; assets at cap stop accepting bonds.
- Redirect cash flows: income, maturities, and new stable reserves refill deficient buckets.
- Direct treasury trade: execute only outside permitted bands or when a risk event requires immediate action.
- Recovery liquidation: sell growth assets only after less destructive tools are inadequate.
Interactive: build an asset USD++ Factor
The waterfall shows how market and operational risk reduce the class ceiling. Presets are illustrative starting profiles, not assessments of any specific tokenized asset.
Interactive: portfolio risk frontier
The lines show the capitalization required by each joint stress scenario as the stable-reserve weight changes. The marker is the current portfolio.
Bonding: Build the Treasury, (3,3), or Max USD++
A bonder transfers an approved RWA to the treasury and receives a protocol-priced combination of USD++ and vested PLUS. The protocol controls eligibility, maximum issuance, total quote, capacity, and reward curve. Users choose only among economically acceptable modes.
Recommended V1 interface: a three-point snapping slider
Build the Treasury
Low or zero USD++, maximum vPLUS. Best when PLUS trades at a strong premium, capitalization is weak, or USD++ is below peg.
Balance-sheet effect: maximum protected external capital, maximum PLUS reserve consumption, no immediate USD++ scale.
(3,3) Grow Together
Incrementally capital-balanced. The bond grows treasury assets and USD++ in the target ratio without consuming pre-existing capital headroom.
This is the default and recommended coordination point.
Max USD++
USD++ up to the asset factor, minimum vPLUS. Best when USD++ demand is strong and the system has sufficient capital headroom.
Balance-sheet effect: fastest monetary expansion, least protected capital per deposited dollar.
Technical detailBond constraints, (3,3) math, and reward pricingThe formulas and peg-state rules behind the three bond modes.
System constraints
For new asset value V, selected USD++ x, current assets A, supply S, and post-bond target C_after:
The post-bond target is recalculated from the resulting portfolio. A diversifying asset may lower aggregate risk; a concentration-increasing asset may raise it.
Corrected (3,3) point
The recommendation must not spend headroom created by earlier fee burns, retained profit, or capital-heavy bonds. Evaluate the pre-bond headroom under the post-bond target:
When the system is already at or above a fixed target, this simplifies to x_3,3 = min(V·F_i, V/C). At 150%, a $100 bond independently supports about 66.67 USD++ while preserving prior headroom.
vPLUS quote and accretion
Let B be the bond’s target market-value compensation, P_x the USD++ TWAP, P_PLUS the PLUS market price, and N_PLUS PLUS hard NAV. Above peg, issued USD++ is valued at its market price; below peg, the quote does not compensate the bonder for the depeg.
When PLUS trades materially above hard NAV, paying market-value compensation in vPLUS is cheaper in hard economic terms than issuing equal market value in USD++. The protocol must still account for circulating supply, future sell pressure, finite reserve consumption, and lower demand for all-PLUS bonds.
Peg-state behavior
| USD++ state | Maximum USD++ | vPLUS quote | Preferred capacity |
|---|---|---|---|
| Above peg | Up to normal asset factor and system limit | Falls dollar-for-dollar as USD++ market value rises | Max USD++ and paid issuance expand |
| Near peg | Normal asset factor and system limit | Normal auction quote | (3,3) default |
| Below peg | Policy cap contracts, potentially to zero | No extra reward for USD++ price below $1 | Capital-heavy stable-asset bonds favored |
| PLUS near/below NAV | Unchanged by itself | vPLUS discounts compress or close | Paid USD++ issuance and non-dilutive recovery favored |
Vesting and supply discipline
Bond rewards are paid as vPLUS with a provisional 7-day linear vest, configurable within a 5–14 day constitutional range. The purpose is to prevent instant bond arbitrage without missing fast DeFi attention cycles. Recursion is controlled by finite capacity and dynamic pricing, not indefinite lockups.
Interactive: bond allocation frontier
Move across the full USD++ payout range. The chart shows what becomes a USD++ claim, what vPLUS costs at hard NAV, and what remains as protected PLUS capital.
Monetary Dividends turn portfolio performance into more roughly $1 USD++
USD++ does not need to appreciate like an investment share. Eligible RWA profit is assigned between USD++ and PLUS, accumulated as credits, and released through positive index updates when the peg and capital position can absorb additional supply.
From treasury profit to holder balance
External RWA produce net interest, dividends, realized gains, or recognized appreciation.
Costs and loss carryforward are deducted before any new profit is allocated.
The m-based rule credits USD++ and retains a larger percentage return for first-loss PLUS.
USD++ credits accumulate until headroom, peg state, reserve health, and rate limits allow release.
Every holder receives more USD++ proportionally without iterating over accounts.
Illustrative 150% / m = 2 example
A 10% return on a $150 treasury creates $15 of eligible profit. The baseline assigns $7.50 to USD++ and $7.50 to PLUS.
Benefits to the joint system
- USD++: a differentiated, portfolio-backed holding return
- PLUS: twice the percentage portfolio upside at the baseline, plus platform economics
- Peg: credits are stored expansion capacity that can be released when demand pushes USD++ upward
- Treasury: profit is never distributed unless post-rebase capitalization and reserve rules still pass
Recognized quickly
Net cash interest, cash dividends, and realized gains after direct costs.
Recognized gradually
Unrealized gold/equity appreciation, subject to oracle confidence, loss carryforward, and a release schedule.
Protected from dividends
New bond principal, PLUS-raised capital, paid-issuance premiums, and permanent platform-fee burns.
Technical detailCapacity, economic ownership, profit recognition, and release rulesWhy safe issuance and dividend entitlement remain separate.
Two values, two purposes
Safe issuance headroom
The most USD++ the current balance sheet can safely support. It is permission to issue, not an ownership claim.
Monetary Dividend credits
Credits belong economically to USD++ holders, but can be reduced by losses before release.
