# ETP Foundry Methodology v1.0 *Public copy, published at etpfoundry.com/documents/methodology-v1.0.md. It is the internal text with internal file and code locations removed, with the figures of worked example B (§5.6) withheld under the source venues' terms, and with internal commercial notes omitted.* Methodology v1.0 is the sole governing methodology (§0.1); the Rulebook v0.2 describes process only where it is consistent with it. **Benchmark determination, input hierarchy and committee governance** | | | |---|---| | Version | 1.0, 28 September 2026, **amended 29 September, 5 October and 6 October 2026** (§16) | | Administrator | ETP Foundry, a trading name of Lucilla, Inc. (formerly CrossDesk) | | Wire protocol | `SIGNER_PROTOCOL v4` (served at `GET https://etpfoundry.com/api/signer-protocol` once the v4 release is deployed) | | Supersedes | Fixing Methodology v0.1 in full, and rulebook v0.1 and v0.2 wherever they differ (§0.1). v0.1's identification, restatement and cessation rules are carried into this document; its strike schedule is replaced by §1 and §3A. The crypto OFFICIAL strike is **16:00 Europe/London**, adopted 28 Sep 2026 (§1, §14) | | Contact | committee@etpfoundry.com (seats, submissions, complaints); security@etpfoundry.com | > **Status, stated plainly.** > - **Environment:** everything below runs on Canton **DevNet** only. > - **Published values:** every value published today is **tier 0**. No committee of third parties has attested a fixing. **No exchange-derived price is published:** the desk's composite of exchange spot prices is not licensed for publication (§3.1, §7), so where no committee-derived value exists the public surfaces say "not published, awaiting a licensed source". > - **Committee:** no seat is held by a third party. Five seats exist on DevNet, and all are operated by the administrator for testing. > - **Signing keys:** L2 (the seat signs with its own key) is built and was proven on DevNet on 26 Sep 2026. **It is switched off on the running desk today**, and will be on before the first seat onboards (§6.4). > - **Regulatory status:** ETP Foundry is **not an authorised or registered benchmark administrator** in any jurisdiction (§12). > - **What is implemented:** the calculation, validation and gates in §3 to §6 are implemented and unit-tested in the desk. None of them has run against a third party's data yet. > - **What is planned:** each item marked *planned* is not built. §11 maps each IOSCO principle to its current state. > - **Built:** the §13.1 rules (simple-median outlier anchor, 50% weight cap, two-venue range test, `selfTradesExcluded`, required `markSource` and `markFromPublicReference`, mark age from submission, no tier 3 while the issuer gate is refused, level (c) never tier 1, the §6.4 conditions above tier 0) are in the desk and unit-tested. The 29 Sep 2026 amendment (§13.1, second table) adds: the 16:00 London crypto strike, the 10% share floor, the weight-proportional tie rule, the two-venue test after the outlier step, a silent issuer blocking tier 3, no public exchange-derived values (tier 3 and level (c) need a licensed reference), the operator-of-record test for condition 3, and oversight and venue records countersigned by the independent members' own accounts. > - **24/7 (phase 1 built, 5 Oct 2026):** the OFF-HOURS SIGNED engine of §3A runs desk-side at 00:00, 08:00 and 16:00 UTC, every day, for every instrument on the schedule (crypto, tokenised equity, baskets) and Canton Coin. Each slot publishes a value ± band or `NO FIXING` with the reason, at tier 0, `pilot — not attested`, never a NAV (§3A.11). The record is off-ledger: the Daml package has no off-hours slot yet (§13.2 item 1). No class-C market input is licensed or wired, so an equity slot rests on token trades alone and is `NO FIXING` under the two-signal-type rule (§3A.5). > - **Tokenised equities and baskets (§3B, 6 Oct 2026):** the reference for a tokenised stock (official close of the primary listing × the token's share ratio), the corporate-action rules, and the basket and index rules (eligibility, weighting, divisor, rebalancing, unscheduled changes) are **written**. Built today: the NYSE calendar and the intersection rule, the issuer's ratio change and corporate-action halt for off-hours values, fixed-unit baskets with NAV and fee arithmetic, and a timelocked rebalance on the EVM vault only. No official closing price is licensed, no equity instrument is on the live desk, and no OFFICIAL equity fixing has been made. > - **Hosted checker (29 Sep 2026):** a seat may let ETP Foundry run its checker ("Hosted by ETP Foundry — pilot, counts as operator-run (tier 0)"). Because the administrator then fetches the seat's inputs, every hosted submission is administrator-operated under §6.4 condition 3 and never counts toward tier 1, even when the seat's own cloud KMS key signs it (§4, §10). Built; the hosted runner is switched off on the running desk until enabled. --- ## 0. Why this document exists The v3 protocol (28 September 2026) priced every instrument from public market data. It asked each committee seat a few yes/no questions. That design had three defects: 1. **Little private information.** Most of what the issuer was asked (reserves ≥ supply) can be read from public sources. 2. **No price information.** A yes/no answer adds nothing to the price. 3. **The price came from outside the committee.** It was computed from off-Canton spot feeds. The committee could only accept it or refuse it. A committee like that looks like a rubber stamp, whatever its intent. Version 1.0 models its input hierarchy on IOSCO Principles 7–8 and BMR Art. 11: - **Inputs are data, not opinions.** Transaction data comes first (IOSCO Principle 7; EU/UK BMR Art. 11). - **Inputs follow a published hierarchy** (IOSCO Principle 8). - **Each seat supplies what only it holds**, as signed numbers: - the **venues** provide the price; - the **lender** challenges it from the risk side (a basis check, §4.2); - the **issuer** gates it on peg integrity; - the **custodian** and **transfer agent** reconcile a fund's holdings and shares. - **The administrator computes and never attests.** ### 0.1 Precedence This document (ETP Foundry Methodology v1.0) is the sole governing methodology for every ETP Foundry fixing. It supersedes Fixing Methodology v0.1 in full, rulebook v0.1 and v0.2 wherever they differ, and every description on etpfoundry.com. `SIGNER_PROTOCOL v4` is the wire specification under it and has no independent force. Where any other text differs from this document, this document governs. The Rulebook v0.2 describes process only where it is consistent with this document; it has no independent force on the determination, the schedule, the tiers or the gates. Superseded versions remain published, marked "SUPERSEDED — not in force", with a link to this document. --- ## 1. Definitions | Term | Meaning | |---|---| | **Fixing** | The official value of an instrument at a strike. Published with its tier and input level (§6.4). Creation, redemption and referencing contracts may settle against it only where a licence permits and only at a tier the contract accepts. Also called the **OFFICIAL** fixing, to distinguish it from an OFF-HOURS SIGNED fixing | | **Indicative value** (live indicative) | A value computed by the desk that no committee attested and nobody signed. Always **tier 0**. Informational only. Layer 1 of the 24/7 family (§3A). "Indicative" is used **only** for unsigned, unattested values | | **OFF-HOURS