# Chain and Wrapper Event Policy **Version 0.2 DRAFT · 29 September 2026 · ETP Foundry (formerly CrossDesk)** > **Governing text.** [ETP Foundry Methodology v1.0](/documents/methodology-v1.0.md) (28 September > 2026) is the sole governing methodology. This policy applies it to chain and wrapper events; > where the two differ, Methodology v1.0 governs. It supersedes > [version 0.1](/documents/chain-event-policy-v0.1.md), which stays published, marked superseded. > Applies to every benchmark in the ETP Foundry Canton Series. Nothing here is in force > until the first value published above tier 0. **Three words, one meaning each** (Methodology §3A.7): - **`NO FIXING`**: no value is published for the strike, with the reason. A gap is published as a gap. - **`EXCEPTIONAL`**: a move of more than Y (10%) against the previous value, **published** and flagged. It has no other meaning in this policy. - **`EVENT-`** (for example `EVENT-FORK`, `EVENT-DEPEG`): a flag that a chain or wrapper event is in progress for the asset. It is shown on every value published while it holds. CF Benchmarks publishes a Hard Fork Policy because chain events break single-asset benchmarks and the rules must exist *before* the event, not be invented during it. Our assets are **wrapped and represented** — cBTC, cETH, tokenised equities — so we face the fork case **plus** four failure modes CF does not: reserve shortfall, registrar failure, registry migration, and a de-peg of the representation from its underlying. **[FIXED] The governing principle:** during a chain or wrapper event, **the correct output is usually `NO FIXING`, not a brave guess.** An administrator that keeps printing through an event it does not understand is the administrator that gets blamed for it. --- ## 1. Hard fork of an underlying chain ### 1.1 Definition A hard fork event has occurred if **all three** hold (CF's definition, adopted): 1. two or more diverging blockchains exist post-fork sharing the same pre-fork chain, 2. the tokens on the post-fork chains are **non-fungible across chains**, and 3. the respective chains are actively validated such that transactions process at reasonable speed. ### 1.2 Significance test [ADOPT] A new token is **significant** if it meets **all** of the following on **at least 2 of the first 7 days** after the fork (CF's test, adopted unchanged — it is proven and the burden of proof sits in the right place): 1. The new token pair trades on **at least 2 constituent venues**. 2. There are **at least 100 trades** in the new pair across all constituent venues. 3. The new pair trades at **≥10%** of the combined price of the original and new pairs. 4. The new pair's volume is **≥10%** of the combined volume of the original and new pairs. **If significant:** we initiate calculation of a benchmark for the new token pair, and the original benchmark continues to track the original token. **If not significant:** no new benchmark. Starting one anyway is at the administrator's discretion and requires committee approval. ### 1.3 During the fork window [ADOPT] - From the fork block until the significance test resolves (max 7 days), any value published for the affected asset carries the flag `EVENT-FORK`. It is published only if it passes every gate of Methodology §6.2 and reaches K of N; otherwise `NO FIXING`. - If venues disagree on which chain carries the original ticker, the asset moves to `NO FIXING` until at least two constituent venues agree on the symbol. - **The administrator does not decide which chain is "real."** The constituent venues' symbol assignment decides it. We follow the market; we do not lead it. --- ## 2. Wrapper events (the part CF does not have) A wrapped asset is a claim. These are the ways a claim breaks. ### 2.1 Reserve shortfall [ADOPT] The reserve attestation shows less than the issued supply, or an attestation is **missed at its stated cadence**. | Condition | Action | |---|---| | Condition | Action | |---|---| | No passing issuer snapshot within the asset's freshness limit (a missed or late attestation, or a silent issuer) | Issuer gate not met → **`NO FIXING`** (off-hours) / tier 4–5 (OFFICIAL); never tier 3 (Methodology §6.2, §3A.7 rule 6) | | Shortfall attested, **any size** | Issuer gate refused → **`NO FIXING`** (off-hours) / tier 4–5 (OFFICIAL); licensees notified the same day | | Redemptions shut, or mint/burn paused | Issuer gate refused → as above | **[FIXED]** A shortfall is never absorbed into the price, and there is no "wrapper factor adjustment" for a small one: the gate is reserves ≥ supply (Methodology §4.3). While the gate is refused, tier 3 (reference × par) is never published, and a prior value is carried forward (tier 4) only if it is under 24 hours old (§6.2). ### 2.2 De-peg [ADOPT] The representation trades persistently away from the value of its underlying claim. - Deviation > **2%** from the implied claim value, sustained across **3 consecutive fixings** → flag `EVENT-DEPEG` on every value published, notify signers. The value itself is still the determination from the venues; the flag does not change it. - Deviation > **10%** sustained → the administrator convenes the committee within 1 business day and refers the question of continuing or ceasing the benchmark to the oversight function (Methodology §9.1, §9.7). The value keeps coming from the venues, flagged `EVENT-DEPEG`; it is never adjusted by a factor to close the gap. - **We publish the de-peg.** A benchmark that hides a discount is worse than no benchmark: the lender relying on it is the party who gets hurt. ### 2.3 Registrar or issuer failure [ADOPT] Insolvency, loss of keys, halt of mint/redeem, or withdrawal of the registrar. - **Immediate `NO FIXING`** for that asset. - Committee convenes within 1 business day. - If redemption is not restored within **30 days**, the asset is removed from every basket at its last reliable price, and single-asset benchmarks on it enter cessation (Methodology §9.7: at least 60 calendar days' notice, enforced on-ledger). ### 2.4 Registry or network migration [ADOPT] A registrar migrates the instrument to a new registry, instrument id, or network. - The asset's identifying tuple *(network, registrar, instrument id, redemption path)* is updated by **committee approval**, announced **before** it takes effect. - Continuity is preserved: the benchmark continues without a level break, the divisor is adjusted if needed, and the migration is recorded in the version history. - If continuity cannot be established, the old asset is removed and the new one treated as a new constituent subject to full eligibility (Methodology §4.1a, §5.2). ### 2.5 Canton domain / synchronizer events [ADOPT] A synchronizer outage, domain migration, or loss of a participant node. - **Nothing reaches the tape without K of N.** If the ledger cannot record the signatures, the strike is **`NO FIXING`** for off-hours fixings, and the OFFICIAL fallback waterfall applies (tier 4, the prior committee value flagged, or tier 5); the determination is kept in the record and the outage disclosed. - If signers cannot reach the ledger to sign, the same applies: fewer than K signatures is never published as a fixing. - **Ledger unavailability is never a reason to alter a value**, only to delay its recording. --- ## 3. Underlying corporate and market events For tokenised equities, Methodology v1.0 (§3A.7 rule 6, `corporateActionPending`) governs corporate actions. In addition: | Event | Action | |---|---| | Underlying market halt, single name | `NO FIXING` for that asset; a basket constituent held at its last reliable price, flagged | | Underlying market holiday | Normal — this is the case the off-hours signed fixings (specified, not built) exist for | | Trading suspension > 5 days | Remove from indices at last reliable price | | Wrapper stops passing dividends through | Material methodology change (Methodology §9.6); factsheet updated; **licensees notified** | --- ## 4. Notification On any event in this policy: signers notified immediately, licensees within 1 business day, a public notice on etpfoundry.com, and a record for the oversight function's review (Methodology §9.1; until one is constituted, the administrator's published review). ## 5. Definitions **Day** — 00:00:00 to 23:59:59 UTC. **Original token / new token** — as recognised by the constituent venues through the trading symbols they operate, not by us. **Constituent venue** — a venue meeting Methodology §4.1a and §5.2. **Cadence** — the attestation frequency stated in the asset's factsheet. ## 6. Version history | Version | Date | Changes | |---|---|---| | 0.1 | 22 Sep 2026 | Initial draft. Fork test adopted from CF Benchmarks Hard Fork Policy v7.3; wrapper, registrar, migration and Canton sections original. Superseded by 0.2. | | 0.2 | 29 Sep 2026 | Conformed to Methodology v1.0: `EXCEPTIONAL` means only a move larger than Y; missed attestation, outage and issuer-gate failures are `NO FIXING` / tier 4–5; forks and de-pegs flagged `EVENT-`; shortfall of any size refuses the issuer gate (no wrapper-factor adjustment); nothing published without K of N. |