# Contributor Bereavement Payment
Forum Link: https://forum.inverse.finance/t/contributor-bereavement-payment/682
## **Summary**
Following Tabboz's passing earlier this year and the operational offboarding completed in the weeks after, this proposal settles the DAO's remaining commitment to his family: a payment of **25,836 DOLA** from the DAO Treasury.
## **Background**
Tabboz was a contributor to Inverse Finance and worked with the Product Working Group throughout his years here. He was part of this DAO for a long time, and he is missed by the people who worked with him every day.
Following his passing earlier in 2026 (see the DAO's[ in-memoriam post](https://x.com/InverseFinance/status/2060325394944016662)), the operational offboarding, multisig signer transitions and infrastructure handover was handled at the time and is reflected in prior proposals.
What remains is the payment to his family. The amount was determined by the core team in May 2026 in line with the DAO's Tier B contributor policy, following the precedent set by[ Proposal 322](https://www.inverse.finance/governance/proposals/mills/322).
## **Recipient**
The destination address 0x7ad367a6b712363ceeca0a8246ed621fc848b90b has been confirmed by Tabboz's family as their receiving address.
## **Proposed Action**
Transfer **25,836 DOLA** from the DAO Treasury multisig to 0x7ad367a6b712363ceeca0a8246ed621fc848b90b.
# RWG Housekeeping: Minter and Governance Cleanup
Forum Link: https://forum.inverse.finance/t/rwg-housekeeping-minter-and-governance-cleanup/677
### **Summary**
This proposal removes stale minting rights and governance permissions that are no longer in active use. It first migrates the stETH market to the live BorrowController so its residual position keeps replenishment coverage, then revokes DBR minting from three legacy BorrowControllers and two superseded jrDOLA deployments, revokes DOLA minting from the retired Gearbox Vault Fed, clears stale ALE allowlist entries on deprecated controllers, removes the sunsetting ODOS swap router from the live ALE v4, and removes one inactive address from the proposer whitelist. Every revocation target is confirmed idle or deprecated; the live BorrowController, the live jrDOLA vault, and all active Feds and integrations are untouched.
### **Motivation**
Over the protocol's life, DBR and DOLA minting rights and ALE allowlist entries accumulated across successive contract versions. Governance replay of the full proposal history confirms twelve DBR minter grants with zero prior revocations, alongside the DOLA grant to the now-retired Gearbox Vault Fed and a set of ALE allowlist entries tied to superseded BorrowControllers. Leaving unused minter roles and allowlist entries live is an unnecessary standing risk surface. Retiring them narrows the set of contracts that can mint DBR or DOLA, or interact with FiRM, to only those in active service.
The stETH market still points at the earliest BorrowController and carries a small residual position. Migrating it to the live BorrowController v4 preserves replenishment on that position, which is why the migration is ordered first, ahead of the revocations. Once the market no longer depends on the legacy controller, revoking that controller's minter role is clean. Per prior review, the minter role on the legacy BorrowControllers does not provide the replenishment-edge protection introduced in v4, so revoking it on the legacy controllers closes an unused path without affecting repayments or liquidations. The two jrDOLA deployments being revoked predate the live v2 vault. Naoufel's proposer-whitelist entry is inactive following the AWG wind-down.
This proposal also removes the ODOS swap router from the ALE v4 proxy whitelist. ODOS has announced it is winding down its protocol effective July 30, 2026, so leaving its router enabled would keep an unsupported integration live on the Automated Leverage Engine.
###
### **On-Chain Actions**
|# | Contract | Call | Target|
|--- | --- | --- | ---|
|1 | stETH Market | setBorrowController | BorrowController v4 (0x01eca33e20a4c379bd8a5361f896a7dd2bae4ce8)|
|2 | DBR | removeMinter | BorrowController v1 (0x44b7895989bc7886423f06deaa844d413384b0d6)|
|3 | DBR | removeMinter | BorrowController v2 (0x2dbad53a647a86b8988e007a33fe78bd55e9dd6f)|
|4 | DBR | removeMinter | BorrowController v3 (0xeebea1ed06eeb120cbf72fad195683746b5a5245)|
|5 | DBR | removeMinter | jrDOLA legacy (0x633821b8e003344e5223509277f2084ea809a452)|
|6 | DBR | removeMinter | jrDOLA legacy (0xf4307a1354c0463812b3ce0f509c227f5cd1ccfd)|
|7 | DOLA | removeMinter | Gearbox Vault Fed (0xe082eb109fad53ea8db9827ce6b8ef74882734fc)|
|8 | BorrowController v1 | deny | ALE v2 (0x5233f4c2515ae21b540c438862abb5603506debc)|
|9 | BorrowController v2 | deny | ALE v2 (0x5233f4c2515ae21b540c438862abb5603506debc)|
|10 | BorrowController v3 | deny | ALE v2 (0x5233f4c2515ae21b540c438862abb5603506debc)|
|11 | BorrowController v3 | deny | ALE v3 (0x4df2eaa1658a220fdb415b9966a9ae7c3d16e240)|
|12 | ALE v4 | denyProxy | ODOS router (0xCf5540fFFCdC3d510B18bFcA6d2b9987b0772559)|
|13 | GovernorMills | updateProposerWhitelist | Naoufel (0xFDa9365E2CDf21d72cb0dc4F5FF46F29e4aC59CE), false|
Total: 13 on-chain actions.
### **Conclusion**
This cleanup retires minting rights, allowlist entries, and governance permissions that are no longer in service, reducing the set of contracts that can mint DBR or DOLA or interact with FiRM to only those actively in use. It is a defense-in-depth hygiene measure with no effect on live user flows.
# Proposal to Relaunch jrDOLA with Initial DBR Reward Budget
Forum Link: https://forum.inverse.finance/t/proposal-to-relaunch-jrdola-with-initial-dbr-reward-budget/666
### Summary
This proposal authorizes the relaunch of the Junior Tranche system (jrDOLA) on an updated and freshly deployed contract suite. Following jrDOLA’s first live period and its absorption of a bad-debt event in a covered market, the system was paused while the design was reviewed. The relaunch carries forward the original architecture while introducing one substantive change: a bounded, governance-controlled withdrawal pause that allows the protocol to hold the insurance layer in place during an active stress event. The proposal sets initial operational parameters and allocates a DBR reward budget to rebuild liquidity through a measured, slow-churn approach. A follow-up proposal will enable FiRM market coverage, designed to execute in parallel, pending governance approval.
### Background
jrDOLA introduces a market-driven insurance layer that addresses a fundamental limitation in Inverse Finance’s risk model. As FiRM continues to scale, the protocol absorbs all bad debt directly into DOLA backing, creating concentration risk that constrains growth potential. This model works adequately at current scale but becomes increasingly fragile as total debt exposure grows.
jrDOLA solves this by creating a first-loss capital buffer where depositors voluntarily accept bad debt risk in exchange for increased yield. When FiRM positions become insolvent, the slashing mechanism draws from jrDOLA deposits to repay bad debt before it impacts DOLA backing. This protects DOLA solvency by establishing a dedicated absorption layer, enables protocol scaling with reduced systemic risk, provides DOLA holders with a new product that earns both sDOLA base yield and DBR rewards, and establishes permissionless bad debt resolution that requires no manual governance action during stress events.
The initial live deployment validated the core mechanism in production: when a covered market sustained losses, jrDOLA absorbed the resulting bad debt exactly as designed, shielding DOLA backing. That episode also surfaced a structural gap. Depositors retained the ability to exit a distressed market before the relevant oracle had repriced and before slashing could be executed. A coordinated, rational exit during the window between a loss becoming likely and that loss becoming enforceable would let depositors escape the very risk they were paid to underwrite, leaving the remaining stakers and ultimately DOLA holders to absorb it. The relaunch closes this gap.
The remedy mirrors the approach taken by Aave’s Umbrella safety system in its response to the rETH depeg event: governance gains the ability to temporarily freeze withdrawals so the insurance layer cannot drain ahead of a crystallizing loss. The capability is deliberately constrained. It can hold withdrawals for a maximum of ninety days, it requires continuous, affirmative governance support to persist rather than locking funds indefinitely, and governance can lift it at any time. It exists to preserve the integrity of the buffer during the narrow window where slashing is pending, not to trap depositor capital.
The jrDOLA codebase underwent rigorous security scrutiny through a dual-audit process with Sherlock: a private audit with researchers Hash and Osidian focused on ERC-4626 vault mechanics, slashing logic, and withdrawal queue edge cases, followed by a public audit contest open to Sherlock’s broader researcher community. The final reports are posted [here](https://docs.inverse.finance/risk-working-group-digest/prevention/audits). The withdrawal-pause change introduced for the relaunch was implemented and reviewed separately, approved, and fork-tested across deposit, withdraw, and slash flows prior to redeployment.
### Technical Implementation
**Deployed Contracts**
The relaunch is built on a newly deployed contract suite on Ethereum mainnet. Addresses below supersede the original launch deployment:
JuniorDola (jrDOLA) — **[0x6f80a22a57C7F0257094eA8D426AF3F747defbC7](https://etherscan.io/address/0x6f80a22a57C7F0257094eA8D426AF3F747defbC7)** The main ERC-4626 vault representing user deposits. All deposits are in sDOLA to provide a base yield layer. The contract integrates an xy=k auction mechanism that converts DBR rewards into DOLA-denominated yield, allowing depositors to earn returns without directly holding or managing DBR tokens.
WithdrawalEscrow — **[0x8554d8a6Bcc5B6D6Eb7bEA2189e6a8F8d24c7e45](https://etherscan.io/address/0x8554d8a6Bcc5B6D6Eb7bEA2189e6a8F8d24c7e45)** Manages the delayed withdrawal queue. The per-withdrawal cooldown duration and exit window are still snapshotted and locked at the moment a withdrawal is queued and cannot be retroactively worsened for users already in the queue. The relaunch adds a bounded, governance-controlled pause over the queue (described under Governance Controls); outside of an active pause, behavior is unchanged. Users continue earning rewards during cooldown since their funds remain slashable.
LinearInterpolationDelayModel — **[0x75FdA12cB3341CcCD41b77C2515F0DA716119B07](https://etherscan.io/address/0x75FdA12cB3341CcCD41b77C2515F0DA716119B07)** Calculates withdrawal delays based on queue utilization, interpolating linearly between the minimum delay (empty queue) and the maximum delay (at the governance-defined threshold). The contract is upgradeable by governance, but active withdrawals continue using the delay parameters from their queue time.
FiRMSlashingModule — **[0x316a01f878AA6d5A4C7ea2080D64D364F9538aa2](https://etherscan.io/address/0x316a01f878AA6d5A4C7ea2080D64D364F9538aa2)** Implements the permissionless slashing mechanism for FiRM bad debt. Anyone can call the slashing function when a position becomes insolvent. Protective parameters include:
◦ **maxCollateralValue**: prevents slashing positions with significant collateral, forcing liquidators to handle those first.
◦ **minDebt**: prevents dust positions from spamming slashing events
◦ **activationDelay**: requires newly added markets to wait before becoming eligible for coverage
A guardian multisig can cancel pending market additions during the delay window.
Helper — **[0xcb1cf17F0e579e520458A3a3aa72ECA65eB8560C](https://etherscan.io/address/0xcb1cf17F0e579e520458A3a3aa72ECA65eB8560C)** Implements helper functions for interacting with the DBR auction in the JuniorDola contract.
Two price feeds support integrations and downstream risk tooling:
jrDOLA/DOLA feed — **[0x6B6e969ED13061058820BFcbaeAd5AB85411AFD6](https://etherscan.io/address/0x6B6e969ED13061058820BFcbaeAd5AB85411AFD6)**
jrDOLA/USD feed — **[0x830A0be197F927ca1673355a85DB5E715F4Ce621](https://etherscan.io/address/0x830A0be197F927ca1673355a85DB5E715F4Ce621)**
### Initial Parameters
**JuniorDola (auction parameters)**
These four values seed and govern the xy=k DBR auction. They are the core economic levers of the relaunch and are carried forward from the original launch calibration as a starting point.
• **dbrReserve:** \[200,000e18\] DBR — virtual reserves for the xy=k auction
• **dolaReserve:** \[5,670e18\] sDOLA — virtual reserves for the xy=k auction (value used at original launch)
• **yearlyRewardBudget:** \[500,000\] DBR — initial annual allocation (operator-controlled)
• **maxYearlyRewardBudget:** 5,000,000 DBR — governance ceiling
• **operator:** Treasury Working Group multisig
The dbrReserve/dolaReserve ratio sets the auction’s opening DBR price. At the original launch the ratio implied ≈ 0.0285 sDOLA per DBR; current DBR trades around $0.0410
**WithdrawalEscrow**
• **withdrawFee:** 5 bps — creates friction against cycling behavior; paid to remaining depositors
• **exitWindow:** 2 days (48 hours) — time to claim a withdrawal after cooldown completes
**LinearInterpolationDelayModel**
• **minDelay:** 1 day — minimum withdrawal delay when the queue is empty
• **maxDelay:** 10 days — applies when queue utilization reaches the threshold (aligned with Aave Umbrella)
• **maxDelayThreshold:** 10,000 bps — delay scales linearly from min to max as the queue fills from 0% to 100% of supply
**FiRMSlashingModule**
• **maxCollateralValue:** $100 — positions above this must be liquidated normally
• **minDebt:** $5 — minimum debt for slashing eligibility
• **activationDelay:** 7 days — review window for new market additions
• **guardian:** Policy Committee multisig
### Governance Controls
The relaunch revises the control surface in exactly one respect: governance gains a bounded withdrawal pause. All other guarantees are preserved.
**Governance CAN:**
• Add or remove FiRM markets for coverage (new markets subject to the activation delay)
• Increase the maxYearlyRewardBudget ceiling
• Replace the LinearInterpolationDelayModel contract
• Adjust FiRMSlashingModule parameters
• Change the guardian address
• **Pause withdrawals** — freeze both queued and new withdrawals for up to a maximum of ninety days during an active stress event. The pause requires continuous governance support to persist and can be lifted by governance at any time.
**Governance CANNOT:**
• Hold a pause beyond the ninety-day maximum without renewed, affirmative governance action
• Worsen the cooldown or exit-window terms snapshotted for users already in the queue
• Access deposited funds except through legitimate slashing
• Bypass market activation delays
**Operator (TWG multisig) CAN:**
• Adjust yearlyRewardBudget within the governance-set ceiling
**Operator CANNOT:**
• Exceed the governance-approved ceiling
• Access deposited funds
• Modify withdrawal or slashing parameters
**Guardian CAN:**
• Remove markets from slashing protection before the activation period has elapsed
**Guardian CANNOT:**
• Interfere with operations of actively protected markets
### Operational Mechanics
**For Depositors**
Depositing into jrDOLA follows standard ERC-4626 vault interactions. Users approve sDOLA to the jrDOLA contract and call either deposit(amount, receiver) or mint(shares, receiver). Upon deposit, users receive jrDOLA shares representing their proportional claim on the vault and begin earning DBR rewards distributed through the xy=k auction, which automatically converts DBR into DOLA-denominated yield without requiring direct DBR interaction.
Withdrawing follows a multi-step process designed to provide security during stress while maintaining a reasonable experience during normal operations. Users first call queueWithdrawal(shares) to enter the queue. At that moment the system snapshots their withdrawal parameters — cooldown duration and exit window — and applies the withdrawal fee, which is distributed to remaining depositors. Users then wait for the cooldown, which ranges from the minimum to the maximum delay based on current queue utilization. During cooldown, users continue earning rewards because their funds remain in the vault and continue to provide slashable coverage. After cooldown, users enter their exit window and claim by calling the claim function, receiving sDOLA equal to their original deposit plus accrued yield, minus any slashing events that occurred while deposited, minus the withdrawal fee. Users may also cancel during cooldown and return to the active pool. Should governance invoke the withdrawal pause during an active stress event, claims and new exits are held for the duration of the pause; queued positions retain their place and resume on lift.
**For the Protocol**
Bad debt coverage operates through a permissionless slashing process. When a FiRM position becomes insolvent such that debt value exceeds collateral value based on oracle pricing, anyone can call slash(market, borrower) on the FiRMSlashingModule. The module verifies insolvency by checking current debt and collateral values, then applies protective checks — collateral value below maxCollateralValue (so positions that should be liquidated normally are excluded) and debt above minDebt (so economically insignificant positions are ignored). If all checks pass, the module calculates the DOLA required to restore the position’s debt-to-collateral ratio to parity and triggers a pro-rata slash against the jrDOLA vault, where all depositors’ share values decrease proportionally to socialize the loss. The recovered DOLA repays the bad debt in the FiRM market, removing the insolvency and protecting DOLA backing before it reaches core reserves.
Reward distribution operates through an ongoing auction integrated into the jrDOLA contract. The protocol allocates DBR according to the yearlyRewardBudget, within governance-set limits. These DBR enter an xy=k constant-product market maker with virtual DOLA reserves, creating a permissionless auction where anyone can swap sDOLA for DBR. This increases the vault’s total assets without changing share supply, raising the sDOLA-per-share exchange rate. Depositors thus earn DOLA-denominated yield without ever directly interacting with DBR, while the auction provides continuous price discovery and self-adjusting reward distribution based on DBR market dynamics.
### Budget Request
The budget operates within a controlled structure. The maxYearlyRewardBudget of 5,000,000 DBR is a governance-enforced ceiling that can only be raised through a full governance proposal. Within that ceiling, the yearlyRewardBudget represents the initial active budget upon approval and is controlled by the operator (Treasury Working Group multisig), which can adjust it up to the ceiling without additional votes — enabling responsive calibration to market conditions while preserving ultimate governance control.
Given that the relaunch deliberately rebuilds liquidity through a measured, slow-churn approach rather than an aggressive bootstrap, the initial yearlyRewardBudget should be calibrated to attract first-loss capital at a sustainable cost rather than to maximize early TVL.
### On-Chain Actions
JuniorDola (setOperator, initialize, setSlashingModule, setMaxYearlyRewardBudget, setYearlyRewardBudget) · WithdrawalEscrow (initialize, setWithdrawFee, setExitWindow) · LinearInterpolationDelayModel (setMinDelay, setMaxDelay, setMaxDelayThresholdBps) · FiRMSlashingModule (setGuardian, setMaxCollateralValue, setMinDebt, setActivationDelay) · DBR (addMinter)
# Proposal to Pause Borrows on FiRM INV Market
Forum Link: https://forum.inverse.finance/t/proposal-to-pause-borrows-on-firm-inv-market/665
### Summary
This proposal pauses borrows on the FiRM INV market and redirects new borrowing demand against INV toward Monolith. The decision is strategic, not risk-driven. The market is not under stress today and existing borrowers are unaffected. Pausing borrows blocks new debt issuance against INV on FiRM while leaving open positions free to be managed, topped up, or repaid at borrower discretion. A secondary effect is to cap DOLA's exposure to INV, a reflexive collateral, by halting further issuance against the protocol's own governance token.
### Background
The INV market on FiRM has operated since[ proposal #139](https://www.inverse.finance/governance/proposals/mills/139), providing DOLA borrowing capacity against the Inverse governance token. INV is reflexive collateral: stress affecting the protocol can correlate with INV price, and DOLA debt backed by INV is partially backed by an equity claim on the entity issuing the DOLA.
Monolith is Inverse Finance's stablecoin-as-a-service protocol. It’s [invusd](https://app.monolith.market/1/coin/0) market provides an alternative venue for borrowing against INV, separate from DOLA and FiRM’s collateralized lending model. Directing new INV-collateralized borrowing interest toward Monolith does two things at once: it builds Monolith adoption at a stage where flow concentration matters, and it lets FiRM reduce reflexive collateral exposure without requiring borrower action. As Monolith scales, the protocol benefits from concentrating new INV borrowing demand in the venue best positioned to absorb it.
The only operation prevented is the creation of new debt against INV on FiRM. CF, LF, liquidation incentive, and supply ceiling are all unchanged. Open positions can still be managed, topped up, or repaid on existing terms.
### Looking Ahead
This proposal does not pre-commit to further action on the INV market. If the RWG or Inverse governance later determines that additional INV-market wind-down steps are warranted, whether to deepen the reflexive-exposure reduction or for unrelated strategic reasons, those will be proposed separately. The RWG retains its standing mandate to escalate parameter changes on the INV market should risk conditions deteriorate, independent of this proposal.
### Actions
**Action 1:** Pause borrows on FiRM INV Market
**Action 2** Set FiRM INV Market Ceiling to 0
# sUSDe Market Consolidation and First Collateral Factor Reduction
Forum Link: https://forum.inverse.finance/t/susde-market-consolidation-and-first-collateral-factor-reduction/661
### Summary
This proposal is the first governance action flowing from the RWG's [Complete Risk Refresh Assessment of USDe/sUSDe Collaterals on FiRM](https://github.com/InverseFinance/Risk-Assessments/blob/main/sUSDe-Risk-Refresh-Assessment/sUSDe-Risk-Refresh-Assessment.md). It seeks to execute the first stage of the RWG's phased sUSDe collateral transition proposed in the assessment. Three changes take effect simultaneously: the standalone sUSDe market is offboarded by reducing its supply ceiling to zero; the collateral factor on FiRM's two FeedSwitch-protected sUSDe LP markets (DOLA/sUSDe LP and yv-sUSDe/DOLA) is reduced from 92% to 91.75%; and market ceilings are brought in line with current borrow utilization — DOLA/sUSDe LP to $50.5M and yv-sUSDe/DOLA to $5M. The existing 100% liquidation factor and 4% liquidation incentive is preserved on both LP markets.
### Background
FiRM currently operates three sUSDe-denominated markets. The two LP markets — DOLA/sUSDe LP and yv-sUSDe/DOLA — are protected by FeedSwitch V2, which prices sUSDe at USDT-equivalent in its default configuration. A standalone sUSDe market with a $5M ceiling and zero active borrowers operates outside FeedSwitch coverage, pricing directly against the live Chainlink sUSDe-USD DEX-state feed.
The RWG's Complete Risk Refresh Assessment documents [five converging risk vectors](https://github.com/InverseFinance/Risk-Assessments/blob/main/sUSDe-Risk-Refresh-Assessment/sUSDe-Risk-Refresh-Assessment.md#top-5-risk-vectors) across the sUSDe collateral stack. The structural finding central to this proposal is a 74% contraction in sUSDe DEX liquidity (ex-DOLA) since January 2026 — from $109M at FeedSwitch deployment to [$28.34M as of April 20, 2026](https://github.com/InverseFinance/Risk-Assessments/blob/main/sUSDe-Risk-Refresh-Assessment/sUSDe-Risk-Refresh-Assessment.md#liquidity). This is the liquidity environment that underpins both the Chainlink sUSDe-USD feed and [every FiRM liquidation path for sUSDe collateral](https://github.com/InverseFinance/Risk-Assessments/blob/main/sUSDe-Risk-Refresh-Assessment/sUSDe-Risk-Refresh-Assessment.md#contagion-mapping). The 92% CF and the current market ceilings were calibrated against the January environment. They no longer reflect the conditions under which the protocol is operating.
The three changes in this proposal are addressed together because they belong together. The standalone market's offboarding is a consolidation step — it removes a surface with zero borrowers and no FeedSwitch protection, focusing the remaining plan on the two markets where the FeedSwitch actually operates. Ceiling alignment with current borrow utilization closes the gap between structural ceiling and actual exposure, removing headroom that serves no function during a managed transition window. The CF reduction is the substantive risk adjustment — the first of two steps that will bring the LP markets to 91% CF ahead of any feed configuration decision.
### Why Now
The LP markets were parameterized at 92% CF against +$100M in independent exit liquidity. That pool depth is now roughly one-quarter of the environment the current parameterization was calibrated against. The Chainlink sUSDe-USD feed derives its price exclusively from on-chain DEX pools; feed behavior under stress is inseparable from the depth of the pools it sources from. Despite the recency of the October 2025 event, the current depth of $28M has [no stress-tested performance record](https://github.com/InverseFinance/Risk-Assessments/blob/main/sUSDe-Risk-Refresh-Assessment/sUSDe-Risk-Refresh-Assessment.md#valuation-methodology), and a comparable event would hit an environment with roughly 4× less absorbing capacity.
The [FeedSwitch](https://github.com/InverseFinance/Risk-Assessments/blob/main/sUSDe-Risk-Refresh-Assessment/sUSDe-Risk-Refresh-Assessment.md#valuation-methodology) currently insulates LP market borrowers from real-time sUSDe price exposure. It was [deployed](https://www.inverse.finance/governance/proposals/mills/344) as a temporary guardian-controlled buffer pending a trustless, PoR-driven automated fallback. That fallback has not materialized, and the current environment makes the interim posture progressively less defensible. Maintaining the FeedSwitch requires a named guardian to monitor, judge, and execute faster than a stress event deteriorates — a reactive model whose correctness is required exactly when the conditions for exercising judgment are most adverse. Even if exercised perfectly, guardian activation is still a reaction to an underlying problem already in motion and therefore cannot substitute for appropriate parameter sizing against the actual liquidity environment. Maintaining a 92% CF and ceilings unconstrained by utilization against a 74%-contracted liquidity picture is not consistent with the RWG's collateral framework.
The RWG will conduct direct outreach to active sUSDe LP borrowers ahead of execution, consistent with prior parameter-change communications.
### Proposed Changes
|Market|Parameter|Current|Proposed|
| --- | --- | --- | --- |
|Standalone sUSDe|Supply Ceiling|$5,000,000|$0|
|DOLA/sUSDe LP|Collateral Factor|92%|91.75%|
|DOLA/sUSDe LP|Supply Ceiling|$80,000,000|$50,500,000|
|yv-sUSDe/DOLA|Collateral Factor|92%|91.75%|
|yv-sUSDe/DOLA|Supply Ceiling|$20,000,000|$5,000,000|
Liquidation incentive preserved at 4% on both LP markets. FeedSwitch configuration unchanged. No changes to LF or daily borrow limits.
Combined sUSDe notional ceiling: $105M → $55.5M. Total ceiling reduction reflects consolidation to the two FeedSwitch-protected LP markets at utilization-appropriate levels.
### Looking Ahead
If Stage 1 is approved via governance, [Stage 2](https://github.com/InverseFinance/Risk-Assessments/blob/main/sUSDe-Risk-Refresh-Assessment/sUSDe-Risk-Refresh-Assessment.md#recommended-path) — a second CF reduction from 91.75% to 91% — is targeted approximately 30 days after this proposal executes, giving borrowers adequate time to adjust before the next step. During the Stage 1 observation window, the RWG continues structured data collection on Chainlink sUSDe-USD feed performance and sUSDe DEX TVL trajectory, and conducts engagement with Ethena on Season 6 status, sENA fee-switch activation timing, and forward guidance on the DEX-liquidity outlook.
If deemed necessary, [Stage 3](https://github.com/InverseFinance/Risk-Assessments/blob/main/sUSDe-Risk-Refresh-Assessment/sUSDe-Risk-Refresh-Assessment.md#recommended-path) — a data-driven ceiling reassessment and FeedSwitch configuration review — follows approximately 30 days after Stage 2, with a hard outer bound of June 26, 2026. It is a window, not a fixed execution date. The full rationale is set out in the Stage 3 proposal.
The RWG pre-commits to timeline acceleration under either of two conditions: sUSDe DEX TVL (ex-DOLA) sustained at $10M or below over a continuous one-week window, or confirmed migration of Aave's sUSDe oracle across any of its Ethereum deployments from USDT-equivalent to live market pricing.
# Adopt the SEAL Safe Harbor Agreement for Monolith
Forum Link: https://forum.inverse.finance/t/adopt-the-seal-safe-harbor-agreement-for-monolith/663
## Summary
This proposal adopts the SEAL Safe Harbor for Whitehats framework on behalf of the Monolith protocol, extending the same on-chain safe harbor protections that Inverse Finance itself has operated under since the execution of [Proposal 273](https://www.inverse.finance/governance/proposals/mills/273).
The proposal contains two on-chain actions, both routed through the INV Treasury, which is the owner of the Monolith Safe Harbor Agreement contract:
1. Set the per-incident bounty cap on the Monolith Agreement to $1,000,000.
2. Register the Monolith Agreement in the SEAL Safe Harbor Registry, formally adopting the framework for Monolith.
## Background
The SEAL Safe Harbor for Whitehats, developed by the Security Alliance (SEAL), provides whitehat security researchers with a defined on-chain safe harbor when intervening to prevent or mitigate active exploits against participating DeFi protocols. Adoption is a two-step on-chain process: a per-protocol Agreement contract describing in-scope assets, bounty terms, and security contacts is deployed, and that Agreement is then registered in the canonical SEAL Safe Harbor Registry.
Inverse Finance has been subscribed to SEAL Safe Harbor since the execution of[ Proposal 273](https://www.inverse.finance/governance/proposals/mills/273). This proposal extends equivalent on-chain protections to Monolith, whose asset recovery flows are controlled by the INV Treasury.
The Monolith Safe Harbor Agreement has already been deployed at[ 0x7fb1970F81aCAa1A39f55c92609CE729b0D6f1C0](https://etherscan.io/address/0x7fb1970F81aCAa1A39f55c92609CE729b0D6f1C0) by SEAL, and ownership has been transferred to the INV Treasury at[ 0x926dF14a23BE491164dCF93f4c468A50ef659D5B](https://etherscan.io/address/0x926dF14a23BE491164dCF93f4c468A50ef659D5B).
## Rationale
Bringing Monolith under SEAL Safe Harbor extends a clear, on-chain incentive framework for whitehats to assist in mitigating active exploits against the protocol, complementing Monolith's existing security posture and aligning Monolith with the broader set of DeFi protocols already covered by the framework — including Inverse Finance itself.
On-chain registration is the binding step of the adoption process. Until the Agreement is recorded in the Registry, Monolith is not formally adopted and the safe harbor protections are not in effect.
## Adoption Details
The following terms reflect the Monolith Safe Harbor configuration that will be in effect once this proposal executes.
Predetermined rewards for successful whitehats that recover protocol funds.
|Field|Value|
| --- | --- |
|Percentage|10%|
|Cap (per incident)|1,000,000 DOLA|
|Aggregate Cap|None|
|Retainable|Yes — whitehats may retain their bounty directly from recovered funds, streamlining the payout process for both the whitehat and the protocol|
|Identity|Pseudonymous — whitehats must identify themselves to the protocol but are not required to provide a real name or any formal identification|
|Diligence Requirements|None|
### Asset Recovery Addresses
Addresses controlled by the protocol to which recovered funds will be returned by the whitehat.
|Chain|Address|
| --- | --- |
|Mainnet|0x926dF14a23BE491164dCF93f4c468A50ef659D5B (INV Treasury)|
### In-Scope Accounts
On-chain assets owned by the protocol that are protected under Safe Harbor.
|Chain|Name|Address|Child Contract Scope|
| --- | --- | --- | --- |
|Mainnet|Factory|0x6D961c9DCF1AD73566822BA4B087892e3839B849|None|
|Mainnet|InterestRateModel|0x5B679dDD0edDce323f74AEc38E3849d70d57C113|None|
Child Contract Scope = None is intentional for the Factory: only the listed addresses are in scope. Child markets deployed via the Factory are explicitly excluded so that coverage cannot extend to wrongfully configured Monolith markets.