SIGNED fixing** (label `OFFHOURS`) | A value at a fixed off-hours time (00:00, 08:00 or 16:00 UTC), signed K-of-N and published with a data-quality band. For margin, liquidation, health factors and haircuts, once the §6.4 conditions hold; until then it is published at tier 0 labelled `pilot — not attested`, and the licence forbids its use for liquidation. **Never a NAV**, and never used for creation or redemption. Layer 2 of the 24/7 family (§3A). Called a "signed INDICATIVE fixing" before 29 Sep 2026 | | **Band** (data-quality band) | The published uncertainty `± b` around an OFF-HOURS SIGNED fixing, computed under §3A.5. Uncalibrated until back-tested (§3A.5) | | **Strike** | The declared time an OFFICIAL fixing describes. Wrapped crypto and Canton Coin: **16:00 Europe/London daily** (adopted 28 Sep 2026; 15:00 UTC during British Summer Time, 16:00 UTC in winter). Equities, and any basket with an equity leg: the home-market close, 16:00 America/New_York on NYSE trading days | | **Observation window** | The **60 minutes ending at the strike** (for crypto, 15:00–16:00 London). Submissions describe this window. For an OFF-HOURS SIGNED fixing, the **15 minutes** ending at the fixing time (§3A.6) | | **Confirmation window** | The period after the strike in which seats confirm a proposal (per instrument, default 30 minutes). Restrikes do not extend it | | **Submission** | A seat's signed numbers for one strike, in the v4 wire format (§4) | | **Contributor** | A seat whose submission is a price input: the **venue** | | **Validator** | A seat whose submission checks the value against a number from its own risk system: the **lender**. Its check is a **risk-side challenge** (a basis check), not an independent valuation of the token (§4.2) | | **Gate** | A seat whose submission can stop publication but never sets the price: the **issuer**, **custodian** and **transfer agent** | | **Determination** | The value the administrator computes from the submissions under §5 | | **VWAP** | Volume-weighted average price: Σ(price × quantity) / Σ quantity over a venue's trades in the window | | **VWM** | Volume-weighted median: the smallest submitted value at which cumulative (capped) weight reaches half the total; at an exact half, the weight-proportional interpolation of the two straddling values (§5.3) | | **Notional** | VWAP × volume, in USD | | **bp** | Basis point, 0.01% | | **K-of-N** | The committee quorum: N members named on-ledger, K signatures required, K ≥ 2 (enforced by the Daml package) | Unless stated otherwise: - **Prices** are in **USD per unit** of the instrument. Settlement is in USDC. - **Quantities** are in units of the instrument, or of the underlying asset where stated. - **Numbers** carry at most **10 decimal places**, the Daml `Numeric 10` limit. - **Times** are ISO-8601 UTC instants. **Crypto strike time (adopted 28 Sep 2026).** The OFFICIAL crypto strike is **16:00 Europe/London**, the time of the CME CF Bitcoin Reference Rate, with the observation window 15:00–16:00 London. It was adopted by the founder on 28 Sep 2026 and replaces the 16:00 UTC stated in rulebook v0.2 §5.1. During British Summer Time it is 15:00 UTC; in winter it is 16:00 UTC. Equities strike at the home-market close. The OFF-HOURS SIGNED fixings of §3A stay at 00:00, 08:00 and 16:00 **UTC**. --- ## 2. Instruments | Type | Examples | What the fixing measures | Status | |---|---|---|---| | **W — wrapped crypto** | CBTC (BitSafe), cETH (onRails) | The USD price of one token on Canton | Registry integration on DevNet. No venue submission yet | | **N — network coin** | Canton Coin (Splice Amulet, desk id `Amulet`) | The USD price of one CC | Indicative only, from the DSO-voted `amuletPrice` (not a traded price) | | **E — tokenised equity** (class C in the rulebook) | none onboarded; xStocks SPYx and QQQx are the design cases | The USD price of one token representing one share, or a stated fraction. OFFICIAL at the home close; OFF-HOURS SIGNED fixings (§3A). Reference, halts and corporate actions: §3B | *Planned* (rules written, §3B; none onboarded) | | **F — fund / basket** | ETPs built on the desk | NAV per share = Σ (units per share × component fixing) − accrued liabilities. Basket and index rules: §3B.4–§3B.8 | Arithmetic implemented. Custodian and transfer-agent seats exist; none is held by a third party. Equal and capped weights, index levels and Canton rebalancing written, not built (§3B.0) | --- ## 3. Input hierarchy IOSCO Principle 8 (FR07/13, printed p.21) lists five kinds of input in a general order of priority: (a) the submitter's own concluded arm's-length transactions in the underlying interest; (b) reported or observed concluded transactions in the underlying interest; (c) concluded transactions in related markets; (d) firm (executable) bids and offers; (e) other market information or expert judgement. It allows that order to be varied. EU/UK BMR Art. 11(1)(a) requires transaction data "if available and appropriate". ETP Foundry applies four levels, in order. **The first level that is eligible sets the determination**, and that level is published with the fixing. **Where the order differs from IOSCO's, and why (our choice).** Level (c) below is a related-market transaction price (BTC spot for CBTC). We rank it **below** the token's own executable quotes, not above them, because a wrapped token can trade at a basis to its underlying, and the token's own book carries that basis while the underlying's price does not. This section covers the **OFFICIAL** fixing. The off-hours inputs for OFF-HOURS SIGNED fixings, including futures and cross-listed instruments, are in §3A.4. | Level | Input | Source | When it applies | |---|---|---|---| | **(a) Transactions** | Each venue's **own trades** in the observation window, submitted as VWAP, volume, trade count, low, high and halt time, signed | The venue's matching engine or trade database | At least `minVenues` venues are eligible under §5.2 | | **(b) Executable quotes** | Each venue's **time-weighted best bid and ask** over the window, as a mid, signed | The venue's order book | No eligible transactions, but at least `minVenues` venues quoted two-sided within the spread and time limits | | **(c) Reference × par** | A **reference-market price** for the underlying × the **par factor**, with the source stated | A **licensed** source, named per instrument below. **Requires a licensed reference**: until one is licensed, level (c) is unavailable for publication | No eligible transactions or quotes | | **(d) Carry-forward / expert judgement** | The prior published value, or a manual proposal with a written rationale | The published series; the operator | Nothing above is available. **Always flagged** | ### 3.1 Per instrument type **W — wrapped crypto (CBTC, cETH)** - (a) and (b): Canton venues that list the token and hold a venue seat. - (c) Reference: - Underlying: BTC-USD for CBTC, ETH-USD for cETH. - Source: a **licensed composite** named per instrument (§14), × the **last attested par factor**, which defaults to 1.0. **Until one is licensed, level (c) is unavailable for publication, and the fallback proceeds to tier 4 or 5** (§6.4). The desk may use the Coinbase, Kraken and Bitstamp median internally as a pre-fill and sanity check only; it is never published. (It does reach the committee's seats as the pre-fill on a proposal; whether that is within the venues' terms is an open licensing question, §5.1 and §14.) Those venues' published terms do not permit