Backtesting and Validation
This page reports the current validation evidence for Cardinal's launch model: historical replay, stress simulation, product-specific test vectors, charting-tool parity.
Scope
| Dimension | Current launch scope |
|---|---|
| Products | Carry Perp and Negative Rate Hedge |
| Markets | sUSDe<>USDT, wstETH<>WETH; plus weETH<>WETH, rsETH<>WETH (new ETH markets on the shared wstETH pool) |
| LP architecture | LP-intermediated pools; the three ETH markets (wstETH, weETH, rsETH) share one wstETH pool |
| Market data | Aave V3 historical lending, borrow-rate, and loop-yield data |
| Product charting data refresh | Through June 3, 2026 |
Launch Parameters
These constants are fixed at launch. Values are shown per market; the evidence that justifies each group follows the table.
Negative Rate Hedge
| Parameter | sUSDe | wstETH |
|---|---|---|
Expected Claim Rate expected_claim_rate | 0.249% | 0.218% |
LP Profit Factor lp_profit_factor | 0.50 | 0.50 |
| Premium basis | expected negative-carry claims × (1 + lp_profit_factor) / 0.90 | expected negative-carry claims × (1 + lp_profit_factor) / 0.90 |
Coverage leverage L | 1x–10x | 1x–10x |
| Premium routing (LP / treasury) | 90% / 10% | 90% / 10% |
| Payout ramp to full coverage | 30 days | 30 days |
Each tick the buyer pays the actuarially-fair cost of the coverage they hold,
expected negative-carry claims × (1 + lp_profit_factor) / 0.90, which scales with coverage leverage
L and is charged continuously while the policy is open (expected_claim_rate × L × (1 + lp_profit_factor) / 0.90 is a calm-window floor reference; expected_claim_rate is set per market from how often that
market's loop carry has historically gone negative). The previous current-carry
band is not used as a hard launch pricing cap because it can underprice policies
exactly when negative-carry claims are being generated. Pricing the premium to
expected claims plus a load keeps the LP underwriting margin positive after the
90/10 LP/treasury split. lp_profit_factor is defined LP-net: with lp_profit_factor = 0.5 the LP retains a +50% margin over expected claims after the 10% treasury
routing, so the buyer-gross premium is expected claims × (1 + lp_profit_factor) / 0.90. In the Track C historical replay the LP's net
insurance result was positive in both markets (+2.31% sUSDe / +0.93%
wstETH). Coverage leverage, the 90/10 routing, and the 30-day ramp were
exercised by nine launch test vectors (tv10–tv18), all passing with zero
invariant breaches, i.e. the policy accounting never broke its rules: a
policy's payout buffer never went negative, cumulative payouts never exceeded
the yield credited into that buffer, and gas tanks never went negative.
Carry Perp
| Parameter | sUSDe | wstETH |
|---|---|---|
| Global notional cap | $76.8M | $322.6M |
Shadow-drawdown scale s_L | 65 | 65 |
| Launch top tier | 5000x | 15000x |
| Performance fee | 35% | 35% |
| Liquidation triggers | equity < 5% of deposit, or shadow drawdown ≥ deposit | (same) |
| Entry fee | max(0, carry) × notional / (365.25 × 24) | (same) |
Build Plan V3 sets s_L = 65 at launch for both markets (raising wstETH from the
PR38 60 to match sUSDe). The launch-tier calibration establishes the kill gradient,
every position eventually liquidates (a 2–3 day median life at the top tier), with
the LP net positive per cycle.
LP pool
| Parameter | sUSDe | wstETH |
|---|---|---|
| Loop leverage | 5 loops (3.05×, 75% LTV) | 5 loops (4.34×, 93% E-Mode) |
| Pause / resume threshold (NAV drawdown) | 10% / 3% | 10% / 3% |
The pool runs a fixed 5 loops (five supply tranches at each market's LTV),
which sets effective leverage at 3.05× (sUSDe) and 4.34× (wstETH); at these
settings the historical replay earned a mean loop APR of 10.97% / 5.16%.