Source ownership
| Source | Creates headroom? | Creates dividend credits? | Owner before later returns |
|---|---|---|---|
| New RWA bond principal | Usually | No | Protected PLUS capital after USD++ paid to bonder |
| PLUS-only / capital-heavy bond | Yes | No | Protected PLUS capital |
| Protocol-share platform-fee USD++ burn | Yes | No | Permanent PLUS capitalization and safety |
| Above-peg paid-issuance premium | Yes | No | PLUS capital |
| Net eligible RWA portfolio profit | Yes | Yes, by the m-based split | Shared between USD++ and PLUS |
Profit recognition ledger
Negative P&L reduces unissued credits first, then becomes loss carryforward. Later gains repair that carryforward before creating new credits. Deposits therefore cannot masquerade as yield, and a fall-and-recovery cycle cannot be paid twice.
First-loss compensation rule
At m = 2 and C target = 150%, USD++ and PLUS each receive 50% of eligible profit. Because PLUS equity is smaller than USD++ supply, PLUS earns twice USD++’s percentage return.
Release policy
- Below peg: release zero credits.
- Near peg: release slowly under the epoch cap.
- Above peg: accelerate release before paid issuance, because the value is already allocated to existing holders.
- Recovery Mode: stop all releases.
Rebase mechanics
The global index update is O(1). wUSD++ provides a fixed-balance claim whose exchange rate tracks the index and is the settlement asset used by canonical v4 pools.
Interactive: watch Monetary Dividends accrue, pause, and release
The allocation bar shows who receives each $100 of eligible profit. The synchronized lanes show holder balance, PLUS hard NAV, and pending USD++ credits through different market paths.
How USD++ stays near $1
The peg is maintained by an ordered supply-control system. Above peg, the protocol releases earned dividends and sells newly issued USD++ only for new assets. Below peg, it stops expansion, buys and burns discounted USD++, and escalates through the recovery waterfall only when ordinary market operations are insufficient.
- Pause dividends and paid expansion
- Pool-first USDC buy-and-burn
- Inverse Reserve Bonds
- PLUS contraction / recapitalization
- Emergency negative rebase last
- Release credits gradually
- Accept normal RWA bonds
- Maintain free stable reserves
- Rebalance treasury through new flows
- Accelerate earned dividends
- Mint → wrap → sell into USDC/wUSD++
- Continue RWA bonds up to asset factors
- Reduce vPLUS as USD++ market value rises
Normalized TWAP plus spot and liquidity
Above, target, defensive, or recovery
Capital, credits, reserves, and epoch limits
Mint/sell or buy/burn to a hard price boundary
Interactive: policy response across the peg
Play a demand or stress path. The response curves show which tools become stronger as the normalized USD++ price moves away from $1.
Canonical market: USD++ UX, wUSD++ settlement
The user-facing route is shown as USD++/USDC. The actual Uniswap v4 pool uses wUSD++/USDC so token balances remain fixed and Monetary Dividends accrue through the wrapper exchange rate. The router wraps or unwraps automatically.
Price discovery
External trades establish wUSD++/USDC spot and time-weighted prices; the hook normalizes them to USD++.
Above-peg expansion
The controller mints USD++, wraps it, and sells wUSD++ atomically for external USDC to a price limit.
Below-peg contraction
The controller spends free USDC, buys wUSD++, unwraps it, and burns the acquired USD++.
LP dividend ownership
wUSD++’s exchange rate rises with Monetary Dividends, so the benefit belongs automatically to the LP position owner.
Technical detailNormalized v4 oracle, liquidity ranges, and intervention safeguardsHow the fixed-balance pool supports policy without share-aware swap accounting.
v4 oracle and policy hook
Uniswap v4 requires custom historical oracle functionality. Because the pool uses fixed-balance wUSD++, the hook does not need to rewrite concentrated-liquidity accounting for rebases. It must:
- Normalize price: if one wUSD++ represents index
IUSD++ and the pool price isP_wUSDC/wUSD++, thenP_USD++ = P_w / I. - Checkpoint index changes: store normalized observations so a new wrapper rate is never applied retroactively to old prices.
- Authorize bounded policy calls: expose TWAP, time-weighted liquidity, cooldown, and price-limit checks to the PegController.
- Classify fees: exclude protocol stabilization trades from external platform revenue.
Treasury-managed liquidity ranges
| Range tranche | Inventory | Purpose | Accounting |
|---|---|---|---|
| Core / oracle range | Balanced USDC and wUSD++ | Routing, observations, and ordinary depth | USDC is NAV but not free reserve while committed; wUSD++ is treasury USD++ inventory |
| Below-peg defensive ranges | USDC-only below spot | Absorb external USD++-equivalent sales | Acquired wUSD++ is periodically removed, unwrapped, and burned |
| Above-peg expansion | Prefer atomic mint-wrap-sell; avoid idle pre-minted inventory | Sell supply only when external USDC enters | Unfilled minted USD++ must be burned in the same transaction |
| Wide oracle backstop | Protocol-owned USDC/wUSD++ | Raise manipulation cost and guarantee minimum depth | Not counted as free stable reserve |
| External active liquidity | Third-party positions | Independent capital and tighter execution | LP fees and wUSD++ appreciation belong to those LPs |
Above-peg order
- Release earned Monetary Dividend credits within all constraints.
- Mint USD++, wrap, and sell wUSD++ atomically when TWAP, spot, liquidity, and capitalization authorize it.
- Continue diversified RWA bonds, valuing the USD++ payout at market and reducing vPLUS accordingly.
Below-peg order
The protocol first buys from the pool while the next marginal all-in USD++-equivalent price is no greater than the Inverse Reserve Bond quote. Only residual contraction demand is offered to inverse bonders.
Oracle safeguards
- TWAP authorizes policy; spot and active liquidity size execution.
- Reserve outflows require longer confirmation than paid expansion.
- Use a fixed observation buffer, minimum time-weighted liquidity, epoch caps, cooldowns, and later multi-venue confirmation.
- Protocol actions are excluded from organic volume and external fee revenue.
Interactive: execute a canonical-pool intervention
The chart models normalized USD++-equivalent execution. On-chain, the controller wraps before an above-peg sale and unwraps before a below-peg burn.
Fees: 80% permanent burn, 20% builders
Genuine external platform and trading fee revenue uses one canonical split. Treasury investment returns and monetary-policy operations are treated separately so principal, internal transfers, and external revenue cannot be conflated.
Protocol Share
Collected or converted to USD++ and permanently burned. The burn creates safe issuance headroom and PLUS hard equity, but does not create Monetary Dividend credits.
