fmd is the ratio of the vault to the supply. v is the quantity of sol held by the program owned vault. s is the circulating supply of the token. there is nothing else in the definition and nothing else in the system.
those are the two operands. neither is held by a person. the vault is owned by the program and can only be moved by an instruction the program defines. the mint has no mint authority and no freeze authority, so the supply cannot be expanded, frozen, or reassigned after deployment.
every figure published on this site is derived from those two accounts and from nothing else. the ratio is computed here, in the browser, from the balances as they are read. it is not fetched from a server, not cached, and not stored anywhere that could be edited. if a number here disagrees with what the accounts say, the site is wrong and the accounts are right.
the program has no upgrade authority. the byte at offset twelve of the program data account reads zero, which means no address is stored after it and no instruction in the loader can create one. the executable cannot be replaced. this is not a policy that could be reversed under pressure. it is a property of an account that anyone can fetch and check in one call.
there is no admin, no multisig, no council, no timelock, and no emergency path. the absence of those is the reason the rest of this record is worth reading, because every claim made elsewhere on this site is a claim about code that can no longer change.
the estate has no team page and will not have one. nothing about the system depends on who wrote it. the parameters were fixed before the first instruction ran, the authority was removed at deployment, and what remains is a set of accounts behaving the way the code says they behave. an identity here means a program address, and that address is the only thing being asked to be trusted.
fmd is the ratio of the vault to the supply. v is the quantity of sol held by the program owned vault. s is the circulating supply of the token. there is nothing else in the definition and nothing else in the system.
those are the two operands. neither is held by a person. the vault is owned by the program and can only be moved by an instruction the program defines. the mint has no mint authority and no freeze authority, so the supply cannot be expanded, frozen, or reassigned after deployment.
every figure published on this site is derived from those two accounts and from nothing else. the ratio is computed here, in the browser, from the balances as they are read. it is not fetched from a server, not cached, and not stored anywhere that could be edited. if a number here disagrees with what the accounts say, the site is wrong and the accounts are right.
the program has no upgrade authority. the byte at offset twelve of the program data account reads zero, which means no address is stored after it and no instruction in the loader can create one. the executable cannot be replaced. this is not a policy that could be reversed under pressure. it is a property of an account that anyone can fetch and check in one call.
there is no admin, no multisig, no council, no timelock, and no emergency path. the absence of those is the reason the rest of this record is worth reading, because every claim made elsewhere on this site is a claim about code that can no longer change.
the estate has no team page and will not have one. nothing about the system depends on who wrote it. the parameters were fixed before the first instruction ran, the authority was removed at deployment, and what remains is a set of accounts behaving the way the code says they behave. an identity here means a program address, and that address is the only thing being asked to be trusted.
the estate holds one asset and one claim against it. the asset is sol in a program owned vault. the claim is the token. the ratio between them is fmd, and it is the only number this system produces.
most things that hold a reserve treat it as a promise. someone announces a backing level, publishes a figure, and defends it when the market disagrees. the defense costs money, the money runs out, and the promise ends the way every promise ends when the entity behind it is out of resources. the reserve was real and the commitment was not.
this is the opposite arrangement. nothing is promised, nothing is defended, and nobody is standing behind the number. the ratio moves because of what the instructions do to the two accounts, and it moves in one direction because of what those instructions are.
any holder may redeem at any time. no window, no queue, no notice period, no minimum, no approval, and no counterparty. burning tokens returns ninety seven percent of the proportional share of the vault, computed at the moment of the call. the remaining three percent stays where it already was.
that retention is the entire mechanism. the exit removes a share of the value and all of the claim. what is left is a smaller vault divided among a supply that shrank faster, which is a larger ratio for everyone who did not leave. nobody bought it back, nobody defended a level, and nobody spent anything to make it happen. the person exiting raised the floor on their way out, and they did it whether they meant to or not.
the vault started empty. every lamport in it arrived through emit, which is the only instruction that puts sol in. there was no seed, no treasury allocation, no presale, and no founder deposit, which means there is no pool of value that could be withdrawn later by whoever put it there. what is in the vault came from people buying, and the only way out of it is the redemption path that is open to all of them equally.