Leverage is quoted as effective × because the same loop count yields different
leverage at different LTVs. The pool deliberately does not loop further: each
additional loop adds gas, slippage, and liquidation-proximity risk, so users who
want more leverage take it synthetically through the Carry Perp rather than the LP
running a riskier loop. The pool auto-deleverages if peak-to-trough NAV falls past
10% and redeploys once it recovers to within 3%.
weETH and rsETH run the same WETH-borrow loop on the shared wstETH pool. In
the current rate regime their loop carry is thin (LST staking ≈ WETH borrow, the
same near-zero spread wstETH shows recently), so the loop-yield contribution is
minimal and any restaking-points / airdrop value is excluded from these figures.
The markets' value is hedge demand (Negative Rate Hedge) and synthetic leverage
(Carry Perp); the main added risk is shared-pool concentration across three
correlated ETH LSTs borrowing the same WETH. Full shared-pool validation
(capacity and correlated-depeg stress) is in progress
(labs/product_calculator/new_markets_tier1_2026-06-25.py).
Actor Outcomes
Projected profit/loss by actor across three regimes. LP and Carry-Perp cells are drawn from the replay / stress / calibration tables; the Hedger cells use the current cost-covering premium and the replay claim rows.
| Actor | Benign (rates stay positive) | Negative-rate event | Severe depeg |
|---|---|---|---|
| LP | integrated launch-scope ROE (loop gross + NRH net + Carry Perp genuine cash): +11.33% / +7.02% | +10.15% sUSDe / -2.31% wstETH annual ROE (full-config stress) | breach risk (-6.29% wstETH at a 20% depeg) |
| Hedger | pays the streaming premium, collects ~nothing → net cost ≈ premium | the policy pays out → net gain | orderly settlement, forced-close, 0 LP breaches |
| Carry-perp user | negative expected value (the LP captures $159.95 / $186.59 per $100 deposit); ~10% (sUSDe) to ~19% (wstETH) ever peak above 2x before liquidation | rational users are not expected to open new Carry Perp positions into negative carry | unaffected, separate margin |
Hedger sizing example. In the current sUSDe charting replay, a
$1M-notional policy at L = 5 prices near $28.6k/yr under the
LP-net expected-claims × (1 + lp_profit_factor) / 0.90 formula. In a mature 30-day stretch where
carry sits near −2%, that same policy receives on the order of $8k in claims
before buffer constraints, so the buyer is net-positive over the event and
net-cost in calm periods.
Executive Summary
| Area | Result |
|---|---|
| LP return view | Integrated launch-scope LP ROE = loop yield (gross) + NRH (net of claims) + Carry Perp genuine cash edge: sUSDe 11.33%, wstETH 7.02%. Carry Perp uses the LP's direct synthetic cash P&L (deposit kept on liquidation; the accrued carry and perf fee inside the captured equity are paper MTM, never cash). Legacy Track C decomposition (7.44% / 3.13%) retained below for provenance. |
| Carry Perp calibration | 5,000 trials per launch tier; day-2 liquidation: 68.80% sUSDe and 41.80% wstETH; LP net per $100 user deposit: $159.95 sUSDe and $186.59 wstETH |
| Negative Rate Hedge validation | 9 launch-scope test vectors passed; 9 replay rows produced 0 simulator-enforced invariant breaches; 144 pricing-study runs produced 0 invariant-breach forms |
| Stress simulation | 11 scenarios x 20 trials x 2 markets; historical-bootstrap rows show 0% breach rates; depeg, drift, and sustained-negative-carry rows identify launch-control cases |
Confidence levels classify current evidence coverage and remaining implementation work.