Builder Share
Paid to the development organization for salaries, infrastructure, security, audits, legal/compliance, operations, growth, and proportional builder profit.
Technical detailRevenue classification and fee-burn growth loopWhich fees qualify, what is excluded, and why burns remain permanent.
Eligible fee sources
| Source | Fee basis | 80/20 treatment | Notes |
|---|---|---|---|
| Launch bonding-curve protocol fee | External launch-token swaps | Yes | Creator and any liquidity share are removed before the platform share is split. |
| Graduated TOKEN/USD++ platform fee | External AMM swaps | Yes | Separate from ordinary LP compensation. |
| USD++/PLUS protocol-owned LP fees | External swaps against protocol-owned liquidity | Yes | Only realized fees, not LP principal or endogenous token face value. |
| USD++/USDC protocol-owned LP fees | External swaps | Yes | Exclude stabilization trades executed by protocol-controlled accounts. |
| Routing / aggregator fee | One-click external asset → USD++ → token routes | Yes | Must remain low enough not to damage launchpad conversion. |
| Launch / graduation / premium tooling fees | Explicit platform services | Yes | Premium SaaS-like services may be separately classified if transparently disclosed. |
Excluded from the Builder Share
- Bonded RWA principal and PLUS capital-raising proceeds
- USD++ issuance, burns, rebases, pool stabilization, and Inverse Reserve Bond principal
- RWA interest, dividends, and capital gains
- Treasury rebalancing and custody movements
- Internal fees paid by the protocol to liquidity it substantially owns
Why permanent fee burns strengthen the joint growth loop
At target capitalization C, a USD++ burn b can support later 1:1 paid issuance y while preserving the burn-funded PLUS equity gain:
At 150%, a $1 permanent burn can support $3 of later 1:1 paid USD++ issuance. If that demand arrives, $3 of new external assets enter while the original $1 equity improvement remains. If demand does not arrive, the protocol simply retains a larger safety buffer.
Builder alignment
The builders also receive a long-vested PLUS allocation, but founder PLUS has no preferential claim, enhanced dividend, or superior liquidation right. A baseline allocation is 15% of fully diluted supply with a one-year cliff and three-year linear vest. The team therefore benefits from both:
- cash flow proportional to genuine platform use; and
- long-term appreciation from preserving the protocol growth system.
Interactive: fee distribution and capital leverage
The top bar shows the settled 80/20 economic split. The curve below shows how much later 1:1 paid issuance a permanent USD++ burn can support at different C targets.
A USD++-native launchpad turns attention into monetary demand
The launchpad is not an unrelated product bolted onto the protocol. It is the consumer demand layer that gives USD++ immediate speculative, transactional, liquidity, and settlement utility.
Canonical lifecycle
Speculative demand
Users need USD++ to acquire newly launched tokens, even when the frontend begins from ETH, USDC, or another asset.
Liquidity demand
Every graduated token structurally commits USD++ to a canonical TOKEN/USD++ market.
Settlement demand
Default routing, charts, creator economics, and discovery keep USD++ at the center even if outside pools later exist.
Creator economics
Creators receive an initial token allocation and a disclosed share of external trading fees. They receive no PLUS rewards. This avoids paying creators to manufacture wash volume, fake TVL, or low-quality launches.
Technical detailLaunchpad fees and security defaultsProvisional rates, routing constraints, and non-ruggable launch requirements.
Provisional fee architecture
| Market stage | Baseline total fee | Illustrative allocation | Optimization objective |
|---|---|---|---|
| Bonding curve | 1.00% | 0.30% creator; 0.70% platform | Maximize net creator launches and user retention, not fee rate per trade |
| Graduated TOKEN/USD++ AMM | 0.50% | 0.30% LP; 0.10% creator; 0.10% platform | Balance durable liquidity, creator alignment, routing competitiveness, and burn revenue |
| One-click external routing | 0–10 bps incremental | Platform fee only | Use only if conversion loss is smaller than monetization gain |
These fee rates were not settled in prior design work and are explicitly provisional. They belong in conversion and wash-trading simulations before implementation.
Launchpad security defaults
- Use standardized, immutable token and curve templates where possible.
- Graduation liquidity must be permanently locked or controlled by a non-ruggable vault.
- Simulate buy and sell paths before listing; detect transfer restrictions, hidden taxes, owner drains, and honeypot behavior.
- Do not use raw volume, transaction count, or market cap as a PLUS reward input.
- Clearly separate platform discovery from an endorsement of any launched token.
- Rate-limit creation and malicious metadata without making the monetary protocol dependent on discretionary moderation.
Genesis: finite PLUS for permanent capital
Genesis is state-based rather than fixed to one month. Its purpose is to build the initial RWA treasury, distribute USD++ and PLUS, seed canonical markets, and launch the USD++ ecosystem. High emissions end when those jobs are complete.
Zero-capital protocol bootstrap
- Users bond approved RWA and choose USD++/vPLUS bond modes.
- The treasury receives real external assets and the first USD++ supply is created.
- A small liquid PLUS allocation is auctioned for existing USD++.
- The treasury uses acquired USD++ and reserved PLUS to seed USD++/PLUS POL.
- Bonded USDC is allocated between free reserves and treasury-managed USD++/USDC ranges.
- The launchpad opens and begins creating transactional USD++ demand.
Technical detailGenesis exit, allocation, and post-Genesis sustainabilityFinite emission budgets, hard sunsets, and the path to zero routine issuance.
Genesis exit conditions
- Risk-derived capitalization target reached with safety margin
- Free stable-reserve target reached
- USD++/USDC and USD++/PLUS markets meet explicit depth targets
- PLUS ownership distribution and vesting concentration pass thresholds
- USD++ peg remains within band for a sustained observation window
- RWA custody and oracle redundancy are operational
Genesis bond emissions stop when conditions are met or the Genesis budget is exhausted. Any temporary restriction on competing PLUS AMM pools ends at the earlier of Genesis completion or a hard sunset, provisionally 90 days. Genesis economic incentives may continue longer without transfer restrictions.
