Surplus Overview
Protocol design specification · v0.5.1 · 31 August 2026

A dollar that compounds with a real-asset portfolio, with equity beneath it and a launchpad above it.

USD++ is soft-pegged, positively rebasing money backed by a diversified treasury of stable reserves, gold, equities, and other approved real-world assets. PLUS is the junior equity layer that governs the treasury, absorbs first loss, and lets the protocol convert speculative demand into additional assets. A USD++-native token launchpad creates the utility and attention required to bootstrap both.

USDC is a dollar backed by cash. USD++ is a dollar backed by a growing portfolio. Holders keep a roughly one-dollar unit of account while receiving more units when eligible portfolio profits are distributed. PLUS is the shock absorber and ownership layer underneath that promise.
No hard redemption Positive rebase + wUSD++ markets No ESD-like Coupons 150% capitalization baseline m = 2 profit-sharing baseline
~$1
USD++ soft price target
Target PLUS upside vs USD++
5–7d
Genesis vPLUS vesting baseline
O(1)
Core ledger updates

What the protocol is trying to accomplish

Build productive money

USD++ should be more compelling to hold than a conventional reserve stablecoin because eligible treasury profits become Monetary Dividends that increase holder balances while the unit remains targeted near one dollar.

Turn speculation into capital

PLUS can float above hard NAV. When it does, finite PLUS issuance can buy RWA, retire USD++, or acquire strategic liquidity at a hard economic cost below the market value paid to bonders.

Create native demand

Every launchpad token is quoted against USD++. Token creation, speculation, liquidity, routing, and fees therefore increase USD++ demand instead of treating the stable asset as an isolated financial product.

Central design principle: use endogenous speculation and platform activity to accumulate exogenous value, then share portfolio performance between USD++ and PLUS without counting the same dollar twice.

The three economic claims

Launchpad demandUsers acquire and route through USD++.
Paid issuanceNew USD++ is sold only when new RWA enters.
Treasury growthStable and growth assets produce income and appreciation.
Value sharingEligible profit funds USD++ dividends and PLUS capital.
Stronger networkFees burn USD++, PLUS capital grows, and demand compounds.
02 · Design record

Decisions, rationale, and explicit non-goals

The protocol is easiest to reason about when settled choices are separated from optimization questions. The following decisions are the current canonical direction.

No hard redemptionPreserves the growth-asset thesis; recovery is explicit
Positive rebasing USD++Portfolio gains arrive as more roughly $1 units
Keep PLUS separateFirst-loss capital, governance, and seigniorage
No ESD-like CouponsAdds future liabilities without adding recovery capital
No routine negative rebasePLUS and reserves absorb losses before final resolution
No creator PLUS rewardsCreators earn token supply and recurring trading fees
Decision registerFull rationale and status for each settled directionOpen for the complete design record.
DecisionCurrent directionWhyStatus
USD++ redemptionNo contractual $1 redemptionHard redemption would force the treasury toward cash-like assets and weaken the differentiated gold/equity thesis. Peg support is policy-driven, with an explicit loss waterfall.Settled for V1
Holder yieldPositive share/index rebases; wUSD++ for v4 markets and fixed-balance integrationsUsers hold one roughly $1 token whose balance compounds. Canonical AMMs use wUSD++ internally to avoid rebasing-balance risk while routers present ordinary USD++ pairs.Settled
Negative rebasesNever routine; available only as final resolutionPLUS and treasury reserves must absorb loss first. A negative rebase is the honest final tool if the system is actually insolvent.Settled
ESD-like CouponsNot includedCoupons exchange liquid USD++ for an interest-bearing future liability rather than adding capital, while complicating creditor priority and recovery.Not included
Two-token modelKeep USD++ and PLUS separateUSD++ needs a price anchor; PLUS needs the freedom to carry speculative premium, absorb first loss, and act as a capital-raising asset.Settled
Bond payoutsUser chooses among protocol-priced USD++/vPLUS modesDifferent bonders want liquidity, balanced exposure, or maximum PLUS. The protocol controls reward and capacity rather than forcing a single demand profile.Three-mode baseline
Launchpad rewardsNo PLUS subsidies to creatorsCreator token allocation and fee share are sufficient. PLUS incentives would create wash-trading and low-quality launch pressure.Settled
Platform fee useProtocol capitalization + sustainable builder fundingExternal usage revenue strengthens the monetary system while funding continued development. The exact allocation is specified later under Fees & monetization.Settled
RWA profit useSplit between USD++ dividends and protected PLUS capitalUSD++ needs differentiated portfolio yield; PLUS needs superior percentage upside for first-loss risk.m = 2 baseline
USDC/USD++ liquidityTreasury-managed predetermined rangesThe protocol should allocate bonded USDC directly, rather than acquire arbitrary user LP positions or subsidize ranges it does not control.Settled direction
Canonical AMMUniswap v4 USDC/wUSD++ pool with a normalized oracle and policy hookFixed-balance wUSD++ limits initial AMM risk. Routers wrap and unwrap automatically, and the UI reports the normalized USD++/USDC price.Settled direction; hook proof required
CapitalizationRisk-responsive target derived from portfolio stress retentionA fixed ratio ignores portfolio composition. Safer diversification should support more USD++; concentrated or risky assets should require more junior capital.150% baseline
Technical detailNon-goals and failure boundariesWhat the protocol deliberately refuses to promise or optimize for.

Non-goals

Not a conventional reserve stablecoin

USD++ is not intended to be a fully redeemable wrapper around USDC or Treasury bills. Stable reserves are defensive liquidity, not the full product thesis.

Not an unbacked algorithmic peg

Supply expansion is bounded by external treasury value. Recovery cannot rely on an unlimited fixed-price USD++-to-PLUS conversion.

Not perpetual liquidity mining

Genesis PLUS emissions acquire treasury assets and strategic liquidity. Post-Genesis operation must be sustainable without permanent reward emissions.

Not a promise of lossless dollars

PLUS takes first loss, but severe insolvency can ultimately reach USD++ through an emergency negative rebase. The design specifies that outcome rather than hiding it.

03 · Architecture

System architecture and balance-sheet model

The protocol is a monetary balance sheet, a floating equity layer, a treasury manager, a canonical market maker, and a consumer launchpad. Each component has a distinct claim and must be accounted for separately.

USD++

Senior soft-pegged monetary claim. It targets ~$1, receives explicitly allocated portfolio profit through positive rebases, and has no hard redemption right.

PLUS

Junior residual equity. It governs risk, absorbs treasury losses first, owns protected capital and platform economics, and can be issued to acquire assets when accretive.

Launchpad

Demand and distribution layer. Every canonical launch market quotes against USD++, turning speculative activity into stable-asset demand, fee burns, and treasury expansion.

Consolidated accounting

Eq. 1PLUS hard equity, E = External Treasury NAV − USD++ notional supply − other external liabilities
Eq. 2PLUS hard NAV, NPLUS = E / fully diluted PLUS supply
Eq. 3Capitalization ratio, C = External Treasury NAV / USD++ notional supply
ItemExternal treasury NAV?Free peg reserve?USD++ backing / capitalization?PLUS hard NAV?
USDC held freelyYesYesYesYes, net of USD++
Tokenized TreasuriesYesOnly if operationally liquidYesYes, net of USD++
Gold / equitiesYesNoYes at MTM for capitalization; constrained by risk rulesYes
USDC inside protocol-owned POLYesNo, while committedYesYes
Protocol-owned USD++No external assetNoExclude if treasury stock; reserve capacity if committed for saleNo
Treasury-owned PLUSNoNoNoNo; it is treasury stock
USD++/PLUS LPExternal assets only; not endogenous token face valueNoStrategic, not free reserveExternal component + realized external fees only
Launch-token LPNot core RWA backingNoNoOnly explicit protocol fee rights, conservatively
Accounting discipline: gross TVL is not equity. Minting a token to the treasury does not create an external asset. An internal token becomes economic value only when exchanged for external assets, used to retire external claims, or attached to a defensible external cash flow.

Economic ownership compact

USD++ holders receive

  • Explicit share of eligible RWA portfolio profit
  • Positive Monetary Dividends when release conditions permit
  • Stronger protection from permanent fee burns and PLUS capital
  • Native launchpad utility and settlement demand

PLUS holders receive

  • Protected bond capital
  • Permanent protocol share of platform-fee economics
  • Residual portfolio-profit share: eligible RWA profit not credited to USD++, retained as protected junior equity (50% at the 150% / m = 2 baseline)
  • First-loss risk and leveraged hard-NAV exposure
  • Governance and accretive issuance optionality

Builders receive

  • A defined minority share of genuine external platform and trading fee revenue
  • Long-vested PLUS allocation
  • No skim from RWA principal, monetary operations, or treasury returns
04 · Coordination and distribution

(3,3) is the protocol-wide coordination strategy, not merely a bond setting

Olympus used “(3,3)” to communicate that participants created more collective value by staking, bonding, and avoiding reflexive selling. This protocol expands that idea into a complete user playbook: capitalize the treasury, preserve PLUS’s financing power, grow USD++ usage, and recycle value through the system.

Memetic ruleBond external value. Hold and govern PLUS. Use and recycle USD++.
Measurable objectiveGrow external assets, USD++ utility, and PLUS hard value faster than dilution and recovery costs
Bond midpointThe (3,3) bond is one leg: it grows assets and USD++ without consuming earlier capital
(3,3)
Bondexternal assets
×
Holdand govern PLUS
×
UseUSD++ across the platform
×
Recycledividends and ecosystem value

The multiplication is intentional: treasury capitalization, low reflexive sell pressure, monetary usage, and reinvestment reinforce one another. Weakness in any leg limits the value created by the others.

