Layered control
| Layer | Who holds it | What it can do |
|---|---|---|
| Multisig (owner) | Founders, N-of-M | Upgrade strategy, change parameters, emergency unwind, manage the alpha tranche |
| Bot (operator) | Backend hot key | Run clearings, rebalance, mark tickets ready — funds can move only to whitelisted destinations |
| Contract invariants | Code | Price delta cap 0.3%/clearing · 1.2%/rolling 7 days · strict accounting · AML-signed deposits only |
A fully compromised bot cannot send funds to an attacker (whitelist), cannot reprice the fund by more than 0.3% per clearing (cap), and cannot mint shares without a matching USDT deposit (accounting). The worst realistic damage is operational delay — which the multisig resolves.
First-loss capital: our money burns first
About 10% of the fund is a private junior tranche funded by the team and early backers. Every loss — a borrow-rate spike, a liquidation penalty, a bad month — is written down against it before depositor value is touched. It would take roughly a year of sustained worst-case borrow rates to burn through it. In exchange, this tranche keeps the yield above what depositors are paid. Aligned incentives, priced in code.
A floating rate, and what actually protects you
We promise no rate. The rate is floating: it follows what the strategy earns and can change on any clearing day — a fund that guaranteed a level would be paying it out of something it would rather not name. What we can put behind you is not a promise but three mechanisms. Hard caps in the contract: the share price cannot move more than 0.3% at any single clearing, nor more than 1.2% across any rolling 7 days — so even an operator bot in an attacker's hands can neither inflate the NAV nor drain it faster than that, and the multisig has days, not minutes, to react. First-loss capital: a private junior tranche is written down in full before depositor value is touched. An open rate history: every rate we have ever set is on-chain and charted on this site, including the bad months. Track record instead of a guarantee — it is the harder thing to fake.
Clean-money pipeline
- Wallet screening via AML providers before any deposit is accepted.
- Deposits enter only through a signed permission the contract verifies — no signature, no deposit.
- Working balances tracked by an internal counter, never by
balanceOf: "dusted" or dirty direct transfers are invisible to the flow and can only be swept to a quarantine wallet, never into the fund.
What remains as real risk
Honesty requires the list: TRON governance re-pricing Energy (this is exactly why the rate floats instead of being promised), JustLend protocol failure, smart-contract bugs (contracts are deliberately small — under 500 lines each — and go to external audit before mainnet), and TRON-network-level events. We publish these in every document because a risk you can name is a risk you can price.