## On-Chain Actions
Both actions are executed by the Treasury Timelock. Action 1 raises the per-incident bounty cap on the previously deployed Agreement from its initial value of $200,000 to $1,000,000; all other bounty parameters remain unchanged from their currently configured values. Action 2 records the Agreement in the SEAL Safe Harbor Registry, completing formal adoption.
### Action 1 — Update bounty cap on the Monolith Safe Harbor Agreement
|Field|Value|
| --- | --- |
|Target|0x7fb1970F81aCAa1A39f55c92609CE729b0D6f1C0|
|Value|0|
|Signature|setBountyTerms((uint256,uint256,bool,uint8,string,uint256))|
Decoded parameters:
|Field|Current|New|
| --- | --- | --- |
|bountyPercentage|10|10|
|bountyCapUSD|200000|1000000|
|retainable|true|true|
|identity (enum)|1 (Pseudonymous)|1 (Pseudonymous)|
|diligenceRequirements|"None"|"None"|
|aggregateBountyCapUSD|0|0|
### Action 2 — Adopt the Agreement into the SEAL Safe Harbor Registry
|Field|Value|
| --- | --- |
|Target|0x326733493E143b8904716E7A64A9f4fb6A185a2c|
|Value|0|
|Signature|adoptSafeHarbor(address)|
|Param agreementAddress|0x7fb1970F81aCAa1A39f55c92609CE729b0D6f1C0|
## References
* SEAL Safe Harbor framework: https://github.com/security-alliance/safe-harbor
* Monolith Safe Harbor Agreement: https://etherscan.io/address/0x7fb1970F81aCAa1A39f55c92609CE729b0D6f1C0
* SEAL Safe Harbor Registry: https://etherscan.io/address/0x326733493E143b8904716E7A64A9f4fb6A185a2c
* Prior Inverse Finance Safe Harbor adoption: [Proposal 273](https://www.inverse.finance/governance/proposals/mills/273)
# Increase sUSDe LP Daily Borrow Limits and Reduce wstUSR LP Market Ceilings on FiRM
Forum Link: https://forum.inverse.finance/t/increase-susde-lp-daily-borrow-limits-and-reduce-wstusr-lp-market-ceilings-on-firm/652
## Summary
This proposal seeks to adjust parameters across four FiRM markets to better align DOLA issuance capacity with the current risk picture. For the sUSDe LP markets (DOLA/sUSDe and yv-DOLA/sUSDe), daily borrow limits are raised from 2M to 5M DOLA each, reflecting sustained high demand and the improved risk posture established by January's [FeedSwitch v2 deployment](https://www.inverse.finance/governance/proposals/mills/344). For the wstUSR LP markets (DOLA/wstUSR and yv-DOLA/wstUSR), supply ceilings are reduced from 40M to 25M DOLA and from 10M to 5M DOLA respectively, and the daily borrow limit on the primary market is reduced from 5M to 2M DOLA, reflecting the RWG's monitoring-only conclusion on USR following an extended reassessment. These changes collectively represent a risk-adjusted reallocation of DOLA issuance capacity; expanding where the evidence supports it, and right-sizing where caution is warranted.
## Background and Rationale
### sUSDe LP Markets
The DOLA/sUSDe and yv-DOLA/sUSDe markets have consistently been among FiRM's highest-utilization markets. In January 2026, the community approved a comprehensive sUSDe LP parameter update that raised the collateral factor to 92%, reduced the liquidation incentive to 4%, set a minimum debt floor of 5,000 DOLA, and activated FeedSwitch v2 across both markets. That update meaningfully strengthened the risk architecture of these markets. FeedSwitch v2 introduced oracle fallback logic tied to observable, objective Ethena health indicators, providing borrowers a layer of protection during market anomalies and stress scenarios.
Since that proposal passed, borrower demand has continued to grow. The current daily borrow limit of 2M DOLA per market constrains legitimate borrowing activity without providing meaningful additional risk protection given the collateral's fundamentals. Raising the daily borrow limit to 5M DOLA per market gives these markets room to accommodate growth while the per-market supply ceiling and the inherent liquidity depth of the underlying collateral continue to act as the binding risk constraints.
### wstUSR LP Markets
The wstUSR LP markets have been under active monitoring since launch. The RWG has been conducting ongoing due diligence on the Resolv ecosystem; tracking USR's collateral composition, collateralization ratio, redemption infrastructure, and liquidity depth through the weekly Risk Observer Checklist and a dedicated FiRM x USR Risk Dashboard. That body of work, now spanning well over a year of continuous data, has led to a monitoring-only conclusion for new USR exposure. The wstUSR LP parameter adjustments in this proposal reflect that conclusion and bring existing governance caps into alignment with what our risk framework actually supports.
Reducing the DOLA/wstUSR supply ceiling from 40M to 25M DOLA and the yv-DOLA/wstUSR ceiling from 10M to 5M DOLA brings total combined ceiling capacity to 30M DOLA; comfortably within the stress model ceiling. Reducing the daily borrow limit on the primary market from 5M to 2M DOLA aligns with the same posture and reduces the rate at which new DOLA exposure can accumulate. Total current DOLA debt across both wstUSR LP markets is approximately $13.1M, well below both the existing and proposed ceilings and no active borrowers are affected by this change. These adjustments are a governance hygiene measure that corrects a parameter overhang relative to the RWG's actual risk assessment, without disrupting any live positions.
## Actions
1. Set Daily Borrow Limit to 5,000,000 DOLA for the DOLA/sUSDe market
2. Set Daily Borrow Limit to 5,000,000 DOLA for the yv-DOLA/sUSDe market
3. Set Supply Ceiling to 25,000,000 DOLA for the DOLA/wstUSR market
4. Set Daily Borrow Limit to 2,000,000 DOLA for the DOLA/wstUSR market
5. Set Supply Ceiling to 5,000,000 DOLA for the yv-DOLA/wstUSR market
# Offboarding Inverse Contributor
Forum Link: https://forum.inverse.finance/t/offboarding-inverse-contributor/643
It is with deep sadness that we share that the Inverse Finance team has recently received confirmation of the passing of a valued contributor. This news has been verified in communication with the contributor’s family.
Tabboz was a thoughtful and dedicated builder whose work contributed meaningfully to the Inverse ecosystem. Beyond his technical contributions, he was a kind and collaborative presence within the team, and he will be deeply missed by everyone who had the privilege of working alongside him.
Our thoughts and heartfelt condolences are with his family and loved ones during this incredibly difficult time.
In light of these circumstances, this proposal seeks to carry out the necessary operational updates to ensure DAO payroll and vesting systems are properly maintained.
This proposal is strictly administrative in nature and does not preclude separate discussions regarding additional gestures of support or recognition from the DAO toward the contributor’s family.
### On-Chain Actions
* Remove Tabboz from active payroll streams
# Proposal to Launch jrDOLA with Initial DBR Reward Budget
Forum Link: https://forum.inverse.finance/t/proposal-to-launch-jrdola-with-initial-dbr-reward-budget/637
## Summary
This proposal authorizes the launch of the Junior Tranche system (jrDOLA) following successful completion of two comprehensive security audits. The proposal sets initial operational parameters and allocates a DBR reward budget to bootstrap liquidity through an initial measured approach. A follow up proposal will set out to enable FiRM market coverage, pending governance approval.
## Background
jrDOLA introduces a market-driven insurance layer that addresses a fundamental limitation in Inverse Finance's current risk model. As FiRM continues to scale, the protocol absorbs all bad debt directly into DOLA backing, creating concentration risk that constrains growth potential. This model works adequately at current scale but becomes increasingly fragile as total debt exposure grows.
jrDOLA solves this by creating a first-loss capital buffer where depositors voluntarily accept bad debt risk in exchange for yield. If and when FiRM positions become insolvent, the slashing mechanism automatically draws from jrDOLA deposits to repay bad debt before it impacts DOLA backing. This achieves several strategic objectives. First, it protects DOLA solvency by establishing a dedicated bad debt absorption layer. Second, it enables protocol scaling with reduced systemic risk exposure. Third, it provides DOLA holders with a new yield-generating product that earns both sDOLA base yield and DBR rewards. Finally, it establishes automated, permissionless bad debt resolution that requires no manual governance action during stress events.
The system is designed for composability and future expansion. While this initial launch intends to cover FiRM markets, the modular architecture allows governance to add coverage for additional markets and protocols such as the PSM or future Fed deployments without requiring contract redeployment or migration.
The jrDOLA codebase has undergone rigorous security scrutiny through a dual-audit process with Sherlock. The first phase consisted of a private audit conducted with specialized security researchers Hash and Osidian, who focused on ERC-4626 vault mechanics, slashing logic, and withdrawal queue edge cases. All identified issues were addressed prior to the second phase, a public audit contest open to Sherlock's broader security researcher community. The final reports for both are posted for public viewing [here](https://docs.inverse.finance/risk-working-group-digest/prevention/audits). Additionally, Sherlock Shield provides 200,000 USDC in exploit insurance coverage for the first month post-deployment, offering an additional layer of financial protection during the critical early launch period.
## Technical Implementation
### Deployed Contracts
The jrDOLA system consists of four core contracts deployed to Ethereum mainnet:
JuniorDola (jrDOLA) — [0x633821b8e003344e5223509277f2084ea809a452](https://etherscan.io/address/0x633821b8e003344e5223509277f2084ea809a452) The main ERC-4626 vault representing user deposits. All deposits are in sDOLA to provide a base yield layer. The contract integrates an xy=k auction mechanism that converts DBR rewards into DOLA-denominated yield, allowing depositors to earn returns without directly holding or managing DBR tokens.
WithdrawalEscrow — [0x3912365Cc44309c99743597F9d18c6CB946Ab5f0](https://etherscan.io/address/0x3912365Cc44309c99743597F9d18c6CB946Ab5f0) Manages the delayed withdrawal queue. This contract is intentionally immutable to protect user interests. Once a withdrawal is queued, the cooldown duration and exit window parameters are locked and cannot be altered by governance. Users continue earning rewards during cooldown since their funds remain slashable.
LinearInterpolationDelayModel — [0x3b1E443aB423c9A7B1B2EA7b3cB7c0be012a4FbF](https://etherscan.io/address/0x3b1E443aB423c9A7B1B2EA7b3cB7c0be012a4FbF) Calculates withdrawal delays based on queue utilization. Uses linear interpolation between minimum delay (when queue is empty) and maximum delay (at governance-defined threshold). The contract is upgradeable by governance, but active withdrawals continue using the delay parameters from their queue time.
FiRMSlashingModule — [0x9c0e166052d69d6f46422525e1f75d4a8f295423](https://etherscan.io/address/0x9c0e166052d69d6f46422525e1f75d4a8f295423) Implements the permissionless slashing mechanism for FiRM bad debt. Anyone can call the slashing function when a position becomes insolvent. Protective parameters include:
* maxCollateralValue: Prevents slashing positions with significant collateral, forcing liquidators to handle those first
* minDebt: Prevents dust positions from spamming slashing events
* activationDelay: Requires newly added markets to wait before becoming eligible for coverage
A guardian multisig can cancel pending market additions during the delay window.
Helper — [0xe0db3f30c96e272c5ef7dfe3d30272bd2ae3d3cf](https://etherscan.io/address/0xe0db3f30c96e272c5ef7dfe3d30272bd2ae3d3cf) Implements helper functions for interacting with the DBR auction in the JuniorDola contract.
### Initial Parameters
JuniorDola:
* dbrReserve: [1,000,000e18] DBR — virtual reserves for xy=k auction
* dolaReserve: [37,930e18] sDOLA — virtual reserves for xy=k auction
* yearlyRewardBudget: [500,000] DBR — initial annual allocation (operator-controlled)
* maxYearlyRewardBudget: [10,000,000] DBR — governance ceiling
* operator: Treasury Working Group multisig
WithdrawalEscrow:
* withdrawFee: [5] bps — creates friction against cycling behavior; paid to remaining depositors
* exitWindow: [48] hours — time to claim withdrawal after cooldown completes
LinearInterpolationDelayModel:
* minDelay: [1] day — minimum withdrawal delay when queue is empty
* maxDelay: [7] days — applies when queue utilization reaches threshold
* maxDelayThreshold: [10000] bps — e.g., 5,000 bps (50%) means delay scales linearly from min to max as queue fills from 0% to 50%
FiRMSlashingModule:
* maxCollateralValue: [$100] — positions above this must be liquidated normally
* minDebt: [$5] — minimum debt for slashing eligibility
* activationDelay: [7] days — review window for new market additions
* guardian: Policy Committee multisig
These parameters are calibrated for initial launch with conservative assumptions about deposit behavior and queue dynamics. Once TVL scales and usage patterns stabilize, a follow-up proposal intends to transition toward more capital-efficient settings including lower utilization thresholds for delay activation and extended maximum delay periods.
### Governance Controls
Governance CAN:
* Add or remove FiRM markets for coverage (new markets subject to activation delay)
* Increase the maxYearlyRewardBudget ceiling
* Replace the LinearInterpolationDelayModel contract
* Adjust FiRMSlashingModule parameters
* Change the guardian address
Governance CANNOT:
* Pause withdrawals or interfere with the active withdrawal queue
* Change withdrawal terms for users already in queue
* Access deposited funds except through legitimate slashing
* Bypass market activation delays
Operator (TWG multisig) CAN:
* Adjust yearlyRewardBudget within the governance-set ceiling
Operator CANNOT:
* Exceed the governance-approved ceiling
* Access deposited funds
* Modify withdrawal or slashing parameters
Guardian CAN:
* Remove markets from slashing protection before the activation period has elapsed.
Guardian CANNOT:
* Interfere with operations of actively protected markets.
### Operational Mechanics
#### For Depositors
Depositing into jrDOLA follows standard ERC-4626 vault interactions. Users approve sDOLA to the jrDOLA contract and call either deposit(amount, receiver) or mint(shares, receiver) depending on whether they prefer to specify deposit amount or desired shares. Upon deposit, users receive jrDOLA shares representing their proportional claim on the vault. Additionally, depositors begin earning DBR rewards distributed through the xy=k auction mechanism, which automatically converts DBR into DOLA-denominated yield without requiring direct DBR interaction.
Withdrawing requires a multi-step process designed to provide security during periods of stress while maintaining reasonable user experience during normal operations. Users first call queueWithdrawal(shares) to enter the withdrawal queue. At this moment, the system snapshots their withdrawal parameters including cooldown duration and exit window timing, and applies the withdrawal fee, which is distributed to remaining depositors. Users then wait for the cooldown period, which ranges from the minimum delay to maximum delay based on current queue utilization as calculated by the LinearInterpolationDelayModel. During this cooldown, users continue earning rewards since their funds remain in the vault and continue to provide slashable insurance coverage. After the cooldown completes, users enter their exit window during which they can claim their withdrawal by calling the claim function. Users receive sDOLA representing their original deposit plus all accrued yield, minus any slashing events that occurred while they were deposited, minus the withdrawal fee. Users can also cancel their withdrawal during the cooldown period and return to the active depositor pool.
#### For the Protocol
Reward distribution operates through an ongoing auction mechanism integrated into the jrDOLA contract. The protocol allocates DBR to the jrDOLA contract according to the yearlyRewardBudget parameter controlled by the operator within governance-set limits. These DBR tokens enter an xy=k constant product market maker with virtual DOLA reserves, creating a permissionless auction where anyone can swap sDOLA for DBR. This increases the vault's total assets without changing the share supply, causing the sDOLA-per-share exchange rate to increase. Depositors thus earn DOLA-denominated yield without ever directly interacting with DBR tokens. The auction mechanism provides continuous price discovery and automatically adjusts reward distribution based on DBR market dynamics.
The bad debt coverage mechanism operates through a permissionless slashing process. When a FiRM position becomes insolvent such that the debt value exceeds collateral value based on oracle pricing, anyone can call slash(market, borrower) on the FiRMSlashingModule contract. The module first verifies that the position is legitimately insolvent by checking current debt and collateral values. It then applies protective checks, ensuring the position's collateral value is below maxCollateralValue to prevent slashing positions that should be liquidated through normal mechanisms, and ensuring debt exceeds minDebt to avoid processing economically insignificant positions. If all checks pass, the module calculates the required DOLA amount needed to bring the position's debt-to-collateral ratio back to parity. It then triggers a pro-rata slash against the jrDOLA vault, where all depositors' share values decrease proportionally to socialize the loss. The recovered DOLA is used to repay the bad debt in the FiRM market, removing the insolvency. This protects DOLA backing by absorbing bad debt into jrDOLA before it impacts core protocol reserves.
## Budget Request
The budget operates within a controlled structure. The maxYearlyRewardBudget parameter of 10,000,000 DBR represents a governance-enforced ceiling that can only be increased through full governance proposals. Within this ceiling, the yearlyRewardBudget parameter of 500,000 DBR represents the initial active budget upon approval of this proposal. This amount is controlled by the operator (Treasury Working Group multisig) and can be adjusted up to the governance ceiling without requiring additional votes, enabling responsive adjustment to market conditions while maintaining ultimate governance control.
The initial budget request was calibrated through analysis of comparable insurance mechanisms in DeFi, modeling of depositor yield requirements given FiRM's historical bad debt frequency and severity, and assessment of total DBR availability relative to competing uses across the protocol ecosystem.
## On-Chain Actions
- jrDOLA (setOperator, initialize, setSlashingModule, setYearlyRewardBudget, setMaxYearlyRewardBudget)
- WithdrawalEscrow (initialize, withdrawFee, exitWindow)
- LinearInterpolationDelayModel (setMinDelay, setMaxDelay, setMaxDelayThresholdBps)
- FiRMSlashingModule (setGuardian, setMaxCollateralValue, setMinDebt, setActivationDelay)
- DBR (addMinter)
# Proposal to Launch jrDOLA with Initial DBR Reward Budget
Forum Link: https://forum.inverse.finance/t/proposal-to-launch-jrdola-with-initial-dbr-reward-budget/637
## Summary
This proposal authorizes the launch of the Junior Tranche system (jrDOLA) following successful completion of two comprehensive security audits. The proposal sets initial operational parameters and allocates a DBR reward budget to bootstrap liquidity through an initial measured approach. A follow up proposal will set out to enable FiRM market coverage, pending governance approval.
## Background
jrDOLA introduces a market-driven insurance layer that addresses a fundamental limitation in Inverse Finance's current risk model. As FiRM continues to scale, the protocol absorbs all bad debt directly into DOLA backing, creating concentration risk that constrains growth potential. This model works adequately at current scale but becomes increasingly fragile as total debt exposure grows.
jrDOLA solves this by creating a first-loss capital buffer where depositors voluntarily accept bad debt risk in exchange for yield. If and when FiRM positions become insolvent, the slashing mechanism automatically draws from jrDOLA deposits to repay bad debt before it impacts DOLA backing. This achieves several strategic objectives. First, it protects DOLA solvency by establishing a dedicated bad debt absorption layer. Second, it enables protocol scaling with reduced systemic risk exposure. Third, it provides DOLA holders with a new yield-generating product that earns both sDOLA base yield and DBR rewards. Finally, it establishes automated, permissionless bad debt resolution that requires no manual governance action during stress events.
The system is designed for composability and future expansion. While this initial launch intends to cover FiRM markets, the modular architecture allows governance to add coverage for additional markets and protocols such as the PSM or future Fed deployments without requiring contract redeployment or migration.
The jrDOLA codebase has undergone rigorous security scrutiny through a dual-audit process with Sherlock. The first phase consisted of a private audit conducted with specialized security researchers Hash and Osidian, who focused on ERC-4626 vault mechanics, slashing logic, and withdrawal queue edge cases. All identified issues were addressed prior to the second phase, a public audit contest open to Sherlock's broader security researcher community. The final reports for both are posted for public viewing [here](https://docs.inverse.finance/risk-working-group-digest/prevention/audits). Additionally, Sherlock Shield provides 200,000 USDC in exploit insurance coverage for the first month post-deployment, offering an additional layer of financial protection during the critical early launch period.
## Technical Implementation
### Deployed Contracts
The jrDOLA system consists of four core contracts deployed to Ethereum mainnet:
JuniorDola (jrDOLA) — [0xf4307a1354c0463812b3ce0f509c227f5cd1ccfd](https://etherscan.io/address/0xf4307a1354c0463812b3ce0f509c227f5cd1ccfd) The main ERC-4626 vault representing user deposits. All deposits are in sDOLA to provide a base yield layer. The contract integrates an xy=k auction mechanism that converts DBR rewards into DOLA-denominated yield, allowing depositors to earn returns without directly holding or managing DBR tokens.
WithdrawalEscrow — [0x3912365cc44309c99743597f9d18c6cb946ab5f0](https://etherscan.io/address/0x3912365cc44309c99743597f9d18c6cb946ab5f0) Manages the delayed withdrawal queue. This contract is intentionally immutable to protect user interests. Once a withdrawal is queued, the cooldown duration and exit window parameters are locked and cannot be altered by governance. Users continue earning rewards during cooldown since their funds remain slashable.
LinearInterpolationDelayModel — [0x3b1e443ab423c9a7b1b2ea7b3cb7c0be012a4fbf](https://etherscan.io/address/0x3b1e443ab423c9a7b1b2ea7b3cb7c0be012a4fbf) Calculates withdrawal delays based on queue utilization. Uses linear interpolation between minimum delay (when queue is empty) and maximum delay (at governance-defined threshold). The contract is upgradeable by governance, but active withdrawals continue using the delay parameters from their queue time.
FiRMSlashingModule — [0x6d27dd57a7dbf5b27a3fcabd75c916ac765a346c](https://etherscan.io/address/0x6d27dd57a7dbf5b27a3fcabd75c916ac765a346c) Implements the permissionless slashing mechanism for FiRM bad debt. Anyone can call the slashing function when a position becomes insolvent. Protective parameters include:
* maxCollateralValue: Prevents slashing positions with significant collateral, forcing liquidators to handle those first
* minDebt: Prevents dust positions from spamming slashing events
* activationDelay: Requires newly added markets to wait before becoming eligible for coverage
A guardian multisig can cancel pending market additions during the delay window.
Helper — [0x93c0610b258e42c43544e74cfc1efec8c1f5459b](https://etherscan.io/address/0x93c0610b258e42c43544e74cfc1efec8c1f5459b) Implements helper functions for interacting with the DBR auction in the JuniorDola contract.
### Initial Parameters
JuniorDola:
* dbrReserve: [1,000,000e18] DBR — virtual reserves for xy=k auction
* dolaReserve: [37,930e18] sDOLA — virtual reserves for xy=k auction
* yearlyRewardBudget: [500,000] DBR — initial annual allocation (operator-controlled)
* maxYearlyRewardBudget: [10,000,000] DBR — governance ceiling
* operator: Treasury Working Group multisig
WithdrawalEscrow:
* withdrawFee: [5] bps — creates friction against cycling behavior; paid to remaining depositors
* exitWindow: [48] hours — time to claim withdrawal after cooldown completes
LinearInterpolationDelayModel:
* minDelay: [1] day — minimum withdrawal delay when queue is empty
* maxDelay: [7] days — applies when queue utilization reaches threshold
* maxDelayThreshold: [10000] bps — e.g., 5,000 bps (50%) means delay scales linearly from min to max as queue fills from 0% to 50%
FiRMSlashingModule:
* maxCollateralValue: [$100] — positions above this must be liquidated normally
* minDebt: [$5] — minimum debt for slashing eligibility
* activationDelay: [7] days — review window for new market additions
* guardian: Policy Committee multisig
These parameters are calibrated for initial launch with conservative assumptions about deposit behavior and queue dynamics. Once TVL scales and usage patterns stabilize, a follow-up proposal intends to transition toward more capital-efficient settings including lower utilization thresholds for delay activation and extended maximum delay periods.
### Governance Controls
Governance CAN:
* Add or remove FiRM markets for coverage (new markets subject to activation delay)
* Increase the maxYearlyRewardBudget ceiling
* Replace the LinearInterpolationDelayModel contract
* Adjust FiRMSlashingModule parameters
* Change the guardian address
Governance CANNOT:
* Pause withdrawals or interfere with the active withdrawal queue
* Change withdrawal terms for users already in queue
* Access deposited funds except through legitimate slashing
* Bypass market activation delays
Operator (TWG multisig) CAN:
* Adjust yearlyRewardBudget within the governance-set ceiling
Operator CANNOT:
* Exceed the governance-approved ceiling
* Access deposited funds
* Modify withdrawal or slashing parameters
Guardian CAN:
* Remove markets from slashing protection before the activation period has elapsed.
Guardian CANNOT:
* Interfere with operations of actively protected markets.
### Operational Mechanics
#### For Depositors
Depositing into jrDOLA follows standard ERC-4626 vault interactions. Users approve sDOLA to the jrDOLA contract and call either deposit(amount, receiver) or mint(shares, receiver) depending on whether they prefer to specify deposit amount or desired shares. Upon deposit, users receive jrDOLA shares representing their proportional claim on the vault. Additionally, depositors begin earning DBR rewards distributed through the xy=k auction mechanism, which automatically converts DBR into DOLA-denominated yield without requiring direct DBR interaction.
Withdrawing requires a multi-step process designed to provide security during periods of stress while maintaining reasonable user experience during normal operations. Users first call queueWithdrawal(shares) to enter the withdrawal queue. At this moment, the system snapshots their withdrawal parameters including cooldown duration and exit window timing, and applies the withdrawal fee, which is distributed to remaining depositors. Users then wait for the cooldown period, which ranges from the minimum delay to maximum delay based on current queue utilization as calculated by the LinearInterpolationDelayModel. During this cooldown, users continue earning rewards since their funds remain in the vault and continue to provide slashable insurance coverage. After the cooldown completes, users enter their exit window during which they can claim their withdrawal by calling the claim function. Users receive sDOLA representing their original deposit plus all accrued yield, minus any slashing events that occurred while they were deposited, minus the withdrawal fee. Users can also cancel their withdrawal during the cooldown period and return to the active depositor pool.
#### For the Protocol
Reward distribution operates through an ongoing auction mechanism integrated into the jrDOLA contract. The protocol allocates DBR to the jrDOLA contract according to the yearlyRewardBudget parameter controlled by the operator within governance-set limits. These DBR tokens enter an xy=k constant product market maker with virtual DOLA reserves, creating a permissionless auction where anyone can swap sDOLA for DBR. This increases the vault's total assets without changing the share supply, causing the sDOLA-per-share exchange rate to increase. Depositors thus earn DOLA-denominated yield without ever directly interacting with DBR tokens. The auction mechanism provides continuous price discovery and automatically adjusts reward distribution based on DBR market dynamics.
The bad debt coverage mechanism operates through a permissionless slashing process. When a FiRM position becomes insolvent such that the debt value exceeds collateral value based on oracle pricing, anyone can call slash(market, borrower) on the FiRMSlashingModule contract. The module first verifies that the position is legitimately insolvent by checking current debt and collateral values. It then applies protective checks, ensuring the position's collateral value is below maxCollateralValue to prevent slashing positions that should be liquidated through normal mechanisms, and ensuring debt exceeds minDebt to avoid processing economically insignificant positions. If all checks pass, the module calculates the required DOLA amount needed to bring the position's debt-to-collateral ratio back to parity. It then triggers a pro-rata slash against the jrDOLA vault, where all depositors' share values decrease proportionally to socialize the loss. The recovered DOLA is used to repay the bad debt in the FiRM market, removing the insolvency. This protects DOLA backing by absorbing bad debt into jrDOLA before it impacts core protocol reserves.
## Budget Request
The budget operates within a controlled structure. The maxYearlyRewardBudget parameter of 10,000,000 DBR represents a governance-enforced ceiling that can only be increased through full governance proposals. Within this ceiling, the yearlyRewardBudget parameter of 500,000 DBR represents the initial active budget upon approval of this proposal. This amount is controlled by the operator (Treasury Working Group multisig) and can be adjusted up to the governance ceiling without requiring additional votes, enabling responsive adjustment to market conditions while maintaining ultimate governance control.
The initial budget request was calibrated through analysis of comparable insurance mechanisms in DeFi, modeling of depositor yield requirements given FiRM's historical bad debt frequency and severity, and assessment of total DBR availability relative to competing uses across the protocol ecosystem.
## On-Chain Actions
- jrDOLA (setOperator, initialize, setSlashingModule, setYearlyRewardBudget, setMaxYearlyRewardBudget)
- WithdrawalEscrow (initialize, withdrawFee, exitWindow)
- LinearInterpolationDelayModel (setMinDelay, setMaxDelay, setMaxDelayThresholdBps)
- FiRMSlashingModule (setGuardian, setMaxCollateralValue, setMinDebt, setActivationDelay)
- DBR (addMinter)
# sUSDe LP FiRM Markets Feed Switch Implementation & Parameter Updates
Forum Link: https://forum.inverse.finance/t/susde-lp-firm-markets-feed-switch-implementation-parameter-updates/636
## Summary
This proposal implements four coordinated actions for the DOLA/sUSDe LP markets on FiRM:
1. Feed Switch Implementation: Transition from the current Chainlink sUSDe-USD derived pricing to FeedSwitch V2 - an audited oracle architecture that defaults to stable pricing ($1 via USDT Chainlink feed) with guardian-controlled fallback to market pricing when conditions warrant.
2. Collateral Factor Increase: Raise the collateral factor from 90% to 92%, enabled by the improved feed stability.
3. Liquidation Incentive Reduction: Lower the liquidation incentive from 5% to 4%, justified by larger FiRM position sizes and reliable, measured liquidator support.
4. Minimum Debt Increase: Raise the minimum debt from $3k to $5k to align with the reduced incentive and keep the market oriented toward larger position sizes.
These actions are interdependent: the feed switch provides the foundation that justifies the market parameter changes.
## Background
The DOLA/sUSDe LP markets have demonstrated strong product-market fit, with approximately $86.5M in outstanding debt (split 77.75M in the Convex implementation and 7.7M in the Yearn vault) representing over half of FiRM's total borrowing activity. User demand continues to grow, supported by competitive yields and efficient looping strategies. Important to note that DOLA’s (via FiRM) total exposure to USDe represents a small fraction of USDe’s circulating supply and redemption capacity.
The price oracle for the markets derives sUSDe LP token pricing through a multi-step process:
1. Pull Chainlink sUSDe-USD feed, normalized by the sUSDe:USDe exchange rate
2. Apply pessimistic pricing: take the lower of DOLA ($1 fixed) and the derived sUSDe value
3. Multiply by the Curve pool's virtual price to determine LP token value
This methodology directly reflects on-chain market conditions, and is the current pricing solution in place for all existing LP FiRM markets. However, market pricing introduces unnecessary volatility that may not always reflect fundamental value.
The RWG has, as of late, conducted extensive analysis of oracle behavior for redemption-backed stablecoins across FiRM markets. This research, spanning price feed mechanics, collateral factor sensitivity, and stress scenario modeling, has informed a two-track approach to address the above:
Immediate: Deploy FeedSwitch V2 as an interim solution providing stable pricing with guardian-controlled market fallback.