What the original meme captured

“(3,3)” was not a solvency guarantee. It was a coordination shorthand: bonding gave the treasury assets, staking or holding reduced liquid sell pressure, and a durable OHM premium let the protocol acquire more assets with less dilution.

Other supports
Other exits
You support
(3,3)Value reinforces value
MixedOne side extracts
You exit
MixedOne side extracts
(−3,−3)Reflexive unwind

The Surplus (3,3) doctrine

01 · BondContribute approved external assets

Default to the capital-balanced bond when it fits. This expands the treasury and the USD++ economy together.

02 · HoldHold or delegate PLUS instead of reflexively selling

Lower liquid sell pressure helps preserve the premium the protocol can exchange for more RWA and strategic liquidity.

03 · UseHold, trade, route, and launch through USD++

USD++ usage creates demand, external fees, paid issuance, and deeper canonical markets.

04 · RecycleKeep monetary dividends and ecosystem income productive

Reuse USD++, rebond external assets, or maintain long-term PLUS exposure instead of immediately extracting all value.

Coordination testΔVaccrued = Δ external NAV + permanent USD++ burns + paid-issuance premium + PV(net new platform fees) − hard-NAV cost of PLUS issued − recovery outflows

An action is protocol-positive only when it raises net accrued value, respects the capitalization floor, and reflects outside demand rather than self-trading. “Hold” is coordination guidance, not a promise of price appreciation or a restriction on exit.

The complete compounding system

Attention and use
Creators and communities
Launches quoted in USD++
Users acquire and use USD++
External volume and fees
The protocol share of external fees permanently burns USD++scarcity, PLUS equity, and paid-issuance headroom increase
Capital formation
Above-peg paid issuance
New USDC and RWA
Larger treasury and deeper markets
Greater portfolio earning power
Eligible RWA profit splits between Monetary Dividends and protected PLUS capitalUSD++ becomes more attractive while PLUS hard NAV and financing capacity rise
Coordination and recapitalization
PLUS holders coordinate
PLUS premium can persist
Accretive PLUS bonds acquire RWA / POL
More value returns to both loops
↑ Better monetary yield, deeper liquidity, and stronger token economics attract the next creators, users, and bonders ↑

How the platform generates and capitalizes on virality

Creators own meaningful upside

Initial token allocation and recurring creator fees motivate builders to recruit communities and sustain activity.

USD++ is the common quote asset

Every canonical launch, route, and graduated market turns attention into demand for the protocol’s monetary asset.

Routing removes acquisition friction

Users can enter with USDC, ETH, or another asset while the router acquires USD++ and settles through it automatically.

Usage becomes hard economic value

External fees burn USD++, paid issuance imports RWA, and portfolio returns strengthen both Monetary Dividends and PLUS.

Virality must import outside demand. Protocol policy trades and self-trading are excluded from organic adoption metrics and eligible platform revenue.

Interactive: attention compounds into protocol value

A stylized 24-month model showing treasury NAV, USD++ supply, and PLUS hard equity in separate synchronized lanes so one fast-growing series cannot hide the others.

Illustrative only. Baseline assumes a 30 bps eligible platform fee, the settled protocol-fee allocation, m = 2, and release of earned dividend credits when permitted.

Treasury NAV
USD++ supply
PLUS hard equity
Cumulative USD++ burned
05 · Treasury and risk

Treasury composition, asset factors, and the risk-responsive capital target

Stable reserves provide intervention capacity; growth assets provide the differentiated return. Asset-level USD++ Factors limit issuance against each RWA, while portfolio-wide stress determines how much junior capital the whole treasury must maintain.

PortfolioGrowth assets plus a separately tracked free stable-reserve floor
Asset riskUSD++ Factor combines stress retention, liquidity, float, scale, and operational quality
System riskC target is derived from the current portfolio’s joint stress retention

Defensive assets

USDC, short-duration tokenized Treasuries, and other liquid dollar-like assets fund buybacks and operations. They are defensive ammunition, not the core debasement-protection thesis.

  • Free reserve baseline: 25% of USD++ supply
  • Used first in pool buybacks and Inverse Reserve Bonds
  • Separated from USDC committed to AMM liquidity

Growth and debasement-sensitive assets

Gold, diversified equities, selected individual equities, and approved productive RWA drive long-term appreciation, Monetary Dividends, and PLUS residual value.

  • Bounded by issuer, custodian, category, and single-name caps
  • New bond terms steer allocation before treasury trades
  • Never assumed instantly liquid during stress

A provisional USD++ Factor model

The USD++ Factor is the maximum USD++ a bond may create per dollar of an asset. It should be reproducible from observable risk inputs, then capped by governance and stress testing rather than selected as a narrative percentage.

Eq. 4Fi = min(Fclass, Rσ, Rσ0.45 · Rliq0.25 · Rfloat0.10 · Rmcap0.05 · Rops0.15)

Price-risk retention

Rσ = exp(−z·σ·√(h/365) − g), using annualized volatility, a stress horizon, confidence level, and explicit gap penalty.

Market capacity

Rliq compares 2% depth and trading capacity with the intended exposure; Rfloat and Rmcap are saturating free-float and market-cap scores.

Non-market risk

Rops scores oracle, custody, transfer, settlement, issuer, and legal enforceability. A class ceiling prevents superficially liquid assets from exceeding policy limits.

Default weights are a calibration prior, not a final risk model. Scenario simulation, issuer/custodian limits, and exposure caps may only reduce the resulting factor.

Technical detailFactor normalization, portfolio stress, reserve sizing, and rebalancingThe equations and safeguards behind the risk controls.

Normalized factor inputs

Eq. 4aRliq = min(1, √(D2% / Qexit))
Eq. 4bRfloat = FFMC / (FFMC + F50),   Rmcap = MC / (MC + M50)

D2% is aggregate depth available before a 2% move, Qexit is the modeled emergency-sale amount, and F50/M50 are governance-set saturation constants. Final calibration should use log-scaled or empirical transforms if simulations show these simple curves misprice large assets.

Illustrative asset classes

Asset classIllustrative class ceilingIllustrative exposure capPrimary risk rationale
USDC / approved reserve stablecoin100%30% per issuer; 50% stable categoryIssuer, blacklist, custody, and depeg risk
Short-duration tokenized Treasuries98%50% category; 25% per issuer/custodianSettlement delay, custody, duration, and NAV reporting
Tokenized gold90%30%Drawdown, custody, redemption logistics, oracle, and issuer risk
Diversified equity index80%50% equities total; 30% per indexTail drawdown, market closure, gap risk, and correlation
Individual equity65%5% per nameConcentration, idiosyncratic gaps, tokenization, and market-hours mismatch

Portfolio-level stress target

For scenario s, let r_i,s be the fraction of asset i retained after stress and w_i its current portfolio weight.

Eq. 5Rs = Σ wi · ri,s
Eq. 6Rportfolio = mins(Rs)
Eq. 7Ctarget = Cpost-stress / Rportfolio

If a gold-only portfolio is modeled to retain 80% of value, 120% starting capitalization leaves only 96% after the shock. Exact 100% coverage requires 125%; preserving 110% coverage requires 137.5%.

Stable-reserve target

Eq. 8Free Stable Reserve ≥ q · b · USD++ supply

At a 20% contraction objective and a $0.95 maximum average purchase price, the mechanical requirement is 19% of supply. The 25% baseline adds operational and market-making separation.

Rebalancing policy

  1. Change bond capacity and reward: underweight assets receive better vPLUS terms; assets at cap stop accepting bonds.
  2. Redirect cash flows: income, maturities, and new stable reserves refill deficient buckets.
  3. Direct treasury trade: execute only outside permitted bands or when a risk event requires immediate action.
  4. Recovery liquidation: sell growth assets only after less destructive tools are inadequate.

Interactive: build an asset USD++ Factor

The waterfall shows how market and operational risk reduce the class ceiling. Presets are illustrative starting profiles, not assessments of any specific tokenized asset.

Stress retention Rσ
Composite score
Provisional USD++ Factor

Interactive: portfolio risk frontier

The lines show the capitalization required by each joint stress scenario as the stable-reserve weight changes. The marker is the current portfolio.

Illustrative scenario retention values must be replaced by formal risk research and tokenization-specific operational stresses.

Worst retention
Required C target
Binding scenario
06 · Treasury acquisition

Bonding: Build the Treasury, (3,3), or Max USD++

A bonder transfers an approved RWA to the treasury and receives a protocol-priced combination of USD++ and vested PLUS. The protocol controls eligibility, maximum issuance, total quote, capacity, and reward curve. Users choose only among economically acceptable modes.

Default(3,3) grows USD++ and assets without spending prior headroom
User choiceThree protocol-priced modes, not arbitrary payout terms
SafetyAsset factor, system capital, peg state, and capacity all bind
Why deviate from pure Olympus: original reserve bonding paid only the protocol token. That maximizes unencumbered capital, but this system also needs an organic way to issue USD++. The mixed bond makes treasury acquisition and monetary distribution one transaction, while retaining a pure-PLUS endpoint.

Recommended V1 interface: a three-point snapping slider

Build the Treasury

Low or zero USD++, maximum vPLUS. Best when PLUS trades at a strong premium, capitalization is weak, or USD++ is below peg.

Balance-sheet effect: maximum protected external capital, maximum PLUS reserve consumption, no immediate USD++ scale.