Provisional PLUS allocation
| Allocation | Baseline | Policy |
|---|---|---|
| Genesis bonding maximum | 35% | A budget ceiling, not a target to spend |
| Post-Genesis strategic bond reserve | 25% | Release only for accretive RWA, USD++ retirement, or strategic POL |
| Founding team | 15% | 1-year cliff + 3-year linear vest; no preferential rights |
| Future contributors / performance | 5% | Durable economic milestones, not price or washable volume |
| Initial market distribution | 5% | Liquid auction and initial price discovery |
| Long-term DAO reserve | 15% | Governance-controlled within constitutional issuance limits |
All committed supply is included in fully diluted PLUS accounting from inception. Unused Genesis allocations should remain reserved or be subject to a future burn decision rather than being emitted merely because they were budgeted.
Post-Genesis sustainability
The system must function with zero routine PLUS emissions. Sustainable sources are:
- RWA portfolio profit;
- launchpad and canonical-market fees;
- permanent USD++ burns;
- paid RWA-backed USD++ issuance;
- organic demand from the launchpad ecosystem; and
- opportunistic, strictly bounded PLUS issuance when the market offers an accretive trade.
Recovery: pool-first, bonds second, rebase last
A non-redeemable soft peg needs an explicit recovery constitution. The system transitions through progressively more expensive stages. No stage may assume that PLUS trades above NAV, and no emergency market action may be based on a single manipulable spot price.
Technical detailRecovery mathematics and trigger thresholdsDetailed stage economics, oracle confirmation, and final loss allocation.
Stage 2: pool-first contraction
If the protocol can purchase USD++ in the pool for less than the reserve value offered by an inverse bond, it should capture that discount itself. The controller buys to a maximum marginal price, burns output in the same transaction, and stops before becoming a predictable unlimited bid.
Stage 3: Inverse Reserve Bonds
For one USD++ burned in exchange for q dollars of external reserve assets:
The bond is accretive while giving arbitrageurs a spread over the secondary-market price. It is capacity-limited by free reserves, epoch outflow limits, and portfolio safety.
Stage 4: relative-value PLUS contraction
Define PLUS’s market-to-hard-NAV ratio:
There exists an accretive reward that a user will accept only when:
If USD++ is $0.80 and PLUS trades at 90% of NAV, the protocol can offer between $0.80 and $0.90 of PLUS market value per USD++ burned. The user profits, while the hard-NAV cost remains below the $1 claim eliminated.
Stage 6: emergency negative rebase
If conservative resolution assets are A_R and USD++ supply is S, the cleanest final haircut is:
This restores approximately 100% asset coverage without transferring value from USD++ holders to surviving PLUS holders. The higher normal capitalization target is rebuilt afterward through new PLUS capital, retained earnings, and fee burns.
Trigger design
| Signal | Baseline trigger | Confirmation | Purpose |
|---|---|---|---|
| Defensive Mode | USD++ TWAP < $0.985 | 4 hours + minimum liquidity | Stop expansion early |
| Pool buyback | USD++ TWAP < $0.975 | 8 hours; spot agrees | Capture discounted supply from market |
| Inverse bonds | Pool marginal price reaches quote or liquidity insufficient | 12 hours below band | Continue contraction without uncontrolled market impact |
| PLUS contraction | PUSD++ < dPLUS with safety margin | Dual oracle + auction bounds | Use relative valuation without Terra-like fixed conversion |
| PLUS recapitalization | Capitalization below floor or free reserve exhaustion | Governance + emergency council within bounded mandate | Add external assets |
| Negative rebase | Conservative external assets < USD++ supply after prior stages | Long oracle window, independent attestations, timelocked resolution unless immediate exploit | Restore honest coverage |
Trigger values are provisional. Simulations must optimize them against depeg duration, reserve exhaustion, false activation, and manipulation cost.
Interactive: play the recovery waterfall
Apply a treasury shock, then watch the protocol move through pool-first contraction and Inverse Reserve Bonds before determining whether PLUS action or resolution is required.
On-chain architecture and O(1) accounting
Core safety checks must be enforced on-chain from aggregate state. Expensive portfolio analytics and scenario design may be computed off-chain, but the signed inputs, bounds, and resulting state transitions must be verifiable and impossible to bypass.
Proposed contract map
Share-based ERC-20 facade, global index, optional non-rebasing account adapters, positive and emergency negative index updates.
Fixed-balance wrapper used by canonical v4 pools and external integrations. Routers wrap and unwrap automatically; its exchange rate can fall only during constitutional resolution.
Fixed maximum supply, vesting claims, governance delegation, reserved issuance accounting, and optional future burn.
Custodies on-chain RWA tokens and external reserve assets; exposes aggregate balances to risk and accounting modules.
Per-asset oracle, USD++ Factor, exposure caps, category, custodian, settlement state, and scenario retention vector.
Maintains aggregate NAV, category exposure, fixed-scenario stressed values, portfolio retention, C target, and issuance capacity.
Quotes three bond modes, applies peg-state rules, transfers RWA, mints USD++, and creates vPLUS vesting positions atomically.
Capital-flow-adjusted RWA P&L, loss carryforward, recognition policy, and signed/corroborated off-chain valuation inputs.
Tracks dividend credits, safe headroom, release velocity, index updates, and pause conditions.
Normalized wUSD++/USD++ oracle observations, time-weighted liquidity, fee classification, and bounded policy authorization. Swap accounting remains standard v4 fixed-balance accounting.
Deploys USDC to approved ranges, tracks free versus committed reserves, and rebalances protocol positions.
Atomic above-peg mint/sell, pool-first buy/burn, state transitions, cooldowns, budgets, and price limits.
Inverse Reserve Bonds, relative-value PLUS contraction, and emergency recapitalization auctions.
Classifies external revenue, sends 80% to USD++ burn and 20% to the Builder Treasury, excluding policy trades.
Deploys standardized tokens/curves, manages graduation, fee splits, locked liquidity, and canonical USD++ routes.
PLUS voting, parameter bounds, slow changes, emergency pause roles, and constitutional restrictions.
Read-only canonical calculations for UIs, keepers, analytics, and invariant monitoring.
One-way terminal state transition and negative rebase execution after objective insolvency conditions.