Ongoing: Continue development of an advanced proof-of-reserves hybrid architecture that programmatically ties pricing to verified backing levels. This longer-term solution will further reduce tail risk while minimizing trust assumptions.
The feed switch represents a pragmatic first step that can be deployed using audited, battle-tested code while the more sophisticated solution is developed. Automation of the switch itself remains the preferred end-state.
## FeedSwitch V2 Overview
### Architecture
FeedSwitch V2 is an evolution of the oracle switch mechanism successfully deployed for PT markets on FiRM. The implementation has been adapted for LP feeds with the following capabilities:
**Feedswitch V2 Contract: [0x3326a10A83B77fAae29aedBB8AAEB18E5872624D](https://etherscan.io/address/0x3326a10A83B77fAae29aedBB8AAEB18E5872624D#code)**
|Feature|Specification|
| --- | --- |
|Primary Feed|Stable pricing via USDT Chainlink feed (USDe = USDT assumption)|
|Fallback Feed|Current market-derived pricing (Chainlink sUSDe-USD methodology)|
|Guardian|RWG Multisig|
|Timelock|Configurable by governance; initially set to 0 (immediate switching)|
The RWG will communicate any feed switch via Inverse channels when practicable; however, because the timelock is 0 and switching is discretionary, borrowers must treat market-derived sUSDe pricing as an always-possible operating state.
Normal Conditions: The feed returns stable LP token pricing based on the USDT reference, insulating users from short-term market volatility that doesn't reflect redemption value.
Stress Conditions: If market conditions warrant (per alert severity framework below), the RWG guardian triggers a switch to market-derived pricing, enabling liquidations to proceed based on actual market conditions.
### Alert Severity Framework
Inverse Finance RWG will continuously monitor a set of non-exhaustive indicators to assess whether FiRM’s sUSDe markets should rely on stable reference pricing or switch to market-derived pricing. These indicators are provided for general transparency only; Inverse Finance reserves the right to switch the feed at its discretion, based on these signals and/or any other relevant information.
### Key indicators we generally observe
* Mint/Redeem Readiness: signs of impaired redemption functionality or degraded operational throughput (e.g., buffer stress, throttling constraints, backlog/processing issues).
* Reserve Fund Monitoring: material changes in availability or usage that indicate persistent negative funding or reduced capacity to stabilize adverse conditions.
* Collateral Integrity/Transparency Drift: sustained changes in collateralization, liquid stable reserves, or other reported backing integrity metrics that may indicate elevated impairment risk.
* Broader Exchange/Contagion Events: major exchange failures or systemic market disruptions that could impair settlement, hedging, or convertibility paths, even absent confirmed direct exposure.
The framework is an internal monitoring process used to guide operational readiness and inform FeedSwitch decisions. The indicators referenced in this proposal are intentionally non-exhaustive. These indicators are operationalized into internal reports (including automated alerting components), but no single metric is intended to serve as a hard trigger; Inverse Finance reserves the right to switch feeds at its discretion, based on these factors and/or any other relevant information.
## Rationale
The transition to FeedSwitch V2 addresses a specific dynamic in successful looping markets: as more liquidity concentrates in FiRM-associated pools, external liquidity sources thin, and market-derived pricing becomes an increasingly imperfect proxy for fundamental value.
For sUSDe specifically:
* Redemption value is backed by Ethena's delta-neutral strategy
* The 7-day unlock creates temporary price dislocations that don't reflect underlying value
* Market volatility can trigger liquidations that are punitive to users without corresponding protocol risk
FeedSwitch V2 introduces a controlled trust mechanism, preserving free-market pricing as the ultimate backstop, while defaulting to stable reference pricing during normal conditions where market dislocations do not reflect redemption value.
### Operational Risk Alignment: USDT Reference
While the mint/redeem contract buffer policy supports both USDT and USDC, Ethena’s critical operating path is meaningfully tied to USDT liquidity, both through the RFQ mint/redeem rails (supported pairs include USDT/USDe and USDC/USDe) and through the stablecoin settlement flows that are most likely to be relied on during stressed conditions. In practice, this matters because if Ethena needs to facilitate redemptions under volatility, it may need to rebalance and refill the mint/redeem contract using the most liquid and operationally available stablecoin path.
Separately, Ethena documents that its delta-neutral hedge stack uses linear perpetuals denominated in USDT, which makes the system positionally long USDT (margin and PnL are in USDT). As a result, a severe USDT idiosyncratic event (e.g., depeg or impaired convertibility) can translate into backing degradation and weaken collateralization dynamics even if the underlying directional hedges are intact. Ethena explicitly frames this as a monitored risk.
Accordingly, referencing USDT rather than hardcoding $1.00 better matches the real settlement and risk surface during stress. It aligns pricing with the asset used in primary redemption/arbitrage flows and avoids overreacting to short-lived venue distortions, while preserving the ability to fall back to market-derived pricing during broader dislocations.
### Policy Actions Validate Feed Design Assumptions
Recent Ethena risk-governance actions reinforce the distinction between fundamental backing risk and venue/market-structure dislocations, which is especially relevant for sUSDe given its 7-day cooldown to USDe. [In November 2025](https://gov.ethenafoundation.com/t/proposal-usde-redeem-for-dislocations-on-secondary-markets/712), Ethena approved a last-resort discount buyback + burn tool that can be used only below a strict threshold (e.g., $0.99), funded from a capped portion of backing assets, with acquired USDe burned after settlement. Ethena has also communicated an ad-hoc proof-of-reserves update within 24 hours if emergency mechanics are used.
This matters because sUSDe discounts can arise from two distinct drivers: USDe-level stress (where anchor support and transparency measures are directly relevant) and sUSDe-specific time-to-liquidity pricing from the cooldown (where a spread can persist even if redemption value remains intact). The proposal’s oracle controls are designed around that reality - stable pricing as the default, with a market-based fallback during acute exchange disruption or broader contagion, without assuming temporary dislocations imply true backing impairment.
## On-Chain Actions
### Collateral Factor Increase (→ 92%)
The current 90% CF was set conservatively given market-derived pricing volatility. With stable pricing as the default:
* Reduced liquidation risk from transient price movements means users can maintain positions through short-term volatility
* 92% is an appropriate figure relative to the underlying collateral quality. This will increase capital efficiency and competitive positioning vs. alternative venues
Additionally, Ethena’s recent enhancements to USDe stress tooling and transparency provide incremental support that severe, venue-specific dislocations are less likely to persist as fundamental impairment, complementing our oracle controls rather than replacing them.
### Liquidation Incentive Decrease (→ 4%)
In the sUSDe-DOLA and yv-sUSDe-DOLA FiRM markets, we’ve observed successful liquidations at meaningful scale (4 liquidation events spanning Dec 2024–Nov 2025), including a large single liquidation with ~336.7k repaid debt and ~462.1k total repaid. Liquidations were executed across four distinct liquidators, suggesting liquidation capacity is not reliant on a single actor and has been effective even for larger position sizes. This observed liquidation performance supports reducing the liquidation incentive from 5% to 4%, particularly given these markets skew toward larger, more liquidatable positions.
### Minimum Debt Increase (→ 5000 DOLA)
We propose increasing the minimum borrow size from 3,000 DOLA to 5,000 DOLA to preserve liquidation efficiency alongside the reduction in liquidation incentive from 5% to 4%. Liquidations carry a relatively fixed execution cost that becomes materially more punitive during stressed markets. In a scenario that drives persistent USDe/sUSDe dislocation or peg impairment, we would also expect a sharp increase in on-chain activity (risk-off flows, arbitrage, liquidations), which typically elevates gas costs and further compresses liquidator margins. A higher minimum debt improves the likelihood that each liquidation remains economically viable and therefore reliably executed by third-party liquidators, even under congestion.
This adjustment is also consistent with observed usage in the sUSDe–DOLA and yv-sUSDe–DOLA markets, where borrower positions are predominantly larger. Raising the minimum debt primarily reduces the long-tail of small borrows that are least attractive to liquidate under elevated gas and a reduced incentive, while having minimal impact on the typical borrower profile in these markets. As a result, this change improves expected liquidation completeness during adverse conditions by avoiding the lowest-notional positions that are most likely to become uneconomic to clear.
### Set Oracle Price Feeds
1. sUSDe-DOLA CLP feed : [0xe741c804Ca2e26a0aa5511a6018119CD6991Aaa5](https://etherscan.io/address/0xe741c804Ca2e26a0aa5511a6018119CD6991Aaa5)
2. sUSDe-DOLA Yearn feed: [0x2dc3ceb337a7b62831f4f27688aacfbb9b4c0afa](https://etherscan.io/address/0x2dc3ceb337a7b62831f4f27688aacfbb9b4c0afa)
# Redeploy DOLA Peg Stability Module
Forum Link: https://forum.inverse.finance/t/redeploy-dola-peg-stability-module/634
## Summary
This proposal redeploys the DOLA PSM for USDS with added Expansion and Contraction events, grants minting rights to the new PSMFed, and deprecates the original PSMFed deployment. The PSM functionality and parameters remain unchanged from the [original activation proposal](https://www.inverse.finance/governance/proposals/mills/311).
## Background
The PSM was originally deployed in August 2025 but lacked standard Expansion and Contraction events present in other Fed contracts. Since the PSM has seen minimal usage to date, redeployment with these events adds no operational risk while improving monitoring and transparency.
## Specification
The redeployed contracts maintain identical parameters to the original deployment:
* Buy Fee: 0 bps (1 USDS = 1 DOLA)
* Sell Fee: 20 bps (1 DOLA = 0.998 USDS)
* Minimum Total Supply: 100,000 shares to mitigate inflation-style attacks
* Supply Cap: 10,000,000 DOLA
New Contracts:
* PSM: 0x1d02f2841afa3cc20435a8c804c24deac5f30dfa
* PSMFed: 0x67fc21332d24fc5250a3b7fc988191ad7f38f9cc
* Controller (unchanged): 0xe3475728673eabaec90a37aa3ae2ced9f0db5ff2
## On-Chain Actions
* PSM.setBuyFeeBps = 0
* PSM.setSellFeeBps = 20
* PSM.setMinTotalSupply = 100k
* PSMFed.setSupplyCap = 10M
* Add PSM as DOLA Minter
* Remove old PSM contract as DOLA Minter
# Redeploy DOLA Peg Stability Module
Forum Link: https://forum.inverse.finance/t/redeploy-dola-peg-stability-module/634
## Summary
This proposal redeploys the DOLA PSM for USDS with added Expansion and Contraction events, grants minting rights to the new PSMFed, and deprecates the original PSMFed deployment. The PSM functionality and parameters remain unchanged from the [original activation proposal](https://www.inverse.finance/governance/proposals/mills/311).
## Background
The PSM was originally deployed in August 2025 but lacked standard Expansion and Contraction events present in other Fed contracts. Since the PSM has seen minimal usage to date, redeployment with these events adds no operational risk while improving monitoring and transparency.
## Specification
The redeployed contracts maintain identical parameters to the original deployment:
* Buy Fee: 0 bps (1 USDS = 1 DOLA)
* Sell Fee: 20 bps (1 DOLA = 0.998 USDS)
* Minimum Total Supply: 100,000 shares to mitigate inflation-style attacks
* Supply Cap: 10,000,000 DOLA
New Contracts:
* PSM: 0x1d02f2841afa3cc20435a8c804c24deac5f30dfa
* PSMFed: 0x67fc21332d24fc5250a3b7fc988191ad7f38f9cc
* Controller (unchanged): 0xe3475728673eabaec90a37aa3ae2ced9f0db5ff2
## On-Chain Actions
* PSM.setBuyFeeBps = 0
* PSM.setSellFeeBps = 20
* PSM.setMinTotalSupply = 100k
* PSMFed.setSupplyCap = 10M
* Add PSM as DOLA Minter
* Remove old PSM contract as DOLA Minter
# FiRM Liquidation Factor Adjustment for Select Volatile Collateral Markets
Forum Link: https://forum.inverse.finance/t/firm-liquidation-factor-adjustment-for-select-volatile-collateral-markets/631
## Summary
Following analysis performed on the October 10th, 2025 liquidation cascade - the largest in cryptocurrency history - the Risk Working Group (RWG) proposes systematic liquidation factor (LF) increases across five volatile collateral markets to align FiRM's safety parameters with empirical evidence from extreme market stress. Throughout this event, Chainlink oracles operated correctly by design, but network congestion created on-chain publication delays that produced step-wise repricing, compressing multiple minutes of price movement into single oracle updates and overwhelming liquidation execution in markets with lower LF settings.
Proposed Changes:
|Market|Current LF|Proposed LF|Change|
| --- | --- | --- | --- |
|wstETH|60%|75%|+15%|
|wBTC|60%|75%|+15%|
|wETH|40%|75%|+35%|
|cbBTC|50%|75%|+25%|
|CRV|60%|100%|+40%|
|No Change|Current|Proposed||
|INV|50%|50%|Maintain|
|st-yETH|100%|100%|Maintain|
|CVX|100%|100%|Maintain|
|cvxCRV|100%|100%|Maintain|
|st-yCRV|100%|100%|Maintain|
These adjustments strengthen FiRM's resilience to oracle latency during extreme market conditions while RWG collaborates with Chainlink to individually backtest each volatile asset's oracle performance against October 10th data, verifying that fine-tuned OCR (Off-Chain Reporting) configurations produce validated improvements that would successfully pass the stress test conditions observed during the event. To clarify, no user action is required at this time.
By securing existing markets, RWG establishes the foundation to confidently pivot toward growth-facing initiatives.
## Background
On October 10, 2025, crypto markets experienced an unprecedented liquidation cascade. Within hours, over $19.2 billion in leveraged positions were liquidated across DeFi and CeFi platforms. Altcoins were significantly impacted, many losing 50-60% of value within 10-minute intervals.
FiRM processed 79 liquidations across three markets (CVX: 72, CRV: 5, cvxCRV: 2), clearing approximately $717,000 DOLA - one of the largest 24-hour liquidation periods in protocol history. CVX dropped 71% in 27 minutes (from $2.94 to $0.85), resulting in $110,310 in bad debt, since repaid through a generous contribution from CVX co-founders C2tp and Winthorpe. RWG published a [comprehensive analysis](https://www.inverse.finance/blog/posts/en-US/october-10th-stress-test-firm-performance-analysis) of the CVX/USD Chainlink oracle performance during the event, which led to [governance action](https://www.inverse.finance/governance/proposals/mills/331) increasing CVX LF from 60% to 100% to secure the market. Markets with 100% LF (cvxCRV, st-yCRV) experienced zero bad debt despite exposure to similar volatility. FiRM remains free of bad debt and fully operational.
The October 10th liquidation cascade - an isolated, unprecedented market shock - occurred against the backdrop of broader Q4 2025 market deterioration. Throughout October and November, DeFi has experienced a series of high-profile protocol exploits (Moonwell, Balancer) and stablecoin depegs (Elixir, Stream, Yala), with on-chain indicators revealing defensive positioning across DeFi ecosystems. The combination of an isolated extreme volatility event layered on top of already fragile market conditions amplified systemic stress, justifying heightened risk management across longtail volatile collateral.
### The Role of Oracle Latency
RWG is conducting comprehensive analysis of Chainlink oracle performance across volatile and stable assets listed on FiRM to understand the relationship between oracle latency and liquidation outcomes during the October 10th event. Chainlink oracles maintained full data integrity throughout the event with no gaps or invalid rounds, demonstrating that the issue was feed provider latency-driven rather than FiRM failure-driven, and responsiveness normalized as volatility subsided. RWG is now working with Chainlink to conduct similar detailed analysis across all other collateral markets to understand oracle behavior patterns and validate whether current LF and CF methodologies provide appropriate safety margins for each asset's specific oracle configuration and latency profile.
## Proposed Parameter Changes
While 100% LF across all FiRM volatile markets is the most protective configuration for protocol safety, borrower experience and loss scaling represent critical trade-offs that must be balanced against risk minimization. In FiRM's model, the liquidation incentive (10-12% for volatile assets) applies to whatever portion of debt gets liquidated - when LF is 100%, that penalty applies to the entire position, amplifying user loss and typically ending borrower retention altogether. Partial liquidations, by contrast, give borrowers the opportunity to re-collateralize or repay without losing their entire position, maintaining borrower relationships even during market stress.
The broader DeFi ecosystem has been moving toward more borrower-friendly unwind mechanisms. Aave v3 and Spark implement dynamic close factors that liquidate only 50% of positions when health factor exceeds 0.95, escalating to 100% only in deep distress. Llamalend by Curve pioneered soft liquidations that typically unwind just 1-5% of debt to restore solvency, with these designs showing clear improvements in user retention and becoming major competitive selling points. FiRM currently has room to improve user experience through dynamic or tiered LF logic that scales with health factor or asset-specific liquidity profiles, though such enhancements would require FiRM v2 architecture with new market contract implementations.
### CRV ( → 100% LF)
The proposed max increase to the CRV market’s LF parameter represents continuation of FiRM's longtail asset risk mitigation strategy that began with CVX's post-October 10th correction to 100% LF. The CRV market on FiRM is rich with operational history and battle-tested solvency across multiple stress events; justifying its continuation. [AAVE moved CRV to non-borrowable status](https://governance.aave.com/t/arfc-deprecation-of-low-demand-volatile-assets-on-aave-v3-instances/23261) following the event, setting borrow caps to 1 and LTV to 0%, citing demonstrated oracle risks and low market efficiency. RWG's analysis and industry findings support maximum protective parameters.
### wETH, wBTC, wstETH, cbBTC ( → 75% LF)
These four markets represent FiRM's highest-quality volatile collateral. Despite varying oracle feed complexity - from wETH's direct ETH/USD feed (0.5% deviation, 1-hour heartbeat) to wstETH's triple-feed architecture (stETH/ETH, stETH/USD, ETH/USD) and bridge asset risk considerations with cbBTC and wBTC's; these assets share a critical characteristic that distinguishes them from longtail collateral: low volatility relative to high liquidity depth. This fundamental property makes them significantly less vulnerable to the granular price latency issues that overwhelmed liquidation execution in longtail markets during October 10th, as their deep order books and slower price movements provide greater time windows for liquidators to execute before positions become underwater. The proposed 75% LF sits on the higher end of industry standards, but FiRM's architectural differentiators provide borrower-focused safety features that enable competitive market positioning despite conservative liquidation parameters.
### No Changes: Validated Parameters
* INV market maintains 50% LF as appropriate for its unique risk profile as Inverse Finance’s governance token. The current setting recognizes that partial liquidations reduce market impact for a thin-orderbook, protecting against cascading liquidations in negative feedback loops. Currently, the largest position in the market represents ~81.5% of outstanding debt and maintains heavy overcollateralization, making 50% LF safe for the dominant exposure.
* CVX market maintains 100% LF following its [post-October 10th correction](https://www.inverse.finance/governance/proposals/mills/331).
* st-yETH market is being offboarded through separate [governance action](https://forum.inverse.finance/t/offboard-the-st-yeth-market-on-firm/626) due to sustained deterioration of its liquid value and operational integrity.
* cvxCRV and st-yCRV markets were proactively [upgraded to 100% LF in July 2025](https://www.inverse.finance/governance/proposals/mills/304) following RWG's identification of liquidity decline. Both assets lack CEX presence and rely on thinning on-chain Curve pools with deteriorating pegs (cvxCRV at 41%, st-yCRV 52%). During October 10th, both markets experienced zero bad debt despite exposure to volatility, validating the preemptive risk management.
## Comparison to Industry Response
AAVE implemented aggressive risk-off measures following October 10th, documented in their governance proposal "[ARFC: Deprecation of Low Demand Volatile Assets](https://governance.aave.com/t/arfc-deprecation-of-low-demand-volatile-assets-on-aave-v3-instances/23261)" authored by Chaos Labs. The DAO voted on setting borrow caps to 1 (effectively non-borrowable) for 14 assets including CRV, UNI, ENS, ARB, BAL, LDO, and 1INCH, while simultaneously setting LTV to 0% (no collateral value) for the same assets. Their rationale centered on oracle deviations of 15-50% during October 10th combined with low market efficiency creating arbitrage exploitation risk.
Chaos Labs' recent analysis cited CRV experiencing sustained 58% price dislocation during the October 10th window, with [Chainlink SVR](https://blog.chain.link/chainlink-smart-value-recapture-svr/) (Smart Value Recapture) oracle updates lagging by a constant 5 blocks (approximately 60 seconds) throughout the crash period. Their technical framework focused on oracle-DEX price divergence: when Chainlink pricing diverged from on-chain DEX reality, the dislocation enabled arbitrage exploitation. They documented approximately $200K deficit from this mispricing mechanism, where market participants could supply high-LT collateral, borrow CRV at oracle's understated price, and immediately sell on DEX venues at higher market prices. This arbitrage could be repeated until either prices converged or protocol liquidity was exhausted.
The oracle-DEX divergence is particularly material for protocols like AAVE and Moonwell (as detailed in a[ report by Anthias Labs](https://forum.moonwell.fi/t/anthias-labs-report-on-the-events-of-october-10th-2025/1983)) because CRV and other volatiles were previously borrowable on their platform, creating direct arbitrage vulnerability. When oracle pricing lags behind on-chain reality during volatility, borrowers can extract value from the protocol through the price differential. This exploitation mechanism drove AAVE's decision to make these select volatiles non-borrowable rather than simply adjusting liquidation parameters.
RWG’s analysis approached the same October 10th event from a different angle, focusing on oracle update latency rather than oracle-DEX divergence. The distinction between RWG and Chaos Labs' analyses reflects different protocol architectures and resulting vulnerabilities. Both studies identify oracle responsiveness issues during extreme volatility but from complementary perspectives - one focused on price divergence exploitation, the other on liquidation execution timing. Chaos Labs' observation that SVR oracle lag "could have been insufficient to support timely liquidations, thereby publishing the price updates with a consistent maximum allowed lag" aligns with RWG’s analysis of oracle latency overwhelming FiRM liquidation execution. The convergence of findings from independent analyses examining the same event strengthens confidence that oracle responsiveness during extreme network congestion is a systemic concern across DeFi lending protocols, regardless of specific architecture differences.
## Future Considerations
This proposal represents immediate market securing via Liquidation Factor optimization based on October 10th empirical evidence. RWG's near-term focus following this proposal will be comprehensive collateral factor analysis, particularly for stablecoin LP markets, as previewed in the CVX post-event analysis. Oracle latency during extreme volatility affects not only liquidation execution but also the appropriate collateral factor settings that determine borrowing capacity. The same October 10th oracle performance data being gathered for liquidation factor validation will inform systematic review of collateral factors across FiRM markets, with stablecoin LPs receiving priority assessment given their 97% concentration of DOLA backing.
Longer-term improvements would require FiRM v2 architecture with new market contract implementations. Dynamic liquidation mechanisms would eliminate the tradeoff between safety and user experience inherent in static LF settings, with soft liquidations enabling gradual position reduction and sliding scale factors adjusting automatically based on real-time volatility. Hybrid oracle systems incorporating pull-based pricing from sources like Pyth or Redstone alongside Chainlink push-based feeds would provide redundancy during network congestion. Multi-oracle validation with automated health monitoring could enable real-time parameter adjustments based on oracle performance degradation.
Chainlink is providing detailed oracle performance data for all volatile collateral markets during the October 10th event and historical patterns, which will be incorporated into ongoing risk assessment. This quantitative evidence will enable data-driven validation of proposed parameters and inform future OCR configuration optimizations that RWG is coordinating with Chainlink to pass October 10th stress test conditions.
Completing this liquidation factor optimization during Q4 market deterioration positions FiRM strategically for future growth. By ironing out parameter vulnerabilities and validating oracle feed integrity across stressed conditions now, RWG can confidently reallocate focus from defensive market securing toward growth-oriented initiatives once analysis concludes and markets stabilize. The comprehensive oracle performance data being gathered establishes quantitative frameworks for evaluating collateral factor increases where appropriate and assessing new collateral candidates with validated risk assessment methodologies. This measured approach - securing existing markets first, then expanding thoughtfully from a position of strength - ensures FiRM scales responsibly without compromising the protocol stability that has differentiated FiRM throughout industry-wide stress events.
## On-Chain Actions
* Set Liquidation Factor for wETH market to 75%
* Set Liquidation Factor for wstETH market to 75%
* Set Liquidation Factor for wBTC market to 75%
* Set Liquidation Factor for cbBTC market to 75%
* Set Liquidation Factor for CRV market to 100%
# Proposal to Fund Global Junior Tranche Audit Contest
Forum Link: https://forum.inverse.finance/t/proposal-to-fund-global-junior-tranche-audit-contest/619/1
## 1. Proposal Summary
This proposal requests an increase of 76,000 DOLA to the BBP multisig allowance to fund a public audit contest for the Junior Tranche product on Sherlock. The contest will provide additional security review following the initial private audit, with a split bounty structure that incentivizes thorough examination of the codebase.
## 2. Background
The Junior Tranche codebase recently completed a private audit with Sherlock, which identified several findings requiring code fixes. The findings from this initial audit warrant an additional security review to ensure comprehensive coverage before deployment.
A public audit contest allows multiple auditors to examine the codebase simultaneously, increasing the likelihood of identifying any remaining edge cases or vulnerabilities. This approach provides broader security coverage compared to a single private audit team.
## 3. Project Details
* Junior Tranche Audit Contest - 76,000 DOLA
* Base pool: 26,000 DOLA
* Critical findings pool: 50,000 DOLA
* Duration: 4 days
* Start date: November 10, 2025
* Platform: Sherlock
The split bounty structure appropriately incentivizes thorough review while managing budget efficiently. If no critical vulnerabilities are found, only the base pool of 26,000 DOLA will be paid out, and the critical findings pool of 50,000 DOLA will remain unspent.
**Any unspent allowance will be burnt/revoked.**
## 4. On-Chain Actions
* Remaining allowance: 119,060 DOLA (reserved for Monolith security audits, granted [here](https://www.inverse.finance/governance/proposals/mills/280))
* New request: 76,000 DOLA (for Junior Tranche audit contest)
* Total approval: 195,060 DOLA
Set BBP multisig DOLA allowance to 195,060 DOLA
# Pause crvUSD LP Markets on FiRM During Observation Period
Forum Link: https://forum.inverse.finance/t/pause-crvusd-lp-markets-on-firm-during-observation-period/609
### Summary
This proposal recommends formally sunsetting four FiRM markets by setting their market ceilings to zero and pausing new borrows. The markets targeted for deprecation include: scrvUSD-sDOLA, yv-scrvUSD-sDOLA, scrvUSD-DOLA, and yv-scrvUSD-DOLA. These actions are part of ongoing operational cleanup initiatives to streamline FiRM’s collateral roster, reduce unnecessary risk exposure, and improve protocol efficiency.
### Motivation
As FiRM matures, periodic reviews of its supported collateral markets are essential to maintaining a healthy, efficient lending protocol. The recent passing of Curve DAO governance proposal #1206, which authorized a credit line of up to 60M crvUSD to bootstrap the Yield Basis protocol, represents a fundamental restructuring that warrants immediate risk reassessment.
Sunsetting these markets serves multiple objectives. It removes operational overhead from the RWG, reduces the monitoring burden for tracking new protocol dependencies, and minimizes governance surface area around parameters that no longer align with our risk tolerance. From a security perspective, deprecating these markets narrows the protocol’s exposure to tail risks during Yield Basis’s initial operational phase and allows the RWG to focus resources on higher-impact opportunities.
### Background & Rationale
The crvUSD LP markets require reassessment following Curve DAO’s approval of a 60M crvUSD pre-mint (~55% of current supply) to bootstrap Yield Basis, a newly deployed leveraged yield farming protocol. Since the initial 60M crvUSD authorization, a new Curve governance proposal has been published seeking to increase crvUSD caps for Yield Basis pools to 300M crvUSD—a figure representing over 2x current total crvUSD supply. This signals the intention for continued aggressive expansion of crvUSD backing into Yield Basis. This structural change introduces new dependencies where crvUSD stability relies on Yield Basis performance, which itself depends on Curve pool mechanics and BTC price action. The magnitude of this change triggers our FiRM Collateral Screening Framework requirement for a hard minimum of 6 months operational history before accepting modified collateral structures.
The new backing mechanism moves crvUSD away from its established infrastructure. While Yield Basis has undergone comprehensive security review, the protocol has zero operational history, and the resource allocation required to monitor this experimental phase does not justify the remaining market opportunity. This decision reflects adherence to our collateral screening framework rather than any assessment of Yield Basis’s security or audit quality.
The RWG is entering a formal 6-month observation period to assess Yield Basis operational performance through our weekly Risk Observer Checklist. Reassessment criteria for potential future reintroduction include successful operational history with no critical incidents, demonstrated stability under market stress, and material reduction in monitoring overhead requirements aligned with our collateral screening standards.
### On-Chain Actions
For each market listed:
scrvUSD-sDOLA: pauseBorrows = true, setMarketCeiling = 0 DOLA
yv-scrvUSD-sDOLA: pauseBorrows = true, setMarketCeiling = 0 DOLA
scrvUSD-DOLA: pauseBorrows = true, setMarketCeiling = 0 DOLA
yv-scrvUSD-DOLA: pauseBorrows = true, setMarketCeiling = 0 DOLA
# Proposal to Fund Global Junior Tranche Security Audit
Forum Link: https://forum.inverse.finance/t/proposal-to-fund-global-junior-tranche-security-audit/610/1
## 1. Proposal Summary
This proposal requests 27,000 DOLA from the DAO treasury to fund a professional security audit of the Junior Tranche system by Sherlock. The Junior Tranche represents critical infrastructure for DOLA solvency protection, and given the expected TVL, a thorough security review is essential before deployment. An official launch proposal will follow post-audit.
## 2. Background
### The Need for Global Junior Tranche
As Inverse Finance scales its lending operations through FiRM and expands DOLA infrastructure, the protocol faces increasing exposure to bad debt risk. Currently, all bad debt events are absorbed directly into DOLA backing, creating a concentration of risk that limits scalable growth potential.
The Junior Tranche introduces a market-driven insurance layer where users deposit DOLA to earn DBR rewards while absorbing losses before they impact core protocol reserves. This mechanism:
* Protects DOLA solvency by providing first-loss capital
* Enables protocol scaling with reduced systemic risk
* Creates a new yield-bearing product (name TBD) for DOLA holders
* Establishes a permissionless, automated bad debt resolution system
### Development Status
The Global Junior Tranche codebase has undergone extensive internal development and review since July 2025:
* Core architecture finalized (global pool covering all FiRM markets)
* Smart contracts implemented with modular design for future expansion
* Internal testing completed with multiple review rounds
* Code incorporates learnings from Aave Umbrella and sDOLA implementations
* The system is feature-complete and ready for professional security assessment.