(3,3) Grow Together

Incrementally capital-balanced. The bond grows treasury assets and USD++ in the target ratio without consuming pre-existing capital headroom.

This is the default and recommended coordination point.

Max USD++

USD++ up to the asset factor, minimum vPLUS. Best when USD++ demand is strong and the system has sufficient capital headroom.

Balance-sheet effect: fastest monetary expansion, least protected capital per deposited dollar.

Technical detailBond constraints, (3,3) math, and reward pricingThe formulas and peg-state rules behind the three bond modes.

System constraints

For new asset value V, selected USD++ x, current assets A, supply S, and post-bond target C_after:

Eq. 9x ≤ min(V · Fi, (A + V) / Cafter − S − committed issuance, policy cap)

The post-bond target is recalculated from the resulting portfolio. A diversifying asset may lower aggregate risk; a concentration-increasing asset may raise it.

Corrected (3,3) point

The recommendation must not spend headroom created by earlier fee burns, retained profit, or capital-heavy bonds. Evaluate the pre-bond headroom under the post-bond target:

Eq. 10Hpre,after = max(0, A / Cafter − S)
Eq. 11x3,3 = min(V · Fi, max(0, (A + V) / Cafter − S − Hpre,after))

When the system is already at or above a fixed target, this simplifies to x_3,3 = min(V·F_i, V/C). At 150%, a $100 bond independently supports about 66.67 USD++ while preserving prior headroom.

vPLUS quote and accretion

Let B be the bond’s target market-value compensation, P_x the USD++ TWAP, P_PLUS the PLUS market price, and N_PLUS PLUS hard NAV. Above peg, issued USD++ is valued at its market price; below peg, the quote does not compensate the bonder for the depeg.

Eq. 12Pquote = max(1, Px)
Eq. 13vPLUS market value = max(0, B − x · Pquote)
Eq. 14Conservative protected capital ≈ V − x − vPLUS units · NPLUS

When PLUS trades materially above hard NAV, paying market-value compensation in vPLUS is cheaper in hard economic terms than issuing equal market value in USD++. The protocol must still account for circulating supply, future sell pressure, finite reserve consumption, and lower demand for all-PLUS bonds.

Peg-state behavior

USD++ stateMaximum USD++vPLUS quotePreferred capacity
Above pegUp to normal asset factor and system limitFalls dollar-for-dollar as USD++ market value risesMax USD++ and paid issuance expand
Near pegNormal asset factor and system limitNormal auction quote(3,3) default
Below pegPolicy cap contracts, potentially to zeroNo extra reward for USD++ price below $1Capital-heavy stable-asset bonds favored
PLUS near/below NAVUnchanged by itselfvPLUS discounts compress or closePaid USD++ issuance and non-dilutive recovery favored

Vesting and supply discipline

Bond rewards are paid as vPLUS with a provisional 7-day linear vest, configurable within a 5–14 day constitutional range. The purpose is to prevent instant bond arbitrage without missing fast DeFi attention cycles. Recursion is controlled by finite capacity and dynamic pricing, not indefinite lockups.

PLUS premium is optional fuel: if PLUS trades near or below hard NAV, vPLUS-heavy markets should contract or close. USD++ solvency and recovery must not assume a permanent premium.

Interactive: bond allocation frontier

Move across the full USD++ payout range. The chart shows what becomes a USD++ claim, what vPLUS costs at hard NAV, and what remains as protected PLUS capital.

(3,3) USD++
Max-vPLUS protected capital
Cheapest payout asset
07 · Core monetary innovation

Monetary Dividends turn portfolio performance into more roughly $1 USD++

USD++ does not need to appreciate like an investment share. Eligible RWA profit is assigned between USD++ and PLUS, accumulated as credits, and released through positive index updates when the peg and capital position can absorb additional supply.

Hold 1,000 USD+++Treasury earns eligible profitBalance grows above 1,000 USD++ while each unit remains targeted near $1
Where yield comes fromInterest, dividends, realized gains, and gradually recognized RWA appreciation
What it is notNot bond principal, not platform-fee burns, and not unbacked token emissions
Why it mattersUSD++ holders receive portfolio upside without turning the unit into a floating fund share

From treasury profit to holder balance

01Portfolio earns

External RWA produce net interest, dividends, realized gains, or recognized appreciation.

02Losses are repaired first

Costs and loss carryforward are deducted before any new profit is allocated.

03Profit is split

The m-based rule credits USD++ and retains a larger percentage return for first-loss PLUS.

04Credits wait for demand

USD++ credits accumulate until headroom, peg state, reserve health, and rate limits allow release.

05The index rises O(1)

Every holder receives more USD++ proportionally without iterating over accounts.

Illustrative 150% / m = 2 example

A 10% return on a $150 treasury creates $15 of eligible profit. The baseline assigns $7.50 to USD++ and $7.50 to PLUS.

USD++ holder1,000 → 1,075 USD++7.5% Monetary Dividend
PLUS hard equity$50 → $57.5015% hard-NAV increase

Benefits to the joint system

  • USD++: a differentiated, portfolio-backed holding return
  • PLUS: twice the percentage portfolio upside at the baseline, plus platform economics
  • Peg: credits are stored expansion capacity that can be released when demand pushes USD++ upward
  • Treasury: profit is never distributed unless post-rebase capitalization and reserve rules still pass

Recognized quickly

Net cash interest, cash dividends, and realized gains after direct costs.

Recognized gradually

Unrealized gold/equity appreciation, subject to oracle confidence, loss carryforward, and a release schedule.

Protected from dividends

New bond principal, PLUS-raised capital, paid-issuance premiums, and permanent platform-fee burns.

Technical detailCapacity, economic ownership, profit recognition, and release rulesWhy safe issuance and dividend entitlement remain separate.

Two values, two purposes

Safe issuance headroom

H = max(0, A / Ctarget − S − committed issuance)

The most USD++ the current balance sheet can safely support. It is permission to issue, not an ownership claim.

Monetary Dividend credits

D = eligible profit explicitly allocated to USD++ but not yet issued

Credits belong economically to USD++ holders, but can be reduced by losses before release.

Eq. 15Allowed rebase ≤ min(H, D, peg-release limit, epoch-rate limit, reserve constraint)

Source ownership

SourceCreates headroom?Creates dividend credits?Owner before later returns
New RWA bond principalUsuallyNoProtected PLUS capital after USD++ paid to bonder
PLUS-only / capital-heavy bondYesNoProtected PLUS capital
Protocol-share platform-fee USD++ burnYesNoPermanent PLUS capitalization and safety
Above-peg paid-issuance premiumYesNoPLUS capital
Net eligible RWA portfolio profitYesYes, by the m-based splitShared between USD++ and PLUS

Profit recognition ledger

Eq. 16Πepoch = NAVend − NAVstart − external capital inflows + external capital outflows

Negative P&L reduces unissued credits first, then becomes loss carryforward. Later gains repair that carryforward before creating new credits. Deposits therefore cannot masquerade as yield, and a fall-and-recovery cycle cannot be paid twice.

First-loss compensation rule

Eq. 17kUSD++ = 1 / (1 + m · (Ctarget − 1))

At m = 2 and C target = 150%, USD++ and PLUS each receive 50% of eligible profit. Because PLUS equity is smaller than USD++ supply, PLUS earns twice USD++’s percentage return.

Release policy

  • Below peg: release zero credits.
  • Near peg: release slowly under the epoch cap.
  • Above peg: accelerate release before paid issuance, because the value is already allocated to existing holders.
  • Recovery Mode: stop all releases.

Rebase mechanics

Eq. 18balanceOf(account) = shares(account) · USD++Index

The global index update is O(1). wUSD++ provides a fixed-balance claim whose exchange rate tracks the index and is the settlement asset used by canonical v4 pools.

Interactive: watch Monetary Dividends accrue, pause, and release

The allocation bar shows who receives each $100 of eligible profit. The synchronized lanes show holder balance, PLUS hard NAV, and pending USD++ credits through different market paths.

USD++ profit share
Holder balance
PLUS hard-NAV index
Pending credits
08 · Peg control and canonical market

How USD++ stays near $1

The peg is maintained by an ordered supply-control system. Above peg, the protocol releases earned dividends and sells newly issued USD++ only for new assets. Below peg, it stops expansion, buys and burns discounted USD++, and escalates through the recovery waterfall only when ordinary market operations are insufficient.

Above pegRelease earned credits, then mint and sell USD++ for external USDC
Near pegGradual dividends, normal bonding, and no discretionary price defense
Below pegPause expansion, buy and burn from the pool, then open inverse bonds
USD++ below bandContract supply
  1. Pause dividends and paid expansion
  2. Pool-first USDC buy-and-burn
  3. Inverse Reserve Bonds
  4. PLUS contraction / recapitalization
  5. Emergency negative rebase last
USD++ near $1Operate normally
  1. Release credits gradually
  2. Accept normal RWA bonds
  3. Maintain free stable reserves
  4. Rebalance treasury through new flows
USD++ above bandExpand against demand
  1. Accelerate earned dividends
  2. Mint → wrap → sell into USDC/wUSD++
  3. Continue RWA bonds up to asset factors
  4. Reduce vPLUS as USD++ market value rises
1Observe

Normalized TWAP plus spot and liquidity

2Select state

Above, target, defensive, or recovery

3Check capacity

Capital, credits, reserves, and epoch limits

4Execute atomically

Mint/sell or buy/burn to a hard price boundary

Interactive: policy response across the peg

Play a demand or stress path. The response curves show which tools become stronger as the normalized USD++ price moves away from $1.