| Confidence area | Current confidence | Basis | Remaining validation |
|---|---|---|---|
| Historical replay outputs | Medium for launch-scope LP projection, high for source artifact integrity | committed replay artifacts, schema checks, hash verification, and per-pool result tables | fresh Build Plan V3 two-product replay and final benchmark ratification |
| Product accounting invariants | High for launch-scope simulator cases | 9/9 Negative Rate Hedge test vectors passed; 0 invariant breaches across replay rows | contract-level implementation tests |
| Carry Perp launch calibration | High for replayed launch tiers | 5,000 trials per tier and positive LP net per cycle in both launch markets | live rollout monitoring against waitlist demand and LP capacity |
| Stress characterization | Medium-high for scenario measurement | 440 total scenario trials across both markets and explicit breach-rate reporting | production control validation for depeg, drift, and emergency paths |
| Production launch readiness | Medium until pre-launch items close | replay, stress, and simulator evidence is available; implementation evidence remains open | hourly production carry/TWAP validation, external audit, governance parameter bounds, operational controls, user disclosures, force-close-on-Emergency logic, wstETH depeg-ladder parameterization |
Validation Summary
| Evidence surface | Count / sample | Result recorded |
|---|---|---|
| Historical LP replay | 2 launch pools | 0 historical LP principal breaches |
| Stress simulation | 11 scenarios x 20 trials x 2 markets | breach rates reported by scenario below |
| Carry Perp calibration | 5,000 trials per launch tier | positive LP net per cycle in both launch markets |
| Negative Rate Hedge test vectors | 9 launch-scope vectors | 9 pass / 0 fail |
| Negative Rate Hedge replays | 9 replay rows | 0 simulator-enforced invariant breaches |
| Pricing study | 144 pricing runs | 0 invariant-breach forms |
Historical LP Replay
Historical replay runs the launch configuration against observed Aave V3 rate paths. ROE is annualized LP return on equity. The integrated LP return is the sum of three separate cash streams, each counted exactly once:
- Loop yield (gross): carry the LP earns on its own deployed capital.
- Negative Rate Hedge: premium net of claims (cost-covering, LP-net after the 90/10 split).
- Carry Perp: genuine cash edge, recomputed from the LP's direct synthetic cash P&L, not a broad fee fraction: the LP keeps a liquidated user's deposit and returns the equity of the rare horizon survivors. A position's accrued carry and its perf fee live inside that equity and are the LP's short-side paper MTM (the LP is counterparty to the user's leveraged carry bet); that MTM is extinguished at the kill and is never LP cash, so it is excluded. It is also not loop carry, so there is no loop double-count. At ~100% liquidation the genuine cash ≈ the forfeited deposit.
This is why the combined is neither the naive sum of the gross bars (which would
double-count the paper MTM) nor a loop-net subtraction (which over-removes loop
carry the LP keeps). The mean loop APR (10.97% / 5.16%) is the raw loop
return over the Track C window; the launch loop leg below is the charting-tool
rolling-year loop yield.
| Pool | Venue days | Replay days | Paused days | Mean loop APR | Integrated LP ROE | Max drawdown | LP principal breaches |
|---|---|---|---|---|---|---|---|
| sUSDe | 597 | 297 | 0 | 10.97% | 11.33% | -1.13% | 0 |
| wstETH | 1,111 | 811 | 0 | 5.16% | 7.02% | -0.45% | 0 |
Integrated LP ROE by stream (annualized contribution). Carry Perp is the genuine
cash edge = the Carry Perp anchor × the direct-cash ratio genuine_cash / (fee + capture), where genuine_cash is the deposit kept on liquidation net of survivor
payouts (the accrued carry and perf fee inside the captured equity are paper MTM):
sUSDe 3.17% × 0.625 = 1.98%; wstETH 1.83% × 0.536 = 0.98%.
| Pool | Loop yield (gross) | Negative Rate Hedge | Carry Perp (genuine cash) | Integrated LP ROE |
|---|---|---|---|---|
| sUSDe | 7.71% | 1.63% | 1.98% | 11.33% |
| wstETH | 4.32% | 1.72% | 0.98% | 7.02% |
These contributions are LP-net of the 10% treasury routing. Idle-cash drag was
negligible (0 paused days in both replays) and realized defaults were zero (the
0 LP principal breaches recorded above). Operating costs beyond the treasury
split are not modeled here.
Legacy Track C anchor decomposition is preserved below for provenance. It uses older Track C product anchors and excludes the non-launch perpetual-spread-options line from launch scope. Full-config is shown only for reference.
| Pool | Track C loop-net leg | Negative Rate Hedge | Carry Perp | Transitional launch-scope estimate | Perpetual spread options (non-launch) | Full-config ROE |
|---|---|---|---|---|---|---|
| sUSDe | 2.62% | 2.31% | 2.51% | 7.44% | 16.97% | 24.41% |
| wstETH | 1.29% | 0.93% | 0.91% | 3.13% | 7.17% | 10.30% |
This applies the 2026-06-08 decisions: NRH lp_profit_factor is LP-net after the
treasury split, NRH capacity is the entitlement-share rule (not the Track C
operating anchor), and the Carry Perp leg is the genuine cash edge (paper MTM
stripped). The integrated engine sums the three streams once each, so the
loop↔Carry-Perp double-count and the loop-net over-subtraction are both resolved.