## 3. Project Details
### Selected Auditors
Sherlock has assigned two lead auditors specifically matched to scope’s risk profile:
**Hash** (Vault & Math Specialist)
* ERC4626 expert with proven track record on accounting corruption and reentrancy issues
* Specialized experience with slashing-sensitive systems and bad debt scenarios
* Audited similar auction systems (Olympus RBS, Axis Finance) and vault mechanics
* Profile: https://audits.sherlock.xyz/watson/hash
**Obsidian** (Juaan + Spearmint)
* Deep expertise in Compound-style lending, yield systems, and AMM mathematics
* Track record identifying yield misallocation, withdrawal DoS, and rounding vulnerabilities
* Experience with oracle integration and complex fee/reward distribution systems
* Profile: https://audits.sherlock.xyz/watson/Obsidian
These auditors bring complementary expertise covering all critical aspects of the Junior Tranche system.
### Sherlock Shield Coverage
In addition to the audit itself, Sherlock provides post-launch security coverage through Sherlock Shield, offering up to $500,000 in exploit coverage for vulnerabilities discovered in production. This coverage:
* Activates immediately upon audit completion and continues for the first month post-deployment with options to extend based on a subscription model
* Coverage amount scales inversely with vulnerabilities found during audit (fewer findings = higher coverage, up to the $500K maximum)
* Provides additional financial protection during the critical early deployment phase
* Demonstrates Sherlock’s confidence in their audit quality by putting capital at risk
This additional layer of protection is particularly valuable for the Junior Tranche given its role as DOLA’s solvency backstop. The Shield coverage will help protect depositors and the protocol during the initial launch period before extensive battle-testing has occurred.
## 4. On-Chain Actions
Action 1: Approve 154,360 DOLA Allowance (+27,000 on top of existing allowance granted for ongoing Monolith audits) to the Bug Bounty Program Multisig
# Sunset PT-sUSDe-25SEP25 and PT-USDe-25SEP25 Markets
Forum Link: https://forum.inverse.finance/t/sunset-pt-susde-25sep25-and-pt-usde-25sep25-markets/608
### Summary
This proposal seeks to formally sunsetting two FiRM markets by setting their market ceilings to zero and pausing new borrows. The markets targeted for deprecation are: PT-sUSDe-25SEP25 and PT-USDe-25SEP25. These actions follow FiRM’s lifecycle management process for expired Pendle principal token markets and form part of ongoing operational cleanup to streamline FiRM’s collateral roster, reduce monitoring overhead, and improve protocol efficiency.
### Motivation
As FiRM continues to evolve, regularly pruning expired markets or those whose risk-reward measure are no longer favorable ensures the protocol remains efficient, secure, and focused on productive opportunities. Principal tokens (PTs) issued by Pendle Finance have clear maturity dates; once past expiry, they no longer serve a viable purpose for new borrowing.
The PT-sUSDe-25SEP25 and PT-USDe-25SEP25 markets are both now past maturity, and continued support would unnecessarily consume RWG monitoring resources while offering no utility to borrowers.
### On-Chain Actions
For each market listed:
PT-sUSDe-25SEP25: pauseBorrows = true, setMarketCeiling = 0 DOLA
PT-USDe-25SEP25: pauseBorrows = true, setMarketCeiling = 0 DOLA
# FiRM Liquidation Coverage Validation Proposal
Forum Link: https://forum.inverse.finance/t/firm-liquidation-coverage-validation-proposal/601/1
## Summary
The Risk Working Group (RWG) requests 5,000 DOLA to create and monitor liquidatable test positions across sensitive FiRM markets to empirically validate liquidation coverage. This proposal represents the evolution of our liquidation research from the grant-based approach to data-driven validation, establishing the foundation for future liquidation infrastructure development.
## Background
The Liquidator Grant Program launched on October 4, 2024, with the objective of incentivizing liquidators to monitor exotic collateral types that traditional MEV bots might not immediately pick up. Almost 11 months later, the program received 11 submissions from unique addresses, resulting in 2 confirmed payouts totaling 500 DOLA, with 4,500 DOLA remaining unused from the original budget.
The program’s primary goal was to demonstrate strategic value by ensuring liquidation coverage for previously unmonitored markets, for example st-yCRV which had never experienced MEV liquidator activity prior to the grant program. Since launch, 36% of all FiRM liquidations (9 out of 25) occurred in grant-eligible markets across 6 different market types, validating the need for targeted attention to exotic collaterals.
Recent internal discussions have raised questions about whether liquidation coverage gaps actually exist across FiRM’s current market ecosystem. Evidence suggests sophisticated liquidation bots are already operating effectively, with multiple different bots utilizing advanced techniques including flash minting and cross-protocol arbitrage strategies. This empirical evidence challenges the assumption that exotic markets lack adequate liquidation coverage.
## Vision
The RWG envisions a three-phase evolution of FiRM’s liquidation infrastructure:
Phase 1 (Past): Liquidator Grant Program - Targeting perceived gaps in exotic market coverage and providing targeted incentives, establishing proof of concept for liquidation ecosystem development.
Phase 2 (Present): Empirical Validation - Deploy controlled test positions to objectively measure liquidation response times and coverage across sensitive markets, providing data-driven insights to inform future infrastructure decisions.
Phase 3 (Future): Comprehensive Infrastructure - One possible future iteration is to develop in-house liquidation bot as protocol backstops, publish open-source reference implementations with technical documentation, and establish gamified community incentives to foster competitive liquidation environments aligned with industry standards.
Our ongoing study into liquidators is meant to positions FiRM alongside leading protocols like Aave, Morpho, Compound, and Maker, which have all invested in comprehensive liquidation infrastructure as foundational protocol safeguards rather than optional enhancements.
## Present Ask
The RWG requests 5,000 DOLA to create liquidatable positions at 100% borrow limits across sensitive FiRM markets, including:
LP Collateral Markets: Uncommon collateral types in DeFi that require distinct liquidation strategies
CRV Derivative Markets: Including cvxCRV and st-yCRV, which have historically been susceptible to significant price swings
Pendle Principal Token Markets: Current and future PT collateral markets that represent novel, although widely adopted, DeFi primitives
Future Exotic Collaterals: As new markets are deployed, particularly those involving niche DeFi derivatives
These positions will be monitored to measure liquidation response times, identify coverage gaps, and validate assumptions about current liquidation infrastructure effectiveness. The data collected will inform decisions about whether additional liquidation infrastructure development is necessary or if current organic coverage is sufficient.
This approach addresses the empirical validation requested by the Product Working Group while maintaining the RWG’s commitment to proactive risk management across FiRM’s expanding collateral universe. The controlled testing environment ensures that liquidation discovery occurs during stable market conditions rather than during actual stress events when rapid response is critical.
## On-Chain Actions
Grant the RWG multisig an allowance refresh of 5,000 DOLA for liquidation testing purposes
# Sunset PT-sUSDe-31JUL25 and deUSD-DOLA LP Markets
Forum Link: https://forum.inverse.finance/t/sunset-pt-susde-31jul25-and-deusd-dola-lp-markets/592
## **Summary**
This proposal recommends formally sunsetting three FiRM markets by setting their market ceilings to zero and pausing new borrows where applicable. The markets targeted for deprecation include: PT-sUSDe-31JUL25, deUSD-DOLA LP, and yv-deUSD-DOLA LP. These actions are part of ongoing operational cleanup initiatives to streamline FiRM's collateral roster, reduce unnecessary risk exposure, and improve protocol efficiency.
## **Motivation**
As FiRM matures, periodic reviews of its supported collateral markets are essential to maintaining a healthy, efficient lending protocol. The PT-sUSDe market is past expiry, while the deUSD markets have been paused for over 2 months following extensive risk assessment that revealed fundamental misalignment with FiRM's risk tolerance and strategic objectives.
Sunsetting these markets serves multiple objectives. It removes operational overhead from the RWG, reduces the monitoring burden for oracles and liquidity, and minimizes governance surface area around parameters that no longer require tuning. From a security perspective, deprecating these markets narrows the protocol's exposure to tail risks and allows the RWG to focus resources on higher-impact opportunities.
By formally winding down these markets, we reinforce our commitment to good protocol hygiene and signal to external partners and users that FiRM collateral is thoughtfully curated and regularly maintained.
## **Background & Rationale**
### **PT-sUSDe-31JUL25**
The PT-sUSDe-31JUL25 market holds a Pendle Finance principal token that expires on July 31, 2025. Now over a week past maturity, this market no longer serves a viable purpose for new borrowing. Principal tokens lose their yield-bearing properties at expiry and convert to their underlying asset, making continued support operationally inefficient. This deprecation follows standard lifecycle management for expiring assets, consistent with our handling of the previously expired PT-sUSDe-27MAR25 and PT-sUSDe-29MAY25 markets.
### **deUSD-DOLA LP & yv-deUSD-DOLA LP**
The deUSD-DOLA LP markets were paused on June 20, 2025, following growing concerns about the Elixir protocol's risk profile. After 2 months of observation, the RWG determined that resuming these markets was not in the best interest of the DAO, and communicated such to the Elixir team. deUSD remains in an early development phase with evolving governance structures, planned technical transitions requiring new audits and expanding multichain strategies that continuously alter the risk assessment for the asset at a time when, we believe, Inverse Finance should prioritize protocols with more immutable underlying infrastructure. The resource allocation required to monitor Elixir through its experimental development phase does not justify the potential market opportunity.
## **On-Chain Actions**
For each market listed:
* **PT-sUSDe-31JUL25:** pauseBorrows = true, setMarketCeiling = 0 DOLA
* **deUSD-DOLA:** setMarketCeiling = 0 DOLA
* **yv-deUSD-DOLA:** setMarketCeiling = 0 DOLA
# Proposal to Adjust Liquidation Factor in cvxCRV and st-yCRV FiRM Markets
Forum Link: https://forum.inverse.finance/t/proposal-to-adjust-liquidation-factor-in-cvxcrv-and-st-ycrv-firm-markets/582
## Summary
This proposal seeks to increase the Liquidation Factor for the cvxCRV and st-yCRV markets on FiRM from 80% to 100%. This adjustment addresses the prolonged negative trends observed in both CRV derivatives; namely persistent peg deterioration and declining liquidity. The change aims to enhance protocol safety by ensuring liquidations remain economically viable for liquidators even under continued adverse market conditions.
## Background
FiRM's operational stability and risk mitigation depend significantly on the accurate calibration of collateral parameterization. The protocol has consistently demonstrated robust performance, successfully processing liquidations even during extreme market stress without incurring bad debt. The Liquidation Factor determines the maximum percentage of a borrower's debt that can be repaid in a single liquidation transaction, directly impacting liquidator economics and protocol safety.
cvxCRV has exhibited poor performance over a prolonged period that warrant careful parameter adjustment:
* Persistent Peg Deterioration: cvxCRV has traded consistently below its theoretical peg to CRV, declining from ~94% in mid-2024 to below 50% by mid-2025, while yCRV has similarly deteriorated from 89.21% to below 50% over the same period. Extended periods below peg prevent CRV derivatives from locking additional veCRV, effectively diluting their voting power relative to direct veCRV holders during that time due to ongoing CRV emissions.
* Liquidity Contraction: cvxCRV pool liquidity has decreased by over 60% from $43.8M to $16.5M between December 2024 and June 2025, while yCRV liquidity has declined from $4.13M to $2.79M (32% decrease) over a similar timeframe.
* Yield Suppression: cvxCRV gauge APRs have compressed significantly from 24.82% to 9.33% over the past year, while yCRV has seen compression from 23.10% to 10.69%, reflecting reduced incentives and diminished market demand for both CRV derivative.
## Recommendations
The RWG recommends increasing the cvxCRV and st-yCRV market liquidation factors to 100% based on comprehensive analysis of current market conditions and liquidation economics for both CRV derivative assets. This adjustment is designed to have no immediate impact on existing positions.
The 100% liquidation factor improves liquidator profitability margins and provides increased flexibility to prevent bad debt accumulation during sudden price drops and high gas costs, which is crucial for assets with deteriorated liquidity conditions and gas intensive liquidation mechanics.
In doing so, we follow established methodology used in previous successful parameter adjustments, ensuring consistency with FiRM's proven risk management framework.
## On-Chain Actions
* Set Liquidation Factor for FiRMs cvxCRV market to 100%
* Set Liquidation Factor for FiRMs st-yCRV market to 100%
# Decommission Unused and Outdated DOLA AMM Feds
Forum Link: https://forum.inverse.finance/t/decommission-unused-and-outdated-dola-amm-feds/580
### Summary
This proposal seeks the decommissioning of several inactive or deprecated DOLA AMM Feds by setting their minting ceilings to 0. These Feds have seen no recent usage, have become outdated due to changing liquidity or strategic priorities, or are no longer aligned with the current deployment roadmap of DOLA across chains and venues.
By formally revoking their minting rights, we simplify DOLA's monetary policy footprint, reduce overhead in Fed monitoring and incident response, and align the active Fed set with where liquidity is actually being utilized today.
### Feds to Be Decommissioned
The following Feds will have their minting ceilings set to 0, effectively disabling any further DOLA expansion via these contracts:
|Fed Name|Address|
| --- | --- |
|Aura Fed|0x5C16aE212f8d721FAb74164d1039d4514b11DB54|
|Arbi Fed|0x0B5ec95257afd9534C953428AC833D19579843CB|
|Aero Fed|0x24a3C49e5Cd8786498e9051F5Be7D6e86B263c8B|
|FraxPyUSD Fed|0x83FB6f6524eb8c85bDAB818981E918dB17e723CD|
|BaseCCTP Fed|0x783719dDf09D2ee0960BB365f7Ef652bfE35F54d|
|OptiCCTP Fed|0x52FFD313cc11882b75879C41d837b20F974ea88f|
### On-Chain Actions
* Remove DOLA minting ceiling for each of the listed AMM Feds.
setBorrowController(address)# Update the FiRM Borrow Controller To Linear Borrow Limit Replenishments [2/2]
# Update the FiRM Borrow Controller
Forum Post: https://forum.inverse.finance/t/update-the-firm-borrow-controller/572
## Summary
This proposal aims to update the borrow controller for all active markets on FiRM to implement an improved method of handling the daily borrow limit. The changes will introduce a rolling 24-hour limit, replacing the current system, which resets the borrow limit at midnight (00:00 UTC).
## Background
The borrow controller in FiRM serves as a gatekeeper for borrowing transactions, determining if users are permitted to borrow based on the following criteria:
* **Market Daily Borrow Limit**: Verifies that the requested borrow amount does not exceed the remaining daily borrow limit for the market.
* **Smart Contract Verification**: Checks whether the borrowing address is a smart contract and, if so, ensures it is on the whitelist.
The daily borrow limit is a key risk management feature designed to:
* Mitigate potential DAO losses in the event of an exploit
* Limit the financial gain for would-be exploiters
Currently, the daily borrow limit resets entirely at midnight (00:00 UTC), leading to the following drawbacks:
* **Double Borrowing Exploitability**: A borrower can execute a transaction just before midnight and another immediately after, effectively doubling the daily limit in a short period.
* **Non-Linear Competition**: In competitive markets like DOLA/USR, borrowers who act first after midnight can consume the entire limit, leaving no capacity for others.
To address these issues, we propose shifting to a rolling 24-hour borrow limit. This updated mechanism will replenish borrowing capacity incrementally with each passing second, rather than resetting at a fixed time.
## Implementation
The rolling-limit borrow controller we are reinstating has already proved itself in production: it was first rolled out by [Grace Protocol](https://github.com/GraceProtocol/grace-protocol/blob/5083e630d60d0ea6b9a28c139d2babb77bcce506/src/BorrowController.sol#L51) and later activated on a group of [pilot markets within FiRM](https://www.inverse.finance/governance/proposals/mills/249), where it underwent rigorous live testing. During the subsequent [Pectra-compliant controller upgrade](https://forum.inverse.finance/t/update-to-pectra-compliant-firm-borrow-controller/547), that rolling-limit module was inadvertently removed from those markets. This proposal simply restores the same, fully validated logic—while keeping every other feature of the current controller—and extends it to every active FiRM market. The code has passed exhaustive internal testing as well as an independent external review, giving the DAO high confidence in its reliability and security.
## On-chain actions
* Set operator of new BorrowController to the BorrowControllerMigrationHelper
* Add new BorrowController as DBR minter
* Add new BorrowController as borrowController for remaining half of FiRM markets (limited by governor action limit)
* Migrate market staleness, mindebt and debtlimit parameters from old BorrowController to new BorrowController
* Set operator of new BorrowController to governance
# [1/7] Update to Pectra-Compliant FiRM Borrow Controller
Forum Link: https://forum.inverse.finance/t/update-to-pectra-compliant-firm-borrow-controller/547
### Summary
This proposal seeks to update the FiRM Borrow Controller across all active markets to a newly-deployed, Pectra-compliant version, addressing security risks introduced by [EIP-7702](https://github.com/ethereum/EIPs/blob/master/EIPS/eip-7702.md#self-sponsoring-allowing-txorigin-to-set-code). The upgrade ensures continued protection against flash loan exploits, reentrancy, and atomic transaction manipulations, while maintaining all previously implemented risk controls such as the rolling 24-hour borrow limit and daily borrow caps.
### Background
The borrow controller in FiRM plays a crucial role in risk management, ensuring that borrowing transactions comply with security measures such as:
* **Minimum Debt Amount**: Protecting the protocol from griefing by enforcing a minimum market debt allowed to be carried per user.
* **Smart Contract Verification**: Restricting borrowing from unauthorized smart contracts to mitigate risk.
* **Rolling 24-Hour Borrow Limit**: Preventing exploitative behaviors related to fixed-time resets.
* **Staleness Threshold**: Addressing stale oracle data exploits by preventing borrowing when price feeds have not updated within a governance-defined timeframe.
However, with the first phase of the Pectra hard fork scheduled for mid-March 2025, [Ethereum's EIP-7702](https://mixbytes.io/blog/the-prague-electra-pectra-hardfork-explained) introduces the ability for EOAs (externally owned accounts) to delegate execution to smart contracts, effectively bypassing FiRM’s existing protections against flash loans and reentrancy attacks.
To mitigate these risks, the new borrow controller enforces a stricter validation, combining `tx.origin == msg.sender` with `msg.sender.code.length == 0` to ensure that the caller is not a delegated smart contract. In doing so, it ensures full compatibility with the Pectra hard fork, maintaining security without sacrificing user experience.
The new borrow controller has been rigorously tested on the Prague EVM and reviewed by 3rd parties, both of which confirm it correctly blocks unauthorized delegated transactions while maintaining expected protocol functionality.
### Implementation Plan
This proposal will standardize the borrow controller across all active markets, eliminating existing discrepancies and bringing the rolling 24-hour borrow limit to all markets. All previously whitelisted addresses as well as market-specific daily borrow limits, staleness thresholds, and min debts will need to be set. As such with 33 live markets, this will require over 100 on-chain actions. As each proposal is limited to 20 on-chain actions, this will be spread out across 7 proposals.
This is Proposal # 1 of 7 and will apply to the following...
### On-Chain Actions
1. Add the new borrow controller as a DBR minter
2. Allow all previously approved smart contracts on the new borrow controller:
- Whitelist the ALE smart contract
- Whitelist user [0x495886947EAce9788360F46be55c758f92Ecd074](https://forum.inverse.finance/t/whitelist-0x4958-multisig-user-on-firm/494)
- Whitelist user [0x496a3Fc15209350487F7136b7c3c163F9204eE70](https://forum.inverse.finance/t/whitelist-safe-multisig-user-on-firm/489)
- Whitelist user [0x0591926d5d3b9cc48ae6efb8db68025ddc3adfa5](https://forum.inverse.finance/t/whitelist-temple-dao-treasury-address-on-firm/481)
- Whitelist DBR helper: [0x0aBb47c564296D34B0F5B068361985f507fe123c](https://forum.inverse.finance/t/proposal-to-whitelist-updated-curvehelper-contract-for-tridbr-lp/316)
3. Set the Borrow Controller and Inherit All Existing Borrow Parameters for the following FiRM Markets:
- INV, wBTC, wETH
# Update PT-sUSDe-29MAY2025 to Newly Deployed Discount to NAV Feed
Forum Link: https://forum.inverse.finance/t/update-pt-susde-29may2025-to-newly-deployed-discount-to-nav-feed/558
### 1. Summary
This proposal finalizes the deployment of the PT-sUSDe-29MAY2025 market on FiRM by switching its price feed to the newly deployed Discount to NAV Feed that returns a proper updatedAt timestamp, preventing stale price reverts. The market was introduced in [Proposal #276](https://www.inverse.finance/governance/proposals/mills/276), with its liquidation incentive subsequently adjusted in [Proposal #279](https://www.inverse.finance/governance/proposals/mills/279). However, borrowers encountered reverts due to the current feed not producing an updatedAt round data, leading to the borrow controller denying the stale answer. With this fix, users will be able to borrow from the market without reverts.
### 2. Background
* Proposal #276 created the PT-sUSDe-29MAY2025 market, aiming for a 91.5% Collateral Factor, a 5% Liquidation Incentive, and an initial 20% discount to NAV rate.
* Proposal #279 set the Liquidation Incentive to 5% first, resolving a revert triggered by the order of operations during on-chain execution.
* Subsequent testing revealed that the original Discount to NAV Feed returned a zero timestamp, causing the staleness check to fail. A revised Discount to NAV Feed now outputs a proper timestamp, enabling the market to function as intended.
### 3. Implementation
1. Deploy Revised NAV Feed & FeedSwitch Contracts
* The Discount to NAV Feed at[ 0xDc229F233EAb9b94Cf48555ab457C95B37987F11](https://etherscan.io/address/0xDc229F233EAb9b94Cf48555ab457C95B37987F11) returns the block timestamp instead of 0.
* The FeedSwitch at[ 0x8f5d8a77e6c1943218854b1eef22401760d4ca10](https://etherscan.io/address/0x8f5d8a77e6c1943218854b1eef22401760d4ca10) coordinates the primary Discount to NAV feed, the before-maturity feed, and the after-maturity feed.
2. Guardian Fallback remains assigned to the Policy multisig, ensuring timely mitigation in extreme events (e.g., a USDe depeg).
### 4. On-Chain Actions
- For PT-sUSDe-29MAY2025, call setFeed on the FiRM PPO Oracle contract to switch from the old FeedSwitch to[ 0x8f5d8a77e6c1943218854b1eef22401760d4ca10](https://etherscan.io/address/0x8f5d8a77e6c1943218854b1eef22401760d4ca10)
# Update wBTC and wETH FiRM Market Price Feeds
Forum Link: https://forum.inverse.finance/t/update-wbtc-and-weth-firm-market-price-feeds/551
### Summary
This proposal seeks to upgrade FiRM’s wBTC and wETH market price feed to the new ChainlinkBridgeAssetFeed logic. Historically, Inverse Finance implemented feeds on a per-feed basis, leading to repeated code, redundant logic, and an increased risk of errors. By consolidating logic into single-purpose, generalized price feed contracts, review of new price feeds is simplified to only reviewing the deployment, allowing for better use of resources. The ChainlinkBridgeAssetFeed, allows FiRM to simplify its pricing mechanism by combining two well-established Chainlink feeds—one for the collateral/bridge-asset pair and another for the bridge-asset/USD pair. This approach standardizes oracle architecture, reduces maintenance overhead, and ensures a more reliable and secure pricing framework.
Additionally, this proposal introduces a fallback oracle for ETH/USD, using a Redstone oracle to improve resilience in case of Chainlink oracle staleness.
### Background
Previously, FiRM relied on individual implementations for compounded price feeds, requiring contracts to handle asset-to-asset conversion, bridge-asset-to-USD conversion, and decimal normalization in a single contract. This resulted in, amongst other things, a more complex verification process.
FiRM has long transitioned away from monolithic price feed implementations toward a modular oracle architecture, which is already used in LP collateral pricing. The new model separates core pricing functions into distinct, independently verified components, which are then composed to derive final price calculations.
Instead of embedding all calculations within a single contract, ChainlinkBridgeAssetFeed aggregates pricing data from two Chainlink feeds—one for a collateral/bridge-asset pair and another for the bridge-asset/USD rate—ensuring clear separation of concerns and easier verification. A boolean flag (bridgeAssetDenominator) allows the contract to handle cases where the denominator in the collateral-bridge pair varies, and thus ensures proper configuration regardless of price feed structure.
By migrating the wBTC market feed to this model, future deployments become faster, verification is streamlined, and protocol reliability improves. This update also introduces a fallback price source for ETH/USD, increasing resilience for the wETH market against temporary oracle failures.
### Implementation
E.g. Oracle Setup for WBTC/USD:
|Feed Type|Oracle|Fallback|Feed Address|
| --- | --- | --- | --- |
|WBTC/BTC|Chainlink|None|0x435419607191F1C1c6809E01bb5C38311957c6a8|
|BTC/USD|Chainlink|Redstone|0xAe6B44ebdd005669B410524eC076424A7308e9e1|
|WBTC/USD (Bridge Asset Feed)|ChainlinkBridgeAssetFeed|Derived from WBTC/BTC & BTC/USD|0xa0c624a99Ec87a8010f65F277787f697346196e6|
E.g. Oracle Setup for WETH/USD (No ChainlinkBridgeAssetFeed needed but missing a fallback):
|Feed Type|Oracle|Fallback|Feed Address|
| --- | --- | --- | --- |
|ETH/USD|Chainlink|Redstone|0x22390B88C53D1631f673b8Dcd91860267137b2c8|
### On-Chain Actions
* Update wBTC FiRM market price feed to 0xa0c624a99Ec87a8010f65F277787f697346196e6
* Update wETH FiRM market price feed to 0x22390B88C53D1631f673b8Dcd91860267137b2c8
# Proposal to add PT-sUSDe-29MAY2025 Market to FiRM
Forum Link: https://forum.inverse.finance/t/proposal-to-add-pt-susde-29may2025-market-to-firm/544
### Summary
This proposal seeks to integrate the PT-sUSDe-29MAY2025 token from Pendle as a collateral asset on FiRM, Inverse Finance’s fixed-rate lending protocol. Like its predecessor (the successfully onboarded PT-sUSDe-27MAR2025), PT-sUSDe-29MAY2025 is a Principal Token representing the right to receive 1 USDe upon maturity—this time on May 28, 2025. While the risk assumptions remain the same as the earlier market, the key distinctions are:
1. A switch to Pendle’s audited Discount to NAV Oracle to price PT-sUSDe-29MAY2025 based on a fixed discount rate of 20% (rather than the fixed $1 approach).
2. A change in the Collateral Factor (CF) to 91.5%.
### Background
Pendle Finance is a yield-trading platform that tokenizes yield-bearing assets into two components:
1. Principal Tokens (PTs), redeemable for the underlying asset at maturity;
2. Yield Tokens (YTs), which accrue the asset’s yield until expiry.
After a successful integration of PT-sUSDe-27MAR2025 on FiRM in late 2024, demand for PT-based strategies has proven to be strong. This new PT, PT-sUSDe-29MAY2025, extends the maturity date and aims to offer continued opportunities for fixed-income and carry-trade strategies, leveraging FiRM’s fixed-rate borrowing.
### Discount to NAV Oracle
When FiRM onboarded PT-sUSDe-27MAR2025, to simplify risk management and minimize potential manipulation, we opted for a fixed $1 oracle along with a policy-multisig–controlled fallback to respond to extreme conditions or potential oracle malfunctions. While this was prudent for the initial launch, it was an imperfect solution as the fixed $1 price feed did not account for market discounts or yield to maturity over time.
For PT-sUSDe-29MAY2025, we propose using the Discount to NAV Oracle originally deployed by Pendle, audited by WatchPug and currently in use for Morpho’s PT markets. The feed accounts for the zero-coupon nature of the PT by applying a fixed discount rate to par value that exponentially converges to $1 as maturity nears. Only two main parameters—discount rate and time (block #) of maturity—must be configured. Importantly, by setting a conservative discount rate, the protocol intentionally underprices the PT relative to potential market optimism, which is safer from a protocol risk perspective.
Based on yield data for sUSDe PT markets, present time to maturity, and referencing methodologies used by other protocols (e.g., Morpho, Aave, and Spark in the Sky forum) — the RWG recommends a 20% discount rate for PT-sUSDe-29MAY2025. This is informed by
1. Historical Pendle PT Yields: sUSDe PT yields have frequently hovered in the 15–25% APY range, with occasional spikes higher.
2. Comparable PT Deployments: The 20% discount rate has been used on other platforms successfully (e.g., Morpho’s PT-USDe-Feb2025) to balance between over- and under-estimating collateral value.
3. Market Growth Expectation: While PT yields can spike briefly, sustained extreme yield environments (>70% APY) remain unlikely with the growth of USDe.
### Oracle Switch Guardian Role
For the PT-sUSDe-27MAR2025 integration, governance [approved the use of an oracle switch guardian](https://www.inverse.finance/governance/proposals/mills/227), assigning it to the Policy multisig. RWG recommends we retain a guardian fallback for the PT-sUSDe-29MAY2025 market to address significant deviations from expected yields or catastrophic scenarios (e.g., a USDe depeg) by swapping the discount to NAV fixed feed to a discount to NAV USDe feed that has sUSDe’s peg factored in.
For a more detailed overview of how the Feed Switch with guardian operates as well as the design choices that went into deciding our choice of PT oracle for FiRM, refer to the [risk assessment prepared by the RWG](https://docs.google.com/document/d/1LHg3M8QORWmDPmueoIrUx88ySoARtvQeJz0mvdCQUjI/edit?usp=sharing).
### Collateral Factor Setting
Collateral Factor (CF) in FiRM determines the maximum DOLA a user can borrow against the discounted value of their PT. For the PT-sUSDe-27MAR2025 market, the CF was set at 87%, balancing capital efficiency with the risk of PT discounts due to spikes in implied yield.
With PT-sUSDe-29MAY2025, we propose raising the CF to 91.5%, matching other PT markets on other lending protocols. The switch to a feed that will underprice the collateral, compared to our previous choice that overpriced it, justifies the increase in CF from 87%. Furthermore, our prior analysis (with PT-sUSDe-27MAR2025 at 87% CF and a fixed $1 oracle) showed that higher CFs could be acceptable if the feed accounts for implied yields. This combination (20% discount rate + 91.5% CF) offers capital efficiency while providing adequate protection in typical yield spikes (e.g., 40–50% APY).
### Risk Assessment
Because PT-sUSDe-29MAY2025 is structurally identical to PT-sUSDe-27MAR2025—just with a different expiry date—the same risk assumptions apply. These were covered in a past [risk assessment document](https://docs.google.com/document/d/15fpdoJSHqZQGnHy_-85_VaC70Mbeu7o9k2YqRfrQQys/edit?usp=sharing) produced by the RWG.