O(1) state strategy
| Requirement | State representation | Update complexity |
|---|---|---|
| Rebase all USD++ holders | Global index + per-account shares | O(1) |
| PLUS hard NAV | Aggregate external NAV, USD++ supply, external liabilities, FD PLUS | O(1) |
| Category and issuer caps | Aggregate value per fixed category / issuer key | O(1) per touched bucket |
| Portfolio stress | Fixed K-scenario stressed-value accumulators | O(K), treated as O(1) because K is constitutionally bounded |
| Profit recognition | NAV checkpoint, net flows, loss carryforward, dividend-credit accumulator | O(1) per epoch |
| Oracle history | Fixed-size circular observation buffer | O(1) per observation |
| Fee distribution | Cumulative counters + batch burn / builder transfer | O(1) |
| Recovery state | Single enum + timestamps + epoch budgets | O(1) |
| Launch graduation | Per-launch curve state and threshold | O(1) per launch action |
Technical detailState transitions and atomic enforcementBounded risk updates, bond settlement, expansion execution, and keeper limits.
Risk aggregation
Adjust external NAV and the affected category/issuer buckets only for the asset whose balance or oracle value changed.
Apply the asset’s fixed retention vector to a constitutionally bounded scenario set K. No transaction loops over all treasury assets.
Select the worst retained portfolio value, derive the risk target, and ratelimit only downward changes. Risk increases pause unsafe actions immediately.
Atomic bond transaction
- Pull and value the approved RWA. The asset enters TreasuryVault before any USD++ or vPLUS is issued.
- Preview the post-bond portfolio. RiskEngine derives the new C target, exposure state, and mode-specific USD++ ceiling from aggregate state.
- Quote one permitted bond mode. BondAuctioneer prices USD++ at the protected TWAP, computes vPLUS at the current market/NAV relationship, and enforces capacity.
- Enforce the post-state before settlement. All asset caps, issuance limits, reserve rules, and PLUS hard-accretion requirements must pass atomically.
- Settle once. Treasury retains the asset, USD++ is minted to the bonder, and a fixed vPLUS vesting claim is created in the same transaction.
Atomic above-peg expansion
- Authorize with the normalized oracle. Both the secured TWAP and spot price must remain above the upper band, with sufficient time-weighted liquidity.
- Compute a bounded mint. The amount is the minimum of paid-issuance capacity, active pool demand, the epoch cap, and the caller’s limit.
- Mint only for immediate execution. USD++ is wrapped into wUSD++ and sold into the canonical pool to a hard normalized price boundary; USDC proceeds transfer directly to TreasuryVault.
- Burn any unfilled amount. Any unfilled wUSD++ is unwrapped and the corresponding USD++ is burned before the transaction completes.
- Verify the final balance sheet. The transaction reverts unless post-trade capitalization, reserve accounting, and pool deltas satisfy every invariant.
Keeper incentives
Routine accounting, rebalancing, and policy calls may pay bounded keeper bounties from explicit operating budgets. Bounties must never be proportional to manipulable spot volume. Critical actions remain permissionless once objective conditions are met, but execute within epoch caps and price limits.
Core invariants and mathematical guarantees
These proofs establish the economic identities the contracts should enforce. They are not substitutes for machine-checked Solidity or theorem-prover proofs, but they define the statements those artifacts must prove.
Invariant A: bond issuance preserves the capitalization floor
AlgebraicIf pre-bond assets and supply are A and S, a bond adds external value V, and USD++ issuance x satisfies:
then post-bond capitalization is at least C_floor.
Proof
The contract must also enforce the asset USD++ Factor, exposure caps, and committed issuance. The minimum of all constraints preserves every individual invariant.
Invariant B: a Monetary Dividend cannot cross the target ratio
AlgebraicFor dividend issuance d:
Proof
The additional credit, peg, rate, and reserve limits can only reduce d, so they cannot violate this guarantee.
Invariant C: the corrected (3,3) bond preserves earlier headroom
IncrementalDefine pre-existing headroom under the post-bond target as:
and choose:
Proof
If A/C ≥ S, then H_pre = A/C − S, so x_3,3 = V/C. Post-bond headroom is:
If the system begins below target, H_pre = 0 and the bond first repairs the deficit. Thus the recommended point never appropriates positive capital created by previous participants.
Invariant D: risk-derived target survives the modeled stress
StressIf the portfolio retains fraction R under the binding scenario and:
Proof
Before stress, A/S = C_target. After stress, assets are R·A and supply is unchanged:
The guarantee is only as strong as the scenario matrix, valuation, custody assumptions, and correlation model.
Invariant E: profit split gives PLUS the target upside multiple
AllocationAt target capitalization, PLUS equity is (C−1)S. Allocate fraction k of profit Π to USD++ and 1−k to PLUS. Setting PLUS’s percentage return to m times USD++’s gives:
Proof
Set r_PLUS = m·r_x and solve:
Invariant F: an Inverse Reserve Bond below $1 is equity-accretive
RecoveryThe protocol gives external reserve value q and burns one USD++ internally valued as a $1 monetary claim.
Proof
Assets fall by q; liabilities fall by one. For q<1, residual equity rises. The user participates only if the market purchase price p<q, creating the feasible interval p<q<1.
Invariant G: relative-value PLUS contraction is feasible exactly when USD++ is cheaper
RecoveryLet hard PLUS NAV be N=E/Q_PLUS, market price P_PLUS, and reward market value r=qP_PLUS for burning one USD++. Per-PLUS NAV is non-decreasing when:
Proof
A user who purchases USD++ at P_x requires r>P_x. A reward satisfying both conditions exists iff:
This proves why the market-relative test is necessary and why the mechanism must remain bounded.
Invariant H: a permanent burn supports leveraged paid issuance
Growth systemStart at A=CS. Burn b USD++. Then accept y dollars of assets and issue y USD++ at 1:1. Returning exactly to C requires:
Proof
At 150%, one permanent burn supports three dollars of later paid issuance without erasing the burn-funded equity gain.
Invariant I: paid issuance and free dividends have different property effects
AccountingFree dividend d changes supply but not assets. Paid issuance y changes both by the external sale proceeds.
Proof
With a free dividend, (A,S)→(A,S+d), so PLUS equity falls by d. With 1:1 paid issuance, (A,S)→(A+y,S+y), so PLUS equity A−S is unchanged. The same capitalization ratio can therefore be reached through materially different property allocations.