A full two-product replay would still tighten the Carry Perp genuine-cash fraction
and the (negligible at ~100% liquidation) horizon-survivor adjustment.
Pool P&L below is full-config (it includes the non-launch perpetual-spread line); the transitional launch-scope pool P&L is the Negative Rate Hedge + Carry Perp + loop-yield columns.
| Pool | Cumulative written | Outstanding at end | Pool P&L (full-config) | Treasury accrued |
|---|---|---|---|---|
| sUSDe | $326.8M | $96.8M | $1.99M | $196.9K |
| wstETH | $874.9M | $82.8M | $2.29M | $222.3K |
| Pool | Perpetual spread P&L (non-launch) | Negative Rate Hedge P&L | Carry Perp P&L | Loop-yield P&L |
|---|---|---|---|---|
| sUSDe | $1.38M | $187.9K | $203.9K | $213.5K |
| wstETH | $1.59M | $206.4K | $201.4K | $286.8K |
Capacity and Pool Size
LP ROE does not hold flat as the pool grows
(labs/product_calculator/capacity_curve_2026-06-25.py). Two saturations act
together:
- Loop leg. The pool runs the Aave V3 loop, borrowing USDT (
2.05×TVL, sUSDe) or WETH (3.34×TVL, wstETH). That borrow raises the reserve's utilization and variable borrow rate, compressing loop carry. The rate is modeled with the Aave two-slope kink IRM anchored to current depth (slope1set to reproduce today's rate;slope2from the reserve's own above-kink history; supply held fixed, which is conservative). At current depth (USDT$3.6Bsupplied at~80%utilization, WETH$5.5Bat~89%) the loop can deploy at most~$269M(sUSDe) and~$100M(wstETH) at full launch leverage before utilization reaches95%. - Negative Rate Hedge and Carry Perp legs. These are funded by user demand,
not by pool size, so their per-NAV contribution scales as
ref × (REF_TVL / TVL)(demand-bounded; pessimistic if demand grows with the protocol).
LP ROE versus pool TVL, anchored to the $10M integrated headline:
| Pool TVL | sUSDe ROE | wstETH ROE |
|---|---|---|
$10M | 11.3% | 7.0% |
$50M | 8.2% | 3.9% |
$100M | 7.5% | 2.3% |
$250M | 0.8% | ~0% |
$500M+ | loop past ceiling | loop past ceiling |
The demand-bounded legs fall fastest at small size; loop compression dominates near the ceiling. The wstETH pool saturates earlier because it borrows more per unit TVL into a WETH market already near its utilization kink. Beyond these sizes the pool must lower loop leverage, trading yield for capacity, or cap deposits.
Carry Perp Calibration
Window note. These figures come from the launch charting-tool calibration: the Carry Perp Monte Carlo runs on each market's realized loop carry through 2026-06-03, at the Build Plan V3 launch
s_L = 65for both markets. They match the same configuration the interactive charting tool exposes (link above), so the numbers here are what reviewers see live. The carry series is the realistic loop spread (lst_yield − borrow), which includes the historical negative-rate days.