Current regime
Primary action
Supply direction

Canonical market: USD++ UX, wUSD++ settlement

The user-facing route is shown as USD++/USDC. The actual Uniswap v4 pool uses wUSD++/USDC so token balances remain fixed and Monetary Dividends accrue through the wrapper exchange rate. The router wraps or unwraps automatically.

Price discovery

External trades establish wUSD++/USDC spot and time-weighted prices; the hook normalizes them to USD++.

Above-peg expansion

The controller mints USD++, wraps it, and sells wUSD++ atomically for external USDC to a price limit.

Below-peg contraction

The controller spends free USDC, buys wUSD++, unwraps it, and burns the acquired USD++.

LP dividend ownership

wUSD++’s exchange rate rises with Monetary Dividends, so the benefit belongs automatically to the LP position owner.

Technical detailNormalized v4 oracle, liquidity ranges, and intervention safeguardsHow the fixed-balance pool supports policy without share-aware swap accounting.

v4 oracle and policy hook

Uniswap v4 requires custom historical oracle functionality. Because the pool uses fixed-balance wUSD++, the hook does not need to rewrite concentrated-liquidity accounting for rebases. It must:

  • Normalize price: if one wUSD++ represents index I USD++ and the pool price is P_w USDC/wUSD++, then P_USD++ = P_w / I.
  • Checkpoint index changes: store normalized observations so a new wrapper rate is never applied retroactively to old prices.
  • Authorize bounded policy calls: expose TWAP, time-weighted liquidity, cooldown, and price-limit checks to the PegController.
  • Classify fees: exclude protocol stabilization trades from external platform revenue.
Risk reduction: wUSD++ lets the pool use ordinary fixed-balance v4 accounting. The remaining custom risk is concentrated in oracle normalization, policy permissions, routing, and intervention limits rather than every swap and liquidity delta.

Treasury-managed liquidity ranges

Range trancheInventoryPurposeAccounting
Core / oracle rangeBalanced USDC and wUSD++Routing, observations, and ordinary depthUSDC is NAV but not free reserve while committed; wUSD++ is treasury USD++ inventory
Below-peg defensive rangesUSDC-only below spotAbsorb external USD++-equivalent salesAcquired wUSD++ is periodically removed, unwrapped, and burned
Above-peg expansionPrefer atomic mint-wrap-sell; avoid idle pre-minted inventorySell supply only when external USDC entersUnfilled minted USD++ must be burned in the same transaction
Wide oracle backstopProtocol-owned USDC/wUSD++Raise manipulation cost and guarantee minimum depthNot counted as free stable reserve
External active liquidityThird-party positionsIndependent capital and tighter executionLP fees and wUSD++ appreciation belong to those LPs
Eq. 19USDC deployable to POL = max(0, USDC total − free-reserve floor − near-term obligations)

Above-peg order

  1. Release earned Monetary Dividend credits within all constraints.
  2. Mint USD++, wrap, and sell wUSD++ atomically when TWAP, spot, liquidity, and capitalization authorize it.
  3. Continue diversified RWA bonds, valuing the USD++ payout at market and reducing vPLUS accordingly.

Below-peg order

The protocol first buys from the pool while the next marginal all-in USD++-equivalent price is no greater than the Inverse Reserve Bond quote. Only residual contraction demand is offered to inverse bonders.

Value preservation: buying and burning at an average $0.925 improves residual equity by $0.075 per USD++, versus $0.05 when an inverse bond pays $0.95.

Oracle safeguards

  • TWAP authorizes policy; spot and active liquidity size execution.
  • Reserve outflows require longer confirmation than paid expansion.
  • Use a fixed observation buffer, minimum time-weighted liquidity, epoch caps, cooldowns, and later multi-venue confirmation.
  • Protocol actions are excluded from organic volume and external fee revenue.

Interactive: execute a canonical-pool intervention

The chart models normalized USD++-equivalent execution. On-chain, the controller wraps before an above-peg sale and unwraps before a below-peg burn.

Simplified single-range math shown in nominal USD++-equivalent units. Production execution must include ticks, wrapper rate, cross-range liquidity, MEV protection, oracle delay, and capitalization limits.

USD++ minted, wrapped, and sold
USDC acquired
Average normalized execution
09 · Monetization

Fees: 80% permanent burn, 20% builders

Genuine external platform and trading fee revenue uses one canonical split. Treasury investment returns and monetary-policy operations are treated separately so principal, internal transfers, and external revenue cannot be conflated.

Platform revenue80% burns USD++ permanently; 20% funds builders
Treasury returns100% protocol-owned, then split by the dividend framework
ExclusionPolicy trades and treasury principal never generate Builder Share
80%

Protocol Share

Collected or converted to USD++ and permanently burned. The burn creates safe issuance headroom and PLUS hard equity, but does not create Monetary Dividend credits.

20%

Builder Share

Paid to the development organization for salaries, infrastructure, security, audits, legal/compliance, operations, growth, and proportional builder profit.

Technical detailRevenue classification and fee-burn growth loopWhich fees qualify, what is excluded, and why burns remain permanent.

Eligible fee sources

SourceFee basis80/20 treatmentNotes
Launch bonding-curve protocol feeExternal launch-token swapsYesCreator and any liquidity share are removed before the platform share is split.
Graduated TOKEN/USD++ platform feeExternal AMM swapsYesSeparate from ordinary LP compensation.
USD++/PLUS protocol-owned LP feesExternal swaps against protocol-owned liquidityYesOnly realized fees, not LP principal or endogenous token face value.
USD++/USDC protocol-owned LP feesExternal swapsYesExclude stabilization trades executed by protocol-controlled accounts.
Routing / aggregator feeOne-click external asset → USD++ → token routesYesMust remain low enough not to damage launchpad conversion.
Launch / graduation / premium tooling feesExplicit platform servicesYesPremium SaaS-like services may be separately classified if transparently disclosed.

Excluded from the Builder Share

  • Bonded RWA principal and PLUS capital-raising proceeds
  • USD++ issuance, burns, rebases, pool stabilization, and Inverse Reserve Bond principal
  • RWA interest, dividends, and capital gains
  • Treasury rebalancing and custody movements
  • Internal fees paid by the protocol to liquidity it substantially owns

Why permanent fee burns strengthen the joint growth loop

At target capitalization C, a USD++ burn b can support later 1:1 paid issuance y while preserving the burn-funded PLUS equity gain:

Eq. 22y = C · b / (C − 1)

At 150%, a $1 permanent burn can support $3 of later 1:1 paid USD++ issuance. If that demand arrives, $3 of new external assets enter while the original $1 equity improvement remains. If demand does not arrive, the protocol simply retains a larger safety buffer.

External volumeLaunchpad and canonical markets produce real fees.
80% USD++ burnSupply falls without reducing external assets.
Capital headroomPLUS equity and safe paid-issuance capacity rise.
New RWA entersAbove-peg demand buys newly issued USD++.
Larger portfolioMore assets create more future portfolio profit and dividends.

Builder alignment

The builders also receive a long-vested PLUS allocation, but founder PLUS has no preferential claim, enhanced dividend, or superior liquidation right. A baseline allocation is 15% of fully diluted supply with a one-year cliff and three-year linear vest. The team therefore benefits from both:

  • cash flow proportional to genuine platform use; and
  • long-term appreciation from preserving the protocol growth system.

Interactive: fee distribution and capital leverage

The top bar shows the settled 80/20 economic split. The curve below shows how much later 1:1 paid issuance a permanent USD++ burn can support at different C targets.

External eligible volume only

Permanent USD++ burn
Builder revenue
Supported paid issuance
10 · Consumer distribution

A USD++-native launchpad turns attention into monetary demand

The launchpad is not an unrelated product bolted onto the protocol. It is the consumer demand layer that gives USD++ immediate speculative, transactional, liquidity, and settlement utility.

Canonical pairEvery launch begins and graduates against USD++
Creator incentiveToken allocation + creator fees; no PLUS subsidy
Network effectSpeculation, liquidity, and routing all increase USD++ utility

Canonical lifecycle

Create tokenPermissionless or policy-gated deployment with standardized immutable launch contracts.
USD++ curveAll initial purchases use USD++; price follows a declared bonding curve.
GraduateA threshold of real USD++ demand triggers migration.
TOKEN/USD++ AMMRemaining token inventory and accumulated USD++ form non-ruggable liquidity.
Route through USD++TOKEN A → USD++ → TOKEN B makes USD++ the settlement hub.

Speculative demand

Users need USD++ to acquire newly launched tokens, even when the frontend begins from ETH, USDC, or another asset.

Liquidity demand

Every graduated token structurally commits USD++ to a canonical TOKEN/USD++ market.

Settlement demand

Default routing, charts, creator economics, and discovery keep USD++ at the center even if outside pools later exist.

Creator economics

Creators receive an initial token allocation and a disclosed share of external trading fees. They receive no PLUS rewards. This avoids paying creators to manufacture wash volume, fake TVL, or low-quality launches.

Technical detailLaunchpad fees and security defaultsProvisional rates, routing constraints, and non-ruggable launch requirements.

Provisional fee architecture

Market stageBaseline total feeIllustrative allocationOptimization objective
Bonding curve1.00%0.30% creator; 0.70% platformMaximize net creator launches and user retention, not fee rate per trade
Graduated TOKEN/USD++ AMM0.50%0.30% LP; 0.10% creator; 0.10% platformBalance durable liquidity, creator alignment, routing competitiveness, and burn revenue
One-click external routing0–10 bps incrementalPlatform fee onlyUse only if conversion loss is smaller than monetization gain

These fee rates were not settled in prior design work and are explicitly provisional. They belong in conversion and wash-trading simulations before implementation.