Invariant J: resolution rebase does not recapitalize PLUS at USD++’s expense
ResolutionWhen conservative external assets are A_R<S, setting new USD++ supply to at most A_R restores coverage with residual PLUS equity no greater than zero.
Proof
Choosing S_new=A_R creates exactly 100% coverage and zero residual equity. Any higher post-resolution buffer should come from new PLUS capital, not a larger USD++ haircut.
Parameter registry and optimization framework
Defaults provide a coherent simulation baseline. They are not governance recommendations until adversarial simulations, market research, custody constraints, and audits justify them.
Core economic parameters
| Parameter | Symbol | Baseline | Suggested bounds | Optimization criterion |
|---|---|---|---|---|
| USD++ target price | P* | $1.00 | Fixed unit | Unit-of-account clarity |
| Upper / lower normal band | U, L | $1.005 / $0.995 | ±10–100 bps | Trade off intervention frequency against price stability |
| Post-stress capitalization objective | Cpost | 110% | 100–125% | Survive modeled stress with recovery cushion |
| Operating target capitalization | Ctarget | 150% | 125–200% | Derived from Cpost / worst stress retention |
| PLUS return multiple | m | 2.0× | 1.5–3.0× | Maximize joint capital inflow while compensating first-loss risk |
| Free stable reserve target | Rstable | 25% of USD++ | 15–40% | Meet contraction objective without forced growth-asset sales |
| Max modeled contraction | b | 20% of USD++ | 10–40% | Acceptable reserve exhaustion probability |
| Inverse-bond maximum quote | qmax | $0.95 | $0.85–$0.99 | Fast contraction while preserving equity |
| vPLUS vest | Tvest | 7 days | 5–14 days | Bond responsiveness versus immediate arbitrage/sell pressure |
| Genesis market restriction sunset | Tsunset | 90 days | 30–180 days | Concentrate launch liquidity without indefinite control |
| Platform / Builder split | φ | 80% / 20% | Protocol share 70–90% | Sustain builders while maximizing permanent capitalization |
| Unrealized profit recognition | ρ | 25% per 30 days | 0–100% with caps | Deliver differentiated yield without overdistributing transient gains |
| USD++ Factor weights | wσ / wliq / wfloat / wmcap / wops | 45% / 25% / 10% / 5% / 15% | Weights sum to 100% | Backtest loss coverage while preserving capital efficiency |
| USD++ Factor stress horizon | h | 30 days | 7–90 days | Reflect time required to rebalance or exit tokenized RWA |
| Float / market-cap saturation | F50 / M50 | $5b / $20b | Asset-class specific | Avoid treating scale as linearly beneficial after sufficient market depth |
Oracle and policy parameters
| Parameter | Baseline | Purpose |
|---|---|---|
| Routine normalized TWAP window | 30 minutes | Bond quotes and non-outflow policy |
| Defensive Mode confirmation | 4 hours below $0.985 | Stop expansion without overreacting to noise |
| Reserve-outflow confirmation | 8–12 hours + spot agreement | Protect free reserves from oracle manipulation |
| Paid expansion epoch cap | 1% of USD++ supply / 6 hours | Bound oracle and execution errors |
| Pool buyback epoch cap | 2% of USD++ supply / 6 hours | Bound treasury outflow and predictable bidding |
| Dividend release cap | 0.25% of supply / day | Prevent abrupt index and integration shocks |
| C target downward ratelimit | 1 percentage point / 7 days after 30-day persistence | Do not monetize temporary low risk |
| C target upward response | Immediate action pause; target updates at next secured oracle epoch | Prevent stale risk from authorizing issuance |
| Scenario count K | 8 | Keep risk updates bounded and auditable |
Technical detailGovernance classes and change authorityWhich settings are constitutional, risk-managed, or operational.
Parameter governance classes
Constitutional
Token claims, 80/20 framework, no hard redemption, recovery seniority, m bounds, negative-rebase ordering, and issuance invariants. Long timelock and supermajority.
Risk
Asset factors, caps, scenario vectors, reserve target, oracle thresholds, and epoch budgets. Bounded updates with independent review and shorter timelock.
Operational
Keeper addresses, range templates within bounds, routing adapters, launch metadata rules, and routine maintenance. Multisig or automated manager under strict limits.
Security considerations and required mitigations
The protocol combines RWA custody, elastic supply, governance, a custom v4 hook, endogenous equity, and a permissionless launchpad. Economic and integration failures are as important as ordinary Solidity exploits.
Threat modelFull failure-mode and mitigation matrixOracle, custody, hook, governance, integration, and launchpad risks.