### On-Chain Actions
1. Add PT-sUSDe-29MAY2025 Market to the DBR contract
2. Set borrowController of this market to the FiRM BorrowController
3. Set market supply ceiling to 20,000,000 DOLA
4. Set daily limit in BorrowController to 2,000,000 DOLA
5. Set Collateral Factor to 91.5%
6. Set Liquidation Factor to 100%
7. Set Liquidation Incentive to 5%
8. Approve PT-sUSDe-29MAY2025 market on the DBR Helper
9. Set Minimum Debt Amount in BorrowController to 3,000 DOLA
10. Set stalenessThreshold for the PT-sUSDe-29MAY2025 market to 86,460 seconds
11. Set FiRM Oracle price feed for PT-sUSDe-29MAY2025 to the deployed FeedSwitch
# Proposal to Add DOLA/USR Convex LP Market to FiRM
Forum Link: https://forum.inverse.finance/t/proposal-to-add-dola-usr-convex-lp-market-to-firm/546/1
### Summary
This proposal seeks to introduce the DOLA/USR Liquidity Pool Token (LPT) from Curve Finance as a collateral option on FiRM, Inverse Finance’s fixed-rate lending protocol. The DOLA/USR LP offers unique advantages due to its stable composition and points program, providing a unique opportunity for capital efficient lending by offering stable liquidity positions that include DOLA as collateral. USR is an ETH-hedged stablecoin developed by Resolv Labs, employing delta-neutral futures positions and an overcollateralization fund (OCF) for peg stability. We plan to deploy two distinct markets; one that adheres to the convex strategy and a market which, utilizing the same underlying LPT, aligns with Yearn’s autocompound strategy. This proposal pertains to the Convex-aligned DOLA/USR LP market on FiRM.
### Background
USR is backed by ETH and a delta-neutral hedging strategy that uses short perp futures to mitigate price volatility. Resolv’s OCF mechanism, partial T-Bill collateralization, and RLP insurance layer offer a sturdy foundation for USR’s peg, while the staked variant (stUSR, or wstUSR) captures daily yields. In this proposal, we focus on the Convex-based DOLA/USR LP, which brings together stable-to-stable liquidity, while Convex auto-boosts Curve rewards. This synergy complements FiRM’s fixed-rate lending by providing stable-collateral positions with attractive yield farming potential.
By leveraging the DOLA/USR LP as collateral, FiRM offers its users the opportunity to capitalize on stable liquidity positions while bolstering our ecosystem’s efficiency and DOLA liquidity depth. Providing stable liquidity positions that include DOLA as collateral allows for cost-efficient lending on behalf of Inverse Finance. Typically, borrowers sell DOLA to buy other assets, impacting DOLA liquidity. Conversely, a borrower collateralizing with a DOLA LP position is likely to add the other stablecoin/s to the liquidity pool initially to obtain the LPT. They may then loop the borrowed DOLA into the LP position repeatedly to increase their reward, benefiting DOLA liquidity as it does not remove other stablecoins. This results in a 150% improvement in lending capital efficiency, as only 1 DOLA needs to be contracted by our AMM Feds for each DOLA added to the liquidity position, compared to 2.5 DOLAs for each DOLA sold.
### Risk Assessment
[Complete Risk Assessment – USR Collaterals on FiRM](https://docs.google.com/document/d/1zSCvnfxMOSKfqKT-BuFI4bKcu5NJOYfrURZVWkVxuH8/edit?usp=sharing)
Key points from the assessment include:
1. Governance: Resolv Labs currently oversees USR minting and redemption parameters through an administrative multisig. Though the protocol plans to transition to a $RESOLV governance token, whitelisted addresses still hold exclusive permission to mint or redeem. Users must rely on Resolv’s operational integrity and roadmap commitments until permissionless minting is fully realized.
2. Security: Audits of USR, RLP, staking contracts (including wstUSR), and related Request Manager logic were conducted by reputable firms such as MixBytes, Pessimistic, and Pashov. No critical vulnerabilities remain unresolved. However, partial reliance on off-exchange custody (Fireblocks, Ceffu) for hedging entails some exposure to exchange or custodian compromise. Ongoing bug bounty programs (expected to expand post-$RESOLV launch) provide a secondary security layer.
3. Regulatory Risks: USR’s design mixes crypto-collateralization (ETH, stETH) and T-Bill–backed assets (via MakerDAO’s USDS). Future regulatory actions against stablecoins, tokenized securities (RWA), or off-exchange custodians could disrupt Resolv’s mint/redeem flows. Regional compliance changes or centralized exchange constraints might also hamper the delta-neutral hedging strategy.
4. Collateral & Liquidity: Because USR is hedged against ETH price movements, its peg remains stable so long as derivatives markets remain liquid. Large-scale USR redemptions still rely on whitelisted participants, but secondary liquidity pools (Uniswap, Curve, Aerodrome) and an on-chain bridging mechanism (LayerZero’s Stargate) help maintain healthy liquidity.
5. Competitive Edge: Unlike purely crypto-backed stablecoins, USR incorporates T-Bill yields via partial MakerDAO integration while leveraging a delta-neutral approach. This structure appeals to users seeking a stable, yield-enriched asset with robust risk mitigations.
6. Oracle & Price Feeds: FiRM will implement a pessimistic LP token oracle for accurate valuation of the DOLA/USR LP. This process uses Chainlink price feeds for USR and the virtual price from the Curve pool’s smart contract and ensures a conservative and reliable estimate of the LP token's USD value. Real-time monitoring will further support price accuracy and integrity.
7. Liquidation Mechanisms: The liquidation factor and incentive are optimized to encourage active liquidator participation. Arbitrage opportunities with other DOLA or USR LPs will ensure that large liquidations do not lead to a liquidation cascade. The liquidation process will pull vault tokens, convert them to LP tokens, and then allow liquidators to realize value through balanced withdrawals, ensuring efficient liquidation routes.
Continuous monitoring of the DOLA/USR LP’s performance, yields, and liquidity conditions will be maintained by the RWG. Should any material changes or newly identified risks emerge, parameter adjustments or additional mitigations will be proposed via governance.
### On-Chain Actions
1. Add DOLA/USR LP Convex Market to DBR Contract
2. Set borrowController of Market to FiRM BorrowController
3. Set Market Supply Ceiling to 10,000,000 DOLA
4. Set Daily Limit in BorrowController to 2,000,000 DOLA
5. Set Collateral Factor to 90%
6. Set Liquidation Factor to 100%
7. Set Liquidation Incentive to 5%
8. Approve DOLA/USR LP Convex Market on the DBR Helper
9. Set Minimum Debt Amount in BorrowController to 3,000 DOLA
10. Set stalenessThreshold for DOLA/USR Convex LP market to 86460 (24 hours)
11. Set FiRM Oracle Price Feed for DOLA/USR Convex LP to the deployed custom tokenPriceFeed contract
12. Add DOLA/USR LP Convex Market to ALE
13. Add DOLA/USR LP Convex Market to CurveDolaLPHelper
# Adopt The SEAL Safe Harbor Agreement
Forum Link: https://forum.inverse.finance/t/adopt-the-seal-safe-harbor-agreement/534
Note: This is a resubmission of [proposal 269](https://www.inverse.finance/governance/proposals/mills/269) with Bounty Cap set to $1,000,000 and Bounty Percentage under Bounty Terms set to 10%.
Authors: Edo, skylock.xyz
---
## Introduction
This proposal outlines Inverse Finance’s adoption of the SEAL ([Security Alliance](https://www.securityalliance.org/)) Whitehat Safe Harbor Agreement (“Safe Harbor Agreement”). By adopting Safe Harbor, Inverse improves the security of its on-chain assets by allowing whitehats to intervene during active exploits to save protocol funds.
### What is the Safe Harbor Agreement?
The Safe Harbor Agreement addresses a critical need in crypto: enabling whitehats to intervene during active exploits when traditional responsible disclosure procedures are not feasible.
Key aspects of the agreement include:
* Encouraging Whitehats to Protect the Protocol: By adopting Safe Harbor, Inverse incentivizes whitehats to step in and protect the protocol during active exploits by limiting their legal exposure.
* Intervention Only During Active Exploits: Whitehats are authorized to act only when there is an active exploit that threatens the protocol. This agreement applies only to critical situations where responsible disclosure procedures would not save funds due to the urgency of the exploit, and it is not intended for routine security testing or vulnerability reporting.
* Mandatory Return of Rescued Funds: Under the terms of the Safe Harbor, whitehats are required to return all rescued assets to a pre-designated recovery address controlled by the protocol within 72 hours of recovery.
* Clear Guidelines and Legal Protection: The agreement establishes strict rules for how whitehats must operate during an exploit, ensuring recovery efforts are conducted professionally and safely, and minimizing the risk of mistakes or further damage to the protocol.
* Incentivized Rescue Efforts: To motivate whitehats to act during critical situations, the agreement offers a bounty system similar to a bug bounty. Whitehats are rewarded with a percentage of the recovered assets, up to a predefined cap, for their successful interventions.
For more information, check out the Safe Harbor Agreement [here](https://github.com/security-alliance/safe-harbor/blob/main/documents/agreement.pdf).
---
## Rationale
The Safe Harbor Agreement empowers whitehats to act immediately during an exploit, offering a swift and structured asset recovery process. Benefits of adopting the Safe Harbor Agreement include:
* Agile Defense Against Exploits: Whitehats are authorized to intervene as soon as an active exploit is detected, enabling them to respond faster than traditional methods. Immediate action minimizes the window for malicious actors, reduces damages, and accelerates the recovery of assets during critical moments.
* Clarified Rescue Process: The agreement ensures that every step, from intervention to fund recovery, is predetermined and streamlined. Whitehats know exactly where to send recovered funds, preventing chaotic negotiations or rushed decisions during an exploit. This clarity ensures efficient, decisive action when it matters most.
* Clear Financial Boundaries: The predefined bounty system, with a cap matching Inverse’s existing bug bounty, ensures that whitehats are incentivized fairly without creating conflicting priorities between exploit intervention and standard vulnerability disclosure. By setting expectations upfront, Safe Harbor eliminates post-exploit negotiations, ensuring funds are returned promptly without attempted negotiations.
* Aligning with Industry Best Practices: By adopting the Safe Harbor Agreement, Inverse aligns itself with leading security practices across the industry, reinforcing its commitment to staying at the forefront of protocol security.
Adoption of the agreement complements audits and bug bounties by providing an additional layer of security, ensuring that the protocol is better prepared to respond to active threats.
---
## Adoption Details
Inverse Finance will adopt the agreement with the following parameters. For a full description of these adoption details, review the [Safe Harbor for Protocols](https://www.notion.so/securityalliance/Safe-Harbor-for-Protocols-76a61d6bfc2747b9a2c0263092e8a51f?pvs=4#05b2a7f1cecb47cf8e977d7cad21dda2) document.
1. Asset Recovery Address:
|Chain|Address|
| --- | --- |
|Ethereum|0x926df14a23be491164dcf93f4c468a50ef659d5b|
|OP|0xa283139017a2f5BAdE8d8e25412C600055D318F8|
|Base|0x586CF50c2874f3e3997660c0FD0996B090FB9764|
|Arbitrum|0x23dEDab98D7828AFBD2B7Ab8C71089f2C517774a|
|BNB Chain|0xF7Da4bC9B7A6bB3653221aE333a9d2a2C2d5BdA7|
2. Scope: The assets under scope will include all assets in scope on Inverse Finance’s immune bug bounty page as of 2025-01-29:[ https://immunefi.com/bug-bounty/inversefinance/scope](https://immunefi.com/bug-bounty/inversefinance/scope)
3. Contact Details:
* Edo - [edo@inverse.finance](mailto:edo@inverse.finance)
* Karm - [karm@inverse.finance](mailto:karm@inverse.finance)
* Harry - [cryptoharry@inverse.finance](mailto:harry@inverse.finance)
* Nour - [nour@inverse.finance](mailto:nour@inverse.finance)
4. Bounty Terms:
* Bounty Percentage: 10%
* Bounty Cap (USD): $1,000,000
* Retainable: true
1. After rescuing funds during an exploit, whitehats may deduct their bounty from the total recovered amount before transferring the remainder to the protocol’s designated asset recovery address.
* Identity Verification: Anonymous
1. Whitehats are allowed to remain anonymous and are not required to provide their legal name or undergo identity verification.
* Diligence Requirements: None
---
## Implementation Plan
1. Register Agreement On-Chain:
* The agreement will be registered on Ethereum in the Safe Harbor Registry at address 0x8f72fcf695523a6fc7dd97eafdd7a083c386b7b6, including all adoptionDetails. This ensures transparency and immutability.
2. Update ToS:
* Exhibit D: User Adoption Procedures will be added to Inverse Finance’s Terms of Services. References to Safe Harbor will also be added to Inverse Finance’s [technical documentation](https://docs.inverse.finance/inverse-finance/technical/bug-bounty).
3. Communicate Adoption:
* An official announcement will be made across all Inverse Finance’s official communication channels, explaining the adoption and its significance to the community.
4. Future Updates to Scope:
* New smart contracts deployed by Inverse Finance will be reviewed and added to the Safe Harbor Agreement scope via governance vote, ensuring continued protection.
---
## Conclusion
Adopting the SEAL Whitehat Safe Harbor Agreement equips Inverse Finance with a rapid response mechanism for active exploits, enabling whitehats to step in effectively when needed most. The agreement provides clear guidelines for action, increasing the protection of user funds and demonstrating Inverse Finance's commitment to proactive security.
---
## References
* SEAL Whitehat Safe Harbor Agreement:[ GitHub Repository](https://github.com/security-alliance/safe-harbor)
* SEAL Whitehat Safe Harbor Agreement Overview: [Notion](https://securityalliance.notion.site/SEAL-Whitehat-Safe-Harbor-Agreement-dbdccd84e279405d89156ff80f83fa01?pvs=74)
* Inverse Finance Bug Bounty: [Immunefi](https://immunefi.com/bug-bounty/inversefinance/information/)
---
Please share your thoughts and feedback in the discussion below before the proposal moves to a formal vote.
# Proposal to launch the GearboxFed – An ERC4626-Based DOLA Fed for Gearbox
Forum Link: https://forum.inverse.finance/t/proposal-to-launch-the-gearboxfed-an-erc4626-based-dola-fed-for-gearbox/539
### Summary
This proposal seeks to introduce GearboxFed, a governance-controlled Fed contract designed to manage DOLA supply by integrating with the Gearbox DOLA vault. Leveraging the standardized ERC4626 interface, GearboxFed provides a modular approach for depositing into and withdrawing from the Gearbox vault, enabling efficient liquidity management while remaining adaptable to future changes.
### Motivation
GearboxFed is developed to streamline DOLA supply management specifically for the Gearbox platform. By employing a unified ERC4626-based strategy, the Fed reduces operational complexity and enhances liquidity efficiency. This approach enables controlled expansions and contractions of the DOLA supply under the supervision of the Fed Chair (delegated by governance), ensuring that the system remains responsive to market conditions and potential liquidity issues.
### Design & Key Functions
GearboxFed expands the DOLA supply by minting tokens directly into the contract and depositing them into the Gearbox DOLA vault. Withdrawals contract the supply by redeeming tokens from the vault and burning them, with functions such as previewWithdraw and previewRedeem ensuring accurate calculations in the presence of fees or rounding discrepancies. A repayDebt mechanism allows external contributions to offset potential losses, thereby maintaining accurate Fed accounting. In emergency situations, a sweep function empowers governance to recover tokens—including vault tokens—thus mitigating risks associated with misbehaving contracts.
### Risk Considerations
The design takes into account potential limitations within the Gearbox DOLA vault, including maximum deposit or withdrawal limits and possible rounding discrepancies. To mitigate these risks, GearboxFed is programmed to revert transactions if discrepancies exceed acceptable thresholds, ensuring that deviations do not compromise protocol integrity. Emergency functions and debt repayment mechanisms provide additional layers of protection, while standard governance timelocks and multi-signature controls further minimize risk exposure.
The Risk Working Group (RWG) has covered additional considerations, as well as recommendations for SupplyCap, in a dedicated [Gearbox Fed Risk Assessment](https://docs.google.com/document/d/1LReATIZYpPJeTUMqEJurZGcMuQ8Q2b4LFgaoythyXw8/edit?usp=sharing).
### Next Steps & Implementation
Upon approval, GearboxFed will be officially recognized as the ERC4626-based DOLA Fed for the Gearbox platform within the Inverse Finance ecosystem. Ongoing maintenance and periodic risk assessments will ensure continued adherence to high security and performance standards. This proposal represents a strategic initiative for versatile and resilient DOLA supply management within the Gearbox ecosystem.
### On-Chain Actions
* Add minter on DOLA contract, assign Gearbox Fed
* setSupplyCap on Gearbox Fed to 3,000,000 DOLA
# Adopt The SEAL Safe Harbor Agreement
Forum Link: https://forum.inverse.finance/t/adopt-the-seal-safe-harbor-agreement/534
Authors: Edo, skylock.xyz
---
## Introduction
This proposal outlines Inverse Finance’s adoption of the SEAL ([Security Alliance](https://www.securityalliance.org/)) Whitehat Safe Harbor Agreement (“Safe Harbor Agreement”). By adopting Safe Harbor, Inverse improves the security of its on-chain assets by allowing whitehats to intervene during active exploits to save protocol funds.
### What is the Safe Harbor Agreement?
The Safe Harbor Agreement addresses a critical need in crypto: enabling whitehats to intervene during active exploits when traditional responsible disclosure procedures are not feasible.
Key aspects of the agreement include:
* Encouraging Whitehats to Protect the Protocol: By adopting Safe Harbor, Inverse incentivizes whitehats to step in and protect the protocol during active exploits by limiting their legal exposure.
* Intervention Only During Active Exploits: Whitehats are authorized to act only when there is an active exploit that threatens the protocol. This agreement applies only to critical situations where responsible disclosure procedures would not save funds due to the urgency of the exploit, and it is not intended for routine security testing or vulnerability reporting.
* Mandatory Return of Rescued Funds: Under the terms of the Safe Harbor, whitehats are required to return all rescued assets to a pre-designated recovery address controlled by the protocol within 72 hours of recovery.
* Clear Guidelines and Legal Protection: The agreement establishes strict rules for how whitehats must operate during an exploit, ensuring recovery efforts are conducted professionally and safely, and minimizing the risk of mistakes or further damage to the protocol.
* Incentivized Rescue Efforts: To motivate whitehats to act during critical situations, the agreement offers a bounty system similar to a bug bounty. Whitehats are rewarded with a percentage of the recovered assets, up to a predefined cap, for their successful interventions.
For more information, check out the Safe Harbor Agreement [here](https://github.com/security-alliance/safe-harbor/blob/main/documents/agreement.pdf).
---
## Rationale
The Safe Harbor Agreement empowers whitehats to act immediately during an exploit, offering a swift and structured asset recovery process. Benefits of adopting the Safe Harbor Agreement include:
* Agile Defense Against Exploits: Whitehats are authorized to intervene as soon as an active exploit is detected, enabling them to respond faster than traditional methods. Immediate action minimizes the window for malicious actors, reduces damages, and accelerates the recovery of assets during critical moments.
* Clarified Rescue Process: The agreement ensures that every step, from intervention to fund recovery, is predetermined and streamlined. Whitehats know exactly where to send recovered funds, preventing chaotic negotiations or rushed decisions during an exploit. This clarity ensures efficient, decisive action when it matters most.
* Clear Financial Boundaries: The predefined bounty system, with a cap matching Inverse’s existing bug bounty, ensures that whitehats are incentivized fairly without creating conflicting priorities between exploit intervention and standard vulnerability disclosure. By setting expectations upfront, Safe Harbor eliminates post-exploit negotiations, ensuring funds are returned promptly without attempted negotiations.
* Aligning with Industry Best Practices: By adopting the Safe Harbor Agreement, Inverse aligns itself with leading security practices across the industry, reinforcing its commitment to staying at the forefront of protocol security.
Adoption of the agreement complements audits and bug bounties by providing an additional layer of security, ensuring that the protocol is better prepared to respond to active threats.
---
## Adoption Details
Inverse Finance will adopt the agreement with the following parameters. For a full description of these adoption details, review the [Safe Harbor for Protocols](https://www.notion.so/securityalliance/Safe-Harbor-for-Protocols-76a61d6bfc2747b9a2c0263092e8a51f?pvs=4#05b2a7f1cecb47cf8e977d7cad21dda2) document.
1. Asset Recovery Address:
|Chain|Address|
| --- | --- |
|Ethereum|0x926df14a23be491164dcf93f4c468a50ef659d5b|
|OP|0xa283139017a2f5BAdE8d8e25412C600055D318F8|
|Base|0x586CF50c2874f3e3997660c0FD0996B090FB9764|
|Arbitrum|0x23dEDab98D7828AFBD2B7Ab8C71089f2C517774a|
|BNB Chain|0xF7Da4bC9B7A6bB3653221aE333a9d2a2C2d5BdA7|
2. Scope: The assets under scope will include all assets in scope on Inverse Finance’s immune bug bounty page as of 2025-01-29:[ https://immunefi.com/bug-bounty/inversefinance/scope](https://immunefi.com/bug-bounty/inversefinance/scope)
3. Contact Details:
* Edo - [edo@inverse.finance](mailto:edo@inverse.finance)
* Karm - [karm@inverse.finance](mailto:karm@inverse.finance)
* Harry - [cryptoharry@inverse.finance](mailto:harry@inverse.finance)
* Nour - [nour@inverse.finance](mailto:nour@inverse.finance)
4. Bounty Terms:
* Bounty Percentage: 20%
* Bounty Cap (USD): $100,000
* Retainable: true
1. After rescuing funds during an exploit, whitehats may deduct their bounty from the total recovered amount before transferring the remainder to the protocol’s designated asset recovery address.
* Identity Verification: Anonymous
1. Whitehats are allowed to remain anonymous and are not required to provide their legal name or undergo identity verification.
* Diligence Requirements: None
---
## Implementation Plan
1. Register Agreement On-Chain:
* The agreement will be registered on Ethereum in the Safe Harbor Registry at address 0x8f72fcf695523a6fc7dd97eafdd7a083c386b7b6, including all adoptionDetails. This ensures transparency and immutability.
2. Update ToS:
* Exhibit D: User Adoption Procedures will be added to Inverse Finance’s Terms of Services. References to Safe Harbor will also be added to Inverse Finance’s [technical documentation](https://docs.inverse.finance/inverse-finance/technical/bug-bounty).
3. Communicate Adoption:
* An official announcement will be made across all Inverse Finance’s official communication channels, explaining the adoption and its significance to the community.
4. Future Updates to Scope:
* New smart contracts deployed by Inverse Finance will be reviewed and added to the Safe Harbor Agreement scope via governance vote, ensuring continued protection.
---
## Conclusion
Adopting the SEAL Whitehat Safe Harbor Agreement equips Inverse Finance with a rapid response mechanism for active exploits, enabling whitehats to step in effectively when needed most. The agreement provides clear guidelines for action, increasing the protection of user funds and demonstrating Inverse Finance's commitment to proactive security.
---
## References
* SEAL Whitehat Safe Harbor Agreement:[ GitHub Repository](https://github.com/security-alliance/safe-harbor)
* SEAL Whitehat Safe Harbor Agreement Overview: [Notion](https://securityalliance.notion.site/SEAL-Whitehat-Safe-Harbor-Agreement-dbdccd84e279405d89156ff80f83fa01?pvs=74)
* Inverse Finance Bug Bounty: [Immunefi](https://immunefi.com/bug-bounty/inversefinance/information/)
---
Please share your thoughts and feedback in the discussion below before the proposal moves to a formal vote.
# Increase Daily Borrow Limits to 2,000,000 DOLA for Select FiRM LP Markets
Forum Link: https://forum.inverse.finance/t/increase-daily-borrow-limits-to-2-000-000-dola-for-select-firm-lp-markets/527
### **Summary**
This proposal seeks to increase the **daily borrow limits** for the same FiRM LP markets recently targeted for market ceiling adjustments. The current daily borrow limit of **1,000,000 DOLA** per market will be increased to **2,000,000 DOLA** to address growing borrower demand and further support FiRM’s operational efficiency.
### **Markets and Addresses**
|**Market**|**Address**|
| --- | --- |
|yv-DOLA-scrvUSD|0x5bb8f6aAcFF2971B42F9fE6945D24726A2541CF2|
|DOLA-scrvUSD|0x2fed508aAc87c0e6f0b647Fe83164A7AA6eb2FC9|
|yv-DOLA-sUSDe|0x4E264618dC015219CD83dbc53B31251D73c2db1a|
|DOLA-sUSDe |0xb427fC22561f3963B04202F9bb5BCEbd76c14A99|
|yv-DOLA-sUSDS|0x4A33baFA8a31E4ec9649f65646022cAD1957808b|
|DOLA-sUSDS |0xD68d3a44d46dd50BFeBa8Cca544717B76e7C4b29|
|scrvUSD-sDOLA|0x63D27fC9d463Ed727676367D3F818999962737E8|
|yv-scrvUSD-sDOLA|0xb8bc1E9c0a2d445bc39d2A745F47619E954dD565|
### **Background**
FiRM LP markets have shown consistent growth in borrower participation and utilization rates, as highlighted in the [**Revised Risk Assessment of Stable LP Markets (December 2024)**](https://docs.google.com/document/d/1rQeGZgSiK3tf21JzVbn7qncW-cLwhNhjjQYVT7pUYgs/preview?tab=t.0#heading=h.usvk0t9pbkoo). The recent increase in market ceilings to **50,000,000 DOLA** has created a strong foundation to scale these markets further.
The current daily borrow limit of **1,000,000 DOLA** per market now presents a bottleneck to borrower activity. Borrowers seeking larger amounts frequently encounter delays or limitations, reducing market efficiency and flexibility. Increasing the daily borrow limits to **2,000,000 DOLA** aligns with borrower demand and eliminates operational friction, enabling sustained growth and improved capital utilization.
This proposal builds on the governance-approved update to the **borrow controller**, which introduced a rolling 24-hour limit. This update ensures equitable access to borrowing capacity while addressing risks of double borrowing and market monopolization.
### **Rationale**
1. **Increased Borrower Demand:** Borrowers in these markets continue to push against the current daily borrow limits, demonstrating sustained and growing interest. Raising the limits will ensure FiRM can meet this demand effectively.
2. **Improved User Experience and Operational Efficiency:** Higher daily borrow limits reduce delays and enable borrowers to access larger loans without needing to split transactions across days.
3. **Alignment with Growth Strategy:** Raising the daily borrow limits complements the recent increase in market ceilings, allowing FiRM to maximize utilization and strengthen its competitive position.
### **Risk Assessment**
The [**Revised Risk Assessment of Stable LP Markets (December 2024)**](https://docs.google.com/document/d/1rQeGZgSiK3tf21JzVbn7qncW-cLwhNhjjQYVT7pUYgs/preview?tab=t.0#heading=h.usvk0t9pbkoo) supports the proposed increase in daily borrow limits based on the following:
* **Collateral and Liquidity Health:** The underlying pools for these markets demonstrate sufficient liquidity to handle higher borrowing volumes without causing instability.
* **Low Liquidation Risk:** The stablecoin-paired nature of these LP markets ensures minimal price volatility, reducing the likelihood of liquidations.
* **Risk Mitigation Measures:**
* **Borrow Controller Update:** The recently implemented rolling 24-hour limit ensures controlled and equitable borrowing.
* **Continuous Monitoring:** The RWG will actively monitor liquidity, utilization rates, and collateral health to adjust parameters as needed.
### **On-Chain Actions**
1. **Increase Daily Borrow Limit** to **2,000,000 DOLA** for the following FiRM markets:
* yv-DOLA-scrvUSD
* DOLA-scrvUSD
* yv-DOLA-sUSDe
* DOLA-sUSDe
* yv-DOLA-sUSDS
* DOLA-sUSDS
* yv-scrvUSD-sDOLA
* scrvUSD-sDOLA
# Proposal to Increase st-yETH Market Parameters
Forum Post: https://forum.inverse.finance/t/proposal-to-increase-st-yeth-market-parameters/509
#### Summary
This proposal recommends adjusting the market parameters for st-yETH as follows:
* Collateral Factor: Increase from 75% to 80%.
* Daily Borrow Limit: Increase from $200,000 to $500,000.
* Market Ceiling: Increase from $2,000,000 to $5,000,000.
These changes aim to transition the st-yETH market out of its guarded launch phase, capitalizing on its demonstrated stability and the activation of the [Liquidator Grant Program](https://www.inverse.finance/governance/proposals/mills/220), which now includes this market.
st-yETH Proposal History:
June 26th, 2024 [Proposal to increase st-yETH market’s Collateral Factor and Daily Borrow Limit](https://www.inverse.finance/governance/proposals/mills/197)
June 17th, 2024 [ALE ERC4626 Integration for sFRAX and st-yETH Markets on FiRM](https://www.inverse.finance/governance/proposals/mills/194)
May 14th, 2024 [Proposal to add st-yETH Market to FiRM](https://www.inverse.finance/governance/proposals/mills/188)
---
#### Background
The st-yETH market was launched as part of the FiRM platform's strategy to offer robust lending solutions. Initially deployed with conservative parameters to mitigate early-stage risks, the market has gained operational stability and user confidence. This stability, along with the broader ecosystem growth, provides an opportunity to expand its market parameters to better align with user demand and the platform’s growth objectives.
Additionally, the launch of the Liquidator Grant Program supports more active participation in the liquidation process, ensuring protocol stability even with higher borrowing activity.
---
#### Risk Assessment
Expanding the st-yETH market requires careful consideration of:
1. Collateral Factor:
* A higher collateral factor (80%) reflects the increased confidence in st-yETH's underlying liquidity and stability.
* The yETH/ETH Curve pool has seen roughly a 20% increase in liquidity depth, reducing volatility and supporting higher collateralization without undue risk.
* Apart from the Curve yETH/ETH liquidity, users and liquidators of the st-yETH market can exit their position through the LST’s that compose the st-yETH product. This allows st-yETH to share these liquidity sources and make for a highly liquid collateral asset.
* The st-yETH LST Composition (as of November 23, 2024) is summarized in the table below.
|LSTs in Pool|Amount in Pool|Composition|
| --- | --- | --- |
|apxETH|699.859333|22.46%|
|mevETH|587.970069|18.73%|
|sfrxETH|510.846083|17.08%|
|swETH|325.697251|10.61%|
|wstETH|278.718180|9.99%|
|rETH|293.902227|9.97%|
|ETHx|188.375734|5.96%|
|cbETH|158.377040|5.21%|
2. Daily Borrow Limit:
* The recommended increase to $500,000 reflects growing user demand and ensures the market remains competitive.
3. Market Ceiling:
* Raising the ceiling to $5,000,000 aligns with anticipated borrowing growth, providing sufficient room for market expansion while maintaining liquidity security.
The adjustments have been modeled to avoid risks of liquidation cascades, with active liquidator participation remaining a priority for market health.
---
#### On-Chain Actions
* Set Collateral Factor for st-yETH FiRM market to 80%.
* Set Daily Borrow Limit for st-yETH FiRM market to 500,000 DOLA
* Set Market Ceiling: for st-yETH FiRM market to 5,000,000 DOLA
# Reimbursement for four users affected by a ALE UI Bug
Forum Link: https://forum.inverse.finance/t/reimbursement-for-four-users-affected-by-a-ale-ui-bug/520
### Summary
This proposal seeks DAO approval to reimburse four users impacted by a UI bug in the Accelerated Leverage Engine (ALE) that resulted in sandwich attacks during their deleverage operations. The bug has been identified, and a fix implemented. We propose utilizing Treasury DOLA to reimburse these users for their documented losses, totaling approximately 23,697.76 DOLA.