Carry distribution inputs:
| Market | Data window | Carry days | Mean carry | Median carry | Min carry | Positive-day share | Inactive negative-entry share |
|---|---|---|---|---|---|---|---|
| sUSDe | 2024-07-28 to 2026-06-03 | 676 | 1.00% | 0.82% | -21.19% | 69.82% | 30.18% |
| wstETH | 2023-03-01 to 2026-06-03 | 1,191 | 0.50% | 0.43% | -19.52% | 92.36% | 7.64% |
Launch-tier simulation outputs:
| Market | Launch tier | s_L | Trials | Total liquidation | Day-2 liquidation | Median liquidation | Crossed 2x before liquidation |
|---|---|---|---|---|---|---|---|
| sUSDe | 5000x | 65.0 | 5,000 | 100.00% | 68.80% | 2 days | 10.44% |
| wstETH | 15000x | 65.0 | 5,000 | 100.00% | 41.80% | 3 days | 18.88% |
s_L = 65 is held common across both markets per Build Plan V3. The PR38-era
≥ 60% day-2 liquidation aspiration is met at sUSDe (68.80%) but not wstETH
(41.80%, 3-day median); wstETH's slower kill gradient is the consequence of
the common V3 s_L; every position still fully liquidates and the LP is net
positive per cycle.
LP economics per $100 user deposit, over a position's full lifecycle (a 2–3 day
median to liquidation), from the 5,000-trial calibration on each market's carry
distribution shown above:
| Market | LP fee | LP liquidation capture | LP net |
|---|---|---|---|
| sUSDe | $21.24 | $138.70 | $159.95 |
| wstETH | $30.38 | $156.21 | $186.59 |
Adversarial Carry Perp Trader
The calibration above holds every position to liquidation or horizon. Because the
LP's Carry Perp cash edge is the deposit kept on liquidation, a trader who closes
a winning position early withdraws equity the LP would otherwise have captured.
Re-running the calibration under three exit policies, with entry sampling, leverage,
s_L, and the carry series held identical
(labs/product_calculator/adversarial_trader_2026-06-25.py), measures that
channel. The ride baseline reproduces the calibration (100% liquidation;
day-2 68.8% / 41.8%; peaked-2× 10.4% / 18.9%).
LP cash per $100 deposit, per cycle (fees + deposit − payout):
| Exit policy | sUSDe | wstETH |
|---|---|---|
ride: hold to liquidation (baseline) | $121 | $130 |
profit_take at 2×: realistic, no foresight | $96 | $87 |
clairvoyant: perfect exit timing | −$19 | −$29 |
A plain 2× take-profit rule cuts the LP's per-cycle Carry Perp cash by 21%
(sUSDe) and 33% (wstETH), trimming the Carry Perp contribution to integrated
LP ROE from 1.98% → 1.56% and 0.98% → 0.65%. Perfect-information exit
timing drives the LP's Carry Perp cash negative; the leg's positive economics
depend on traders not timing exits. The loop-yield and Negative Rate Hedge legs
are unaffected, so integrated LP ROE stays positive (~10.9% / ~6.7% under the
realistic rule), but the Carry Perp edge is the fragile component.
Stress Simulation
Stress simulation parameters:
| Parameter | sUSDe | wstETH |
|---|---|---|
| Scenarios | 11 | 11 |
| Trials per scenario | 20 | 20 |
| Days per trial | 800 | 800 |
| Scenario trials | 220 | 220 |
| Pause threshold | 10% | 10% |
| Resume threshold | 3% | 3% |
| R1 percentile | 90% | 90% |
| R5 fee routing | 20% | 20% |
| R5 target fraction | 15% | 15% |
Breach rate is the share of the 20 trials in a scenario with at least one LP principal-breach event.
| Scenario | sUSDe mean ROE | sUSDe mean DD | sUSDe breach rate | wstETH mean ROE | wstETH mean DD | wstETH breach rate |
|---|---|---|---|---|---|---|
| historical_bootstrap | 10.81% | -1.98% | 0% | 5.04% | -0.87% | 0% |
| fat_tail_2x | 12.38% | -1.91% | 0% | 5.10% | -0.92% | 5% |
| fat_tail_5x | 17.78% | -1.49% | 0% | 6.27% | -0.77% | 5% |
| fat_tail_10x | 25.95% | -2.26% | 30% | 9.25% | -0.64% | 5% |
| regime_shift_mid | 11.39% | -9.25% | 35% | 5.50% | -4.16% | 20% |
| sustained_neg_carry_30d | 10.63% | -2.29% | 0% | 5.05% | -1.40% | 5% |
| sustained_neg_carry_90d | 10.15% | -1.86% | 0% | -2.31% | -9.08% | 100% |
| sudden_depeg_10pct | 4.50% | -6.67% | 100% | -3.00% | -9.55% | 100% |
| sudden_depeg_20pct | 2.23% | -8.42% | 100% | -6.29% | -12.94% | 100% |
| sudden_depeg_30pct | 0.29% | -9.64% | 100% | -8.92% | -16.54% | 100% |
| slow_drift_180d | 8.11% | -3.47% | 65% | -4.74% | -9.54% | 100% |
What a breach measures
A breach in these tables is a per-policy event: a single Negative Rate
Hedge policy pays out more than it collected, so that policy's own book turns
negative. It is not a loss of LP principal. Payouts are bounded by available
pool NAV, so LP principal is never drawn to honor a policy; the pool absorbs the
shortfall from loop yield and the rest of the book.