Launchpad security defaults

  • Use standardized, immutable token and curve templates where possible.
  • Graduation liquidity must be permanently locked or controlled by a non-ruggable vault.
  • Simulate buy and sell paths before listing; detect transfer restrictions, hidden taxes, owner drains, and honeypot behavior.
  • Do not use raw volume, transaction count, or market cap as a PLUS reward input.
  • Clearly separate platform discovery from an endorsement of any launched token.
  • Rate-limit creation and malicious metadata without making the monetary protocol dependent on discretionary moderation.
11 · Bootstrapping

Genesis: finite PLUS for permanent capital

Genesis is state-based rather than fixed to one month. Its purpose is to build the initial RWA treasury, distribute USD++ and PLUS, seed canonical markets, and launch the USD++ ecosystem. High emissions end when those jobs are complete.

PurposeSpend finite PLUS to acquire RWA, distribution, and permanent markets
End stateRoutine PLUS emissions fall to zero
Supply disciplineUnused budget remains reserved; it is not emitted by default

Zero-capital protocol bootstrap

  1. Users bond approved RWA and choose USD++/vPLUS bond modes.
  2. The treasury receives real external assets and the first USD++ supply is created.
  3. A small liquid PLUS allocation is auctioned for existing USD++.
  4. The treasury uses acquired USD++ and reserved PLUS to seed USD++/PLUS POL.
  5. Bonded USDC is allocated between free reserves and treasury-managed USD++/USDC ranges.
  6. The launchpad opens and begins creating transactional USD++ demand.
Zero protocol capital is not zero operating capital: audits, engineering, legal work, infrastructure, custody integration, and initial operations still require funding by the builder organization.
Technical detailGenesis exit, allocation, and post-Genesis sustainabilityFinite emission budgets, hard sunsets, and the path to zero routine issuance.

Genesis exit conditions

  • Risk-derived capitalization target reached with safety margin
  • Free stable-reserve target reached
  • USD++/USDC and USD++/PLUS markets meet explicit depth targets
  • PLUS ownership distribution and vesting concentration pass thresholds
  • USD++ peg remains within band for a sustained observation window
  • RWA custody and oracle redundancy are operational

Genesis bond emissions stop when conditions are met or the Genesis budget is exhausted. Any temporary restriction on competing PLUS AMM pools ends at the earlier of Genesis completion or a hard sunset, provisionally 90 days. Genesis economic incentives may continue longer without transfer restrictions.

Provisional PLUS allocation

AllocationBaselinePolicy
Genesis bonding maximum35%A budget ceiling, not a target to spend
Post-Genesis strategic bond reserve25%Release only for accretive RWA, USD++ retirement, or strategic POL
Founding team15%1-year cliff + 3-year linear vest; no preferential rights
Future contributors / performance5%Durable economic milestones, not price or washable volume
Initial market distribution5%Liquid auction and initial price discovery
Long-term DAO reserve15%Governance-controlled within constitutional issuance limits

All committed supply is included in fully diluted PLUS accounting from inception. Unused Genesis allocations should remain reserved or be subject to a future burn decision rather than being emitted merely because they were budgeted.

Post-Genesis sustainability

The system must function with zero routine PLUS emissions. Sustainable sources are:

  • RWA portfolio profit;
  • launchpad and canonical-market fees;
  • permanent USD++ burns;
  • paid RWA-backed USD++ issuance;
  • organic demand from the launchpad ecosystem; and
  • opportunistic, strictly bounded PLUS issuance when the market offers an accretive trade.
12 · Safety state machine

Recovery: pool-first, bonds second, rebase last

A non-redeemable soft peg needs an explicit recovery constitution. The system transitions through progressively more expensive stages. No stage may assume that PLUS trades above NAV, and no emergency market action may be based on a single manipulable spot price.

PriorityStop expansion, then buy the cheapest USD++ first
Loss orderReserves and PLUS absorb losses before USD++
Final honestyNegative rebase is constitutional resolution, not routine policy
STAGE 0
Normal
Dividends release according to policy; paid issuance and all bond modes operate; reserve and capitalization targets are maintained.
STAGE 1
Defensive Mode
Pause Monetary Dividends and pool expansion; close or restrict Max USD++ bonds; continue fee burns; direct liquid RWA income to buybacks; improve stable capital-heavy bond terms; never defend PLUS with reserves.
STAGE 2
Pool-first buy and burn
Spend free USDC to buy USD++ from the canonical pool and burn it while the next marginal all-in price is no greater than the Inverse Reserve Bond quote.
STAGE 3
Inverse Reserve Bonds
Offer reserve assets worth q for one surrendered USD++, where market price p < q < 1. Stable reserves are used first; every USD++ is burned immediately.
STAGE 4
Relative-value PLUS contraction
Issue a bounded amount of PLUS for burned USD++ only when USD++ trades at a deeper relative discount than PLUS. This is an auction, never an unlimited fixed conversion.
STAGE 5
Emergency PLUS recapitalization
Sell PLUS for external assets, potentially below NAV. Existing holders may receive participation rights, but USD++ stability takes priority over avoiding PLUS dilution.
STAGE 6
Resolution rebase
After PLUS is economically exhausted, wiped, or substantially diluted, reduce the USD++ index to restore conservative asset coverage. This is a formal loss allocation, not ordinary monetary policy.
Technical detailRecovery mathematics and trigger thresholdsDetailed stage economics, oracle confirmation, and final loss allocation.

Stage 2: pool-first contraction

If the protocol can purchase USD++ in the pool for less than the reserve value offered by an inverse bond, it should capture that discount itself. The controller buys to a maximum marginal price, burns output in the same transaction, and stops before becoming a predictable unlimited bid.

Eq. 23Equity improvement per pool purchase = 1 − average USD++ purchase price

Stage 3: Inverse Reserve Bonds

For one USD++ burned in exchange for q dollars of external reserve assets:

Eq. 24Δ PLUS hard equity = 1 − q, for q < 1

The bond is accretive while giving arbitrageurs a spread over the secondary-market price. It is capacity-limited by free reserves, epoch outflow limits, and portfolio safety.

Stage 4: relative-value PLUS contraction

Define PLUS’s market-to-hard-NAV ratio:

Eq. 25dPLUS = PPLUS / NPLUS

There exists an accretive reward that a user will accept only when:

Eq. 26PUSD++ < dPLUS

If USD++ is $0.80 and PLUS trades at 90% of NAV, the protocol can offer between $0.80 and $0.90 of PLUS market value per USD++ burned. The user profits, while the hard-NAV cost remains below the $1 claim eliminated.

Stage 6: emergency negative rebase

If conservative resolution assets are A_R and USD++ supply is S, the cleanest final haircut is:

Eq. 27Snew ≤ AR

This restores approximately 100% asset coverage without transferring value from USD++ holders to surviving PLUS holders. The higher normal capitalization target is rebuilt afterward through new PLUS capital, retained earnings, and fee burns.

No mechanism can manufacture solvency: if external assets are genuinely insufficient and recapitalization fails, the honest choices are a negative rebase, prolonged impairment, outside capital, or wind-down. The protocol must disclose that tail outcome at launch.

Trigger design

SignalBaseline triggerConfirmationPurpose
Defensive ModeUSD++ TWAP < $0.9854 hours + minimum liquidityStop expansion early
Pool buybackUSD++ TWAP < $0.9758 hours; spot agreesCapture discounted supply from market
Inverse bondsPool marginal price reaches quote or liquidity insufficient12 hours below bandContinue contraction without uncontrolled market impact
PLUS contractionPUSD++ < dPLUS with safety marginDual oracle + auction boundsUse relative valuation without Terra-like fixed conversion
PLUS recapitalizationCapitalization below floor or free reserve exhaustionGovernance + emergency council within bounded mandateAdd external assets
Negative rebaseConservative external assets < USD++ supply after prior stagesLong oracle window, independent attestations, timelocked resolution unless immediate exploitRestore honest coverage

Trigger values are provisional. Simulations must optimize them against depeg duration, reserve exhaustion, false activation, and manipulation cost.

Interactive: play the recovery waterfall

Apply a treasury shock, then watch the protocol move through pool-first contraction and Inverse Reserve Bonds before determining whether PLUS action or resolution is required.

StartShockPoolInverseNext stage

USD++ burned by reserves
Post-reserve coverage
Next required stage
13 · On-chain architecture

On-chain architecture and O(1) accounting

Core safety checks must be enforced on-chain from aggregate state. Expensive portfolio analytics and scenario design may be computed off-chain, but the signed inputs, bounds, and resulting state transitions must be verifiable and impossible to bypass.

Ledger designGlobal indexes and bounded accumulators keep core updates O(1)
AtomicityEvery mint, bond, burn, and policy swap checks its final state
SeparationOff-chain analytics may propose inputs; contracts enforce bounds

Proposed contract map

USD++Token

Share-based ERC-20 facade, global index, optional non-rebasing account adapters, positive and emergency negative index updates.

wUSD++

Fixed-balance wrapper used by canonical v4 pools and external integrations. Routers wrap and unwrap automatically; its exchange rate can fall only during constitutional resolution.

PLUSToken / vPLUS

Fixed maximum supply, vesting claims, governance delegation, reserved issuance accounting, and optional future burn.