display of derived values outside the organisation, and the CME CF Bitcoin and Ether Reference Rates also need a licence. - A wrapped token can trade at a basis to its underlying. That is why (c) ranks below the token's own prints. - (d) The prior fixing, flagged. **N — Canton Coin** - (a) and (b): Canton venues that list CC. - (c) Reference: - The DSO's `amuletPrice` on the latest opened mining round, read from Scan. - This is a **voted** USD price set by the super validators, not a traded one. It is published as such. A voted governance parameter is not a transaction (IOSCO Principle 7), so a CC value at level (c) is never tier 1 (§6.4). - There is no issuer and no reserve. The issuer seat does not sit (reserve model `native`). - (d) The prior fixing, flagged. **E — tokenised equity** (*planned*; the full rules are in §3B) - (a) and (b): Canton venues that list the token. - (c) Reference: - The **official closing price of the primary listing**. This is the closing auction price where one exists, following index-provider practice (FTSE Russell, *Closing Prices used for Index Calculation*). - It is multiplied by the token's share ratio. - The primary listing, halts, early closes and holidays: §3B.1–§3B.2. Corporate actions follow the issuer's notice, checked against the company's and the exchange's announcements, applied on the ex-date as the token terms say (reinvest, distribute or accrue); a disagreement halts the fixing (§3B.3). - **When the home market is closed:** - There is no OFFICIAL fixing. The OFFICIAL series strikes only at the home close, on home-market trading days. - Off-hours values are **OFF-HOURS SIGNED fixings** under §3A: the home close anchor × the change implied by live off-hours inputs (futures, overnight sessions, cross-listed instruments, the token's own trades), bounded, with a data-quality band. - They are never a NAV and never the basis for creation or redemption. **F — funds** - NAV per share = Σ (units per share × the component's own fixing) − accrued fees and liabilities. - A missing component fixing means **no NAV**. A gap is published as a gap. - The custodian and transfer-agent reconciliations (§4.4, §4.5) gate publication. No venue determination applies at fund level. - A fund with any equity leg strikes its OFFICIAL NAV on the NYSE calendar only (a fund strikes on a day only when every component strikes). Off-hours, it has OFF-HOURS SIGNED values under §3A.8, which are not a NAV. ### 3.2 Expert judgement Expert judgement is permitted only as a manual proposal by the administrator, with a written rationale recorded on the proposal. It needs the same K-of-N and gates as any other value. Automatic flagging of such a proposal as level (d) is *planned*. Today the rationale is on the record, but the level is not set automatically. The administrator does not use expert judgement to override an eligible level (a) or (b) determination. --- ## 3A. Schedule and the 24/7 fixing family **Why this section exists.** A tokenised stock such as xStocks SPYx trades 24/7, but its home market, the NYSE, is open for about 32.5 of the 168 hours in a week. Lenders and liquidation engines still need a number at 02:00 on a Sunday. Nobody publishes a trustworthy one: Chainlink's own documentation says its tokenized-equity feeds "do not publish updates, including heartbeat updates, while markets are closed" (A31). ETP Foundry's answer is three layers, specified here. They extend, and never replace, the OFFICIAL fixing of §3 to §6. > **Status, stated plainly (5 Oct 2026).** Layer 3 (OFFICIAL) is implemented for wrapped crypto and funds, as §5 describes. Layer 1 exists for BTC and ETH only. **Layer 2, the OFF-HOURS SIGNED fixings, is built in a first phase, desk-side** (§3A.11): > - the 00/08/16 UTC schedule, the class-C determination, the band, the seats' off-hours submissions, the gates and the labels; > - publication at `GET /api/offhours`. > > It records off the ledger, because the deployed Daml package cannot yet hold three fixings a day for one instrument. Every value is tier 0. No class-C market input (home-market live, futures, overnight sessions, cross-listed ETFs, token trades off Canton) is licensed or wired. Its inputs today are the committee seats' own submissions and the instrument's last OFFICIAL fixing. > > **TOKEN-CONSENSUS fallback (§3A.5a), built 5 Oct 2026, switched off on the live desk.** When no hard signal is live, it may take the median move of at least three independent issuers' tokens, read from public venues, flagged "tokens only, lower confidence", tier 0. It runs in the sandbox. ### 3A.0 Schedule at a glance | Layer | What it is | When | Signed? | Band? | Use it for | Never use it for | Status | |---|---|---|---|---|---|---|---| | **1. Live indicative** | The desk's own composite of the inputs, recomputed as fast as they arrive | Continuous (today: 15-second cache) | **No.** Tier 0 | Dispersion shown, no band | Internal screens, monitoring, pre-filling a proposal | Anything contractual; any public display while its source is not licensed for publication (§3.1) | BTC and ETH spot only (signed-in and internal only). No equity inputs | | **2. OFF-HOURS SIGNED fixing** (`OFFHOURS`) | Home close anchor × implied change, bounded, with a data-quality band | **00:00, 08:00 and 16:00 UTC, every day, weekends and holidays included** | **Yes**, automatically, K-of-N, with at least one venue signature among the K | **Yes**, `± b` | Margin, liquidation, health factors, collateral haircuts, **once the §6.4 conditions hold**. Until then: tier 0, `pilot — not attested`, not for liquidation | **NAV**, creation, redemption, fund reporting | **Built, phase 1** (desk-side, tier 0, §3A.11) | | **3. OFFICIAL fixing** | The fixing of §3 to §6 | Crypto (types W, N): **16:00 Europe/London daily** (adopted 28 Sep 2026). Any equity, and any basket with an equity leg: **16:00 America/New_York on NYSE trading days** (20:00 UTC while the US is on daylight time, 21:00 UTC otherwise) | **Yes**, K-of-N | No: tier and input level (§6.4) | NAV, creation and redemption, reporting, audited records | — | Implemented for W and F; E *planned* | **Label rule.** Every value carries its layer on the ledger and on the tape: `LIVE` (tier 0, unsigned: the only values called "indicative"), `OFFHOURS` (with its band), or `OFFICIAL`. **Nobody may present an `OFFHOURS` fixing as a NAV**, and the licence says so (rulebook v0.2 "Prohibited representations"). Until the four conditions of §6.4 hold, every `OFFHOURS` fixing is published at tier 0 with the label `pilot — not attested`, and the licence forbids its use for liquidation. **Where a time coincides.** Where an OFFICIAL strike and an off-hours time fall at the same instant for the same instrument, only the OFFICIAL is published; the `OFFHOURS` slot points to it. With the crypto strike at 16:00 London, this happens **only in winter** (GMT), when 16:00 London is 16:00 UTC. During British Summer Time the OFFICIAL crypto strike is 15:00 UTC and the 16:00 UTC `OFFHOURS` fixing is published one hour later, separately. On NYSE days, the 16:00 UTC off-hours slot for an equity falls inside regular trading hours (12:00 New York in summer) and uses the live home market. ### 3A.1 How the three layers differ | | Live indicative (layer 1) | OFF-HOURS SIGNED (layer 2) | OFFICIAL (layer 3) | |---|---|---|---| | Who stands behind it | Nobody | K-of-N seats, each attesting its own inputs and that the published rule was applied; at least one venue among the K | K-of-N seats and the gates of §6.2 | | Inputs | Whatever is live, unfiltered beyond the median | The class-C waterfall (§3A.4), each input with a maximum age | The hierarchy of §3 (levels a to d) | | Window | Instantaneous | **15 minutes** ending at the fixing time | 60 minutes ending at the strike | | Uncertainty | Venue dispersion only | Published band `± b`, and `NO FIXING` when data is insufficient | Tier and input level | | Failure | Shows a stale age | `NO FIXING` with the reason; the last good fixing stays visible with its age | Tier 3 to 5 fallback (§6.4) | | Restatement | Never | Never: a correction is a new, linked record | §6.5 | | Precedent | CME CF Real Time Index, about once a second (row S1) | Fund fair-value practice when the home market is closed (rows S4–S5) | CME CF BRR (§5.0) | **Why the signed layer is not just the live one with signatures.