| Threat | Failure mode | Required mitigation |
|---|---|---|
| Canonical-pool oracle manipulation | False expansion, reserve outflow, favorable bond quote, or recovery activation | Normalized TWAP, minimum time-weighted liquidity, spot confirmation, epoch caps, cooldowns, wide oracle-hardening liquidity, and multi-market median when available |
| RWA price/NAV oracle failure | Phantom treasury profit, unsafe issuance, or false insolvency | Issuer feed + independent market oracle where possible, staleness bounds, circuit breakers, confidence intervals, delayed profit recognition, and manual resolution path |
| Custodian / token issuer failure | Asset freeze, redemption halt, legal seizure, or loss | Issuer and custodian caps, diversified legal entities, proof/attestation requirements, scenario retention vectors, rapid asset disablement, and explicit impairment accounting |
| Rebase integration error | Lost LP yield, incorrect balance, donation/skim extraction, or broken lending position | Shares as USD++ source of truth, wUSD++ for every canonical v4 pool and unsupported integration, normalized-oracle tests, router invariants, and no assumption that the wrapper exchange rate can only rise |
| v4 custom-accounting bug | Delta mismatch, insolvency, fee theft, denial of service, or cross-pool contamination | Minimal hook permissions, fixed pool keys, formal delta conservation, separate accounting vault if necessary, multiple audits, invariant fuzzing, and staged value caps |
| Bond quote manipulation | Acquire excess vPLUS or USD++ at stale prices | TWAP inputs, quote expiry, slippage bounds, capacity decay, per-address and global epoch limits where useful, and atomic post-state checks |
| Wash trading | Artificial fees or volume become profitable due to rewards | No launchpad PLUS rewards, no rewards based on raw volume, classify self-trades, exclude protocol actions, and ensure any rebates remain below round-trip costs |
| Recovery front-running / sandwiching | Extract reserve value around predictable buybacks | Marginal price limits, private/orderflow-aware execution where appropriate, randomized bounded timing, batch auctions, and no automatic afterSwap treasury bid |
| Governance capture | Lower risk constraints, divert reserves, increase Builder Share, or prevent resolution | Constitutional bounds, long timelocks, emergency veto with sunset, delegated voting safeguards, quorum requirements, and immutable seniority rules where possible |
| PLUS death spiral | Falling PLUS blocks capital formation while USD++ depegs | No fixed USD++-to-PLUS redemption, reserve-first recovery, relative-value condition, finite PLUS auctions, recapitalization rights, and terminal negative rebase |
| Launch-token exploit / honeypot | User loss and platform reputational contagion | Standard templates, bytecode checks, sell simulation, ownership-risk labels, non-ruggable liquidity, metadata moderation, and isolation from treasury accounting |
| Upgrade or pause abuse | Backdoor changes, frozen user funds, or permanent emergency control | Immutable core where practical, module-specific upgradeability, timelocks, narrow pause scope, escape paths, and transparent role registry |
| Rounding / precision drift | Slow issuance leakage or share imbalance | High-precision fixed-point math, round issuance down, round liabilities up, bounded dust, and cumulative reconciliation tests |
| Cross-chain supply divergence | Rebase mismatch or unbacked bridged USD++ | Do not launch native cross-chain USD++ in V1; use canonical wrappers with explicit index sync and global supply accounting only after proof |
Role and upgrade model
- Governance: slow constitutional and treasury-policy changes.
- Risk council: bounded asset pauses, factor reductions, and cap reductions; cannot increase risk beyond timelocked limits.
- Emergency council: pause affected modules and accelerate defensive restrictions; cannot transfer treasury assets or trigger a negative rebase unilaterally.
- Keepers: permissionless or allowlisted executors with no discretion beyond contract-calculated amounts.
- Builder organization: recipient of the Builder Share, with no privileged monetary claim or unilateral control over treasury principal.
Mandatory monitoring
Balance sheet
External NAV, capitalization, stress retention, free reserves, committed issuance, dividend credits, loss carryforward, and PLUS hard NAV.
Markets
Normalized USD++ TWAP/spot, PLUS premium to NAV, active liquidity by range, external LP share, manipulation cost, and execution slippage.
Operations
Oracle staleness, custody attestations, bridge exposure, fee classification, keeper failures, recovery budgets, and governance queues.
Validation, optimization, and launch gates
The protocol has enough degrees of freedom that intuition alone cannot select the final target capitalization, reserve ratio, bond quote, or recovery thresholds. Simulations should optimize the joint USD++/PLUS ecosystem rather than either token in isolation.
Primary optimization objective
Subject to:
- maximum probability and severity of an emergency negative rebase;
- maximum expected USD++ depeg duration and volatility;
- maximum free-reserve exhaustion probability;
- bounded PLUS dilution and sustainable PLUS premium assumptions;
- minimum USD++ holder yield and launchpad liquidity;
- minimum post-stress capitalization and oracle manipulation cost.
Technical detailSimulation dimensions, agents, and adversarial scenariosThe complete parameter sweep and minimum scenario suite.
Parameter sweeps
| Dimension | Suggested sweep | Key outputs |
|---|---|---|
| Risk-derived C target | 125%, 140%, 150%, 160%, 175%, 200% | USD++ issuance, yield, emergency loss probability, PLUS return |
| PLUS return multiple m | 1.5×, 2×, 2.5×, 3× | USD++ demand elasticity, PLUS premium, RWA per PLUS issued |
| Free stable reserves | 15–40% of USD++ | Depeg duration, forced growth-asset sales, opportunity cost |
| Asset mix | Stable / gold / equity grids with correlation regimes | Stress retention, portfolio return, dividend stability |
| Bond modes | Fixed allocation vs 3 modes vs continuous slider | Total capital attracted, mode take-rate, PLUS sell pressure, USD++ scale |
| vPLUS vest | 5, 7, 10, 14 days | Bond fill, recursive farming, post-vest sell pressure |
| Fee rates | Launch curve 30–150 bps; graduated 10–100 bps | Conversion, volume, burns, builder revenue, wash economics |
| Recovery thresholds | Multiple TWAP windows, quotes, and epoch budgets | False activation, reserve value preserved, time to peg |
| Unrealized-profit recognition | 0–100% over 7–180 days | USD++ yield smoothness, loss carryforward, negative-rebase risk |
Agent model
- USD++ holders: demand depends on expected yield, peg history, liquidity, and launchpad utility.
- PLUS investors: price future fees, portfolio growth, dilution, first-loss risk, and recovery seniority.
- Bonders: choose modes based on immediate USD++ value, PLUS discount, vesting, volatility, and alternatives.
- Arbitrageurs: exploit above/below peg opportunities subject to fees, capacity, and latency.
- Launchpad users: react to token novelty, creator economics, routing friction, and fee levels.
- Attackers: manipulate oracles, wash trade, sandwich recovery, concentrate custody risk, and exploit stale parameters.
Minimum scenario suite
Growth shock
Equities −50%, gold −20%, stable reserves intact, launch volume collapses.
Correlated risk-off
Equities −40%, gold −25%, Treasury token liquidity impaired, PLUS below NAV.
Stable issuer event
Primary stable reserve loses 15–50%, freezes transfers, or becomes temporarily inaccessible.
Oracle attack
Canonical pool manipulated across one or more blocks while TWAP liquidity changes.
Viral expansion
Launchpad demand pushes USD++ above peg while PLUS trades at a high premium and bonds fill rapidly.
Slow death
USD++ at $0.90–$0.98 for months, PLUS near/below NAV, low fee revenue, modest portfolio yield.
Formal and software verification
- Foundry invariant tests for every algebraic invariant in this document
- Differential tests against a high-precision Python/Rust reference model
- Stateful fuzzing across bonds, rebases, fee burns, hook swaps, and recovery transitions
- Symbolic checks for integer overflow, rounding direction, and inaccessible recovery states
- Lean or another theorem prover for issuance, profit split, recovery accretion, and resolution seniority
- Economic Monte Carlo and adversarial agent-based simulation before choosing constants
- Fork tests against the selected Uniswap v4 deployment and RWA token implementations
Launch gates
- No unresolved critical or high audit findings.