TreasuryVault

Custodies on-chain RWA tokens and external reserve assets; exposes aggregate balances to risk and accounting modules.

AssetRegistry

Per-asset oracle, USD++ Factor, exposure caps, category, custodian, settlement state, and scenario retention vector.

RiskEngine

Maintains aggregate NAV, category exposure, fixed-scenario stressed values, portfolio retention, C target, and issuance capacity.

BondAuctioneer

Quotes three bond modes, applies peg-state rules, transfers RWA, mints USD++, and creates vPLUS vesting positions atomically.

ProfitOracle

Capital-flow-adjusted RWA P&L, loss carryforward, recognition policy, and signed/corroborated off-chain valuation inputs.

DividendController

Tracks dividend credits, safe headroom, release velocity, index updates, and pause conditions.

MonetaryPoolHook

Normalized wUSD++/USD++ oracle observations, time-weighted liquidity, fee classification, and bounded policy authorization. Swap accounting remains standard v4 fixed-balance accounting.

TreasuryLiquidityManager

Deploys USDC to approved ranges, tracks free versus committed reserves, and rebalances protocol positions.

PegController

Atomic above-peg mint/sell, pool-first buy/burn, state transitions, cooldowns, budgets, and price limits.

RecoveryAuctioneer

Inverse Reserve Bonds, relative-value PLUS contraction, and emergency recapitalization auctions.

FeeRouter

Classifies external revenue, sends 80% to USD++ burn and 20% to the Builder Treasury, excluding policy trades.

LaunchFactory

Deploys standardized tokens/curves, manages graduation, fee splits, locked liquidity, and canonical USD++ routes.

Governance / Timelock

PLUS voting, parameter bounds, slow changes, emergency pause roles, and constitutional restrictions.

AccountingLens

Read-only canonical calculations for UIs, keepers, analytics, and invariant monitoring.

EmergencyResolution

One-way terminal state transition and negative rebase execution after objective insolvency conditions.

O(1) state strategy

RequirementState representationUpdate complexity
Rebase all USD++ holdersGlobal index + per-account sharesO(1)
PLUS hard NAVAggregate external NAV, USD++ supply, external liabilities, FD PLUSO(1)
Category and issuer capsAggregate value per fixed category / issuer keyO(1) per touched bucket
Portfolio stressFixed K-scenario stressed-value accumulatorsO(K), treated as O(1) because K is constitutionally bounded
Profit recognitionNAV checkpoint, net flows, loss carryforward, dividend-credit accumulatorO(1) per epoch
Oracle historyFixed-size circular observation bufferO(1) per observation
Fee distributionCumulative counters + batch burn / builder transferO(1)
Recovery stateSingle enum + timestamps + epoch budgetsO(1)
Launch graduationPer-launch curve state and thresholdO(1) per launch action
Technical detailState transitions and atomic enforcementBounded risk updates, bond settlement, expansion execution, and keeper limits.

Risk aggregation

01Update touched value

Adjust external NAV and the affected category/issuer buckets only for the asset whose balance or oracle value changed.

02Update bounded scenarios

Apply the asset’s fixed retention vector to a constitutionally bounded scenario set K. No transaction loops over all treasury assets.

03Recompute the binding target

Select the worst retained portfolio value, derive the risk target, and ratelimit only downward changes. Risk increases pause unsafe actions immediately.

Atomic bond transaction

  1. Pull and value the approved RWA. The asset enters TreasuryVault before any USD++ or vPLUS is issued.
  2. Preview the post-bond portfolio. RiskEngine derives the new C target, exposure state, and mode-specific USD++ ceiling from aggregate state.
  3. Quote one permitted bond mode. BondAuctioneer prices USD++ at the protected TWAP, computes vPLUS at the current market/NAV relationship, and enforces capacity.
  4. Enforce the post-state before settlement. All asset caps, issuance limits, reserve rules, and PLUS hard-accretion requirements must pass atomically.
  5. Settle once. Treasury retains the asset, USD++ is minted to the bonder, and a fixed vPLUS vesting claim is created in the same transaction.

Atomic above-peg expansion

  1. Authorize with the normalized oracle. Both the secured TWAP and spot price must remain above the upper band, with sufficient time-weighted liquidity.
  2. Compute a bounded mint. The amount is the minimum of paid-issuance capacity, active pool demand, the epoch cap, and the caller’s limit.
  3. Mint only for immediate execution. USD++ is wrapped into wUSD++ and sold into the canonical pool to a hard normalized price boundary; USDC proceeds transfer directly to TreasuryVault.
  4. Burn any unfilled amount. Any unfilled wUSD++ is unwrapped and the corresponding USD++ is burned before the transaction completes.
  5. Verify the final balance sheet. The transaction reverts unless post-trade capitalization, reserve accounting, and pool deltas satisfy every invariant.

Keeper incentives

Routine accounting, rebalancing, and policy calls may pay bounded keeper bounties from explicit operating budgets. Bounties must never be proportional to manipulable spot volume. Critical actions remain permissionless once objective conditions are met, but execute within epoch caps and price limits.

14 · Formal reasoning

Core invariants and mathematical guarantees

These proofs establish the economic identities the contracts should enforce. They are not substitutes for machine-checked Solidity or theorem-prover proofs, but they define the statements those artifacts must prove.

Invariant A: bond issuance preserves the capitalization floor

Algebraic

If pre-bond assets and supply are A and S, a bond adds external value V, and USD++ issuance x satisfies:

x ≤ (A + V) / Cfloor − S

then post-bond capitalization is at least C_floor.

Proof
S + x ≤ (A + V) / Cfloor ⇒ (A + V)/(S + x) ≥ Cfloor

The contract must also enforce the asset USD++ Factor, exposure caps, and committed issuance. The minimum of all constraints preserves every individual invariant.

Invariant B: a Monetary Dividend cannot cross the target ratio

Algebraic

For dividend issuance d:

d ≤ A / Ctarget − S
Proof
S + d ≤ A / Ctarget ⇒ A/(S + d) ≥ Ctarget

The additional credit, peg, rate, and reserve limits can only reduce d, so they cannot violate this guarantee.

Invariant C: the corrected (3,3) bond preserves earlier headroom

Incremental

Define pre-existing headroom under the post-bond target as:

Hpre = max(0, A/C − S)

and choose:

x3,3 = max(0, (A + V)/C − S − Hpre)
Proof

If A/C ≥ S, then H_pre = A/C − S, so x_3,3 = V/C. Post-bond headroom is:

(A + V)/C − (S + V/C) = A/C − S = Hpre

If the system begins below target, H_pre = 0 and the bond first repairs the deficit. Thus the recommended point never appropriates positive capital created by previous participants.

Invariant D: risk-derived target survives the modeled stress

Stress

If the portfolio retains fraction R under the binding scenario and:

Ctarget = Cpost / R
Proof

Before stress, A/S = C_target. After stress, assets are R·A and supply is unchanged:

Cafter = R·A/S = R·Ctarget = Cpost

The guarantee is only as strong as the scenario matrix, valuation, custody assumptions, and correlation model.

Invariant E: profit split gives PLUS the target upside multiple

Allocation

At target capitalization, PLUS equity is (C−1)S. Allocate fraction k of profit Π to USD++ and 1−k to PLUS. Setting PLUS’s percentage return to m times USD++’s gives:

k = 1 / (1 + m(C − 1))
Proof
rx = kΠ/S
rPLUS = (1−k)Π/((C−1)S)

Set r_PLUS = m·r_x and solve:

(1−k)/(C−1) = mk ⇒ 1 = k(1 + m(C−1))

Invariant F: an Inverse Reserve Bond below $1 is equity-accretive

Recovery

The protocol gives external reserve value q and burns one USD++ internally valued as a $1 monetary claim.

ΔE = −q − (−1) = 1 − q
Proof

Assets fall by q; liabilities fall by one. For q<1, residual equity rises. The user participates only if the market purchase price p<q, creating the feasible interval p<q<1.

Invariant G: relative-value PLUS contraction is feasible exactly when USD++ is cheaper

Recovery

Let hard PLUS NAV be N=E/Q_PLUS, market price P_PLUS, and reward market value r=qP_PLUS for burning one USD++. Per-PLUS NAV is non-decreasing when:

(E + 1)/(QPLUS + q) ≥ E/QPLUS ⇒ q ≤ 1/N ⇒ r ≤ PPLUS/N = dPLUS
Proof

A user who purchases USD++ at P_x requires r>P_x. A reward satisfying both conditions exists iff:

Px < r ≤ dPLUS ⇒ Px < dPLUS

This proves why the market-relative test is necessary and why the mechanism must remain bounded.

Invariant H: a permanent burn supports leveraged paid issuance

Growth system

Start at A=CS. Burn b USD++. Then accept y dollars of assets and issue y USD++ at 1:1. Returning exactly to C requires:

y = Cb/(C−1)
Proof
(CS + y)/(S − b + y) = C
CS + y = CS − Cb + Cy ⇒ (C−1)y = Cb

At 150%, one permanent burn supports three dollars of later paid issuance without erasing the burn-funded equity gain.

Invariant I: paid issuance and free dividends have different property effects

Accounting

Free dividend d changes supply but not assets. Paid issuance y changes both by the external sale proceeds.

Proof

With a free dividend, (A,S)→(A,S+d), so PLUS equity falls by d. With 1:1 paid issuance, (A,S)→(A+y,S+y), so PLUS equity A−S is unchanged. The same capitalization ratio can therefore be reached through materially different property allocations.