there is no promise here that fmd will be high. it may be low, it may sit still for long stretches, and it began at close to nothing. the claim is narrower and stranger than a promise about level: whatever the ratio is, it is not going to be lower next slot than it is now.
that is the whole premise. one vault, one supply, an open exit that costs three percent, and a number that only moves one way as a consequence.
the estate holds one asset and one claim against it. the asset is sol in a program owned vault. the claim is the token. the ratio between them is fmd, and it is the only number this system produces.
most things that hold a reserve treat it as a promise. someone announces a backing level, publishes a figure, and defends it when the market disagrees. the defense costs money, the money runs out, and the promise ends the way every promise ends when the entity behind it is out of resources. the reserve was real and the commitment was not.
this is the opposite arrangement. nothing is promised, nothing is defended, and nobody is standing behind the number. the ratio moves because of what the instructions do to the two accounts, and it moves in one direction because of what those instructions are.
any holder may redeem at any time. no window, no queue, no notice period, no minimum, no approval, and no counterparty. burning tokens returns ninety seven percent of the proportional share of the vault, computed at the moment of the call. the remaining three percent stays where it already was.
that retention is the entire mechanism. the exit removes a share of the value and all of the claim. what is left is a smaller vault divided among a supply that shrank faster, which is a larger ratio for everyone who did not leave. nobody bought it back, nobody defended a level, and nobody spent anything to make it happen. the person exiting raised the floor on their way out, and they did it whether they meant to or not.
the vault started empty. every lamport in it arrived through emit, which is the only instruction that puts sol in. there was no seed, no treasury allocation, no presale, and no founder deposit, which means there is no pool of value that could be withdrawn later by whoever put it there. what is in the vault came from people buying, and the only way out of it is the redemption path that is open to all of them equally.
there is no promise here that fmd will be high. it may be low, it may sit still for long stretches, and it began at close to nothing. the claim is narrower and stranger than a promise about level: whatever the ratio is, it is not going to be lower next slot than it is now.
that is the whole premise. one vault, one supply, an open exit that costs three percent, and a number that only moves one way as a consequence.
a holder redeems b tokens. their proportional share of the vault is b times fmd. they receive ninety seven percent of it. the vault falls by what they were paid, and the supply falls by everything they burned.
the new ratio is the new vault over the new supply.
v is gone. the size of the vault does not appear in the result. what remains is a comparison between two numbers that differ only in a coefficient, and since 0.97b is smaller than b, the numerator is larger than the denominator.
the numerator falls by ninety seven percent of the share. the denominator falls by all of it. a denominator shrinking faster than its numerator produces a larger quotient. that is the mechanism, complete, with no second step.
what the result does not depend on
it does not depend on the size of the exit. a holder burning a hundred tokens and a holder burning half the supply produce the same inequality, only at different magnitudes. large exits raise the ratio more than small ones.
it does not depend on the size of the vault. v cancelled. an empty vault and a full one behave identically in ratio terms.
it does not depend on price, on volume, on anyone watching, on anyone being solvent, or on anyone behaving well. no participant has to do anything for the arithmetic to hold, because the arithmetic is not a behaviour. it is a division that the program performs and cannot decline to perform.
the boundary
at b equal to s the denominator is zero and the expression is undefined. that is the terminal case: the last holder burns the entire remaining supply and receives what is left of the vault. the program guards it, the ratio ceases to be defined, and nothing further happens. this is a real end state and it is described in limits.
the other two instructions
emit adds sol and adds supply. the ask is priced above the current ratio, always, so every emission brings in more backing per token than the existing average and the ratio rises or holds. it never dilutes, because a sale below fmd is not a price the instruction will accept.
sweep spends vault sol to buy tokens on the market and burns them in the same instruction. the vault falls by what was spent and the supply falls by what was bought. it is only permitted to execute when the market sits below fmd, which means it always pays less than the ratio for what it destroys. spending x to remove tokens worth more than x raises the ratio by the same logic as the exit fee.
three instructions, three ways for the numerator and denominator to move, and no combination of them that produces a smaller quotient. there is no fourth instruction, which is why this is a proof about the system and not just about redemption.