Read that way, the depeg column is the hedge doing its job. A depeg is exactly
when the Negative Rate Hedge is meant to pay, so across the ladder (10% /
20% / 30%) at least one policy pays out in every trial and the breach rate
sits at 100%. The cost shows up as margin compression, not principal loss: in
those same trials the LP pool stays net-positive (+4.5% / +2.2% / +0.3%
ROE on sUSDe) with peak-to-trough drawdown inside the 10% pause band (6.7% /
8.4% / 9.6%). The historical replay records 0 such events; they appear
only under the synthetic depeg shocks. wstETH also reaches 100% under
sustained_neg_carry_90d and slow_drift_180d; sUSDe stays at 0% through the
sustained-negative-carry rows.
The bounds that keep principal whole are specified elsewhere on this page:
pool-bounded payouts, the 10% / 3% NAV pause-and-deleverage gate, and
emergency-tier force-close.
Targeted Stress-Test Scenarios
The scenarios below map specific platform risk vectors to the mechanism that responds to each. Quantitative breach rates for the market scenarios are reported in the Stress Simulation table above.
| Scenario | Trigger | System response |
|---|---|---|
| Collateral or asset depeg | A loop collateral or borrowed asset loses its peg, widening the loop's mark-to-market loss. | The pool auto-deleverages once peak-to-trough NAV passes 10%. Negative Rate Hedge payouts are capped by available pool NAV, so delivered coverage compresses. Emergency tiers force-close affected positions in an orderly settlement (adversarial replays s6, s7). |
| Sharp borrow rate spike | The Aave borrow rate rises sharply and loop carry turns negative. | Negative Rate Hedge positions pay from their accrued buffers. Carry Perp equity drains through the shadow-drawdown accumulator toward the liquidation triggers. The pool deleverages if NAV drawdown passes 10%. |
| Sustained negative carry | Loop carry stays negative across an extended window. | Hedge buffers drain and payouts compress to the buffer and available pool NAV. The streaming premium continues to refund the reserve. Positions whose gas tanks empty lapse, with forced closes settling in order (adversarial replay s5). Carry Perp positions liquidate as shadow drawdown reaches the deposit. |
| Oracle staleness or anomaly | The carry feed is stale or returns an anomalous reading. | Settlement runs hourly on a gross-carry input rather than a per-block spot read. Premium continues to debit through a stale oracle and settlement resumes from the next valid reading (test vector tv18). |
| Aave venue health degradation | The Aave V3 health factor on the LP loop falls below threshold. | The worker auto-deleverages the loop to reduce exposure and redeploys only once NAV recovers to 3% below peak. |
| Mass LP exodus | A large share of LPs request withdrawal at once. | Withdrawals are served only from free_NAV, the NAV not committed to open positions, hedge rights, and pool safety gates. Each request runs a 7-day cooldown. Capacity committed to open Carry Perp and Negative Rate Hedge obligations stays locked. |
| Spike in high-leverage Carry Perp demand | Carry Perp open interest rises quickly and concentrates in high-leverage tiers. | New notional is bounded by the per-market global notional cap ($76.8M sUSDe, $322.6M wstETH). Committed capacity reserves backing for open positions. The shadow-drawdown kill gradient liquidates top-tier positions on a 2 to 3 day median life, with the LP capturing remaining equity. |
| Regulatory and jurisdiction | Operating requirements differ across the testing and launch phases. | Pre-launch testing operates under a Panama entity. The production launch operates under a Cayman entity. |
Correlated Stress
The stress table above varies one factor at a time; a real tail event is the
concurrence of several. A transparent leveraged-loop NAV model
(labs/product_calculator/correlated_stress_2026-06-25.py, complementary to the
harness table rather than a re-run of it) applies shocks jointly: a leveraged
depeg mark-to-market loss, a borrow-rate spike, and sustained negative carry,
with the 10% / 3% pause-deleverage gate active.