- All core invariants hold under at least 10 million stateful fuzz sequences.
- Chosen parameter set meets defined stress and negative-rebase probability thresholds.
- RWA custody and oracle failure drills complete successfully.
- Canonical hook survives independent formal review and capped-value testnet/mainnet pilot.
- Recovery Stage 1–6 tabletop and fork simulations have deterministic outputs.
Open issues before implementation is complete
These are not minor polish items. Several determine whether the current design is technically or economically viable.
Specify the wUSD++ v4 oracle hook and router invariants
Prove normalized USD++ pricing across wrapper-rate changes, observation checkpoints, atomic wrap/swap/unwrap flows, pool-specific permissions, fee classification, and cross-pool isolation. Canonical v4 pools use wUSD++ rather than raw rebasing USD++.
Priority P0 · Protocol engineering + formal methodsCalibrate the USD++ Factor model
Validate the volatility horizon, gap penalty, liquidity/exit-size transform, free-float and market-cap saturation constants, operational score, class ceilings, and weights against historical and simulated losses.
Priority P1 · Risk research + simulationOptimize C target and scenario matrix
Select joint stress scenarios, retention factors, correlation assumptions, post-stress cushion, update cadence, and hard bounds. The 150% target is only a baseline.
Priority P0 · Risk research + simulationDefine RWA custody, eligibility, and transfer architecture
Resolve issuer access, KYC/whitelisting, custody, market hours, corporate actions, NAV reporting, sanctions/freeze risk, token transfer restrictions, and bankruptcy remoteness for each asset class.
Priority P0 · Legal, operations, integrationsChoose bond interface: three modes or continuous slider
The three-mode snapping slider is the current recommendation, but simulation must compare total capital attracted, user comprehension, mode gaming, and protocol steering versus a single protocol-selected allocation.
Priority P1 · Product + mechanism designSpecify vPLUS auction curve and reserve opportunity cost
Define total bond quote, capacity decay, price sources, minimum hard accretion, treatment of fully diluted reserved supply, vesting, and behavior when PLUS approaches NAV.
Priority P1 · Mechanism designSet unrealized-profit recognition
Determine the lag, fraction, loss carryforward, oracle confidence, and reversal policy for equity/gold gains. The current 25% per 30 days is a placeholder.
Priority P1 · Risk + accountingOptimize protocol-owned USD++/USDC range templates
Choose core, defensive, expansion, and oracle-hardening ranges; free-reserve priority; rebalance cadence; committed-issuance accounting; external LP incentives; and MEV-aware execution.
Priority P1 · AMM researchDefine exact launchpad curve and fee schedule
Choose curve shape, graduation threshold, creator allocation/vesting, creator fee, platform fee, LP fee, locked-liquidity implementation, anti-honeypot rules, and conversion-optimal routing.
Priority P1 · Launchpad simulation + productDefine oracle redundancy
Specify the normalized v4 oracle, observation buffer, time-weighted liquidity, independent stablecoin markets, PLUS price/NAV oracle, RWA feeds, failure hierarchy, and stale-data behavior.
Priority P1 · Oracle engineeringChoose recovery governance and automation boundaries
Decide which stages are fully automatic, which require an auction start, which require governance, and how to prevent both delayed action and malicious reserve release.
Priority P1 · Security + governanceCalibrate PLUS genesis and strategic allocations
Test whether 35% Genesis and 25% strategic reserve maximize durable assets per PLUS without excessive circulating supply, and define what happens to unused emissions.
Priority P1 · Token economicsRegulatory and tax architecture
Analyze stablecoin, securities, commodities, money transmission, investment-company/fund, launchpad, broker/dealer, RWA transfer, revenue-sharing, and rebasing tax treatment in target jurisdictions before finalizing permissions and claims.
Priority P0/P1 · Specialized counselProtocol and product naming
USD++ and PLUS are functional placeholders. Final names should communicate portfolio-backed compounding money, junior equity, and launchpad utility without implying sovereign or government ownership.
Priority P2 · BrandPrimary references and implementation precedents
The protocol is novel in combination, but several individual components have useful production or historical precedents. These sources inform the design; they do not validate this protocol as a whole.
| Area | Reference | Relevant lesson |
|---|---|---|
| Reserve, liquidity, and inverse bonds | Olympus Bonds documentation | Issue endogenous equity to acquire reserves or POL; use inverse bonds to sell reserves for the protocol token during contraction. |
| Rebasing shares | Lido share accounting | Store fixed shares and derive visible balances from a global pooled-value/index relationship. |
| Wrapper compatibility | wstETH documentation | Expose a non-rebasing adapter for integrations that assume balances change only through transfers. |
| Uniswap v4 hooks | Uniswap v4 hook concepts | A pool can invoke fixed hook callbacks whose permissions are encoded in the hook address. |
| Custom accounting | Uniswap v4 custom accounting | Flash accounting and hook-returned deltas can support custom fees and curves, including specialized treatment for rebasing or RWA-like assets. |
| Oracle gap in v4 | Uniswap price-oracle documentation | v3 pools include historical oracle observations; v4 requires oracle functionality to be supplied separately, such as through a hook. |
| Rebasing LP caveat | Uniswap rebasing-token support note | Native v3/v4 positions do not automatically handle positive-rebase LP yield, motivating wUSD++ as the canonical fixed-balance settlement asset. |
| Risk factors and caps | Aave risk documentation | Per-asset factors, limits, monitoring, and governance are standard tools for bounding collateral risk. |
| Risk-factor calibration | Aave / RiskDAO LTV methodology | Volatility and available liquidity can be combined into an explicit confidence-based risk ceiling rather than chosen qualitatively. |
| Float, liquidity, and exposure caps | Gauntlet supply-cap methodology | Circulating supply, market depth, and trading volume provide quantitative bounds on safe protocol exposure. |
| Tail-risk framework | Basel market-risk framework | Tail loss models should be supplemented by scenario and non-modelable-risk treatment rather than trusted alone. |