how to check it
read the vault balance and the mint supply from any explorer at two different slots and divide each pair. the second figure will not be smaller than the first. that check does not require reading the program, trusting this page, or believing anything written on it.
a holder redeems b tokens. their proportional share of the vault is b times fmd. they receive ninety seven percent of it. the vault falls by what they were paid, and the supply falls by everything they burned.
the new ratio is the new vault over the new supply.
v is gone. the size of the vault does not appear in the result. what remains is a comparison between two numbers that differ only in a coefficient, and since 0.97b is smaller than b, the numerator is larger than the denominator.
the numerator falls by ninety seven percent of the share. the denominator falls by all of it. a denominator shrinking faster than its numerator produces a larger quotient. that is the mechanism, complete, with no second step.
what the result does not depend on
it does not depend on the size of the exit. a holder burning a hundred tokens and a holder burning half the supply produce the same inequality, only at different magnitudes. large exits raise the ratio more than small ones.
it does not depend on the size of the vault. v cancelled. an empty vault and a full one behave identically in ratio terms.
it does not depend on price, on volume, on anyone watching, on anyone being solvent, or on anyone behaving well. no participant has to do anything for the arithmetic to hold, because the arithmetic is not a behaviour. it is a division that the program performs and cannot decline to perform.
the boundary
at b equal to s the denominator is zero and the expression is undefined. that is the terminal case: the last holder burns the entire remaining supply and receives what is left of the vault. the program guards it, the ratio ceases to be defined, and nothing further happens. this is a real end state and it is described in limits.
the other two instructions
emit adds sol and adds supply. the ask is priced above the current ratio, always, so every emission brings in more backing per token than the existing average and the ratio rises or holds. it never dilutes, because a sale below fmd is not a price the instruction will accept.
sweep spends vault sol to buy tokens on the market and burns them in the same instruction. the vault falls by what was spent and the supply falls by what was bought. it is only permitted to execute when the market sits below fmd, which means it always pays less than the ratio for what it destroys. spending x to remove tokens worth more than x raises the ratio by the same logic as the exit fee.
three instructions, three ways for the numerator and denominator to move, and no combination of them that produces a smaller quotient. there is no fourth instruction, which is why this is a proof about the system and not just about redemption.
how to check it
read the vault balance and the mint supply from any explorer at two different slots and divide each pair. the second figure will not be smaller than the first. that check does not require reading the program, trusting this page, or believing anything written on it.
three instructions. there is no fourth.
that table is the security model. every path that removes sol from the vault also removes supply, and removes proportionally more of it. there is no instruction that takes sol out without burning claim against it, which is why the ratio cannot fall.
emit takes sol and releases supply. it is permissionless and anyone may call it.
supply is not on a schedule. there is no vesting, no drip, no epoch allocation, and no cliff. one ask price decays exponentially per slot and ratchets upward by a fixed multiple on every fill.
the ask is floored at the current ratio. the instruction will not sell below fmd, so every emission brings in at least as much backing per token as the existing average. emit cannot dilute.
the exponential is computed in fixed point, not floating point, because floats are not available and would not be deterministic across nodes if they were.
redeem burns tokens and pays out the proportional share of the vault, less three percent.
it is permissionless and unconditional. it does not check who is calling. it does not check when they acquired. it has no window, no queue, no cooldown, no maximum, and no minimum.
the payout is computed from the vault balance and the mint supply as they stand at the moment of the call, not from a stored figure, not from an oracle, and not from a cached snapshot.
redeem is what makes fmd a floor rather than a claim. because anyone can take the ratio at any time, a market price below it is an open arbitrage, and closing that arbitrage burns supply and raises the ratio again.
sweep is the only instruction the desk calls, and it is the only one with a condition attached.
it buys tokens on the market with vault sol and burns them before the instruction returns. the buy and the burn are one instruction, not two.
it only executes when the market price sits below fmd, checked in the program rather than assumed by the caller. it may spend up to two percent of the vault per interval, also enforced in the program.
what does not exist
no withdraw. no admin withdraw. no emergency withdraw. no fee setter. no parameter setter. no pause. no upgrade. no authority transfer. no mint. no freeze. no blacklist. no allowlist.