### Background
The ALE is a feature within FiRM designed to facilitate leveraging and deleveraging of collateral for users by performing multiple actions in a single transaction, including minting and burning DOLA without affecting the total supply. It enables users to flash mint DOLA for collateral purchases or debt repayments, reducing risks associated with multi-step transactions and improving efficiency. Despite its widespread use and adoption, a recent bug in the UI logic was identified that affected in some cases the minAmount parameter during deleverage operations. This issue exposed some users who didn’t take additional precautionary measures to MEV sandwich attacks.
### Analysis
With the help of the Analytics Working Group, an investigation revealed that four transactions were affected by this bug, with a combined loss of 23,697.76 DOLA across four wallets but predominantly from one. The UI used for those cases displayed an incorrect minAmount during deleverage, creating conditions for MEV bots to execute sandwich attacks. The impacted users have been identified, and losses have been [verified using on-chain data](https://app.inverse.watch/queries/1035/source). Safeguards have been implemented to prevent similar incidents, including UI fixes and MEV protection recommendations. To reaffirm the DAO’s principles of accountability and user trust, we propose reimbursing these affected users from the DAO treasury.
### On-Chain Actions
1. Transfer 19,000.61 DOLA from DAO Treasury to 0x75E70dB620d5491f69526E22355236f65B46834E
2. Transfer 3,143.07 DOLA from DAO Treasury to 0x9c0D1F4a029c46265831D120DeE9CDc72F0aB3C3
3. Transfer 974.58 DOLA from DAO Treasury to 0x1e121993b4A8bC79D18A4C409dB84c100FFf25F5
4. Transfer 579.50 DOLA from DAO Treasury to 0x154001A2F9f816389b2F6D9E07563cE0359D813D
# Proposal to Increase st-yETH Market Parameters
Forum Link: https://forum.inverse.finance/t/proposal-to-increase-st-yeth-market-parameters/509
#### Summary
This proposal recommends adjusting the market parameters for st-yETH as follows:
* Collateral Factor: Increase from 75% to 80%.
* Daily Borrow Limit: Increase from $200,000 to $500,000.
* Market Ceiling: Increase from $2,000,000 to $5,000,000.
These changes aim to transition the st-yETH market out of its guarded launch phase, capitalizing on its demonstrated stability and the activation of the [Liquidator Grant Program](https://www.inverse.finance/governance/proposals/mills/220), which now includes this market.
st-yETH Proposal History:
June 26th, 2024 [Proposal to increase st-yETH market’s Collateral Factor and Daily Borrow Limit](https://www.inverse.finance/governance/proposals/mills/197)
June 17th, 2024 [ALE ERC4626 Integration for sFRAX and st-yETH Markets on FiRM](https://www.inverse.finance/governance/proposals/mills/194)
May 14th, 2024 [Proposal to add st-yETH Market to FiRM](https://www.inverse.finance/governance/proposals/mills/188)
---
#### Background
The st-yETH market was launched as part of the FiRM platform's strategy to offer robust lending solutions. Initially deployed with conservative parameters to mitigate early-stage risks, the market has gained operational stability and user confidence. This stability, along with the broader ecosystem growth, provides an opportunity to expand its market parameters to better align with user demand and the platform’s growth objectives.
Additionally, the launch of the Liquidator Grant Program supports more active participation in the liquidation process, ensuring protocol stability even with higher borrowing activity.
---
#### Risk Assessment
Expanding the st-yETH market requires careful consideration of:
1. Collateral Factor:
* A higher collateral factor (80%) reflects the increased confidence in st-yETH's underlying liquidity and stability.
* The yETH/ETH Curve pool has seen roughly a 20% increase in liquidity depth, reducing volatility and supporting higher collateralization without undue risk.
* Apart from the Curve yETH/ETH liquidity, users and liquidators of the st-yETH market can exit their position through the LST’s that compose the st-yETH product. This allows st-yETH to share these liquidity sources and make for a highly liquid collateral asset.
* The st-yETH LST Composition (as of November 23, 2024) is summarized in the table below.
|LSTs in Pool|Amount in Pool|Composition|
| --- | --- | --- |
|apxETH|699.859333|22.46%|
|mevETH|587.970069|18.73%|
|sfrxETH|510.846083|17.08%|
|swETH|325.697251|10.61%|
|wstETH|278.718180|9.99%|
|rETH|293.902227|9.97%|
|ETHx|188.375734|5.96%|
|cbETH|158.377040|5.21%|
2. Daily Borrow Limit:
* The recommended increase to $500,000 reflects growing user demand and ensures the market remains competitive.
3. Market Ceiling:
* Raising the ceiling to $5,000,000 aligns with anticipated borrowing growth, providing sufficient room for market expansion while maintaining liquidity security.
The adjustments have been modeled to avoid risks of liquidation cascades, with active liquidator participation remaining a priority for market health.
---
#### On-Chain Actions
* Set Collateral Factor for st-yETH FiRM market to 80%.
* Set Daily Borrow Limit for st-yETH FiRM market to 500,000 DOLA
* Set Market Ceiling: for st-yETH FiRM market to 5,000,000 DOLA
setBorrowController(address)# Proposal to Add DOLA/scrvUSD Convex LP Market to FiRM
Forum Link: https://forum.inverse.finance/t/proposal-to-add-dola-scrvusd-convex-lp-market-to-firm/514
### Summary
This proposal seeks to integrate the DOLA/scrvUSD Liquidity Pool Token (LPT) from Curve Finance as a collateral asset on FiRM, Inverse Finance’s fixed-rate lending protocol. The DOLA/scrvUSD LP offers unique advantages due to its stable composition, providing a unique opportunity for capital efficient lending by offering stable liquidity positions that include DOLA as collateral.We plan to deploy two distinct markets; one that adheres to the convex strategy and a market which, utilizing the same underlying LPT, aligns with Yearn’s autocompound strategy. This proposal pertains to the Convex-aligned DOLA/scrvUSD LP market on FiRM.
### Background
scrvUSD is yield-bearing crvUSD, a decentralized stablecoin native to the Curve Finance ecosystem designed with advanced stabilization mechanisms to maintain its peg to the USD. Utilizing Peg Keeper contracts, oracles, and a dynamic monetary policy, crvUSD ensures stability and resilience. Peg Keepers actively mint or burn crvUSD tokens to balance liquidity pools and keep the price near $1. Additionally, the protocol adjusts interest rates on crvUSD loans to dynamically influence supply and demand. The recent introduction of scrvUSD, developed in collaboration with Yearn Finance and powered by its V3 vault infrastructure, expands crvUSD's utility by providing a low-risk, yield-bearing alternative. By depositing crvUSD into the scrvUSD vault, users earn autocompounding interest derived from crvUSD borrowers’ interest payments.
By leveraging the DOLA/scrvUSD LP as collateral, FiRM offers its users the opportunity to capitalize on stable liquidity positions while bolstering our ecosystem’s efficiency and DOLA liquidity depth. This addition would enable liquidity providers to leverage their positions. Providing stable liquidity positions that include DOLA as collateral allows for cost-efficient lending on behalf of Inverse Finance. Typically, borrowers sell DOLA to buy other assets, impacting DOLA liquidity. Conversely, a borrower collateralizing with a DOLA LP position is likely to add the other stablecoin/s to the liquidity pool initially to obtain the LPT. They may then loop the borrowed DOLA into the LP position repeatedly to increase their reward, benefiting DOLA liquidity as it does not remove other stablecoins. This results in a 150% improvement in lending capital efficiency, as only 1 DOLA needs to be contracted by our [AMM Feds](https://docs.inverse.finance/inverse-finance/inverse-finance/product-guide/dola-feds) for each DOLA added to the liquidity position, compared to 2.5 DOLAs for DOLA sold.
### Risk Assessment
[Complete Risk Assessment - DOLA/scrvUSD LP Collateral on FiRM](https://docs.google.com/document/d/1baBOoS41_S0XN_T9x1ofclckxxZga8Th8uFYCG4Ktl0/edit?usp=sharing)
The RWG conducted a risk assessment linked above which explores the integration of the DOLA/scrvUSD LPT as collateral on FiRM. This report, summarized below, was compiled as an addendum to a previously issued report exploring the unique characteristics of crvUSD, the DOLA/crvUSD LP, and the broader market context.
1. Governance: Curve Finance is governed by the Curve DAO, with decisions made by veCRV token holders. While the DAO ensures decentralized governance, an emergency multisig can temporarily pause pools and liquidity gauges if necessary.
2. Security: Curve has a strong security track record, underpinned by multiple audits conducted by reputable firms. The smart contracts governing crvUSD, Yearn’s V3 Vaults, and the DOLA/scrvUSD LP have all been rigorously tested and are subject to ongoing security reviews. Additionally, both Yearn and Curve maintain an active bug bounty program, incentivizing the identification and reporting of vulnerabilities.
3. Regulatory Risks: As with any stablecoin, regulatory scrutiny is a significant consideration. Both DOLA and crvUSD are subject to global regulatory scrutiny, especially regarding stablecoin issuance and trading. While Curve isn’t misaligned with current regulations, any changes could affect its viability.
4. Collateral & Liquidity: Our analysis of crvUSD liquidity demonstrates that it is both deep and decentralized. A snapshot from December shows that the total TVL for crvUSD liquidity pools was > $30MM. Furthermore, crvUSD DEX liquidity and peg stability is supported by the Curve Lend markets totalling $68.77MM debt / backstop support, protecting against downward peg movement. Continuous monitoring of the pool’s TVL and performance will be necessary to mitigate risks tied to market operations.
5. Competitive Edge: The integration of DOLA/scrvUSD LP as a collateral option on FiRM distinguishes it from competitors. While other platforms like FraxLend have introduced liquidity pool tokens as collateral, FiRM offers distinct advantages, including a fixed interest rate of unlimited duration and the ability to leverage up/down through ALE.
6. Oracle and Price Feed Considerations: FiRM will implement a pessimistic LP token oracle for accurate valuation of the DOLA/scrvUSD LP. This process uses Chainlink price feeds for crvUSD and the virtual price from the Curve pool’s smart contract and ensures a conservative and reliable estimate of the LP token's USD value. Real-time monitoring will further support price accuracy and integrity.
7. Liquidation Mechanisms: The liquidation factor and incentive are optimized to encourage active liquidator participation. Arbitrage opportunities with other DOLA, scrvUSD or crvUSD LPs will ensure that large liquidations do not lead to a liquidation cascade. The liquidation process will pull vault tokens, convert them to LP tokens, and then allow liquidators to realize value through balanced withdrawals, ensuring efficient liquidation routes.
The DeFi landscape is dynamic, and the RWG is committed to continuous monitoring of the DOLA/scrvUSD LP’s performance as collateral. Regular updates to risk models, market parameters, and liquidity metrics will be made to study any changing conditions. This proactive approach will ensure that FiRM remains a resilient and adaptable platform, capable of managing new risks as they emerge.
### On-Chain Actions
1. Add DOLA/scrvUSD LP Convex Market to DBR contract
2. Set borrowController of Market to FiRM BorrowController
3. Set market supply ceiling to 10,000,000 DOLA
4. Set daily limit in BorrowController to 1,000,000 DOLA
5. Set Collateral Factor to 90%
6. Set Liquidation Factor to 100%
7. Set Liquidation Incentive to 5%
8. Approve DOLA/scrvUSD LP Convex market on the DBR Helper
9. Set Minimum Debt Amount in BorrowController to 3,000 DOLA
10. Set stalenessThreshold for DOLA/scrvUSD Convex LP market to 86460
11. Set FiRM Oracle price feed for DOLA/scrvUSD Convex LP to the deployed DOLA/scrvUSD custom LP tokenPriceFeed contract
12. Add DOLA/scrvUSD LP Convex Market to ALE
13. Add DOLA/scrvUSD LP Convex Market to CurveDolaLPHelper
setBorrowController(address)# Proposal to Add DOLA/sUSDS Convex LP Market to FiRM
Forum Link:https://forum.inverse.finance/t/proposal-to-add-dola-susds-convex-lp-market-to-firm/511
### Summary:
This proposal seeks to integrate the DOLA/sUSDS LPT from Curve Finance as a collateral asset on FiRM, Inverse Finance’s fixed-rate lending protocol. The DOLA/sUSDS LP offers stable liquidity positions that include DOLA and sUSDS, making it a strong candidate for capital-efficient lending within FiRM.
The proposed DOLA/sUSDS LP market will help expand FiRM’s offerings in line with previous successful LPT collateral integrations like the DOLA/crvUSD LP, the DOLA/FRAXpyUSD LP, the DOLA/FRAXBP and the DOLA/sUSDe LP. We plan to deploy two distinct DOLA/sUSDS LP markets; one that adheres to the convex strategy and the market which, utilizing the same underlying LPT, aligns with Yearn’s autocompound strategy. This proposal pertains to the Convex-aligned DOLA/sUSDS LP market on FiRM.
This integration is another step in Inverse Finance’s broader strategy to deepen its collaboration with Sky Protocol and Curve, while enhancing the capital efficiency of FiRM and increasing borrowing opportunities for users.
### Background:
The DOLA/sUSDS LP is hosted on Curve Finance and represents a strategic collaboration between Inverse Finance and Sky Protocol. The LP is designed to support efficient, low-slippage trades between DOLA and sUSDS, allowing liquidity providers to earn competitive yields while maintaining stable liquidity in the pool. sUSDS, through the approval of the [sDAI market](https://www.inverse.finance/governance/proposals/mills/130), had been thoroughly assessed by Inverse Finance’s RWG prior to this latest proposal.
When FiRM borrowers leverage up their LP positions using ALE, single-sided DOLA is pumped into the liquidity pool via the flashminter, creating an arbitrage opportunity due to the pool imbalance. The 200 A Parameter of the Curve pool allows the pool to level off as sUSDS is added by arbitragers. This approach enhances DOLA liquidity without removing other stablecoins from the pool. As a result, lending capital efficiency is significantly improved. For example, typically for every 1 DOLA lent out and sold, the [AMM Feds](https://docs.inverse.finance/inverse-finance/inverse-finance/product-guide/dola-feds) 1 need to contract 2.5 DOLAs to counteract the impact on liquidity. In contrast, when 1 DOLA is lent out and added to a DOLA liquidity position, only 1 DOLA needs to be contracted, resulting in a 150% increase in lending capital efficiency.
### Risk Assessment:
[Complete Risk Assessment - DOLA/sUSDS LP Collateral on FiRM](https://docs.google.com/document/d/15NjIzscIX4pFU6X0mb427Xm2-9-YgdfbHKpzQiqLAoE/edit?usp=sharing)
The RWG conducted a risk assessment (linked above) which explored the integration of the DOLA/sUSDS LPT as collateral on FiRM. This assessment combines both quantitative and qualitative analysis, covering governance, security, liquidity, and competitive factors, and considering the unique characteristics of sUSDS and the broader market context. These are summarized below:
* **Governance**: Sky Protocol incorporates a decentralized governance model that builds on Maker’s well-established framework. Its innovative SubDAO structure, now termed "Sky Stars," allows for parallelized operations and delegation of responsibilities, such as collateral management and innovation. This decentralization streamlines governance while reducing systemic risks, ensuring decisions are made efficiently and transparently. However, Sky’s current governance setup retains some centralized elements, including key roles for managing deployments and adjusting critical parameters. This ensures operational stability while the ecosystem transitions fully to decentralized decision-making.
* **Security**: Sky Protocol inherits MakerDAO's rigorous security practices, including extensive private audits, competitive audit contests, and a robust bug bounty program. Notably, Sky has collaborated with ChainSecurity for over 50 private audits across its modules and integrations, and recently concluded a $1.35M bug bounty contest hosted on Sherlock. Sky also boasts a $10MM Bug Bounty Program, amongst the largest in DeFi, and has a history of paying out whitehats for vulnerabilities identified.
* **Regulatory Risks:** Sky faces potential scrutiny due to its operation as a decentralized stablecoin issuer. However, by leveraging over-collateralization and maintaining robust on-chain transparency, Sky may mitigate key regulatory risks. The protocol's partnerships with regulated real-world asset facilitators further diversify its collateral base, providing stability while aligning with evolving compliance standards. Although the regulatory landscape remains uncertain for DeFi, Sky’s proactive measures and emphasis on transparency position it well to navigate potential challenges.
* **Competitive Edge**: FiRM’s inclusion of the DOLA/sUSDS LP marks its fifth stable LP market, showcasing a competitive edge by offering fixed-rate borrowing for liquidity providers. While competitors like FraxLend have integrated LPs, FiRM’s fixed-rate loans and ALE leverage mechanics present a distinct advantage in capital efficiency.
* **Oracle and Price Feed Considerations**: The DOLA/sUSDS LP relies on a robust oracle mechanism leveraging Chainlink’s DAI price feed, a fixed $1 DOLA price, and Curve’s virtual price to determine the LP token value. This pessimistic pricing model, already in production with the other stable LP FiRM markets, ensures stability and mitigates manipulation risks while maintaining high reliability.
* **Liquidation Mechanisms**: The liquidation factor and incentive market parameters are optimized to encourage active liquidator participation. Arbitrage opportunities with other DOLA and/or sUSDS LPs will ensure that large liquidations do not lead to a liquidation cascade. The liquidation process will pull vault tokens, convert them to LP tokens, and then allow liquidators to realize value through balanced withdrawals, ensuring efficient liquidation routes.
The DeFi landscape is dynamic, and the RWG is committed to continuous monitoring of the DOLA/sUSDS LP’s performance as collateral. Regular updates to risk models, market parameters, and liquidity metrics will be made to study any changing conditions. This proactive approach will ensure that FiRM remains a resilient and adaptable platform, capable of managing new risks as they emerge.
### On-Chain Actions
1. Add DOLA/sUSDS Convex Market to DBR contract
2. Set borrowController of Market to FiRM BorrowController
3. Set market supply ceiling to 10,000,000 DOLA
4. Set daily limit in BorrowController to 1,000,000 DOLA
5. Set Collateral Factor to 90%
6. Set Liquidation Factor to 100%
7. Set Liquidation Incentive to 5%
8. Approve DOLA/sUSDS Convex market on the DBR Helper
9. Set Minimum Debt Amount in BorrowController to 3,000 DOLA
10. Set stalenessThreshold for DOLA/sUSDS Convex market to 3600
11. Set FiRM Oracle price feed for DOLA/sUSDS Convex to the deployed DOLA/sUSDS custom LP tokenPriceFeed contract
12. Add DOLA/sUSDS Convex Market to ALE
13. Add DOLA/sUSDS Convex Market to CurveDolaLPHelper
addMarket(address)# Proposal to Add DOLA/sUSDe Convex LP Market to FiRM
Forum Link: https://forum.inverse.finance/t/proposal-to-add-dola-susde-convex-lp-market-to-firm/506
### Summary:
This proposal seeks to integrate the DOLA/sUSDe LPT from Curve Finance as a collateral asset on FiRM, Inverse Finance’s fixed-rate lending protocol. The DOLA/sUSDe LP offers stable liquidity positions that include DOLA and sUSDe, making it a strong candidate for capital-efficient lending within FiRM.
The proposed DOLA/sUSDe LP market will help expand FiRM’s offerings in line with previous successful LPT collateral integrations like DOLA/crvUSD LP, the DOLA/FRAXpyUSD LP, and the DOLA/FRAXBP. We plan to deploy two distinct DOLA/sUSDe LP markets; one that adheres to the convex strategy and the market which, utilizing the same underlying LPT, aligns with Yearn’s autocompound strategy. This proposal pertains to the Convex-aligned DOLA/sUSDe LP market on FiRM.
This integration is another step in Inverse Finance’s broader strategy to deepen its collaboration with Frax Finance and Curve, while enhancing the capital efficiency of FiRM and increasing borrowing opportunities for users.
### Background:
The DOLA/sUSDe LP is hosted on Curve Finance and represents a strategic collaboration between Inverse Finance and Ethena Labs. The LP is designed to support efficient, low-slippage trades between DOLA and sUSDe, allowing liquidity providers to earn competitive yields while maintaining stable liquidity in the pool. sUSDe, through the approval of the [sUSDe market](https://www.inverse.finance/governance/proposals/mills/209), and the recent [PT-sUSDe-MAR272025 market](https://www.inverse.finance/governance/proposals/mills/227) had been thoroughly assessed by Inverse Finance’s RWG prior to this latest proposal.
When FiRM borrowers leverage up their LP positions using ALE, single-sided DOLA is pumped into the liquidity pool via the flashminter, creating an arbitrage opportunity due to the pool imbalance. The 200 A Parameter of the Curve pool allows the pool to level off as FRAX and/or USDC is added by arbitragers. This approach enhances DOLA liquidity without removing other stablecoins from the pool. As a result, lending capital efficiency is significantly improved. For example, typically for every 1 DOLA lent out and sold, the [AMM Feds](https://docs.inverse.finance/inverse-finance/inverse-finance/product-guide/dola-feds) 1 need to contract 2.5 DOLAs to counteract the impact on liquidity. In contrast, when 1 DOLA is lent out and added to a DOLA liquidity position, only 1 DOLA needs to be contracted, resulting in a 150% increase in lending capital efficiency.
### Risk Assessment:
[Complete Risk Assessment - DOLA/sUSDe LP Collateral on FiRM](https://docs.google.com/document/d/1yM1u-ypft4QDcsfqMmL3jQ7KmplsC0qhN9DDN7V7NSQ/edit?usp=sharing)
The RWG conducted a risk assessment (linked above) which explored the integration of the DOLA/sUSDe LPT as collateral on FiRM. This assessment combines both quantitative and qualitative analysis, covering governance, security, liquidity, and competitive factors, and considering the unique characteristics of sUSDe and the broader market context. These are summarized below:
* Governance: Ethena operates under a mostly centralized governance model centered around the ENA token, with current decisions primarily managed by the Ethena team. However, initial progress towards decentralization is underway, as recent proposals—such as the Wintermute-authored ENA fee switch—signal advancements toward an eventual decentralized governance.
* Security: Ethena prioritizes security with extensive audits, including evaluations from Zellic, Quantstamp, Pashov, and Spearbit, and runs a robust Immunefi bug bounty program with a $3M maximum payout. At the same time, the Curve-related smart contracts governing the DOLA/sUSDe have been rigorously tested and are subject to ongoing security reviews and Curve’s own bug bounty program. Overall, despite these measures, the LPT and the sUSDe component of the LP carries inherent risks users must be aware of.
* Regulatory Risks: Ethena's reliance on custodians introduces potential regulatory and operational risks, but the protocol’s robust attestations and compliance measures bolster its resilience.
* Competitive Edge: FiRM’s inclusion of the DOLA/sUSDe LP marks its fourth stable LP market, showcasing a competitive edge by offering fixed-rate borrowing for liquidity providers. While competitors like FraxLend have integrated LPs, FiRM’s fixed-rate loans and ALE leverage mechanics present a distinct advantage in capital efficiency.
* Oracle and Price Feed Considerations: FiRM employs a conservative oracle mechanism using Chainlink feeds for sUSDe, the sUSDe:USDe exchange rate, and the Curve pool’s virtual price to calculate the LP’s USD value. This pessimistic price feed ensures robust collateral valuation and stability in volatile scenarios.
* Liquidation Mechanisms: The liquidation factor and incentive are optimized to encourage active liquidator participation. Arbitrage opportunities with other DOLA and/or sUSDe LPs will ensure that large liquidations do not lead to a liquidation cascade. The liquidation process will pull vault tokens, convert them to LP tokens, and then allow liquidators to realize value through balanced withdrawals, ensuring efficient liquidation routes.
The DeFi landscape is dynamic, and the RWG is committed to continuous monitoring of the DOLA/FRAXpyUSD LP’s performance as collateral. Regular updates to risk models, market parameters, and liquidity metrics will be made to study any changing conditions. This proactive approach will ensure that FiRM remains a resilient and adaptable platform, capable of managing new risks as they emerge.
### On-Chain Actions
1. Add DOLA/sUSDe Convex Market to DBR contract
2. Set borrowController of Market to FiRM BorrowController
3. Set market supply ceiling to 10,000,000 DOLA
4. Set daily limit in BorrowController to 1,000,000 DOLA
5. Set Collateral Factor to 90%
6. Set Liquidation Factor to 100%
7. Set Liquidation Incentive to 5%
8. Approve DOLA/sUSDe Convex market on the DBR Helper
9. Set Minimum Debt Amount in BorrowController to 3,000 DOLA
10. Set stalenessThreshold for DOLA/sUSDe Convex market to 86460
11. Set FiRM Oracle price feed for DOLA/sUSDe Convex to the deployed DOLA/sUSDe custom LP tokenPriceFeed contract
12. Add DOLA/sUSDe Convex Market to CurveDolaLPHelper
13. Add DOLA/sUSDe Convex Market to ALE
# Risk Working Group - Season 3 Proposal
Forum Link: https://forum.inverse.finance/t/risk-working-group-season-3-proposal/485
Authors: Edo
Reviewers: Karm
## 1. Summary
The Risk Working Group (RWG) of Inverse Finance has successfully completed two seasons of proactive risk management, framework development, and security enhancements. Building upon the solid foundation established in Seasons 1 and 2, the RWG proposes to continue its mission in Season 3. This proposal outlines the objectives, projects, success metrics, and budget required for the RWG to operate effectively over the next six months, from November 1, 2024, to April 30, 2025.
## 2. RWG @ Inverse Finance
The RWG is integral to Inverse Finance DAO, responsible for identifying, assessing, and mitigating risks to the protocol and its users. It supports all existing and future functions of Inverse Finance, providing sound risk analysis, risk management, and risk monitoring for all DAO products. Collaborating closely with other groups such as the Product, Analytics, Growth, and Treasury working groups, the RWG pursues shared security goals and promotes safe practices among DAO members.
Compared to traditional finance, significantly more risks are present in DeFi for individual users and protocols: malicious actors, esoteric smart contract risks, unknown correlations between tokens and projects, short track records, unproven and experimental economic theories, anon teams/devs, and the irreversibility of transactions to name just a few. Inverse Finance faces unique challenges as a lending protocol operator and a stablecoin issuer. The presence of DOLA bad debt necessitates meticulous attention and a zero-tolerance policy for errors, demanding constant vigilance throughout the year. Therefore, a robust risk management function within Inverse Finance is indispensable for protecting the DAO and its users.
The RWG is well-positioned to build upon established risk management practices, ensuring that any value added to the DAO is accompanied by a heightened and ongoing awareness of risk. As a reminder, we compile all directives and accomplishments in the [Risk Working Group Digest](https://docs.inverse.finance/inverse-finance-risk), our dedicated website that serves as a comprehensive archive of our work.
### 2.0. Season 2 Recap
For a comprehensive recap of our Season 2, including goals, projects and success metrics be sure to review our latest forum post titled: [“Behind the Scenes: Season 2 Recap”](https://forum.inverse.finance/t/behind-the-scenes-rwg-season-2-recap/480).
### 2.1. WG Goals
During Season 3 like in Season 2, the RWG intends to build upon several key directives defined during Season 1. These align with the [DAO’s “North Star” objectives](https://forum.inverse.finance/t/s1-strategy-proposal/291) laid out before the start of Season 1, demonstrating our WG’s contribution to Inverse Finance’s overarching objectives. Season 3 RWG goals include:
1. Enhance Existing Frameworks - We aim to complete the transition of all existing risk management frameworks from Google Sheets to a more advanced platform equipped with real-time updates. This modernization will significantly improve data accuracy, efficiency, and collaborative capabilities. By integrating APIs and automating data feeds, we can make timely adjustments to risk parameters based on market conditions, enhancing our ability to proactively manage risks.
2. Develop New Frameworks - To address emerging risks and challenges in managing Inverse's suite of products, we may develop new risk management frameworks. We recognize the value of collaboration and learning from the broader DeFi risk management community. By leveraging communications and materials made publicly available by other risk teams we aim to adapt and tailor these insights to our specific use cases and products.
3. Conduct Comprehensive Risk Assessments - Regularly assessing existing and prospective FiRM markets is crucial for maintaining the protocol's safety. We will continue to perform thorough risk assessments for all new proposed markets and periodically reassess existing markets to account for changes in market dynamics, ensuring that our risk evaluations remain current and comprehensive.
4. Drive Security-Related Cooperation - Strengthening our security posture requires collaboration both within the DAO and with external partners. We will carry out our vision for Security Operations at Inverse Finance by continuing to build out the "[four lines of defense](https://docs.inverse.finance/inverse-finance-risk/prevention/sec-ops)" approach, which includes preventive measures, real-time monitoring, incident response, and recovery strategies.
5. Facilitate Governance Participation - Increasing engagement in DAO governance is essential for transparency and community involvement. We will actively participate in governance forums by providing regular updates and encouraging discussions. Our goal is to foster an engaged community that actively contributes to the protocol's success, thereby improving the health of DAO governance.
6. Maintain an Updated Library of Directives - Maintaining comprehensive and accessible documentation is crucial for transparency and continuity. We will keep the [Risk Working Group Digest](https://docs.inverse.finance/inverse-finance-risk) updated with all directives, frameworks, assessments, and reports. By ensuring our work is archived and easily navigable, we facilitate knowledge sharing and provide a valuable resource for DeFi.
### 2.2 Responsibilities
The RWG will be responsible for:
* Monitoring: Utilizing tools like the Risk Observer Checklist and further developing our alerting system on Inverse Watch to continuously monitor risks across the protocol.
* Policy Recommendations: Recommending policies for FiRM markets, DOLA health, and more, based on the application of our in-house frameworks.
* Auditing Oversight: Serve as the authority in determining what components are audit-worthy and specify the type and scope of audits required based on potential impact and funds at risk.
* Security Operations Vision: Carrying out our vision for Security Operations at Inverse Finance, implementing the “[four lines of defense](https://docs.inverse.finance/inverse-finance-risk/prevention/sec-ops)” approach.
* Multisig Duties: Fulfilling our duties as signers on various DAO multisigs, including the RWG multisig, TWG multisig on various chains, Policy multisig, and Fed Chair. Our participation ensures that actions requiring multisig approval are executed securely and in alignment with risk management practices (see recent [Radiant](https://rekt.news/radiant-capital-rekt2/) and [Tapioca](https://rekt.news/tapioca-dao-rekt/) exploits).
* Governance Proposals: Drafting and guiding risk-related and product-focused proposals through the governance process.
* DAO Governance Health: Monitoring and promoting the health of DAO governance by encouraging participation, facilitating discussions, and ensuring transparency in decision-making processes.
* Documentation Maintenance: Maintaining up-to-date records of all directives, frameworks, assessments, and reports.