Invariant J: resolution rebase does not recapitalize PLUS at USD++’s expense

Resolution

When conservative external assets are A_R<S, setting new USD++ supply to at most A_R restores coverage with residual PLUS equity no greater than zero.

Proof
Eafter = AR − Snew ≥ 0 only if Snew ≤ AR

Choosing S_new=A_R creates exactly 100% coverage and zero residual equity. Any higher post-resolution buffer should come from new PLUS capital, not a larger USD++ haircut.

Formalization requirement: the production repository should convert these statements into property tests, invariant fuzzing, executable simulations, and machine-checked proofs for the highest-risk arithmetic and state transitions. Integer rounding must always favor protocol solvency, never additional issuance.
15 · Configuration

Parameter registry and optimization framework

Defaults provide a coherent simulation baseline. They are not governance recommendations until adversarial simulations, market research, custody constraints, and audits justify them.

Baseline150% C target, m = 2, 25% free stable reserves
StatusDefaults are simulation priors, not governance recommendations
GovernanceConstitutional, risk, and operational parameters have different controls

Core economic parameters

ParameterSymbolBaselineSuggested boundsOptimization criterion
USD++ target priceP*$1.00Fixed unitUnit-of-account clarity
Upper / lower normal bandU, L$1.005 / $0.995±10–100 bpsTrade off intervention frequency against price stability
Post-stress capitalization objectiveCpost110%100–125%Survive modeled stress with recovery cushion
Operating target capitalizationCtarget150%125–200%Derived from Cpost / worst stress retention
PLUS return multiplem2.0×1.5–3.0×Maximize joint capital inflow while compensating first-loss risk
Free stable reserve targetRstable25% of USD++15–40%Meet contraction objective without forced growth-asset sales
Max modeled contractionb20% of USD++10–40%Acceptable reserve exhaustion probability
Inverse-bond maximum quoteqmax$0.95$0.85–$0.99Fast contraction while preserving equity
vPLUS vestTvest7 days5–14 daysBond responsiveness versus immediate arbitrage/sell pressure
Genesis market restriction sunsetTsunset90 days30–180 daysConcentrate launch liquidity without indefinite control
Platform / Builder splitφ80% / 20%Protocol share 70–90%Sustain builders while maximizing permanent capitalization
Unrealized profit recognitionρ25% per 30 days0–100% with capsDeliver differentiated yield without overdistributing transient gains
USD++ Factor weightswσ / wliq / wfloat / wmcap / wops45% / 25% / 10% / 5% / 15%Weights sum to 100%Backtest loss coverage while preserving capital efficiency
USD++ Factor stress horizonh30 days7–90 daysReflect time required to rebalance or exit tokenized RWA
Float / market-cap saturationF50 / M50$5b / $20bAsset-class specificAvoid treating scale as linearly beneficial after sufficient market depth

Oracle and policy parameters

ParameterBaselinePurpose
Routine normalized TWAP window30 minutesBond quotes and non-outflow policy
Defensive Mode confirmation4 hours below $0.985Stop expansion without overreacting to noise
Reserve-outflow confirmation8–12 hours + spot agreementProtect free reserves from oracle manipulation
Paid expansion epoch cap1% of USD++ supply / 6 hoursBound oracle and execution errors
Pool buyback epoch cap2% of USD++ supply / 6 hoursBound treasury outflow and predictable bidding
Dividend release cap0.25% of supply / dayPrevent abrupt index and integration shocks
C target downward ratelimit1 percentage point / 7 days after 30-day persistenceDo not monetize temporary low risk
C target upward responseImmediate action pause; target updates at next secured oracle epochPrevent stale risk from authorizing issuance
Scenario count K8Keep risk updates bounded and auditable
Technical detailGovernance classes and change authorityWhich settings are constitutional, risk-managed, or operational.

Parameter governance classes

Constitutional

Token claims, 80/20 framework, no hard redemption, recovery seniority, m bounds, negative-rebase ordering, and issuance invariants. Long timelock and supermajority.

Risk

Asset factors, caps, scenario vectors, reserve target, oracle thresholds, and epoch budgets. Bounded updates with independent review and shorter timelock.

Operational

Keeper addresses, range templates within bounds, routing adapters, launch metadata rules, and routine maintenance. Multisig or automated manager under strict limits.

16 · Threat model

Security considerations and required mitigations

The protocol combines RWA custody, elastic supply, governance, a custom v4 hook, endogenous equity, and a permissionless launchpad. Economic and integration failures are as important as ordinary Solidity exploits.

Highest riskCustom v4 accounting, RWA custody, and oracle manipulation
DefenseValue caps, bounded state transitions, multiple oracles, and formal invariants
Tail riskThe protocol explicitly specifies insolvency resolution
Threat modelFull failure-mode and mitigation matrixOracle, custody, hook, governance, integration, and launchpad risks.
ThreatFailure modeRequired mitigation
Canonical-pool oracle manipulationFalse expansion, reserve outflow, favorable bond quote, or recovery activationNormalized TWAP, minimum time-weighted liquidity, spot confirmation, epoch caps, cooldowns, wide oracle-hardening liquidity, and multi-market median when available
RWA price/NAV oracle failurePhantom treasury profit, unsafe issuance, or false insolvencyIssuer feed + independent market oracle where possible, staleness bounds, circuit breakers, confidence intervals, delayed profit recognition, and manual resolution path
Custodian / token issuer failureAsset freeze, redemption halt, legal seizure, or lossIssuer and custodian caps, diversified legal entities, proof/attestation requirements, scenario retention vectors, rapid asset disablement, and explicit impairment accounting
Rebase integration errorLost LP yield, incorrect balance, donation/skim extraction, or broken lending positionShares as USD++ source of truth, wUSD++ for every canonical v4 pool and unsupported integration, normalized-oracle tests, router invariants, and no assumption that the wrapper exchange rate can only rise
v4 custom-accounting bugDelta mismatch, insolvency, fee theft, denial of service, or cross-pool contaminationMinimal hook permissions, fixed pool keys, formal delta conservation, separate accounting vault if necessary, multiple audits, invariant fuzzing, and staged value caps
Bond quote manipulationAcquire excess vPLUS or USD++ at stale pricesTWAP inputs, quote expiry, slippage bounds, capacity decay, per-address and global epoch limits where useful, and atomic post-state checks
Wash tradingArtificial fees or volume become profitable due to rewardsNo launchpad PLUS rewards, no rewards based on raw volume, classify self-trades, exclude protocol actions, and ensure any rebates remain below round-trip costs
Recovery front-running / sandwichingExtract reserve value around predictable buybacksMarginal price limits, private/orderflow-aware execution where appropriate, randomized bounded timing, batch auctions, and no automatic afterSwap treasury bid
Governance captureLower risk constraints, divert reserves, increase Builder Share, or prevent resolutionConstitutional bounds, long timelocks, emergency veto with sunset, delegated voting safeguards, quorum requirements, and immutable seniority rules where possible
PLUS death spiralFalling PLUS blocks capital formation while USD++ depegsNo fixed USD++-to-PLUS redemption, reserve-first recovery, relative-value condition, finite PLUS auctions, recapitalization rights, and terminal negative rebase
Launch-token exploit / honeypotUser loss and platform reputational contagionStandard templates, bytecode checks, sell simulation, ownership-risk labels, non-ruggable liquidity, metadata moderation, and isolation from treasury accounting
Upgrade or pause abuseBackdoor changes, frozen user funds, or permanent emergency controlImmutable core where practical, module-specific upgradeability, timelocks, narrow pause scope, escape paths, and transparent role registry
Rounding / precision driftSlow issuance leakage or share imbalanceHigh-precision fixed-point math, round issuance down, round liabilities up, bounded dust, and cumulative reconciliation tests
Cross-chain supply divergenceRebase mismatch or unbacked bridged USD++Do not launch native cross-chain USD++ in V1; use canonical wrappers with explicit index sync and global supply accounting only after proof

Role and upgrade model

  • Governance: slow constitutional and treasury-policy changes.
  • Risk council: bounded asset pauses, factor reductions, and cap reductions; cannot increase risk beyond timelocked limits.
  • Emergency council: pause affected modules and accelerate defensive restrictions; cannot transfer treasury assets or trigger a negative rebase unilaterally.
  • Keepers: permissionless or allowlisted executors with no discretion beyond contract-calculated amounts.
  • Builder organization: recipient of the Builder Share, with no privileged monetary claim or unilateral control over treasury principal.

Mandatory monitoring

Balance sheet

External NAV, capitalization, stress retention, free reserves, committed issuance, dividend credits, loss carryforward, and PLUS hard NAV.

Markets

Normalized USD++ TWAP/spot, PLUS premium to NAV, active liquidity by range, external LP share, manipulation cost, and execution slippage.

Operations

Oracle staleness, custody attestations, bridge exposure, fee classification, keeper failures, recovery budgets, and governance queues.

17 · Research and validation

Validation, optimization, and launch gates

The protocol has enough degrees of freedom that intuition alone cannot select the final target capitalization, reserve ratio, bond quote, or recovery thresholds. Simulations should optimize the joint USD++/PLUS ecosystem rather than either token in isolation.