these are not absent by convention. they are absent from the instruction set, and the program has no upgrade authority, so they cannot be added.
cranks
emit and redeem are called by whoever wants them. sweep is called by the desk but is permissionless, so if the desk stops, anyone else may call it under the same conditions with the same limits. nothing in this system requires a specific party to be awake.
three instructions. there is no fourth.
that table is the security model. every path that removes sol from the vault also removes supply, and removes proportionally more of it. there is no instruction that takes sol out without burning claim against it, which is why the ratio cannot fall.
emit takes sol and releases supply. it is permissionless and anyone may call it.
supply is not on a schedule. there is no vesting, no drip, no epoch allocation, and no cliff. one ask price decays exponentially per slot and ratchets upward by a fixed multiple on every fill.
the ask is floored at the current ratio. the instruction will not sell below fmd, so every emission brings in at least as much backing per token as the existing average. emit cannot dilute.
the exponential is computed in fixed point, not floating point, because floats are not available and would not be deterministic across nodes if they were.
redeem burns tokens and pays out the proportional share of the vault, less three percent.
it is permissionless and unconditional. it does not check who is calling. it does not check when they acquired. it has no window, no queue, no cooldown, no maximum, and no minimum.
the payout is computed from the vault balance and the mint supply as they stand at the moment of the call, not from a stored figure, not from an oracle, and not from a cached snapshot.
redeem is what makes fmd a floor rather than a claim. because anyone can take the ratio at any time, a market price below it is an open arbitrage, and closing that arbitrage burns supply and raises the ratio again.
sweep is the only instruction the desk calls, and it is the only one with a condition attached.
it buys tokens on the market with vault sol and burns them before the instruction returns. the buy and the burn are one instruction, not two.
it only executes when the market price sits below fmd, checked in the program rather than assumed by the caller. it may spend up to two percent of the vault per interval, also enforced in the program.
what does not exist
no withdraw. no admin withdraw. no emergency withdraw. no fee setter. no parameter setter. no pause. no upgrade. no authority transfer. no mint. no freeze. no blacklist. no allowlist.
these are not absent by convention. they are absent from the instruction set, and the program has no upgrade authority, so they cannot be added.
cranks
emit and redeem are called by whoever wants them. sweep is called by the desk but is permissionless, so if the desk stops, anyone else may call it under the same conditions with the same limits. nothing in this system requires a specific party to be awake.
the desk is an agent with one decision. when the market sits below fmd, it buys and burns. that is the entire scope of its judgement.
it runs on an interval. every four hundred slots it reads the market price and the two account balances, compares them, and either calls sweep or does nothing. most intervals it does nothing, because most of the time the market is not below the ratio.
what it cannot do
it cannot withdraw. no instruction exists that moves sol out of the vault to an address, so there is no call for the desk to make and no key that would authorise one.
it cannot hold inventory. sweep buys and burns inside a single instruction. there is no recipient account in the struct, no transfer path, and no branch where tokens end up anywhere but destroyed.
it cannot buy above the ratio. the condition is checked in the program, not by the desk. a call submitted when the market is above fmd fails.
it cannot spend freely. the cap is two percent of the vault per interval, enforced in the program.
it cannot pause, upgrade, set parameters, mint, freeze, or change any figure on this site. none of those instructions exist and the authority to add them was burned at deployment.
the compromise case
assume the desk's key is stolen tomorrow. the attacker has one instruction available and it is bounded on both sides. the worst available action is to call sweep repeatedly at the cap whenever the market is below the ratio, buying tokens and burning them.
that raises fmd.
the attack is arithmetically indistinguishable from the intended behaviour. a hostile desk and a diligent one do the same thing, and the difference is only in how often.
why it exists at all
it does not need to. redeem raises the ratio without it. emit raises the ratio without it. if the desk went offline permanently the system would continue to behave exactly as described everywhere else on this site.
sweep is also permissionless. the desk holds no privileged position on it. if the desk stops, anyone may call it, under the same conditions and the same cap.
it exists because a discount to backing is an opportunity that should be taken, and something has to be awake to take it. it was given the smallest amount of power that lets it do that and nothing beyond.