** The live price is the fastest reading of the inputs, and nobody attests it. An OFF-HOURS SIGNED fixing is a **fixed-time, rule-bound determination**: it uses only inputs within their maximum ages, it is bounded by what could actually be traded, it states its own uncertainty, and each seat signs its own data. A liquidated borrower can later see exactly what was known at that instant, and who said so. **Borrower side: a disclosed conflict.** Off-hours, the only price-side validator is the lender, and a lender that liquidates gains from a *low* value. §4.2's rationale ("the seat that loses money if the value is too high") holds for the OFFICIAL fixing, not for liquidations. There is no borrower seat. The mitigations are: the order-book depth bound (§3A.5 step 4), which limits how far below the market the value can sit; the rule that **at least one venue signature (not only the lender's) is among the K** for any OFF-HOURS SIGNED fixing; and the lender's tolerance, which is declared in advance and never widened (§3A.6). This is disclosed as a conflict (§9.2); it is mitigated, not removed. ### 3A.2 What we price, and what we do not - **We price the token** (e.g. SPYx), which trades 24/7 and is pledged as collateral. - **We do not price the underlying share off-hours.** When the NYSE is shut, the share has no primary market. - **The token-to-share ratio is the issuer's multiplier.** xStocks launch at 1 token = 1 share and reinvest dividends through a multiplier increase (A33). On 28 Sep 2026 the xStocks public API gave SPYx a `currentMultiplier` of 1.005714560286254, after four dividend changes (A33, live data, not methodology). Every SPYx value below is therefore SPY × multiplier. ### 3A.3 Which layer uses which inputs, by instrument type | Type | OFFICIAL | OFF-HOURS SIGNED at 00:00 / 08:00 / 16:00 UTC | |---|---|---| | **W, N** (crypto) | §3 to §6, 60-minute window ending 16:00 London | The §5.3 determination on a **15-minute window** (levels a and b), else level (c) from a **licensed** reference at the fixing instant, flagged (while no reference is licensed: `NO FIXING`). The issuer gate applies. No futures or equity inputs | | **E** (tokenised equity) | Home close, NYSE days (§3.1) | The **class-C waterfall** (§3A.4) and computation (§3A.5) | | **F** (fund) with an equity leg | NYSE calendar only (§3.1) | §3A.8: crypto legs at their off-hours value, equity legs by the class-C waterfall | | **F** with crypto legs only | Its crypto strike | Σ units × each leg's OFF-HOURS SIGNED value | ### 3A.4 The class-C input waterfall Each input carries a **maximum age**, measured at the fixing time. Past that age it is **stale**: it drops out and is listed as stale on the fixing. The rows follow the internal 15 September 2026 draft (§3), with row 0 and row 2a added. | # | Input | Max age | Role | Source today | Precedent row | |---|---|---|---|---|---| | 0 | **Home market live** (consolidated last sale or NBBO mid), during regular hours only | 1 min | Sets the value directly when the home market is open | Not wired | S4 | | 1 | **Home-market official close** (closing auction) × the issuer's multiplier | Until the next official close | **The anchor, always included** | Not wired | S3 (§5.0 row 20) | | 2 | **Futures** on the index (ES for SPYx, NQ for QQQx) or on the single stock | 5 min | Change signal, first in priority. The best off-hours signal for index tokens | Not wired; needs a CME market-data licence | S5, S6 | | 2a | **Extended and overnight sessions** in the underlying itself (pre-market, post-market, overnight ATS such as Blue Ocean, 24X once live) | 5 min | Change signal, second in priority | Not wired; no consolidated overnight tape yet | S7 | | 3 | **Token secondary trades**: CEX, DEX and Canton venues, volume-weighted over the **15 minutes** ending at the fixing time, outliers trimmed (§5.3 rules) | 15 min | Change signal, fourth in priority; on weekends usually the only one | Canton venues via `window-trades`. For the §3A.5a fallback only (off on the live desk): Kraken (xStocks) and Binance (bStocks) public trades, and pinned DEX pools: Robinhood stock tokens on Robinhood Chain, Ondo Global Markets on Ethereum, xStocks on Solana | S8 | | 4 | **Token order-book depth**: best bid and ask at a size threshold, across the token's venues | 1 min | **Bound**, not a price: the result may not lie outside it | Not wired | S9 | | 5 | **Cross-listed instruments in open regions** (e.g. a London-listed S&P 500 UCITS ETF in European hours; an Asian-listed one in Asian hours) | 5 min | Change signal, third in priority | Not wired | S10 | | 6 | **Issuer primary create/redeem level** | Since publication; exists only while primary issuance is open (xStocks: 24/5) | **Sanity bound** | Not wired | S11 | | 7 | **Stablecoin FX** (USDC/USD, USDT/USD) and any currency leg | 5 min | **Multiplier**, applied to every non-USD input, never ignored | Not wired, except for the §3A.5a windows: Kraken's public USDT/USD, USDC/USD and USDG/USD trades over the same window convert the Binance (USDT), Ethereum and Solana (USDC) and Robinhood Chain (USDG) windows | S12 | | 8 | **Corporate actions** (dividends, splits, spin-offs) and the issuer's multiplier changes | As announced; applied at the issuer's activation time | **Adjustment**, not a price (rules: §3B.3) | Not wired (the issuer seat's ratio change is accepted, §3A.11) | S13 | **Change-signal priority:** futures (2) → overnight sessions (2a) → cross-listed instruments (5) → token trades (3). The first eligible signal sets the value; every other eligible signal is a cross-check that feeds the band (§3A.5). This is the same "first eligible level" rule as §3, applied to the off-hours inputs, and it keeps each value traceable to one named input. **Independent live inputs.** For the insufficiency rule below, the minimum is **two live inputs of distinct signal types**, each meeting its own size floor, each from an operator that holds a venue seat or from a licensed source. The signal types are: futures (row 2), overnight sessions (row 2a), cross-listed listings (row 5) and token trades (row 3). - **Token trades are one signal type**, however many venues print. They count only where a venue's 15-minute window has at least `minTradesOffHours` (default **5**) trades and at least `minNotionalOffHoursUsd` (default **USD 10,000**), with `selfTradesExcluded` = true, from a venue that holds a seat (a venue that is not a seat cannot attest self-trade exclusion or data-sharing, §4.1a). **Two token trades, on however many venues, never make two independent inputs.