Risks
Every risk below is stated with what actually mitigates it, what residual remains, and — the column that matters — whether the mitigation is proved, implemented, contracted, or merely intended. A mitigation that is only intended is not a mitigation yet.
The instrument-level detail is on the first facility; the default sequence is on default and workout; parameter authority is on governance.
Concentration — read this before the tables
The single largest risk is not in any table below, because it is structural rather than contingent. At launch, sdrUSD exposure is not diversified.
One vehicle per facility is a legal requirement, not a preference — pooling triggers the fund regime, as /spv sets out. The consequence is that early holders are exposed to one obligor group, one commodity, one refinery and one custody chain, with no portfolio effect to absorb an idiosyncratic failure.
Everything the protection stack does — insurance, monitoring, the collateral pool, the waterfall — mitigates severity. None of it mitigates concentration. A single obligor failing is not a tail scenario in this structure; it is the scenario.
Two things would change this materially, and neither has happened: additional facilities actually closing, and a published concentration policy stating the maximum share of the reserve any one obligor, commodity or jurisdiction may represent. No such policy exists yet.
Credit and collateral
| Risk | Mitigation | Status | Residual |
|---|---|---|---|
| Borrower fails to pay | Metal collateral, monitored pool, senior ranking, counter-indemnity | Contracted (facility docs) | Recovery depends on realising metal at liquidation value, not NAV |
| Same collateral pledged twice | Second pledge over pledged stock refused at the state layer | Proved (whr_double_pledge_rejected) | Only binds state the system controls; a pledge granted outside it is a documentary problem |
| Collateral does not exist | Pledge over non-existent stock refused | Proved (whr_phantom_stock_pledge_rejected) | Depends on the attestation that the goods exist — an attested fact, not a proved one |
| Short or wrong delivery | Delivery of less than the specified quantity discharges nothing | Proved (pp_short_cargo_rejected) | |
| Collateral value falls | Advance rate below collateral value; the remainder is haircut | Implemented in the borrowing base | The haircut is uncalibrated — no field ties it to observed liquidation experience |
| Metal lost in transit or storage | Cargo and specie cover | Contracted | Covers goods, not borrower default — a distinction that is routinely blurred |
The protection stack, and its limits
| Risk | Mitigation | Status | Residual |
|---|---|---|---|
| Loss exceeds recovery | Layered protection cannot pay more than was lost, and the same loss cannot be recovered twice | Proved (stacked_protection_le_loss, no_double_recovery) | |
| Insurer does not pay | Reinsurance behind the fronting carrier | Contracted | The policy is narrower than the marketing. The first-tranche policy names a different insured and a smaller insured amount than the deck describes, and policy rights cannot be assigned without the leading insurer's approval. Loss-payee status needs an approved endorsement. Treat direct holder recourse as not granted until an endorsement exists |
| Claim paid, but late | — | — | Unmitigated and material. A 90-day waiting period reduces ultimate credit loss while leaving a severe short-term liquidity hole. The delay is carried in the model and proved to be read by nothing (eval_arch_ignores_unmodeled_params) — it is excluded, not solved |
Liquidity
| Risk | Mitigation | Status | Residual |
|---|---|---|---|
| Redemption demand exceeds available cash | 30-day primary queue matched to the facility cycle; treasury buffer; secondary pool | Implemented (queue, buffer) | The secondary pool is not a redemption right. It can trade below NAV, and its depth is supplied by a party that can withdraw |
| Depositor believes exit is instant | Primary redemption is the queue; the pool is a market | Documented | Marketing language elsewhere has described this as instant exit. It is not |
| Liquidity provider withdraws | Modelled as the evaporation shock, with the provider as a named player | Proved (the shock has an agent, not just a magnitude) | Retainer required to hold depth is unverified — held at zero rather than invented |
| Solvency mistaken for liquidity | Scored as separate conjuncts throughout | Implemented | A solvent portfolio can still fail on a maturity mismatch |
Economic
| Risk | Mitigation | Status | Residual |
|---|---|---|---|
| The margin is not achievable | Ceiling searched exhaustively and proved | Proved (deck_ceiling_band) | The 4.5% target needs a 12.62% borrower alternative — above the 9–12% the deck's own facility page states. See economics |
| The trade does not finance itself | Frontiers published rather than inputs tuned | Proved (modest_pipeline_breaks_participation) | At 1% margin on a 30-day cycle it fails outright; the sourced worked deal clears with 2.3× cover. Which regime the operator is in is unmeasured |
| Leverage flatters the numbers | Real deployed capital reported separately from TVL | Proved (loop_creates_reserve_not_financing) | A loop past originated capacity dilutes the yield — see the simulation |
| Originated capacity runs out | Capacity stated to exceed the programme | Asserted by the deck | Not independently verified here |
Legal and regulatory
| Risk | Mitigation | Status | Residual |
|---|---|---|---|
| The token is an unlicensed fund | One vehicle per facility; passive SPV; debenture, not a pooled interest | Proved conditional (spvNoteRouteStatus) | Classification turns on substance. Calling the vehicle passive does not make it so |
| The pooled route is used by accident | Pooled route evaluates to provedInfeasible, naming the missing permission | Proved | |
| Reasoning from law we have not read | The engine cannot return a favourable verdict from an unsourced rule | Proved (eval_unsourced_never_feasible) | |
| The law changes | Certificates bound to the old text are provably stale | Proved (material_legal_change_stales_compliance_certificate) | Detection is mechanical; re-sourcing is manual |
| Fund-side (pooled) route | Not used; one vehicle per facility instead | Proved (sdrusd_route_after_fetch) | The pooled route is provedInfeasible on a named missing permission. Using it would require a fund-manager permission nobody holds |
| Secondary transfer | — | — | Open. Do not assume permissionless transfer; whitelisting and venue treatment must be cleared |
| No authorisation exists | — | — | Open. No FSRA authorisation has been sought |
Technical
| Risk | Mitigation | Status | Residual |
|---|---|---|---|
| NAV booked without cash | Transfer precedes accrual; invariant nav() <= backing() on the intended path | Implemented and tested | This bug existed and was caught by a full-cycle test, not by review |
| Settlement replayed | Occurrence booked at most once | Implemented and tested | |
| Contract defect | 24 tests, each naming the theorem or provision it discharges | Implemented | No third-party audit. Nothing deployed. No fuzzing — tests are example-based |
| Formalization is vacuous | The commitment layer was found uninhabited — every theorem true, every one empty — and rebuilt | Fixed, and the method retained | This is the failure mode proofs are most exposed to. It was found by attacking our own formalization; it would not have been found by review |
| Proved ≠ safe | Only deterministic rules are proved; facts are attested and legal conclusions documented | Documented | A verified protocol can still lose money. Correctness is not judgment |
The honest summary
Four things would most plausibly cause an allocator real loss, ranked:
- The insurance is thinner than described. Named insured, insured amount and assignability are not what the marketing implies. This is the largest single gap between claim and document in the whole package.
- The 90-day claim delay is a liquidity event that the model explicitly excludes rather than solves.
- The margin target may be unreachable inside the deck's own stated yield band, so the retained economics could be materially thinner than planned.
- Nothing is live. No deployment, no audit, no authorisation, no attestor — so none of the operating controls has ever run under load.
What would change our mind
We would treat the design as validated when: an attestor and auditor are engaged and publishing; an FSRA route is granted rather than argued; the insurance endorsement naming the intended beneficiary exists; a third-party audit of the contracts is complete; and the operator's actual margin and cycle length are measured rather than assumed.
Until then the correct description of this documentation is a specification with proofs, not a track record.