### 2.3 Projects
Due to the dynamic nature of our jobs and the ongoing responsibilities of the RWG, new projects and initiatives often emerge throughout the season; some are scrapped while others evolve or reach a natural conclusion earlier than anticipated. As such, it's challenging to list every project we will undertake during Season 3. However, we have identified several key initiatives that align with our goals and will form the core of our efforts. These projects include:
1. Participate in FiRM v2 Design Process - Given our experience within the DAO, our input is valuable in the design process of FiRM v2. We will actively participate in its development, providing insights on risk management, security considerations, and best practices to ensure the next iteration of FiRM is robust and secure.
2. Implement Liquidator Grant Program - Building on the [proposal](https://www.inverse.finance/governance/proposals/mills/220), we will oversee the implementation of this program, which aims to incentivize and onboard proficient liquidators to our platform thereby enhancing the efficiency and reliability of the liquidation process. Our responsibilities will include coordinating with grant recipients, monitoring their activity, and ensuring they adhere to the protocol's standards and guidelines.
3. Strengthen Risk Monitoring and Alerts - We plan to further develop our risk monitoring systems as new needs emerge, enhancing our ability to respond promptly to potential risks. Specialized alerts will be custom-tailored to the unique characteristics of the assets we monitor. These will range from basic alerts—such as tracking liquidity pool events for assets with lower on-chain liquidity —to generalized oracle variance alerts for all collaterals, and specific price feed alerts for our more exotic markets.
4. Adopt SafeHarbor Framework - Through collaboration with the Security Alliance, we plan to adopt [this framework](https://github.com/security-alliance/safe-harbor) to enhance our bug bounty program by enabling proactive defense measures against active exploits. Safe Harbor grants whitehats and MEV rescuers legal protection when intervening during an active exploit attempt to the protocol. In doing so, we aim to empower security experts and create a stronger safety net for Inverse.
5. Review Operational Processes - To ensure our operations align with industry best practices, we will conduct a comprehensive review of our operational processes. This includes conducting a fire drill in accordance with the frameworks laid out by the [Security Alliance](https://securityalliance.org/).
6. Author Risk-Centric Content - Education is a vital component of risk management. We will resume the "Behind the Scenes" series, committing to publish posts that delve into our methodologies, frameworks, and insights.
### 2.4 Success Metrics
To measure the success of the RWG, the following key metrics will be tracked, and reported on at the end of the Season 3 period:
* Framework Modernization Completion: Successful transition of all existing frameworks away from Google Sheets to an advanced platform equipped with real-time updates.
* “Four Lines of Defense” Adoption: Have active and/or completed initiatives for all four lines of defense; in accordance with our [SecOps vision](https://docs.inverse.finance/inverse-finance-risk/prevention/sec-ops).
* Risk Assessments Conducted: Completion of risk assessments for all new proposed markets and periodic reassessment of existing ones.
* Incident Response Improvement: Conduct a “SEAL War Games” either in collaboration with the Security Alliance team or by own accord.
* Governance Participation: Increased engagement measured by the number of forum posts, and community interactions.
* Content Production: Publication of at least one "Behind the Scenes" post per month or other risk-authored educational materials.
* Bug Bounty Program Engagement: Increase in submissions from non-novice (a rating provided by ImmuneFi) whitehats.
### 2.5 Decision making power
The RWG is requesting the DAO to continue to grant us the following delegated decision-making powers throughout our Season 3 engagement:
* Enacting the role of the RWG Guardian: The RWG will act within its rights to bring collateral markets on FiRM to an immediate pause if any one of three multisig signers believe a critical threat to the DAO is imminent.
* Proposing and implementing risk mitigation policies: The RWG seeks the ability to propose and implement off-chain risk mitigation strategies and protocols without requiring individual approval for each policy.
* Championing auditing requirements: The RWG requests the authority to determine internal auditing needs, acting as the deciding voice on what is audit-worthy and the necessary form of auditing. Decisions will be based on criteria such as impact and funds at risk, ensuring that critical components receive appropriate scrutiny.
* Recommending on-chain changes to the protocol based on risk assessments: The RWG aims to recommend changes to the protocol based on risk assessments. This allows the RWG to suggest modifications to smart contracts, operational processes, or other protocol components to address identified risks effectively.
* Leading incident response and recovery procedures: The RWG requests decision-making authority during incident response and recovery processes. This enables the RWG to make timely and informed decisions to mitigate security incidents and ensure a swift recovery. This is especially pertinent to incident response where a clear point of accountability can ensure effective resolution of the issue.
## 3. Budget
### 3.1 Contributors
No contributor compensation changes are requested within the RWG.
|Name|FTE|Band|Pro-rata Monthly Salary|Total For Season 3|
| --- | --- | --- | --- | --- |
|Edo|1.0|B|12,000|72,000|
|Karm|1.0|B|12,000|72,000|
Edo [WGL]
Edo, with a robust DeFi background, has been contributing to the RWG at Inverse Finance DAO since April 2022. His multifaceted role extends beyond risk management, encompassing SecOps leadership and strategizing DOLA adoption. He pioneered the RWG, fostering risk awareness and best practices across all working groups and DAO functions. Prior to his time at Inverse, Edo's leadership drove a hedge fund's success. He has extensive start-up experience, and has successfully restructured operations for a luxury travel brand through adopting frameworks and spearheading strategic decisions. His entrepreneurial spirit shines through founding ventures and his interests in DAO Governance. Outside of work, Edo holds interests in travel, tennis, running, and culinary arts.
Karm
Karm is a DeFi enthusiast with over two years of active involvement in Inverse Finance. He has taken on a wide range of crucial responsibilities, including risk management within the RWG, participation in essential Multisigs like the Treasury Working Group, and contributing to business development and growth strategies. Additionally, he plays a pivotal role in community engagement as the Discord server administrator and as a first responder during emergencies as a SecOps member and multisig facilitator. Karm's dedication and multifaceted contributions underscore his commitment to Inverse Finance's mission and its growth in DeFi.
### 3.2 Ad hoc & Tooling
It's important to note that, unlike in Seasons 1 and 2, starting in Season 3, budget requests pertaining to SecOps will be made separately from the RWG’s budget. This separation allows for more focused resource allocation and clearer financial planning for both the RWG and SecOps initiatives.
|Details|Type|Requested $INV|Requested $DOLA|
| --- | --- | --- | --- |
|-|-|0|0|
### 3.3 Flexible Budget
RWG requests a flexible budget as follows to cover unforeseen expenditure that arises during the Season.
|Additional flexible budget in $INV|0|
| --- | --- |
|Additional flexible budget in $DOLA|0|
### 3.4 Summary
In summary RWG requested the following budget for the 6 months of Season 2.
|Season 3|$DOLA allowance|$INV allowance|
| --- | --- | --- |
|Contributors|144,000|0|
|Ad Hoc & Tooling|0|0|
|Flexible Budget|0|0|
|Total|144,000|0|
We believe this budget accurately reflects the resources needed to achieve our goals and deliver value to the Inverse Finance ecosystem in Season 3.
# Proposal to Update Price Feed for DOLA/FraxPyUSD LP Markets on FiRM
Forum Link: https://forum.inverse.finance/t/proposal-to-update-price-feed-for-dola-fraxpyusd-yearn-lp-market-on-firm/496
### Summary
We propose updating the oracle price feed for the DOLA/FraxPyUSD LP markets on FiRM to a newly deployed price feed contract. This update addresses valuation inaccuracies due to the previous incorrect inclusion of the virtual price of the FraxpyUSD LP token in our price feed calculations. By removing the virtual price from the calculation, we ensure accurate and conservative pricing for our collateral asset.
### Background
In September 2024, we integrated two distinct DOLA/FraxPyUSD LP markets on FiRM:
1. DOLA/FraxPyUSD Convex LP Market
2. DOLA/FraxPyUSD Yearn LP Market
These markets enable users to leverage their stable liquidity positions, enhancing capital efficiency and strengthening our partnership with Curve, Frax, pyUSD, Convex, and Yearn.
During a renewed technical review, our development team identified a small accounting error regarding the FRAXpyUSD LP’s virtual price that could potentially lead to a collateral mispricing in the distant future. The virtual price represents the accumulated fees and rewards within the LP token, causing its value to slowly appreciate over time. However, in this context,, we propose adopting new price feed contracts that exclude the virtual price from the price feed calculations for the FraxpyUSD LP token.
### Price Feed
1. FraxPyUSD LP Price Feed
* Contract Address: [0x791480e7a74a256a7d3468ac2f914a66472d8589](https://etherscan.io/address/0x791480e7a74a256a7d3468ac2f914a66472d8589)
* Functionality: Retrieves the USD price of the FraxPyUSD LP token by selecting the minimum price from its underlying assets (Frax and PayPal USD), without incorporating the virtual price from the Curve pool.
2. DOLA/FraxPyUSD LP Price Feed
* Contract Address: [0x147e0a14402bd02ba544595c26a6fab1d88df321](https://etherscan.io/address/0x147e0a14402bd02ba544595c26a6fab1d88df321)
* Functionality: Uses the new FraxPyUSD LP price feed and the DOLA fixed price feed ($1) to calculate the USD value of the DOLA/FraxPyUSD LP token.
3. DOLA/FraxPyUSD Yearn LP Price Feed
* Contract Address: [0xd3dc7a44242b17f045d4de763f489b4a13c69d94](https://etherscan.io/address/0xd3dc7a44242b17f045d4de763f489b4a13c69d94)
* Functionality: Extends the DOLA/FraxPyUSD LP price feed by incorporating the conversion rate from Yearn Vault tokens to the underlying LP tokens.
### On-Chain Actions
1. Set FiRM Oracle Price Feed for DOLA/FraxPyUSD Convex LP to newly deployed feed
2. Set FiRM Oracle Price Feed for DOLA/FraxPyUSD Yearn LP to newly deployed feed
# Proposal to Increase Daily Borrow Limits for FiRM Stable LP Markets
Forum Link: https://forum.inverse.finance/t/proposal-to-increase-daily-borrow-limits-for-firm-stable-lp-markets/498
### Summary
This proposal seeks to increase the daily borrow limits for all six FiRM Stable LP Markets from the current 250,000 DOLA to 1,000,000 DOLA per market. The adjustment aims to accommodate growing borrower demand, enhance liquidity, and support the sustainable growth of the FiRM protocol.
### Background
Inverse Finance's FiRM protocol offers fixed-rate lending services across multiple Stable LP Markets. Since their inception, these six live LP markets have demonstrated robust activity and consistent utilization of their daily borrow limits. The existing daily borrow limit of 250,000 DOLA has frequently been reached or closely approached, indicating strong and sustained market demand. Borrowers are increasingly seeking larger loan amounts, and the current limits may hinder their ability to fully participate and benefit from the protocol's offerings.
Increasing the borrow limits aligns with FiRM's objective to expand its services and cater to a broader user base. By enhancing the daily borrow limits, the protocol can improve user experience by allowing borrowers to access larger loans without delays or limitations. This adjustment is also expected to increase protocol revenue, as higher loan amounts will lead to increased interest income. Moreover, raising the borrow limits will strengthen FiRM's market position, positioning it as a more competitive player in the DeFi lending space and attracting more users to the platform.
### Risk Assessment
[Revised Risk Assessment of Stable LP FiRM Markets (November '24)](https://docs.google.com/document/d/1rhrnUHW8z4ubYY7fxPFAxTSD9vmw_cQ921KO_AmHD5A/edit?usp=sharing)
The RWG's latest assessment of the markets, which can be accessed [here](https://docs.google.com/document/d/1rhrnUHW8z4ubYY7fxPFAxTSD9vmw_cQ921KO_AmHD5A/edit?usp=sharing), supports raising the daily borrow limits for each of the LP markets, based on analyses that incorporate liquidity metrics, market utilization, and stability considerations. Liquidity depths in the underlying DOLA, FRAX, crvUSD, and pyUSD pools are sufficient to handle higher borrowing levels without causing liquidity strain. Since the launch of these LP Markets, observed activity has shown consistent utilization at current limits, high engagement, and zero liquidation events. The low volatility profile of stablecoin pairs further reduces liquidation risk, and FiRM’s liquidation mechanisms and incentives (set at 5%) are structured to ensure cost-effective and prompt liquidation responses if needed, especially as MEVs are incentivized through the upcoming Liquidator Grant Program.
Moving daily borrow limits from 250,000 to 1,000,000 DOLA per market aligns with FiRM’s growth objectives by addressing increased borrower demand without altering core risk parameters. The proposal excludes changes to collateral factors, liquidation thresholds, and supply ceilings, as these settings remain well-suited to the protocol’s risk management strategy. Ongoing monitoring of key metrics will ensure FiRM’s capacity to adjust to any shifts in liquidity, utilization, or collateral health, ensuring that the protocol remains secure and responsive to market evolution.
### On-Chain Actions
* Set Daily Borrow Limit for DOLA/crvUSD LP Convex Market to 1,000,000 DOLA
* Set Daily Borrow Limit for DOLA/crvUSD LP Yearn Market to 1,000,000 DOLA
* Set Daily Borrow Limit for DOLA/FRAXpyUSD LP Convex Market to 1,000,000 DOLA
* Set Daily Borrow Limit for DOLA/FRAXpyUSD LP Yearn Market to 1,000,000 DOLA
* Set Daily Borrow Limit for DOLA/FRAXBP LP Convex Market to 1,000,000 DOLA
* Set Daily Borrow Limit for DOLA/FRAXBP LP Yearn Market to 1,000,000 DOLA
# Proposal to Add DOLA/FRABP Yearn LP Market to FiRM
Forum Link: https://forum.inverse.finance/t/proposal-to-add-dola-frabp-yearn-lp-market-to-firm/479
### Summary:
This proposal seeks to integrate the DOLA/FRAXBP Liquidity Pool Token (LPT) from Curve Finance as a collateral asset on FiRM, Inverse Finance’s fixed-rate lending protocol. The DOLA/FRAXBP LP offers stable liquidity positions that include DOLA and FRAX, making it a strong candidate for capital-efficient lending within FiRM.
The proposed DOLA/FRAXBP LP market will help expand FiRM’s offerings in line with previous successful LPT collateral integrations like DOLA/crvUSD and DOLA/FRAXpyUSD. We plan to deploy two distinct DOLA/FRAXBP markets; one that adheres to the convex strategy and the market which, utilizing the same underlying LPT, aligns with Yearn’s autocompound strategy. This proposal pertains to the Yearn-aligned DOLA/FRAXBP market on FiRM.
This integration is another step in Inverse Finance’s broader strategy to deepen its collaboration with Frax Finance and Curve, while enhancing the capital efficiency of FiRM and increasing borrowing opportunities for users.
### Background:
The DOLA/FRAXBP LP is hosted on Curve Finance and represents a strategic collaboration between Inverse Finance and Frax Finance. The LP is designed to support efficient, low-slippage trades between DOLA and FRAX, allowing liquidity providers to earn competitive yields while maintaining stable liquidity in the pool. FRAX, through the approval of the [sFRAX market](https://www.inverse.finance/governance/proposals/mills/191), the FRAXpyUSD Fed, and the recent[ FRAXpyUSD LP markets](https://www.inverse.finance/governance/proposals/mills/222) had been thoroughly assessed by Inverse Finance’s RWG prior to this latest proposal.
As of October 16th, 2024, the DOLA/FRAXBP LP holds $4.43 million in TVL, with Inverse Finance’s Convex Fed being the largest liquidity provider, contributing $2 million to the pool. The DOLA/FRAXBP via the Convex Fed has played a key part of Inverse’s liquidity strategy, offering a balanced mechanism to support DOLA’s liquidity.
When FiRM borrowers leverage up their LP positions using ALE, single-sided DOLA is pumped into the liquidity pool via the flashminter, creating an arbitrage opportunity due to the pool imbalance. The 200 A Parameter of the Curve pool allows the pool to level off as FRAX and/or USDC is added by arbitragers. This approach enhances DOLA liquidity without removing other stablecoins from the pool. As a result, lending capital efficiency is significantly improved. For example, typically for every 1 DOLA lent out and sold, the [AMM Feds](https://docs.inverse.finance/inverse-finance/inverse-finance/product-guide/dola-feds) 1 need to contract 2.5 DOLAs to counteract the impact on liquidity. In contrast, when 1 DOLA is lent out and added to a DOLA liquidity position, only 1 DOLA needs to be contracted, resulting in a 150% increase in lending capital efficiency.
### Risk Assessment:
[Complete Risk Assessment - DOLA/FRAXBP LP Collateral on FiRM](https://docs.google.com/document/d/1TjkpjiM3trvXPp6YMYpjsQJH0u3Ht5YbLz6qQYIXY6c/edit?usp=sharing)
The RWG conducted a risk assessment (linked above) which explored the integration of the DOLA/FRAXBP LPT as collateral on FiRM. This assessment combines both quantitative and qualitative analysis, covering governance, security, liquidity, and competitive factors, and considering the unique characteristics of FRAX, the DOLA/FRAXBP, and the broader market context. These are summarized below:
* **Governance**: Frax Finance operates under an increasingly-decentralized governance model, controlled by veFXS token holders who vote on protocol parameters and integrations through on-chain mechanisms. This governance structure has proven resilient, with multiple risk management tools and a strong track record in handling liquidity, market changes, and external integrations. USDC, on the other hand, is issued by Circle, a fully regulated entity overseen by the NYDFS.
* **Security**: Security is paramount for Frax Finance. Frax Finance has undergone multiple independent security audits by reputable firms such as Trail of Bits, and it also runs one of the largest bug bounty programs in DeFi, offering significant rewards for any vulnerabilities found. At the same time, the Curve-related smart contracts governing the DOLA/FRAXBP have been rigorously tested and are subject to ongoing security reviews and bug bounty programs. Overall, despite these measures, the LPT and the FRAX component of the LP carries inherent risks users must be aware of.
*** Regulatory Risks**: As with any stablecoin, regulatory scrutiny is a significant consideration. DOLA, FRAX and USDC are subject to global regulatory scrutiny, especially regarding stablecoin issuance and trading. While Circle, as a regulated entity, is aligned with current regulations, any changes could affect USDC viability. At the same time, Frax’s increasing integration with RWAs could attract more regulatory attention in the future.
*** Liquidity and Collateral Stability**: The DOLA/FRAXBP LP holds $4.43M in TVL, and is comprised of three highly liquid stablecoins. DOLA’s peg stability is further supported by Inverse Finance’s AMM Fed. On-chain liquidity for FRAX and USDC is well-established, making this LP a stable and reliable source of collateral.
*** Competitive Edge**: The integration of DOLA/FRAXBP as a collateral option on FiRM distinguishes it from competitors. While other platforms like FraxLend have introduced liquidity pool tokens as collateral, FiRM offers distinct advantages, including a fixed interest rate of unlimited duration and the ability to leverage up/down through ALE. This stable pair LP is not currently available on other lending platforms.
*** Oracle and Price Feed Considerations**: FiRM will implement a pessimistic LP token oracle for accurate valuation of the DOLA/FRAXBP. This process uses Chainlink price feeds for both FRAX and USDC and the virtual price from the Curve pool’s smart contract. First, the Chainlink price feed is pulled for FRAX, USDC to get its USD value. Then, the lowest price between DOLA (fixed at $1), FRAX and USDC is selected. The LP token value is calculated by multiplying this lowest price by the virtual price from the Curve pool’s smart contract. Since we assume DOLA price to be $1 always in FiRM, essentially we use the lower between FRAX and USDC price * virtual_price when either FRAX or USDC USD price is under 1, and when it is over 1 we just use the virtual_price, ensuring a conservative and reliable estimate of the LP token’s USD value. Real-time monitoring will further support price accuracy and integrity.
*** Liquidation Mechanisms**: The liquidation factor and incentive are optimized to encourage active liquidator participation. Arbitrage opportunities with other DOLA, FRAX and/or USDC LPs will ensure that large liquidations do not lead to a liquidation cascade. The liquidation process will pull vault tokens, convert them to LP tokens, and then allow liquidators to realize value through balanced withdrawals, ensuring efficient liquidation routes.
The DeFi landscape is dynamic, and the RWG is committed to continuous monitoring of the DOLA/FRAXpyUSD LP’s performance as collateral. Regular updates to risk models, market parameters, and liquidity metrics will be made to study any changing conditions. This proactive approach will ensure that FiRM remains a resilient and adaptable platform, capable of managing new risks as they emerge.
### On-Chain Actions
1. Add DOLA/FRAXBP Yearn Market to DBR contract
2. Set borrowController of Market to FiRM BorrowController
3. Set market supply ceiling to 10,000,000 DOLA
4. Set daily limit in BorrowController to 250,000 DOLA
5. Set Collateral Factor to 90%
6. Set Liquidation Factor to 100%
7. Set Liquidation Incentive to 5%
8. Approve DOLA/FRAXBP Yearn market on the DBR Helper
9. Set Minimum Debt Amount in BorrowController to 3,000 DOLA
10. Set stalenessThreshold for DOLA/FRAXBP Yearn market to 86460
11. Set FiRM Oracle price feed for DOLA/FRAXBP Yearn to the deployed DOLA/FRAXBP custom LP tokenPriceFeed contract
12. Add DOLA/FRAXBP Yearn Market to ALE
13. Add DOLA/FRAXBP Yearn Market to CurveDolaLPHelper
# Proposal to Unpause FiRM’s yvyCRV Market
Forum Link: https://forum.inverse.finance/t/proposal-to-unpause-firm-s-yvycrv-market/463/1
### Summary:
This proposal seeks to unpause the st-yCRV market, herein out referred to as yvyCRV market, on FiRM, Inverse Finance’s fixed-rate lending protocol. The yvyCRV market, along with CRV and cvxCRV markets, was previously paused due to events, namely significant [leverage built up](https://blog.yearn.fi/st-ycrv-ajna) and [exploits](https://rekt.news/uwulend-rekt/) affecting the Curve ecosystem, which led to an alteration of risk profile of the underlying asset. Following a [comprehensive risk assessment](https://docs.google.com/document/d/1leq51GdAQ9Mk7q6GKx_OO9dgN-ZzOtXi3pxFw94f1-Q/edit?usp=sharing) by the RWG, this proposal outlines the findings and supports the unpausing of the yvyCRV market with adjusted parameters to ensure the stability and security of our protocol.
### Background
yvyCRV, a tokenized version of staked Yearn CRV (yCRV), is one of Yearn Finance’s core products. The yvyCRV market on FiRM was initially launched as part of Inverse Finance's broader strategy to expand its collateral offerings and attract a diverse user base seeking fixed-rate lending solutions.
In August 2023, the yvyCRV market, along with the CRV and cvxCRV markets, was paused following a series of events that exposed vulnerabilities. The initial trigger was a set of exploits targeting Curve pools, specifically due to a bug in older versions of the Vyper compiler. These exploits significantly impacted the liquidity and stability of CRV, the underlying asset for both cvxCRV and yvyCRV. As a result, the RWG recommended pausing these markets to protect FiRM from potential cascading liquidations and to reassess the risks associated with these collateral types.
Since the market pause, the RWG has continuously monitored the liquidity conditions and concentration, user behavior, and potential risks associated with yvyCRV. The shallow liquidity raised concerns about the market’s stability. [An incident in December 2023](https://github.com/yearn/yearn-security/blob/master/disclosures/2023-12-11.md) highlighted this, when a faulty multisig script inadvertently sold a significant amount of Yearn-owned yCRV, reminding us of the potential for risks associated with operational errors and the importance of robust safeguards.
Despite these challenges, the demand for yvyCRV as a collateral asset remains strong, supported by Yearn's continued innovation and the ongoing utility of the token within the DeFi ecosystem. It wasn't until June, 2024, when a massive liquidation event occurred, that the RWG had a significant data point to re-evaluate the situation for both yvyCRV, as well as CRV, and cvxCRV. The latest [RWG’s assessment](https://docs.google.com/document/d/1leq51GdAQ9Mk7q6GKx_OO9dgN-ZzOtXi3pxFw94f1-Q/edit?usp=sharing) indicates that, with the appropriate risk parameters, the yvyCRV market can be safely reactivated, providing holders with renewed opportunities for fixed-rate lending on FiRM.
### Risk Assessment:
[Revised Risk Assessment of yvyCRV FiRM Markets (Sep '24)](https://docs.google.com/document/d/1leq51GdAQ9Mk7q6GKx_OO9dgN-ZzOtXi3pxFw94f1-Q/edit?usp=sharing)
Since the market’s initial deployment, changes have occurred with yCRV namely an upgrade which allows yvyCRV holders to choose between autocompounding their yields or earning rewards in ycrvUSD, a new rewards vault introduced by Yearn. The RWG, together with the PWG, has decided for the time being to forgo deploying a new market with integration of both staking options into a single escrow, and instead promote the unpausing of the current market which only supports the auto-compounding yvyCRV vault.
The RWG employed a robust risk assessment methodology, focusing on several key models and frameworks to evaluate the current risk profile of yvyCRV:
* Collateral Parameterization Model: This model analyzes the interaction between various market parameters, such as Supply Ceiling, Collateral Factor, Liquidation Factor, and Liquidation Incentive. It uses simulation data derived from price impacts on the underlying asset to ensure that the parameters set are optimal for market performance and risk management.
* Liquidation Factor Model: This model, powered by Tenderly simulations, determines cost-effectiveness in setting the liquidation factor by evaluating total gas expenditure by liquidators. This ensures that the liquidation processes are favorable for liquidators, thereby maintaining the health and stability of the market.
* Daily Borrow Limits Framework: The RWG uses this framework to extract and analyze data from the largest liquidity pools of yCRV. This approach helps set daily borrow limits that mitigate the risks of liquidity crises and market manipulation while ensuring the protocol’s resilience.
* Risk Observer Checklist: A weekly overview provided by the RWG includes key health indicators for FiRM, such as collateral integrity, DOLA health, and parameter modeling with price impact data. This proactive monitoring ensures that the protocol remains adaptable to evolving market conditions, and parameters can be adjusted as needed.
### Conclusion:
The RWG’s risk assessment provides a comprehensive analysis of the viability of reactivating the yvyCRV market on FiRM. The following settings are derived from detailed simulations and analyses. The focus on liquidation dynamics, considering both max liquidation impact and max profitable liquidation scenarios, confirms that the settings are favorable for liquidators even in adverse market conditions.
### On Chain Actions:
We recommend reactivating the yvyCRV market on FiRM with the following parameters:
Market Ceiling: 400,000 DOLA
Collateral Factor (CF): 48%
Liquidation Factor: 80%
Daily Borrow Limit: 50,000 DOLA
Liquidation Incentive: 12%
Liquidation Fee: 0%
We also approve the market for ALE integration, making use of the new yvyCRVHelper (action #6)
# Proposal to Add DOLA/FRAXpyUSD Convex LP Market to FiRM
Forum Link: https://forum.inverse.finance/t/proposal-to-add-dola-fraxpyusd-convex-lp-market-to-firm/474
### Summary
Following the early success of our [first LPT collateral market](https://www.inverse.finance/governance/proposals/mills/215), this proposal seeks to integrate the DOLA/FRAXpyUSD Liquidity Pool Token (LPT) from Curve Finance as a collateral asset on FiRM, Inverse Finance’s fixed-rate lending protocol. The DOLA/FRAXpyUSD LP offers unique advantages due to its stable composition, making it an excellent candidate for capital-efficient lending through stable liquidity positions that include DOLA as collateral.
We plan to deploy two distinct FRAXpyUSD/DOLA LP markets; one that adheres to the convex strategy and the market which, utilizing the same underlying LPT, aligns with Yearn’s autocompound strategy. The two markets will help us gauge demand for each strategy and potentially help prioritize future LP market deployments. This proposal pertains to the Convex-aligned DOLA/FRAXpyUSD LP market on FiRM.
This integration will not only provide users with a new exotic collateral option but also strengthen the overall stability and utility of FiRM. The DOLA/FRAXpyUSD LP is uniquely positioned to offer low-slippage, stable swaps, and its addition as collateral will further solidify Inverse’s partnership with Curve, Frax, and the pyUSD ecosystem, as well as FiRM’s reputation as a leading platform for innovative and reliable DeFi solutions.
### Background
The DOLA/FRAXpyUSD LP, hosted on Curve Finance, represents a strategic collaboration between Inverse Finance, Frax Finance, and the pyUSD ecosystem; enabling efficient, low-slippage trading between DOLA, FRAX, and pyUSD, while offering liquidity providers the opportunity to earn competitive yields. As of September 19, 2024, the pool holds $11.7MM TVL, 7MM of which is being provided by Inverse Finance’s FRAXpyUSD Fed. The FRAXpyUSD Fed, [deployed in April 2024](https://www.inverse.finance/governance/proposals/mills/180), has played a key role in stabilizing the DOLA peg.
Both FRAX, through the [approval of the sFRAX market](https://www.inverse.finance/governance/proposals/mills/191), and pyUSD, through the approval of the FRAXpyUSD Fed, had been thoroughly assessed by Inverse Finance's RWG prior to this latest proposal.
When FiRM borrowers leverage up their LP positions using ALE, single-sided DOLA is pumped into the liquidity pool via the flashminter, creating an arbitrage opportunity due to the pool imbalance. The 200 A Parameter of the Curve pool allows the pool to level off as FRAX and/or pyUSD is added by arbitragers. This approach enhances DOLA liquidity without removing other stablecoins from the pool. As a result, lending capital efficiency is significantly improved. For example, typically for every 1 DOLA lent out and sold, the [AMM Feds](https://docs.inverse.finance/inverse-finance/inverse-finance/product-guide/dola-feds) need to contract 2.5 DOLAs to counteract the impact on liquidity. In contrast, when 1 DOLA is lent out and added to a DOLA liquidity position, only 1 DOLA needs to be contracted, resulting in a 150% increase in lending capital efficiency.
### Risk Assessment
[Complete Risk Assessment - DOLA/FRAXpyUSD LP Collateral on FiRM](https://docs.google.com/document/d/1lZClX_phiIS0oO51YJx5jLAwNmyzq9EtHJ3cmJWUqAA/edit?usp=sharing)
The RWG conducted a risk assessment (linked above) which explored the integration of the DOLA/FRAXpyUSD LPT as collateral on FiRM. This assessment combines both quantitative and qualitative analysis, covering governance, security, liquidity, and competitive factors, and considering the unique characteristics of FRAXpyUSD, the DOLA/FRAXpyUSD LP, and the broader market context. These are summarized below:
1. Governance: Frax Finance operates under an increasingly-decentralized governance model, controlled by veFXS token holders who vote on protocol parameters and integrations through on-chain mechanisms. This governance structure has proven resilient, with multiple risk management tools and a strong track record in handling liquidity, market changes, and external integrations. pyUSD, on the other hand, is issued by Paxos, a fully regulated entity overseen by the NYDFS. Paxos ensures that pyUSD is fully backed by reserves held in cash and U.S. Treasuries, providing a high level of security and reliability. Paxos operates under a fully centralized paradigm, but its strict regulatory compliance and reserve transparency ensure that pyUSD remains stable and trustworthy.