** - Within a type, further venues or listings are cross-checks for the band (§3A.5), not extra inputs. - **One exception, switched off on the live desk:** when no hard signal type is live at all, the TOKEN-CONSENSUS fallback of §3A.5a may stand in for the missing second type, from at least three independent **issuer families** of the same underlying, flagged `TOKEN-CONSENSUS` ("tokens only, lower confidence"), tier 0. - The anchor, the order book, the issuer level, FX and corporate actions are not counted: they anchor, bound or adjust, but do not say where the price is now. - *Why (our choice):* token trades on different venues can be printed by one arbitrageur, and for a DEX "operator" is undefined. A second input of a different kind is the only cross-check that one party cannot supply alone. Token-trade data from venues that are not seats would also meet the licensing limits of §3.1. **Single stocks.** Index futures are not used as a change signal for a single-stock token (no committee-approved beta). Where no single-stock future trades, a single-stock token relies on overnight sessions and token trades, and its band is wider. *Our choice; founder decision.* ### 3A.5 The computation, and the data-quality band **Step 1: anchor.** `A = C × m`, where C is the home market's official close and m is the issuer's multiplier in force at the fixing time, adjusted for any corporate action whose ex-date or activation falls between the close and the fixing (row 8). **Step 2: implied change**, from the first eligible signal: | Signal | Implied value M | |---|---| | Home market open (row 0) | M = live price × m. No anchor needed | | Futures (row 2) | M = A × F_t / F_0, where F_0 is the same contract's mid at the anchor instant (16:00:00 New York) and F_t its mid within 5 minutes of the fixing time. A contract roll uses the published roll calendar, with both prices from the new contract. Carry over the gap is ignored (about 1 bp a day; *our choice*) | | Overnight session (row 2a) | M = U_t × m, where U_t is the underlying's own 5-minute VWAP in the session | | Cross-listed instrument (row 5) | M = E_t × FX_t × k, where k is the ratio of the home listing to the cross-listed instrument (FX-converted) at the last instant both traded, recomputed each trading day | | Token trades (row 3) | M = A × V_t / V_0, where V_t is the token's 15-minute determination (USD) and V_0 the same over the 15 minutes ending at the anchor. This carries the token's move since the close, without carrying its basis at the close | **Step 3: screen.** With three or more eligible signals, any signal more than **X** from their median is dropped and flagged (default X = 5% for class C off-hours, rulebook v0.2 §7.4). With exactly two that disagree by more than X, neither can be preferred: `NO FIXING`. Signals are counted by type (§3A.4): token trades on several venues are one signal, screened internally by the §5.3 rules on their 15-minute windows. **Step 4: bound.** `P = min(max(M, bid_S), ask_S)`, where bid_S and ask_S are the token's best bid and ask for size S (row 4, default S = USD 25,000). If the bound binds, P is flagged `BOUNDED`. If the issuer's primary level is live and P differs from it by more than the issuer tolerance (default 2%), P is flagged `PRIMARY-DIVERGENCE`. The primary level never sets the value. **Step 5: FX and rounding.** Every non-USD input has already been converted at its own stablecoin rate (row 7). P is published in USD per token to at most 10 dp. **The data-quality band.** Every OFF-HOURS SIGNED fixing publishes `P ± b`, with b in basis points: b = max( b_min , √( (z · σ · √τ)² + D² + s² ) ) | Term | Meaning | Default | |---|---|---| | σ | Daily volatility of the anchor series: standard deviation of the last 60 daily log returns of official closes, in bp | computed | | τ | Days since the freshest **hard** signal: the home market, futures, an overnight session or a cross-listed instrument. Token trades do not reset τ | computed | | z | Coverage multiplier | 1.0 in the specification; **2.0 recommended** before any lender sets haircuts from the band (see *Calibration* below) | | D | Dispersion: the largest deviation, in bp of P, of any other eligible signal (and, for token trades, of any venue's VWAP from the determination), **and the dispersion of the Friday basis estimate V_0** (the spread of the venue VWAPs in the anchor window), which otherwise enters M one-for-one without appearing in the band | computed | | s | Half the bid–ask spread at size S, in bp of P | computed | | b_min | Floor | 5 bp | The √τ term makes the band grow with time since the last hard information, as square-root-of-time scaling of volatility does in the Basel market-risk rules (row S14). On a weeknight with futures live, τ is minutes and the band is set by D and s. On a weekend, τ is 35 hours or more by Sunday morning, and the band widens accordingly. That reproduces the qualitative table of the 15 September draft: | Situation | Typical band | |---|---| | Home market open | Tightest (τ ≈ 0) | | Weeknight, futures live | Moderate (Example C2: about 20 bp) | | **Weekend, futures closed** | **Widest** (the Example C1 arithmetic: about 114 bp, had a value been determined) | | Fewer than 2 live inputs of distinct signal types | **`NO FIXING`**: no value, no band | **Insufficient data → NO FIXING.** If fewer than **two independent live inputs of distinct signal types** (§3A.4) remain after the maximum ages, the size floors and the screen, no OFF-HOURS SIGNED fixing is computed. `NO FIXING` is published with the reason, the last good fixing stays visible with its age, and **nothing is guessed**. This is the rulebook's two-input minimum (v0.2 §5.2, §7.1), modelled on CF's two-constituent minimum (§5.0 row 7). A band wider than **b_max** (default 1,000 bp) also gives `NO FIXING` (*founder decision*). **Exception:** with no hard signal type live, the TOKEN-CONSENSUS fallback (§3A.5a), when switched on, takes the place of the second type. **Why a band, not a precise number.** Lenders set haircuts from the band, and a liquidated borrower can see what was known. Pyth publishes every price with a confidence interval "intended to achieve 95% coverage" (A32). Our band is modelled on that practice, and the formula is **our choice**. **Calibration, stated plainly.** The band is **uncalibrated**. It mixes statistics of different kinds: σ√τ is a one-standard-deviation term measured in calendar days (weekend equity variance is well below that many trading days' worth, so it overstates a weekend gap); D is a maximum deviation, which grows with the number of signals; s is a half-spread; and they are added in quadrature as if they were independent standard deviations. **At z = 1 its nominal coverage would be about 68% if the errors were normal, and that has never been measured.** At z = 2 the nominal figure is about 95%, which is why z = 2 is recommended for haircuts. Rules: - before any OFF-HOURS SIGNED fixing is published as attested, the band is **back-tested on at least 12 months** of Friday-close → Monday-open (and holiday) gaps for each asset; - the **realised coverage** at the chosen z is published, and reviewed quarterly; - z is set to achieve a stated coverage target (90% or 95%, a founder decision, §14); - until then, every published band carries the words "uncalibrated band". ### 3A.5a TOKEN-CONSENSUS fallback (tokens only, lower confidence) > **New rule, 5 Oct 2026. Founder-approved direction; switched OFF on the live desk** (`offhours.token-consensus-enabled` = false) **until the founder approves it there.