Here breach is read at the pool level: the share of paths where the LP
pool's own NAV ends more than 5% below its principal. This is stricter than the
per-policy hedge breach above, where principal is protected; a collateral depeg
is a direct, leveraged mark-to-market loss the safety gates can dampen but not
undo. 400 trials per scenario, shock timing randomized.
| Scenario | sUSDe breach | wstETH breach | sUSDe ROE | wstETH ROE |
|---|---|---|---|---|
2% depeg, alone | 0% | 37% | +13.9% | +1.9% |
+10% borrow spike (120d), alone | 0% | 39% | +13.4% | ~0% |
sustained −2% carry (120d), alone | 0% | 0% | +17.0% | +9.0% |
| all three jointly | 2% | 46% | +9.9% | −0.4% |
borrow ~35% held 6 months, alone | 66% | 100% | −5.0% | −14.8% |
| severe cascade (depeg + borrow + sustained) | 100% | 100% | −23.2% | −40.2% |
Two readings, both about known edges rather than baseline behavior. First, a
sustained high-borrow regime the historical window never contained (borrow
~35% for six months) is on its own enough to pull the pool below principal in
most paths (66% sUSDe, 100% wstETH); this is the regime a backward-looking
calibration cannot price. Second, the severe cascade is the protocol's worst-case
corner: a large depeg, a borrow explosion, and sustained negative carry at once
put every path below principal at mean ROE −23% / −40%. The individually
survivable single-factor rows confirm the gates absorb ordinary stress; the pool
is exposed only at the extreme combined tail, which wstETH (loop leverage 4.34×
vs 3.05×) reaches sooner.
Negative Rate Hedge
Launch-scope test vectors:
| Vector | Case | Status | Invariant breaches |
|---|---|---|---|
| tv10 | top-up, no state change | PASS | 0 |
| tv11 | voluntary close returns gas tank | PASS | 0 |
| tv12 | forced close emergency | PASS | 0 |
| tv13 | premium floor / load accounting | PASS | 0 |
| tv14 | cost-covering premium covers expected claims | PASS | 0 |
| tv15 | premium debits through negative-carry periods | PASS | 0 |
| tv16 | perpetual, no rollover at day 180 | PASS | 0 |
| tv17 | lapse on empty gas tank | PASS | 0 |
| tv18 | premium debits during stale oracle | PASS | 0 |
Pricing basis note. The current charting branch prices NRH from expected negative-carry claims times
(1 + lp_profit_factor) / 0.90, charged continuously while the policy is open.expected_claim_rate(0.249%sUSDe /0.218%wstETH) remains a market-specific floor / calibration reference.
Historical replay summary:
| Replay | Days | Requested policies | Admitted policies | Rejected policies | Claims paid | Premium earned | NAV change | Forced closes | Invariant breaches |
|---|---|---|---|---|---|---|---|---|---|
| historical_susde | 676 | 32 | 32 | 0 | $50.9K | $38.3K | +17.84% | 0 | 0 |
| historical_wsteth | 1,220 | 56 | 4 | 52 | $0.0K | $0.0K | -14.64% | 0 | 0 |
Adversarial replay summary:
| Replay | Requested policies | Admitted policies | Claims paid | Premium earned | NAV change | Forced closes | Invariant breaches |
|---|---|---|---|---|---|---|---|
| s1_single_30d | 20 | 20 | $58.2K | $17.6K | +4.01% | 0 | 0 |
| s2_two_30d_6mo_apart | 32 | 32 | $116.8K | $40.0K | +5.30% | 0 | 0 |
| s3_two_30d_1yr_apart | 40 | 40 | $197.5K | $66.5K | +7.67% | 0 | 0 |
| s4_four_30d_stacked | 36 | 36 | $137.4K | $46.7K | +2.78% | 0 | 0 |
| s5_sustained_12mo | 40 | 24 | $62.5K | $14.9K | -0.73% | 2 | 0 |
| s6_depeg_crisis_orderly_settlement | 24 | 20 | $62.0K | $13.6K | -0.25% | 7 | 0 |
| s7_emergency_tier4_force_close | 20 | 20 | $57.3K | $13.6K | +2.99% | 3 | 0 |
Replay totals:
| Replays | Requested policies | Admitted policies | Claims paid | Premium earned | Forced closes | Invariant breaches |
|---|---|---|---|---|---|---|
| 9 | 300 | 228 | $742.7K | $251.2K | 12 | 0 |
Pricing study note:
The May 27 pricing study remains useful as historical mechanism evidence, but
its variable-band forms are superseded for the premium formula decision. The
current charting branch prices policies from expected negative-carry claims
times (1 + lp_profit_factor) / 0.90, then routes premium 90/10 to LP/treasury. Do not use
the old pricing-study "LP ok vs baseline" column as direct underwriting-margin
evidence for the launch formula.