2. Security: Security is paramount for both Frax Finance and Paxos. Frax Finance has undergone multiple independent security audits by reputable firms such as Trail of Bits, and it also runs one of the largest bug bounty programs in DeFi, offering significant rewards for any vulnerabilities found. Paxos conducts regular internal audits and reserve attestations, ensuring the security of its assets. Paxos also maintains rigorous operational oversight to prevent unauthorized minting or freezing of pyUSD. At the same time, the Curve-related smart contracts governing the DOLA/FRAXpyUSD LP have been rigorously tested and are subject to ongoing security reviews and bug bounty programs. Overall, despite these measures, the LPT and the FRAXpyUSD component of the LP carries inherent risks users must be aware of.
3. Regulatory Risks: As with any stablecoin, regulatory scrutiny is a significant consideration. DOLA, FRAX and pyUSD are subject to global regulatory scrutiny, especially regarding stablecoin issuance and trading. While Paxos, as a regulated entity, is aligned with current regulations, any changes could affect pyUSD’s viability. At the same time, while Frax’s increasing integration with RWAs could attract more regulatory attention in the future.
4. Collateral & Liquidity: The DOLA/FRAXpyUSD LP is backed by three robust stablecoins, each offering deep on-chain liquidity or, in the case of pyUSD, a reliable redemption mechanism. As of September 19, 2024, the LP holds $11.7MM in TVL, with Inverse Finance’s FRAXpyUSD Fed contributing $7MM. On-chain liquidity for FRAX is particularly strong, with the stablecoin integrated into multiple DeFi protocols, ensuring its ability to maintain peg stability across markets. Additionally, pyUSD’s full backing by U.S. Treasuries and cash ensures high liquidity, making the LP well-suited for use as collateral.
5. Competitive Edge: The integration of DOLA/FRAXpyUSD LP as a collateral option on FiRM distinguishes it from competitors. While other platforms like FraxLend have introduced liquidity pool tokens as collateral, FiRM offers distinct advantages, including a fixed interest rate of unlimited duration and the ability to leverage up/down through ALE. This stable pair LP is not currently available on other lending platforms.
6. Oracle and Price Feed Considerations: FiRM will implement a pessimistic LP token oracle for accurate valuation of the DOLA/FRAXpyUSD LP. This process uses Chainlink price feeds for both FRAX and pyUSD and the virtual price from the Curve pool’s smart contract. First, the Chainlink price feed is pulled for FRAXpyUSD to get its USD value. Then, the lowest price between DOLA (fixed at $1), FRAX and pyUSD is selected. The LP token value is calculated by multiplying this lowest price by the virtual price from the Curve pool's smart contract. Since we assume DOLA price to be $1 always in FiRM, essentially we use the lower between FRAX and pyUSD price * virtual_price when either FRAX or pyUSD USD price is under 1, and when it is over 1 we just use the virtual_price, ensuring a conservative and reliable estimate of the LP token's USD value. Real-time monitoring will further support price accuracy and integrity.
7. Liquidation Mechanisms: The liquidation factor and incentive are optimized to encourage active liquidator participation. Arbitrage opportunities with other DOLA, FRAX and/or pyUSD LPs will ensure that large liquidations do not lead to a liquidation cascade. The liquidation process will pull vault tokens, convert them to LP tokens, and then allow liquidators to realize value through balanced withdrawals, ensuring efficient liquidation routes.
The DeFi landscape is dynamic, and the RWG is committed to continuous monitoring of the DOLA/FRAXpyUSD LP’s performance as collateral. Regular updates to risk models, market parameters, and liquidity metrics will be made to study any changing conditions. This proactive approach will ensure that FiRM remains a resilient and adaptable platform, capable of managing new risks as they emerge.
### On-Chain Actions
1. Add DOLA/FRAXpyUSD LP Convex Market to DBR contract
2. Set borrowController of Market to FiRM BorrowController
3. Set market supply ceiling to 10,000,000 DOLA
4. Set daily limit in BorrowController to 250,000 DOLA
5. Set Collateral Factor to 90%
6. Set Liquidation Factor to 100%
7. Set Liquidation Incentive to 5%
8. Approve DOLA/FRAXpyUSD LP Convex market on the DBR Helper
9. Set Minimum Debt Amount in BorrowController to 3,000 DOLA
10. Set stalenessThreshold for DOLA/FRAXpyUSD Convex LP market to 86460
11. Set FiRM Oracle price feed for DOLA/FRAXpyUSD Convex LP to the deployed DOLA/FRAXpyUSD custom LP tokenPriceFeed contract
12. Add DOLA/FRAXpyUSD LP Convex Market to ALE
13. Add DOLA/FRAXpyUSD LP Convex Market to CurveDolaLPHelper
# Risk Working Group Liquidator Grant Program
Forum Link: https://forum.inverse.finance/t/proposal-to-launch-liquidator-grant-program/465
**Problem Summary**
FiRM offers exotic collateral types such as illiquid tokens, niche DeFi derivatives, and real-world assets (RWAs) that may not be monitored by traditional liquidators. These assets pose risks of delayed liquidation due to their illiquidity or lack of clear liquidation routes.
**Objective**
The Liquidator Grant Program aims to:
* Attract liquidators to monitor and liquidate exotic collateral markets.
* Establish direct communication with liquidators for ongoing engagement and updates.
---
### **Strategic Benefits**
**Feedback Loop for Market Health**
By engaging liquidators, we can gather feedback on asset volatility, liquidity issues, and suggest improvements to the liquidation process. Liquidators will help us adjust collateral parameters and optimize liquidation strategies.
**Strengthening Liquidator Commitment**
Building a liquidator network promotes long-term engagement and efficiency, ensuring the health of exotic collateral markets.
**Mitigating Risk in Illiquid Markets**
Exotic collaterals are riskier. Incentivizing liquidators to monitor them closely reduces the chance of liquidity crises or sudden price drops.
---
### **Program Rollout**
**Manual Liquidation Proof Submission**
Liquidators submit proof of successful liquidations via our website, including transaction details.
The team will verify liquidations, ensuring they meet program criteria, and rewards will be distributed to liquidators’ wallets on-chain.
**Direct Communication with Liquidators**
We will establish channels (e.g., Telegram/Discord) for liquidators to ask questions, give feedback, and stay updated on new collateral types and liquidation processes.
---
### **Incentive Structure**
**Reward Program**
Liquidators will receive DBR tokens for their first unique liquidation in an eligible market, up to $250. Exotic or harder-to-monitor collaterals will offer higher rewards (up to $500), encouraging liquidators to prioritize these assets. The RWG will maintain an open dashboard of eligible markets and the first 3 liquidators of a market will be rewarded. The RWG also reserves the right to veto suspicious submissions.
---
### **KPIs and Objectives**
The program aims to onboard 20 new liquidators, increasing unique liquidator participation by ~50%.
---
### **On-Chain Actions**
Grant the RWG Multisig an allowance of 120,000 DBR (equivalent to ~$5000 at Sep 23rd, 2024 prices) to fund the Liquidator Grant Program.
# Proposal to add cbBTC Market to FiRM
Forum Link: https://forum.inverse.finance/t/proposal-to-add-cbbtc-market-to-firm/468
### Summary
This proposal seeks to integrate cbBTC as a collateral asset on FiRM, Inverse Finance’s fixed-rate lending protocol. cbBTC, launched by Coinbase as a wrapped Bitcoin asset, offers users the ability to leverage their Bitcoin holdings within DeFi ecosystems, with its backing by 1:1 native Bitcoin held in Coinbase’s cold storage. By adding cbBTC to FiRM, users will be able to borrow DOLA against their Bitcoin holdings, enhancing FiRM’s offerings and expanding collateral options within the platform.
### Background
Coinbase launched cbBTC on September 12th, 2024, introducing a wrapped Bitcoin asset to enable DeFi participation for Bitcoin holders. As a custodied asset, cbBTC is managed and issued solely by Coinbase smart contracts, with each token fully backed by Bitcoin held in Coinbase’s cold storage. cbBTC has been designed to interact seamlessly with DeFi applications, providing an easy entry point for Coinbase users to participate in on-chain DeFi activities.
cbBTC is entering the wrapped Bitcoin market, which is currently dominated by WBTC. While WBTC maintains a strong foothold across multiple DeFi protocols with billions of dollars in TVL, cbBTC’s introduction by Coinbase offers a compelling alternative backed by one of the most reputable centralized exchanges. This competition is expected to drive diversification in the wrapped Bitcoin space, benefiting the DeFi ecosystem as a whole.
The first cbBTC liquidity pools have already been set up on UniswapV3 and Curve, and an upcoming integration on Aave V3 is already in the works. These partnerships are expected to expand the asset’s adoption across DeFi protocols. Although cbBTC offers the benefit of utilizing Bitcoin on-chain, its centralized nature introduces counterparty risks, specifically due to the reliance on Coinbase as the sole custodian. However, Coinbase’s strong regulatory compliance and reputation mitigate some of these concerns.
### Risk Assessment
[Complete Risk Assessment - cbBTC Collateral on FiRM](https://docs.google.com/document/d/15TQvZgyPKzEugsUtVBfWLrqkH3CYCsjFyJBJyj6UgPQ/edit?usp=sharing)
A detailed risk assessment of cbBTC (linked above) was conducted by the RWG, and the key considerations include:
* Centralization and Custodial Risks: cbBTC is a custodial asset, with Coinbase retaining control over minting, burning, and contract management. This introduces significant dependency on Coinbase's operations and regulatory standing. The absence of a Proof of Reserves adds a significant element of trust reliance that increases custodial risk.
* Governance and Administrative Control: cbBTC lacks decentralization in its governance, as Coinbase retains the ability to upgrade contracts, blacklist addresses, and pause operations. The presence of these admin roles raises concerns about the centralized control over collateral operations.
* Liquidity: cbBTC’s liquidity is still in its early stages, with liquidity pools on UniswapV3 and Curve amounting to approximately $77.5M. Liquidators can also redeem cbBTC for native Bitcoin through Coinbase. While geoblocking may introduce some friction compared to on-chain liquidations, time delays are less likely given cbBTC allows any user with a Coinbase account outside restricted regions to mint/redeem. This broader access should attract automated arbitrage participants, helping to maintain a tight peg to BTC.
* Competition: cbBTC is set to compete against other wrapped Bitcoin assets, most notably WBTC. Aave’s upcoming integration of cbBTC will provide additional supply and borrow markets, though its early liquidity limits the asset’s capacity to challenge WBTC immediately.
* Security: cbETH contracts have undergone audits by OpenZeppelin, and “no material contract code has been modified [from cbETH] in deploying cbBTC’. Coinbase’s strong security measures, such as Multi-Party Computation (MPC) for wallet security, further reduce smart contract risk. cbBTC is covered under Coinbase’s bug bounty program.
### On-Chain Actions
1. Add cbBTC Market to DBR contract.
2. Set borrowController of the Market to FiRM BorrowController.
3. Set market supply ceiling to 10,000,000 DOLA.
4. Set daily limit in BorrowController to 1,000,000 DOLA.
5. Set Collateral Factor to 80%.
6. Set Liquidation Factor to 50%.
7. Set Liquidation Incentive to 10%.
8. Approve cbBTC market on the DBR Helper.
9. Set Minimum Debt Amount in BorrowController to 3000 DOLA.
10. Set stalenessThreshold for cbBTC market to 86460.
11. Set FiRM Oracle price feed for cbBTC to the deployed Chainlink cbBTC/USD PriceFeed contract.
12. Add cbBTC Market to ALE.
# Proposal to Add DOLA/crvUSD Yearn LP Market to FiRM
Forum Link: https://forum.inverse.finance/t/proposal-to-add-dola-crvusd-yearn-lp-market-to-firm/456
### Summary
This proposal seeks to integrate the DOLA/crvUSD Liquidity Pool Token (LPT) from Curve Finance as a collateral asset on FiRM, Inverse Finance’s fixed-rate lending protocol. The DOLA/crvUSD LP offers unique advantages due to its stable composition, providing a unique opportunity for capital efficient lending by offering stable liquidity positions that include DOLA as collateral.
We plan to deploy two distinct crvUSD/DOLA LP markets; one that adheres to the convex strategy and the market which, utilizing the same underlying LPT, aligns with Yearn’s autocompound strategy. The two markets will help us gauge demand for each strategy and potentially help prioritize future LP market deployments. This proposal pertains to the Yearn-aligned crvUSD/DOLA LP market on FiRM.
This integration will not only provide users with a new exotic collateral option but also strengthen the overall stability and utility of FiRM. The DOLA/crvUSD LP is uniquely positioned to offer low-slippage, stable swaps, and its addition as collateral will further solidify Inverse’s partnership with Curve, as well as FiRM’s reputation as a leading platform for innovative and reliable DeFi solutions.
### Background
crvUSD is a decentralized stablecoin native to the Curve Finance ecosystem, designed to maintain its peg to the US dollar through several stabilization mechanisms. These include Peg Keepers, oracles, and a dynamic monetary policy. The Peg Keeper contracts actively monitor the price of crvUSD in liquidity pools, minting or burning tokens as needed to keep the price near $1. The protocol's monetary policy adjusts interest rates on crvUSD loans to influence supply and demand, further supporting the peg. This system, combined with the ability to earn rewards by providing liquidity to Curve pools, makes crvUSD an attractive stablecoin with built-in risk management features like soft liquidations and oracle manipulation prevention. Furthermore, these innovations are supported by Curve DAO's transparent governance, ensuring crvUSD remains a robust and reliable stablecoin in the evolving DeFi landscape.
The DOLA/crvUSD LP on Curve Finance represents a pivotal integration between Inverse and Curve Finance; facilitating efficient, low-slippage swaps between DOLA and crvUSD, rewarding liquidity providers who stake their assets in the LP, and, with this proposal, providing users with a new way to leverage their liquidity positions without needing to sell their LP tokens. As of September 5th, 2024, the LP holds $1.2MM in TVL.
When FiRM borrowers leverage up their LP positions using ALE, single-sided DOLA is pumped into the liquidity pool via the flashminter, creating an arbitrage opportunity due to the pool imbalance. The 200 A Parameter of the Curve pool allows the pool to level off as crvUSD is added by arbitragers. This approach enhances DOLA liquidity without removing other stablecoins from the pool. As a result, lending capital efficiency is significantly improved. For example, typically for every 1 DOLA lent out and sold, the [AMM Feds](https://docs.inverse.finance/inverse-finance/inverse-finance/product-guide/dola-feds) need to contract 2.5 DOLAs to counteract the impact on liquidity. In contrast, when 1 DOLA is lent out and added to a DOLA liquidity position, only 1 DOLA needs to be contracted, resulting in a 150% increase in lending capital efficiency.
### Risk Assessment
[Complete Risk Assessment - DOLA/crvUSD LP Collateral on FiRM](https://docs.google.com/document/d/1IfBc7TFIHrpaKV5gSCHV_YB_rRwiygp81r7cI4h179M/preview#heading=h.oni9x89fborj)
The RWG conducted a risk assessment, which explores the integration of the DOLA/crvUSD LPT as collateral on FiRM. This assessment combines both quantitative and qualitative analysis, summarized below, considering the unique characteristics of crvUSD, the DOLA/crvUSD LP, and the broader market context.
1. Governance: Curve Finance is governed by the Curve DAO, with decisions made by veCRV token holders. While the DAO ensures decentralized governance, an emergency multisig can temporarily pause pools and liquidity gauges if necessary.
2. Security: Curve has a strong security track record, underpinned by multiple audits conducted by reputable firms. The smart contracts governing the DOLA/crvUSD LP have been rigorously tested and are subject to ongoing security reviews. Additionally, Curve maintains an active bug bounty program, incentivizing the identification and reporting of vulnerabilities. The Peg Keeper mechanisms that support crvUSD are designed to mitigate risks associated with liquidation and price stability. Despite these measures, the crvUSD component of the LP carries inherent risks associated with its algorithmic stabilization, particularly during extreme market volatility.
3. Regulatory Risks: As with any stablecoin, regulatory scrutiny is a significant consideration. Both DOLA and crvUSD are subject to global regulatory scrutiny, especially regarding stablecoin issuance and trading. While Curve is aligned with current regulations, any changes could affect its viability, particularly concerning its reliance on stablecoins like USDC, USDT, and USDe.
4. Collateral & Liquidity: The DOLA/crvUSD LP demonstrates limited liquidity, normally a crucial factor for its use as collateral. However, the market’s design is such that crvUSD liquidity is what’s pertinent to the collateral’s viability as well as parameter setting. Our analysis of crvUSD liquidity demonstrates that it is both deep and decentralized. A snapshot from August shows that the total TVL for crvUSD liquidity pools was $33.27 million, with the top 10 addresses holding just 36.68% of the total, and 22 unique addresses making up 50% of the pool. Additionally, there were 89 addresses holding more than $100,000 and 150 addresses above $10,000, highlighting the broad distribution of liquidity across a large number of participants. Furthermore, crvUSD DEX liquidity and peg stability is supported by the crvUSD markets totalling $71.4M debt / backstop support, protecting against downward peg movement. Continuous monitoring of the pool’s TVL and performance will be necessary to mitigate risks tied to market operations.
5. Competitive Edge: The integration of DOLA/crvUSD LP as a collateral option on FiRM distinguishes it from competitors. While other platforms like FraxLend have introduced liquidity pool tokens as collateral, FiRM offers distinct advantages, including a fixed interest rate of unlimited duration and the ability to leverage up/down through ALE. This stable pair LP is not currently available on other lending platforms.
6. Oracle and Price Feed Considerations: FiRM will implement a pessimistic LP token oracle for accurate valuation of the DOLA/crvUSD LP. This process uses Chainlink price feeds for crvUSD and the virtual price from the Curve pool’s smart contract. First, the Chainlink price feed is pulled for crvUSD to get its USD value. Then, the lowest price between DOLA (fixed at $1) and crvUSD is selected. The LP token value is calculated by multiplying this lowest price by the virtual price from the Curve pool's smart contract. Since we assume DOLA price to be $1 always in FiRM, essentially we use crvUSD price * virtual_price when crvUSD USD price is under 1, and when it is over 1 we just use the virtual_price, ensuring a conservative and reliable estimate of the LP token's USD value. Real-time monitoring will further support price accuracy and integrity.
7. Liquidation Mechanisms: The liquidation factor and incentive are optimized to encourage active liquidator participation. Arbitrage opportunities with other DOLA or crvUSD LPs will ensure that large liquidations do not lead to a liquidation cascade. The liquidation process will pull vault tokens, convert them to LP tokens, and then allow liquidators to realize value through balanced withdrawals, ensuring efficient liquidation routes.
The DeFi landscape is dynamic, and the RWG is committed to continuous monitoring of the DOLA/crvUSD LP’s performance as collateral. Regular updates to risk models, market parameters, and liquidity metrics will be made to study any changing conditions. This proactive approach will ensure that FiRM remains a resilient and adaptable platform, capable of managing new risks as they emerge.
### On-Chain Actions
1. Add DOLA/crvUSD LP Yearn Market to DBR contract
2. Set borrowController of Market to FiRM BorrowController
3. Set market supply ceiling to 10,000,000 DOLA
4. Set daily limit in BorrowController to 250,000 DOLA
5. Set Collateral Factor to 90%
6. Set Liquidation Factor to 100%
7. Set Liquidation Incentive to 5%
8. Approve DOLA/crvUSD LP Yearn market on the DBR Helper
9. Set Minimum Debt Amount in BorrowController to 3,000 DOLA
10. Set stalenessThreshold for DOLA/crvUSD Yearn LP market to 86400
11. Set FiRM Oracle price feed for DOLA/crvUSD Yearn LP to the deployed DOLA/crvUSD custom LP tokenPriceFeed contract
12. Add DOLA/crvUSD LP Yearn Market to ALE
13. Add DOLA/crvUSD LP Yearn Market to CurveDolaLPHelper
addMinter(address)setMarket(address,address,address,bool)# Proposal to Update ALE and FlashMinter
Forum link: https://forum.inverse.finance/t/proposal-to-update-ale-and-flashminter/457
## Summary
This proposal seeks to update the current ALE and FlashMinter contracts.
A new ALE without minting rights which will use the new flash minter for leveraging and deleveraging operations. The new ALE also allows to optionally use or not the exchange proxy (currently 1Inch V6) depending on each Market supported by FiRM.
A new Flash minter with Zero fee and a custom max flash loan amount managed by governance.
This will allow the new ALE to support markets which don’t require the exchange proxy and reduce risk by removing the ALE minting rights while the flash minter will have a limited amount that can be flashloaned.
A flash loan limit set to 5M should easily cover all liquidations and arbitrage opportunities using DOLA considering the current size of Ethereum DOLA liquidity.
## Background
The current ALE has minting rights and a virtually unlimited amount that can be flashloaned while performing leveraging and deleveraging operations. To limit exposure to this factor and remove minting rights from the contract we planned to use the flash minter.
In addition to that, some new markets like the Curve Dola LPs, cannot be bought via 1Inch proxy but require a conversion by adding 1 side liquidity via Dola.
In order to achieve this we added the option to use or not the exchange proxy and this configuration is per market and controlled by the DAO.
The current Flash Minter has a very high flash loan limit and a small fee. For using it with the new ALE we would need to adjust the fee to zero but it would introduce a risk because of the high amount available to be flashloaned without any fee mitigating a potential issue.
The new Flash minter has a custom max flash loan limit adjustable by the DAO and zero fee.
## Contracts
New ALE:
https://etherscan.io/address/0x5233f4C2515ae21B540c438862Abb5603506dEBC
New FlashMinter:
https://etherscan.io/address/0x6C5Fdc0c53b122Ae0f15a863C349f3A481DE8f1F
## On-Chain Actions
1 - Remove minting rights from the Current ALE
2 - Remove minting rights from the Current FlashMinter
3 - Remove current ALE from borrow controller
4 - Allow new ALE on borrow controller
5 - Add minting rights to the new FlashMinter
6 - Set max flash loan limit to 5M
7- 18 - Set markets config from the current ALE into the new one
7 - INV
8 - WETH
9 - DAI
10 - CRV
11 - cvxCRV
12 - wstETH
13 - WBTC
14 - sFRAX
15 - st-yETH
16 - COMP
17 - sUSDe
18 - CVX
# Proposal to Increase Daily Borrow Limits for DAI, sFRAX, and sUSDe Markets
Forum Link: https://forum.inverse.finance/t/proposal-to-increase-daily-borrow-limits-for-dai-sfrax-and-susde-markets/454/1
### Summary
This proposal seeks to increase the daily borrow limits for FiRM’s DAI, sFRAX, and sUSDe markets.
### Background
As part of our ongoing strategy to enhance FiRM's lending platform and accommodate increasing user demand, the RWG regularly evaluates market parameters such as daily borrow limits, supply ceilings, and liquidation factors. These evaluations are aimed at ensuring a balance between growth, user accessibility, and the stability of the platform.
The current daily borrow limits for the DAI, sFRAX, and sUSDe markets aren’t favorable for efficient rate arbitrage via looping. This limitation hinders users from fully leveraging opportunities to optimize their borrowing and lending strategies on FiRM. To address this and enhance FiRM's competitiveness, it is necessary to increase the daily borrow limits for these markets.
As of August 21st, 2024:
* The DAI market has $2.79MM in TVL and $2.42MM in borrows, with an average borrow limit of 96.13% and 9 borrowers. This indicates high utilization and suggests that users are comfortable positioning close to the boundaries of the current borrow limit.
* The sFRAX market has $1.95MM in TVL and $820k in borrows, with an average borrow limit of 58.39%, signaling slightly more conservative positions compared to DAI (though one user is currently in the process of building out his position, limited by the daily borrow limit), and 6 borrowers. This suggests growing interest, but with room for more aggressive borrowing, especially considering the higher APY (7.1% vs sDAI’s 6%).
* The sUSDe market has yet to see its first position opened, indicating underutilization that could be addressed by offering more attractive borrowing conditions. A forthcoming integration with Ethena’s SATs program will see a 5x points multiplier added to this market.
### Risk Assessment
DAI, sFRAX, and sUSDe are all well-established stablecoins with significant liquidity and adoption across the DeFi ecosystem. Their use as collateral in FiRM is supported by robust market data and deep liquidity pools, making them relatively low-risk assets for lending activities.
sUSDe carries some unique risks due to its redemption mechanism, which has a 7-day lockup period and unlike sDAI and sFRAX where redemptions are instant. For FiRM, this situation poses a risk if the price of sUSDe drops rapidly and outpaces our liquidators' ability to complete necessary liquidations, perhaps caused by a significant loss in the backing of USDe where the full extent is not immediately known. In such a case, the market could become highly speculative about the true value of USDe, potentially leading to a large disconnect between sUSDe and USDe. However, FiRM is better positioned than most other protocols because we use a Chainlink price feed specifically for sUSDe, unlike others which hardcode USDe to $1.00 and rely on the on-chain exchange rate to sUSDe. This advantage means that in a severe market dislocation, FiRM would likely be first in line to execute liquidations, potentially allowing us to exit positions before the full extent of the price drop materializes, thereby mitigating risk.
Given the strong liquidity profiles of these stablecoins, increasing the daily borrow limits is a prudent step that aligns with user demand while maintaining a manageable risk level for the protocol. By increasing the daily borrow limits, FiRM can better accommodate larger borrowing needs and reduce friction for users seeking to leverage these stablecoins. This adjustment also positions FiRM more competitively against other lending platforms that may offer higher borrowing capacities. Additionally, it enables more efficient rate arbitrage via looping, which can attract sophisticated users and increase overall platform utilization.
Importantly, these proposed increases are supported by the findings from our latest simulations and analyses, which take into account the liquidity profiles of DAI, sFRAX, and sUSDe and show no increased risk to the protocol. The adjustments are designed to maintain the health of the protocol while offering users greater flexibility in their borrowing activities.
### Parameter Recommendations
The RWG recommends increasing the daily borrow limits for the following markets:
* DAI market: Increase from 500,000 DOLA to 2,000,000 DOLA.
* sFRAX market: Increase from 500,000 DOLA to 2,000,000 DOLA.
* sUSDe market: Increase from 250,000 DOLA to 1,000,000 DOLA.
The collateral factors, liquidation factors, liquidation incentives, and minimum debt amounts for these markets are recommended to remain unchanged, as they have proven effective in managing risks and maintaining market equilibrium.
The increase in daily borrow limits will allow for larger borrow volumes, making FiRM a more attractive option for users looking to leverage these stablecoins and engage in efficient rate arbitrage.
# Proposal to Revise Liquidation Factor for Live FiRM Markets
Forum Link: https://forum.inverse.finance/t/proposal-to-revise-liquidation-factor-for-live-firm-markets/444
#### Summary
This proposal aims to adjust the Liquidation Factor settings for various collaterals in FiRM, Inverse Finance's fixed-rate lending protocol. These adjustments are designed to enhance the protocol's resilience and ensure economically viable liquidations under heightened network congestion scenarios. During the latest stress test, despite the very high gas environments, FiRM processed liquidations successfully and incurred no bad debt, demonstrating the protocol's robustness and effective risk management.
#### Background
FiRM’s operational stability and risk mitigation depend significantly on the accurate calibration of collateral parameterization. Borrow positions are created when users borrow assets against their collateral, and these positions must remain liquidatable to protect the interests of both borrowers and lenders. With regards to the Liquidation Factor and Minimum Debt parameters, these are crucial for managing the protocol's exposure to market volatility and ensuring that the liquidation system is both responsive and equitable. As a reminder, the Liquidation Factor determines the maximum amount of debt a liquidator can repay in a single liquidation transaction. The revisions are based on a recalibration of our existing framework following the recent August 4th stress test, which made apparent the need to model for a 600 gwei gas base case.
#### Methodology
Following the methodology used in previous [analyses](https://www.inverse.finance/blog/posts/en-US/firms-new-guard-minimum-debt-amounts), the RWG has revised the Liquidation Factor modeling to accommodate a 600 gwei gas price base case. This adjustment ensures that liquidations remain feasible and economically rational for liquidators even during periods of heightened network congestion.
The first step in determining the optimal Liquidation Factor for each FiRM market is to estimate the total gas incurred by a liquidator following a three step process;
Acquire DOLA starting with ETH,
Perform the liquidation,
Sell the liquidated asset for ETH.
To collect gas spent for steps one and three, the RWG makes use of Tenderly to simulate swaps on Uniswap or Curve, where appropriate. For step two, liquidations are simulated in forked environments designed to mirror current FiRM borrowers. These three values are then summed, resulting in Tot Gas Used. Each market has an associated Tot Gas Used value unique to the underlying collateral. These are then converted to a Cost of Liquidation, measured in USD, assuming a price of ETH and gas price (in GWEI) that reflects the market conditions at the time of the analysis.
In the latest revision analysis, we utilized ETH price of $3000 and a gas price of 600 gwei. In the past, these were carried out using an ETH price of $3500 and a gas price of 300 GWEI and even before that, an ETH price of $2000 and gas price of 60 GWEI. The revision to the ETH price parameter reflects the current market valuation of ETH. On the other hand, the choice of setting the gas price at 600 GWEI is a direct result of observations made during the latest August 4th stress test and is designed to prepare the protocol for extreme scenarios. It aims to ensure that liquidations remain feasible and economically rational for liquidators even during periods of heightened and prolonged network congestion —a scenario not uncommon when volatility picks up in the crypto markets.
Finally, minimum viable Liquidation Factor for each market is derived from Cost of Liquidation, market Minimum Debt and Liquidation Incentives, and the ETH and Gas price assumptions mentioned above. A safety buffer is added to this value, resulting in our final recommendation for this parameter.
#### Findings and Recommendations
The table below summarizes the recommended adjustments to the Liquidation Factors for various FiRM markets, considering a gas price of 600 gwei and an ETH price of $3000. The RWG recommends changes to the liquidation factor of the INV market be adjusted upwards but not to the full extent the model recommends, and that this be postponed until INV has deeper on-chain liquidity. The recommended changes are designed to have no adverse impact on the protocol's ability to conduct profitable liquidations or increase the risk of liquidation cascades, as per the findings from the FiRM [collateral parameter modeling](https://forum.inverse.finance/t/behind-the-scenes-collateral-parameterization/376).
|Market|Recommended Liquidation Factor (%)|Current Liquidation Factor (%)|Δ from Current Setting (%)|
| --- | --- | --- | --- |
|wETH|40.0%|31.0%|9.0%|
|wstETH|60.0%|41.0%|19.0%|
|CRV|60.0%|20.0%|40.0%|
|cvxCRV|80.0%|32.0%|48.0%|
|st-yCRV|70.0%|32.0%|38.0%|
|DAI|70.0%|47.0%|23.0%|
|CVX|60.0%|41.0%|19.0%|
|wBTC|60.0%|41.0%|19.0%|
|st-yETH|70.0%|48.0%|22.0%|
|sFRAX|70.0%|50.0%|20.0%|
|COMP|60.0%|41.0%|19.0%|
|INV|50.0%|35.0%|15.0%|
#### Conclusion
The RWG's latest analysis underscores the necessity of these adjustments to maintain FiRM's operational stability and economic viability of liquidations. By implementing these changes, Inverse Finance will ensure that liquidations can continue to be conducted profitably even under extreme gas price scenarios, thereby protecting the protocol and its users.
#### On-Chain Actions:
* Update the Liquidation Factor for each market as per the recommended values in the table above.