** The sandbox runs it ON. Every value it produces is tier 0, flagged `TOKEN-CONSENSUS`, and labelled "tokens only, lower confidence". **Why.** With futures, overnight sessions and cross-listed instruments unlicensed (§3A.4), a weekend equity slot has one signal type, token trades, and §3A.5 gives `NO FIXING`. Several issuers now tokenise the same US share (xStocks, Robinhood, Ondo Global Markets, Dinari), and their tokens trade on different venues with different arbitrageurs. One party can print one issuer's token on several venues; it is much harder for one party to move three issuers' tokens the same way at the same time. The fallback uses that independence in place of the missing second signal type. It is weaker than a hard signal, and is labelled so. **When it applies.** Only when **no hard signal type** (home market, futures, overnight session, cross-listed instrument) is live at the fixing time, so that the second signal type is unavailable, and only while the parameter is on. A live hard signal always takes precedence; the fallback never stands beside it as a second type. **Inputs.** For the underlying of the priced token (TSLA for TSLAx, TSLAon, Robinhood TSLA): - **Issuer families.** A family is an **issuer**, not a venue: xStocks (Backed), Robinhood stock tokens, Ondo Global Markets, Dinari dShares. Every venue of one issuer is the same family. - **One venue per family: its most liquid eligible venue**, meaning the largest notional among that family's 15-minute windows that meet the off-hours floors (`minTradesOffHours` 5, `minNotionalOffHoursUsd` USD 10,000). The family's other venues are recorded and not used. - **Window:** the 15 minutes ending at the fixing time, as row 3. **V_0:** the same venue's VWAP of the same token over the 15 minutes ending at the anchor instant (§3A.5). A venue with no trades in that window cannot contribute: its move since the close is unknown. - **Quote currency:** USD. A stablecoin-quoted window (USDT, USDC, USDG) is converted at the VWAP of Kraken's public trades of that stablecoin against USD over the **same 15 minutes** (row 7, for this path only). With no such print in the window, the window is excluded and listed. **No stablecoin is assumed to be worth one dollar** (on 3 Oct 2026 Kraken's USDG/USD printed 7 to 12 times in every slot window, VWAP 0.99993–1.00000). - **Source:** the priced token's own seat venues, when they qualify, are its family's contribution. Other families are read by the administrator (§3A.6, *Administrator*) from the venues' **public, keyless, read-only** market-data endpoints, each response recorded with its SHA-256. A public venue is not a seat: it cannot attest self-trade exclusion, and that is one reason this path is lower confidence. **Independence (our choice).** At least **`tokenConsensusMinFamilies`** (default **3**, never fewer) distinct issuer families must contribute, and **at least two of them must be issuers other than the priced token's own**. The priced token's own family may contribute, because its trades are evidence of where the token trades; it cannot make up the independent minimum on its own. Two venues of one issuer are never two families. **Computation.** 1. **Per family:** `M_f = A × V_t,f / V_0,f`, the row-3 formula on that family's venue. Each family carries its own move since the close, so neither its issuer's multiplier nor its basis to the share enters the value. 2. **Screen:** any family more than **X** (5%) from the median of the families is dropped and flagged `SOURCE-DROPPED`. If fewer than the minimum remain (or fewer than two independent), `NO FIXING`. 3. **Value:** `M = median of the M_f` that remain. 4. **Then the existing rules, unchanged:** the depth bound (`BOUNDED`, or `UNBOUNDED` when no seat submitted a book), the issuer primary level (`PRIMARY-DIVERGENCE`), the band of §3A.5 with **τ measured from the anchor** (token trades never reset τ) and **D the largest deviation of any contributing family from P**, b_max (`NO FIXING` above it), and `EXCEPTIONAL` for a move larger than Y since the previous value (published and flagged, never suppressed). 5. **Seats:** the §3A.6 gates apply unchanged: K signatures with a venue among them, the lender gate, the issuer gate and the halts. The fallback replaces the second signal type; it does not replace any signature. **Flags and tier.** `TOKEN-CONSENSUS`, and the reason "tokens only, lower confidence". **Tier 0 always**, whatever the §6.4 conditions, until the founder decides otherwise. **Fewer families → `NO FIXING`**, with the families that did qualify and the reason each other window did not. **Venues, as found on 5 Oct 2026** (public, keyless requests; Saturday 3 Oct 2026 data and the same day's). A venue has a reader only when its public data gives a 15-minute window's trade count, notional and VWAP, either for **any past** window, or for a recent one that the desk records when it closes (the close-window recorder, below). Every reader was verified with real calls before it was built; none is a stub. A DEX pool is a venue, pinned by address after its token contract (named by CoinGecko as the issuer's token), token order and decimals were read on-chain. | Issuer family | Most liquid public venue on Saturday | Public data | Reader | Why / why not | |---|---|---|---|---| | **xStocks** (Backed) | Solana DEX pools (USDC); among USD-quoted venues, **Kraken** | Yes | **Kraken** (`Trades`, per trade, USD); **Solana Raydium CLMM pools** NVDAx, SPYx, TSLAx / USDC (GeckoTerminal's public trade list, per trade, priced from the token amounts; USDC at Kraken USDC/USD) | Kraken's history reaches back to the close. GeckoTerminal keeps only the last 300 trades of the last 24 hours, so a Solana window counts only as the recorder captured it minutes after it closed (V_0 at the close, V_t at an off-hours slot). The busier Orca pools turn over 300 trades in a few minutes and are not pinned. Bybit, Gate and MEXC list xStocks against USDT, with no trade count in their candles. One family: its most liquid qualifying venue contributes | | **bStocks** (Binance-listed "bStocks Tokenized Stock"; issuer not verified) | **Binance** | Yes | **Binance** (`klines`, one 15-minute bucket: exact trade count, base and quote volume), USDT converted at Kraken's public USDT/USD trades over the same window | Treated as its own family pending verification of its issuer; if it shares an issuer with another family, the two are one family | | **Robinhood stock tokens** | Robinhood Chain DEX pools (USDG, Paxos Global Dollar) | Yes, on-chain | **Robinhood Chain pools** (9 pinned: NVDA, TSLA, SPY / USDG on Uniswap v3 and v4, Ramses v3, Alandale CL), every swap read with `eth_getLogs` from Robinhood's public RPC (`rpc.mainnet.chain.robinhood.com`, keyless; full history); USDG at Kraken USDG/USD | No public Robinhood price API (the EU app is in-app only), but the chain is public: a pool's swaps for any past window are on-chain, so V_0 needs no capture (the recorder keeps it anyway). The block range of the window is found from block timestamps. A pool on a DEX with another event shape (Giga) is not pinned. The publicnode mirror refuses `eth_getLogs` | | **Ondo Global Markets** | MEXC (USDT); Ethereum Uniswap v3 pools (USDC) | Yes | **Ethereum Uniswap v3 pools** NVDAon, TSLAon, SPYon / USDC, every swap by `eth_getLogs` from a public keyless Ethereum RPC (Tenderly's public gateway, MEV Blocker as fallback); USDC at Kraken USDC/USD | Full on-chain history. Thin: on 3 Oct 2026 the busiest (NVDAon) printed 0–4 swaps and under USD 500 per slot window. **MEXC is not built:** its candles carry no trade count and its trade list holds only recent trades; its NVDAon, SPYon and TSLAon windows held USD 900–2,400 per slot on 3 Oct 2026, far below the floor. publicnode refuses past-block `eth_getLogs` without a token | | **Dinari dShares** | Dinari's own platform | No | **None** | No public trade data; the only DEX pool found had no volume | **RPC provider.