failed reads
when the desk fails to read an account, the failure is recorded as a failure. it is not retried, not smoothed, and not backfilled with the last known value. the row keeps an em dash where the figures would be.
a record that quietly substitutes a stale value for one it did not obtain is worth less than a record with visible holes in it, because a reader cannot tell the difference between the two afterwards. the holes stay.
the desk is an agent with one decision. when the market sits below fmd, it buys and burns. that is the entire scope of its judgement.
it runs on an interval. every four hundred slots it reads the market price and the two account balances, compares them, and either calls sweep or does nothing. most intervals it does nothing, because most of the time the market is not below the ratio.
what it cannot do
it cannot withdraw. no instruction exists that moves sol out of the vault to an address, so there is no call for the desk to make and no key that would authorise one.
it cannot hold inventory. sweep buys and burns inside a single instruction. there is no recipient account in the struct, no transfer path, and no branch where tokens end up anywhere but destroyed.
it cannot buy above the ratio. the condition is checked in the program, not by the desk. a call submitted when the market is above fmd fails.
it cannot spend freely. the cap is two percent of the vault per interval, enforced in the program.
it cannot pause, upgrade, set parameters, mint, freeze, or change any figure on this site. none of those instructions exist and the authority to add them was burned at deployment.
the compromise case
assume the desk's key is stolen tomorrow. the attacker has one instruction available and it is bounded on both sides. the worst available action is to call sweep repeatedly at the cap whenever the market is below the ratio, buying tokens and burning them.
that raises fmd.
the attack is arithmetically indistinguishable from the intended behaviour. a hostile desk and a diligent one do the same thing, and the difference is only in how often.
why it exists at all
it does not need to. redeem raises the ratio without it. emit raises the ratio without it. if the desk went offline permanently the system would continue to behave exactly as described everywhere else on this site.
sweep is also permissionless. the desk holds no privileged position on it. if the desk stops, anyone may call it, under the same conditions and the same cap.
it exists because a discount to backing is an opportunity that should be taken, and something has to be awake to take it. it was given the smallest amount of power that lets it do that and nothing beyond.
failed reads
when the desk fails to read an account, the failure is recorded as a failure. it is not retried, not smoothed, and not backfilled with the last known value. the row keeps an em dash where the figures would be.
a record that quietly substitutes a stale value for one it did not obtain is worth less than a record with visible holes in it, because a reader cannot tell the difference between the two afterwards. the holes stay.
everything else on this site describes what the system does. this describes what it does not do, and where holding it can lose you money.
the ratio is denominated in sol
fmd is a quantity of sol per token. it is not a quantity of dollars. if sol falls fifty percent, the ratio is unchanged and what it is worth has halved.
this is a ratio, not a hedge. nothing here protects against the vault asset itself declining, and nothing is designed to. every figure published on this site is an amount of sol, and any conversion to another unit happens outside this system and carries all of that unit's risk.
three percent is real
it is not a fee that gets waived, rebated, or refunded. a round trip in and out loses it in full.
the retention is the mechanism. the mechanism is therefore paid for entirely by people who use the exit, and it is paid to the people who do not. if you buy and sell you are on the paying side of that transfer. this is stated plainly because it is the cost of the thing that makes the rest of the system work, and it is not small.
a large exit raises the ratio and shrinks the pool
both are true at once and only one of them is comfortable.
a redemption that removes a third of the supply raises fmd for everyone remaining and leaves a vault a third smaller. the claim per token went up. the total amount of sol available to claim went down. someone holding through a wave of exits ends up with a higher ratio against a pool that may no longer be deep enough to matter at the size they hold.
the arithmetic does not distinguish between a healthy system and a draining one. it only reports the quotient.
the ratio can sit still indefinitely
nothing forces fmd to rise on a schedule. if nobody buys and nobody sells, the number does not move. long flat stretches are the expected shape of this record, not a malfunction. the guarantee is directional, not about rate, and a system that never sees another transaction has a ratio that never changes again.
fmd also started near zero. the claim is not that it is high.
the market can trade below the ratio for a long time
the exit makes a discount to backing an arbitrage, but it does not make it instant. someone has to notice and act. the desk is capped at two percent of the vault per interval and may be offline. a token can trade under its own backing for as long as nobody bothers, and there is no mechanism that forces convergence within any particular window.