Charting Tool
The launch economics are explorable interactively in the Charting Tool (the product calculator at cardinal-product-calculator.vercel.app), now its own page in this Data Room.
Measurement Boundaries
| Result class | Boundary |
|---|---|
| Historical replay | Observed Aave V3 rate paths during the stated windows |
| Stress simulation | Specified scenario parameters and 20 trials per scenario; shocks are applied one factor at a time; joint-shock results are in Correlated Stress above |
| Carry Perp calibration | Launch-tier replay artifacts and 5,000 trials per tier; representative entry timing; the perfect-information exit bound is in Adversarial Carry Perp Trader above |
| Negative Rate Hedge tests | Launch-scope vectors and replay rows in the referenced artifacts |
| LP yield | Computed at the stated launch notional caps; the ROE-versus-TVL curve is in Capacity and Pool Size above |
| Live deployment | Realized rates, LP participation, user demand, liquidity depth, and production controls |
The projections on this page hold under the assumptions below. Conditions outside them are characterized only by the stress scenarios above, not by the launch-scope return figures.
- Carry distributions and
expected_claim_ratereflect the stated historical windows. - Aave V3 supply, borrow, liquidation, and withdrawal behave within their historical parameters.
- The hourly carry / TWAP oracle settles within its stated cadence.
- Loop deleveraging executes at or near quoted rates.
- Depegged assets stay within the modeled depeg ladder.
- LP withdrawals are bounded by the
7-daycooldown and thefree_NAVgate.
Evidence Package
All artifact paths below live in the Cardinal /research repo.
| Evidence area | Artifact root |
|---|---|
| Historical LP replay | output/phase4_track_c_historical_2026-04-21/ |
| Stress validation | output/phase4_track_c_combined_2026-04-21/ |
| Carry Perp launch-tier calibration | labs/product_calculator/ and output/product_calculator/data.json (charting-tool MC, s_L = 65) |
| Negative Rate Hedge replay and test vectors | output/negative_rate_hedge_per_policy_2026-05-27/ |
| Negative Rate Hedge pricing study | output/negative_rate_hedge_pricing_study_2026-05-27/ |
| Product charting tool | output/product_calculator/ and labs/product_calculator/ |
| Capacity / TVL curve | output/capacity_curve_2026-06-25/ and labs/product_calculator/capacity_curve_2026-06-25.py |
| Adversarial Carry Perp trader | output/adversarial_trader_2026-06-25/ and labs/product_calculator/adversarial_trader_2026-06-25.py |
| Correlated / joint-shock stress | output/correlated_stress_2026-06-25/ and labs/product_calculator/correlated_stress_2026-06-25.py |
Reviewer Commands
python3 labs/benchmarks/check_artifact_schemas.py
python3 labs/benchmarks/verify_participant_econ_v6_artifacts.py
python3 -m unittest tests.test_product_calculator_guardrails
python3 labs/product_calculator/capacity_curve_2026-06-25.py
python3 labs/product_calculator/adversarial_trader_2026-06-25.py
python3 labs/product_calculator/correlated_stress_2026-06-25.py