** The on-chain pools (Robinhood Chain, Ethereum) may be read first through a keyed Alchemy endpoint, with the public RPCs above kept as fallbacks in the same order; the provider does not change the data, which is public chain data either way, and each recorded window names the provider that served it. **The close-window recorder (§13.2 item 17).** At each NYSE close (16:00 New York; 13:00 on the listed early closes; none on a holiday or weekend, from the desk's calendar), two minutes after it, the desk reads every venue's 15-minute window ending at the close for each watched underlying (NVDA, SPY, TSLA and every NYSE token on the schedule) and appends it to its audit log: trade count, notional, volume and VWAP in USD, the stablecoin conversion applied, every response's URL and **SHA-256**, and the SHA-256 of the record. At each off-hours slot while NYSE is shut it does the same for the venues that keep no history. A failed read is retried every 5 minutes for 45 minutes; the first failure is recorded too. The TOKEN-CONSENSUS reader takes a window from this record before calling any venue, so V_0 and V_t exist for a venue whose public API forgets. The recorder only records: it runs on the live desk while the fallback stays off, so the fallback can later be judged on data the desk captured itself. **What this means today** (re-run 5 Oct 2026 with every reader above, live calls, Saturday 3 Oct 2026, V_0 at Friday's 16:00 New York close). Qualifying families per slot (floors: 5 trades, USD 10,000): | Underlying | 00:00 UTC | 08:00 UTC | 16:00 UTC | |---|---|---|---| | NVDA | **2**: bStocks (Binance, 227 trades, USD 26.0k), Robinhood (Ramses v3, 41 swaps, USD 25.1k; Uniswap v3 also qualified) | **1**: Robinhood (Ramses v3, 334 swaps, USD 295k) | **1**: Robinhood (Ramses v3, 279 swaps, USD 284k) | | SPY | **0** | **1**: Robinhood (Alandale CL, 32 swaps, USD 22.0k) | **0** | | TSLA | **1**: bStocks (Binance, 74 trades, USD 39.9k) | **0** | **0** | Kraken's xStocks windows held 0 to 2 trades at every slot, and Ondo's Ethereum pools 0 to 4 swaps under USD 500. The Solana xStocks pools could not be read for that Saturday (the recorder did not exist yet, and their source keeps 24 hours); their 15-minute volume, from the same aggregator's candles (no trade count), was about USD 11.1k for NVDAx at 00:00, USD 11.2k for SPYx at 16:00 and USD 18.3k for TSLAx at 00:00, below USD 10k elsewhere. Had the recorder been running and those windows held 5 trades, **NVDA at 00:00 UTC would have reached three families** (bStocks, Robinhood, xStocks), the only one of the nine slots to do so; every other slot would have been `NO FIXING`. A Robinhood-issued or xStocks-issued desk instrument would also need two families other than its own. **Licensing.** Public market-data endpoints are free to read, but their terms (read 5 Oct 2026) do not permit publishing a value derived from them without a licence or written consent: Kraken's terms allow its content "only for your own benefit"; Binance's public datasets are CC BY-NC-SA 4.0 and "any commercial utilization requires a separate, written enterprise data license"; MEXC prohibits, without written consent, "Data feeding or streaming services that make use of any market data of MEXC"; Gate grants use "for non-commercial or personal use"; CoinGecko's API terms (which govern GeckoTerminal's API) forbid to "derive from" its data except as the terms allow, and its free tier requires "Powered by CoinGecko", with commercial licences on paid plans only; Bybit's terms could not be read (region-blocked); DexScreener allows commercial API use but does not address derived values. **On-chain swap logs** read from a public RPC (Robinhood Chain, Ethereum) are public ledger data, not a vendor's market data; the RPC operators' own terms still govern the access. That is a reason, besides the founder's approval, why the fallback is off on the live desk: before it is switched on there, each venue used must permit publishing the derived value, or be licensed. Per-family figures are disclosed to members only (§7), as per-venue figures are. ### 3A.6 What each seat submits for an OFF-HOURS SIGNED fixing The v4 wire format of §4 is reused. The differences are the window, the ages and the new fields below. The **submission cut-off** is the fixing time + 10 minutes. Only submissions received by the cut-off count; a late one is recorded as late. If K is not reached by the fixing time + 30 minutes, the result is `NO FIXING`. At least one of the K signatures must be a venue's (§3A.1, borrower side); a K made of lender, issuer and other non-venue seats alone gives `NO FIXING`. Each seat's checker (`signer-service`, §10) runs this automatically; no human is in the loop per fixing. **Venue (`window-trades`)**, required: - Every §4.1 field, for the **15 minutes** ending at the fixing time (`windowStart` exclusive, `windowEnd` inclusive). - A venue whose range excludes P is recorded without a signature, as in §4.1. A venue with no trades attests `no-prints-attested`, and P must sit inside its quote. - New fields (*planned*): | Field | Type | Unit | Rule | |---|---|---|---| | `quoteCurrency` | string | — | `USD`, `USDC` or `USDT`. The desk converts at row 7 | | `depthSizeUsd` | number | USD | The size threshold S the depth figures describe | | `bidAtSize` / `askAtSize` | number | quote currency per unit | Best price at which S could be sold / bought at `bookAsOf`. `bidAtSize` ≤ `askAtSize` | | `bookAsOf` | instant | UTC | Within 1 minute of the fixing time | | `selfTradesExcluded` | boolean | — | As §4.1 | **Lender (`independent-mark`)**, required: - Every §4.2 field, including `markFromPublicReference`. `markAsOf` at most **15 minutes** before the submission (60 for OFFICIAL). - **Gate:** |P − mark| / P ≤ **`markBpsOffHours`**, a tolerance the lender declares in advance in its seat settings for OFF-HOURS SIGNED fixings (default: its `markBps`). The published band is shown beside the lender's result but **never widens the lender's tolerance**. A lender that wants a wider off-hours tolerance declares it in advance; the declared value is published with every fixing. This keeps §9.3(3): nobody, and least of all the administrator, widens a tolerance to make a check pass. - The lender's `haircutPct` is recorded with the band, so the tape shows how the lender translated uncertainty into margin. **Issuer (`reserve-snapshot`)**, required for W and E. **The gate still applies**: a refused issuer gate, or no passing snapshot inside the freshness limit (a silent issuer), means `NO FIXING` (issuer gate not met; never reference × par, §6.2). Off-hours changes: - `asOf` freshness for a **custodial** reserve model: the last business-day custodian statement, at most **96 hours** old, so that a Friday statement covers a weekend and a Monday holiday. *Our choice; founder decision.