the terminal state
if every token is redeemed, the vault empties and the final redeemer takes the remainder. the program then holds nothing, does nothing, and continues to exist as an account that no longer has anything to compute.
this is a valid ending rather than a failure. the system is a slow transfer from those who leave to those who stay, and if everyone leaves, the last one out collects what the others paid on the way. that is not a bug in the design, it is the design followed to its end.
what immutability does not cover
the program cannot change. that is a claim about the executable and nothing else.
it does not mean the code is correct. an immutable program with a bug is immutably wrong, and there is no path to fix it. it does not mean the deployed bytes match any published source; establishing that requires a reproducible build and is a separate exercise. it does not mean anything about the market, the venue the desk trades on, the rpc that serves this page, or the network itself.
immutability removes one category of risk, which is discretionary change, and leaves every other category exactly where it was.
what this site is
a view of accounts that exist elsewhere. it computes the ratio in the browser from balances it reads, so it cannot show a figure the accounts disagree with, but it can be down, stale, or wrong about anything it did not compute. the accounts are the record. this is a rendering of it.
everything else on this site describes what the system does. this describes what it does not do, and where holding it can lose you money.
the ratio is denominated in sol
fmd is a quantity of sol per token. it is not a quantity of dollars. if sol falls fifty percent, the ratio is unchanged and what it is worth has halved.
this is a ratio, not a hedge. nothing here protects against the vault asset itself declining, and nothing is designed to. every figure published on this site is an amount of sol, and any conversion to another unit happens outside this system and carries all of that unit's risk.
three percent is real
it is not a fee that gets waived, rebated, or refunded. a round trip in and out loses it in full.
the retention is the mechanism. the mechanism is therefore paid for entirely by people who use the exit, and it is paid to the people who do not. if you buy and sell you are on the paying side of that transfer. this is stated plainly because it is the cost of the thing that makes the rest of the system work, and it is not small.
a large exit raises the ratio and shrinks the pool
both are true at once and only one of them is comfortable.
a redemption that removes a third of the supply raises fmd for everyone remaining and leaves a vault a third smaller. the claim per token went up. the total amount of sol available to claim went down. someone holding through a wave of exits ends up with a higher ratio against a pool that may no longer be deep enough to matter at the size they hold.
the arithmetic does not distinguish between a healthy system and a draining one. it only reports the quotient.
the ratio can sit still indefinitely
nothing forces fmd to rise on a schedule. if nobody buys and nobody sells, the number does not move. long flat stretches are the expected shape of this record, not a malfunction. the guarantee is directional, not about rate, and a system that never sees another transaction has a ratio that never changes again.
fmd also started near zero. the claim is not that it is high.
the market can trade below the ratio for a long time
the exit makes a discount to backing an arbitrage, but it does not make it instant. someone has to notice and act. the desk is capped at two percent of the vault per interval and may be offline. a token can trade under its own backing for as long as nobody bothers, and there is no mechanism that forces convergence within any particular window.
the terminal state
if every token is redeemed, the vault empties and the final redeemer takes the remainder. the program then holds nothing, does nothing, and continues to exist as an account that no longer has anything to compute.
this is a valid ending rather than a failure. the system is a slow transfer from those who leave to those who stay, and if everyone leaves, the last one out collects what the others paid on the way. that is not a bug in the design, it is the design followed to its end.
what immutability does not cover
the program cannot change. that is a claim about the executable and nothing else.
it does not mean the code is correct. an immutable program with a bug is immutably wrong, and there is no path to fix it. it does not mean the deployed bytes match any published source; establishing that requires a reproducible build and is a separate exercise. it does not mean anything about the market, the venue the desk trades on, the rpc that serves this page, or the network itself.
immutability removes one category of risk, which is discretionary change, and leaves every other category exactly where it was.
what this site is
a view of accounts that exist elsewhere. it computes the ratio in the browser from balances it reads, so it cannot show a figure the accounts disagree with, but it can be down, stale, or wrong about anything it did not compute. the accounts are the record. this is a rendering of it.