Optimize jointlyMaximize external treasury value and platform fees, not one token
Must modelAgents, market reflexivity, custody failure, and oracle attacks
Launch gateParameter and hook safety must be proven before uncapped value

Primary optimization objective

Maximize E[terminal external treasury NAV + NPV of external platform fees]

Subject to:

  • maximum probability and severity of an emergency negative rebase;
  • maximum expected USD++ depeg duration and volatility;
  • maximum free-reserve exhaustion probability;
  • bounded PLUS dilution and sustainable PLUS premium assumptions;
  • minimum USD++ holder yield and launchpad liquidity;
  • minimum post-stress capitalization and oracle manipulation cost.
Technical detailSimulation dimensions, agents, and adversarial scenariosThe complete parameter sweep and minimum scenario suite.

Parameter sweeps

DimensionSuggested sweepKey outputs
Risk-derived C target125%, 140%, 150%, 160%, 175%, 200%USD++ issuance, yield, emergency loss probability, PLUS return
PLUS return multiple m1.5×, 2×, 2.5×, 3×USD++ demand elasticity, PLUS premium, RWA per PLUS issued
Free stable reserves15–40% of USD++Depeg duration, forced growth-asset sales, opportunity cost
Asset mixStable / gold / equity grids with correlation regimesStress retention, portfolio return, dividend stability
Bond modesFixed allocation vs 3 modes vs continuous sliderTotal capital attracted, mode take-rate, PLUS sell pressure, USD++ scale
vPLUS vest5, 7, 10, 14 daysBond fill, recursive farming, post-vest sell pressure
Fee ratesLaunch curve 30–150 bps; graduated 10–100 bpsConversion, volume, burns, builder revenue, wash economics
Recovery thresholdsMultiple TWAP windows, quotes, and epoch budgetsFalse activation, reserve value preserved, time to peg
Unrealized-profit recognition0–100% over 7–180 daysUSD++ yield smoothness, loss carryforward, negative-rebase risk

Agent model

  • USD++ holders: demand depends on expected yield, peg history, liquidity, and launchpad utility.
  • PLUS investors: price future fees, portfolio growth, dilution, first-loss risk, and recovery seniority.
  • Bonders: choose modes based on immediate USD++ value, PLUS discount, vesting, volatility, and alternatives.
  • Arbitrageurs: exploit above/below peg opportunities subject to fees, capacity, and latency.
  • Launchpad users: react to token novelty, creator economics, routing friction, and fee levels.
  • Attackers: manipulate oracles, wash trade, sandwich recovery, concentrate custody risk, and exploit stale parameters.

Minimum scenario suite

Growth shock

Equities −50%, gold −20%, stable reserves intact, launch volume collapses.

Correlated risk-off

Equities −40%, gold −25%, Treasury token liquidity impaired, PLUS below NAV.

Stable issuer event

Primary stable reserve loses 15–50%, freezes transfers, or becomes temporarily inaccessible.

Oracle attack

Canonical pool manipulated across one or more blocks while TWAP liquidity changes.

Viral expansion

Launchpad demand pushes USD++ above peg while PLUS trades at a high premium and bonds fill rapidly.

Slow death

USD++ at $0.90–$0.98 for months, PLUS near/below NAV, low fee revenue, modest portfolio yield.

Formal and software verification

  • Foundry invariant tests for every algebraic invariant in this document
  • Differential tests against a high-precision Python/Rust reference model
  • Stateful fuzzing across bonds, rebases, fee burns, hook swaps, and recovery transitions
  • Symbolic checks for integer overflow, rounding direction, and inaccessible recovery states
  • Lean or another theorem prover for issuance, profit split, recovery accretion, and resolution seniority
  • Economic Monte Carlo and adversarial agent-based simulation before choosing constants
  • Fork tests against the selected Uniswap v4 deployment and RWA token implementations

Launch gates

  1. No unresolved critical or high audit findings.
  2. All core invariants hold under at least 10 million stateful fuzz sequences.
  3. Chosen parameter set meets defined stress and negative-rebase probability thresholds.
  4. RWA custody and oracle failure drills complete successfully.
  5. Canonical hook survives independent formal review and capped-value testnet/mainnet pilot.
  6. Recovery Stage 1–6 tabletop and fork simulations have deterministic outputs.
18 · Unresolved work

Open issues before implementation is complete

These are not minor polish items. Several determine whether the current design is technically or economically viable.

P0Hook feasibility, risk target, and RWA custody
P1Bond pricing, profit recognition, range templates, and recovery automation
RuleNo unresolved P0 issue may be treated as an implementation detail

Specify the wUSD++ v4 oracle hook and router invariants

Prove normalized USD++ pricing across wrapper-rate changes, observation checkpoints, atomic wrap/swap/unwrap flows, pool-specific permissions, fee classification, and cross-pool isolation. Canonical v4 pools use wUSD++ rather than raw rebasing USD++.

Priority P0 · Protocol engineering + formal methods

Calibrate the USD++ Factor model

Validate the volatility horizon, gap penalty, liquidity/exit-size transform, free-float and market-cap saturation constants, operational score, class ceilings, and weights against historical and simulated losses.

Priority P1 · Risk research + simulation

Optimize C target and scenario matrix

Select joint stress scenarios, retention factors, correlation assumptions, post-stress cushion, update cadence, and hard bounds. The 150% target is only a baseline.

Priority P0 · Risk research + simulation

Define RWA custody, eligibility, and transfer architecture

Resolve issuer access, KYC/whitelisting, custody, market hours, corporate actions, NAV reporting, sanctions/freeze risk, token transfer restrictions, and bankruptcy remoteness for each asset class.

Priority P0 · Legal, operations, integrations

Choose bond interface: three modes or continuous slider

The three-mode snapping slider is the current recommendation, but simulation must compare total capital attracted, user comprehension, mode gaming, and protocol steering versus a single protocol-selected allocation.

Priority P1 · Product + mechanism design

Specify vPLUS auction curve and reserve opportunity cost

Define total bond quote, capacity decay, price sources, minimum hard accretion, treatment of fully diluted reserved supply, vesting, and behavior when PLUS approaches NAV.

Priority P1 · Mechanism design

Set unrealized-profit recognition

Determine the lag, fraction, loss carryforward, oracle confidence, and reversal policy for equity/gold gains. The current 25% per 30 days is a placeholder.

Priority P1 · Risk + accounting

Optimize protocol-owned USD++/USDC range templates

Choose core, defensive, expansion, and oracle-hardening ranges; free-reserve priority; rebalance cadence; committed-issuance accounting; external LP incentives; and MEV-aware execution.

Priority P1 · AMM research

Define exact launchpad curve and fee schedule

Choose curve shape, graduation threshold, creator allocation/vesting, creator fee, platform fee, LP fee, locked-liquidity implementation, anti-honeypot rules, and conversion-optimal routing.

Priority P1 · Launchpad simulation + product

Define oracle redundancy

Specify the normalized v4 oracle, observation buffer, time-weighted liquidity, independent stablecoin markets, PLUS price/NAV oracle, RWA feeds, failure hierarchy, and stale-data behavior.

Priority P1 · Oracle engineering

Choose recovery governance and automation boundaries

Decide which stages are fully automatic, which require an auction start, which require governance, and how to prevent both delayed action and malicious reserve release.

Priority P1 · Security + governance

Calibrate PLUS genesis and strategic allocations

Test whether 35% Genesis and 25% strategic reserve maximize durable assets per PLUS without excessive circulating supply, and define what happens to unused emissions.

Priority P1 · Token economics

Regulatory and tax architecture

Analyze stablecoin, securities, commodities, money transmission, investment-company/fund, launchpad, broker/dealer, RWA transfer, revenue-sharing, and rebasing tax treatment in target jurisdictions before finalizing permissions and claims.

Priority P0/P1 · Specialized counsel

Protocol and product naming

USD++ and PLUS are functional placeholders. Final names should communicate portfolio-backed compounding money, junior equity, and launchpad utility without implying sovereign or government ownership.

Priority P2 · Brand
19 · Design precedents

Primary references and implementation precedents

The protocol is novel in combination, but several individual components have useful production or historical precedents. These sources inform the design; they do not validate this protocol as a whole.

AreaReferenceRelevant lesson
Reserve, liquidity, and inverse bondsOlympus Bonds documentationIssue endogenous equity to acquire reserves or POL; use inverse bonds to sell reserves for the protocol token during contraction.
Rebasing sharesLido share accountingStore fixed shares and derive visible balances from a global pooled-value/index relationship.
Wrapper compatibilitywstETH documentationExpose a non-rebasing adapter for integrations that assume balances change only through transfers.
Uniswap v4 hooksUniswap v4 hook conceptsA pool can invoke fixed hook callbacks whose permissions are encoded in the hook address.
Custom accountingUniswap v4 custom accountingFlash accounting and hook-returned deltas can support custom fees and curves, including specialized treatment for rebasing or RWA-like assets.
Oracle gap in v4Uniswap price-oracle documentationv3 pools include historical oracle observations; v4 requires oracle functionality to be supplied separately, such as through a hook.
Rebasing LP caveatUniswap rebasing-token support noteNative v3/v4 positions do not automatically handle positive-rebase LP yield, motivating wUSD++ as the canonical fixed-balance settlement asset.
Risk factors and capsAave risk documentationPer-asset factors, limits, monitoring, and governance are standard tools for bounding collateral risk.
Risk-factor calibrationAave / RiskDAO LTV methodologyVolatility and available liquidity can be combined into an explicit confidence-based risk ceiling rather than chosen qualitatively.
Float, liquidity, and exposure capsGauntlet supply-cap methodologyCirculating supply, market depth, and trading volume provide quantitative bounds on safe protocol exposure.
Tail-risk frameworkBasel market-risk frameworkTail loss models should be supplemented by scenario and non-modelable-risk treatment rather than trusted alone.