* - `redemptionsOpen` means the issuer is **accepting** redemption requests, even if they are processed on the next business day. xStocks run primary issuance and redemption 24/5 (A33). - New fields (*planned*): | Field | Type | Unit | Rule | |---|---|---|---| | `multiplier` | number | shares per token | > 0, ≤ 10 dp. Must equal the issuer's published multiplier | | `multiplierNext` / `multiplierActivatesAt` | number / instant | — | Required when a change is pending (e.g. xStocks activate at 00:30 UTC the day after the ex-date, A33) | | `primaryLevel` / `primaryLevelAsOf` | number / instant | USD per token | The last create/redeem price; omitted while primary issuance is closed | | `corporateActionPending` | boolean | — | `true` pauses the fixing for that asset if the action's terms are not yet final (§3A.9) | **Custodian and transfer agent:** not used. An OFF-HOURS SIGNED fixing is never a NAV. **Administrator:** reads and records the reference inputs (futures, overnight sessions, cross-listed instruments, FX) from named, licensed sources, each with its source, timestamp and a SHA-256 digest of the response. It computes P and b, and never signs. ### 3A.7 Failure rules, EXCEPTIONAL moves and halts Agreed in advance, never in the moment: 1. **Not enough inputs** (fewer than two live inputs of distinct signal types, or two that disagree by more than X): `NO FIXING`, with the reason. **Never guess.** With no hard signal type live and the TOKEN-CONSENSUS fallback switched on, fewer than three qualifying issuer families (two of them independent of the priced token's issuer) is the same `NO FIXING` (§3A.5a). 2. **A source disagrees** by more than X from the median of three or more signals: it is dropped and flagged on the tape. 3. **A signer's system is down:** the fixing proceeds if K of N sign by the cut-off, with at least one venue among them. 4. **Fewer than K signatures:** `NO FIXING`. There is **no tier 3 or tier 4 fallback** for OFF-HOURS SIGNED fixings. The last good fixing stays visible **with its age**, as oracle consumers are told to check a feed's last update time (row S16). 5. **EXCEPTIONAL move:** a move of more than **Y** since the previous OFF-HOURS SIGNED or OFFICIAL value (default Y = 10%, rulebook v0.2 §7.5) is **published**, flagged `EXCEPTIONAL`, and every signer and licensee is notified. Consumers decide how to treat it. **We do not suppress a real move.** For scale: CME's hard limit on ES outside US hours is 7% (row S17). **`EXCEPTIONAL` has this one meaning only**, in this methodology, the committee terms and the Chain-Event Policy: a move larger than Y, published and flagged. A missed attestation, a ledger outage or an issuer gate that is not met is `NO FIXING` (issuer gate not met, rule 6, §6.2), never `EXCEPTIONAL`. A chain event such as a fork or a de-peg is flagged separately as `EVENT-` (for example `EVENT-FORK`, `EVENT-DEPEG`). 6. **Halts.** `NO FIXING` for the asset, until the committee agrees a rule, while any of these holds: - the underlying is halted or suspended on its home market, or delisted; - the issuer has paused minting, burning or redemptions, attested a reserve shortfall of any size, or not submitted a passing snapshot within its freshness limit (the issuer gate is not met); - a corporate action is pending whose terms are not final (`corporateActionPending`). A market-wide circuit-breaker halt during US hours stops the home-market input (row 0), and the waterfall moves on to the next signal. Limit-locked futures are not a price: a future trading at its limit is treated as stale. 7. **Corrections.** An OFF-HOURS SIGNED fixing is never restated. An error is corrected by a **new, linked record**; consumers decide what to do about liquidations made against the original. Any licensee or signer may raise a challenge within **24 hours**, and the outcome is recorded. ### 3A.8 Mixed baskets (crypto and equity legs) - **OFFICIAL:** on the **NYSE calendar only**, at 16:00 New York. A basket strikes only on days when every component strikes (the intersection rule; implemented in the desk). - **Off-hours: OFF-HOURS SIGNED values at 00:00, 08:00 and 16:00 UTC**, every day: - **crypto legs** at their live levels: the §5.3 determination on a 15-minute window, else level (c) from a licensed reference at the fixing instant, flagged (while none is licensed: `NO FIXING`); - **equity legs** by the class-C waterfall (§3A.4–3A.5); - value per share = Σ (units per share × leg value) − accrued liabilities; - **band:** b_basket = Σ (w_i × b_i), where w_i is leg i's share of the value. This linear sum assumes the legs' errors are perfectly correlated, so it is conservative (*our choice*); crypto legs carry their dispersion as b_i; - **any leg `NO FIXING` → basket `NO FIXING`.** A gap is published as a gap. - It is labelled `OFFHOURS`, **never NAV**. Creation and redemption never settle against it; they wait for the next OFFICIAL NAV. ### 3A.9 Design choices and their precedents Same conventions as §5.0: **modelled on** a cited practice, **lifted** where a fact is taken as is, or **our choice**. ETP Foundry does not claim compliance with any of them. Full references are in Appendix A (A22–A37). | # | Design choice | Our rule | Precedent (source, section, page) | How used | |---|---|---|---|---| | S1 | A live indicative beside a daily reference rate | Layer 1 continuous, layer 3 once a day | **CF Benchmarks**, *CME CF Real Time Indices Methodology* v17.0 (21 Sep 2026) §7, p.24: BRTI disseminated "approximately every second … including weekends and holidays"; §4.2, p.15: "a robust, yet highly timely indication of the current price". The BRR is the separate daily rate (§5.0 rows 3–5) | Modelled on. Our live layer is a median of spot venues, not CF's order-book method | | S2 | Price the token, not the closed share | Layer 2 (OFF-HOURS SIGNED) values the token off-hours | **Chainlink**, *Report Schema: Tokenized Asset (v10)*, "Weekend Usage Disclaimer": "The price field does not update during weekends … However, the tokenizedPrice field continues to update as it reflects trading activity on centralized exchanges" | Modelled on | | S3 | Anchor on the official close | A = official close × multiplier | **FTSE Russell**, *Closing Prices used for Index Calculation* v5.3, p.3 (§5.0 row 20). **SEC** Rule 2a-5 adopting release, 86 FR 772–773, §II.D: funds "use previous closing prices for securities that principally trade on a closed foreign market" unless an event has occurred since | Lifted (anchor); modelled on (adjust when events occur) | | S4 | Fair value when the home market is closed | Anchor × implied change, not a stale close | **SEC** Release IC-34128, 86 FR 748 (6 Jan 2021), §II.A.3(c), 86 FR 754: the board "generally should identify and monitor for the kinds of significant events that, if they occurred after the market closes", require fair value. Rule 2a-5(c), 86 FR 808: a quotation is readily available only if it is "a quoted price (unadjusted) in active markets … at the measurement date". Historical: SEC staff letter to the ICI, 30 Apr 2001, §I.C–I.D (withdrawn 8 Sep 2022, 86 FR 774–775) | Modelled on. We are not a fund, and an OFF-HOURS SIGNED fixing is not a NAV | | S5 | Futures, ETFs and ADRs as the off-hours signal | Change signals rows 2, 2a, 5 | **ICI**, *Fund Valuation Under the SEC's New Fair Value Rule* (Dec 2021), §V.C.3, p.23 and fn 77: adjustment factors "often provided by pricing services", using "proxies and historical correlation data". **Vanguard** International Equity Index Funds, N-CSRS (Apr 2014), Note A: "foreign market proxies (for example, ADRs, futures contracts, or exchange-traded funds)". ICE FVIS: **not verified** from a primary ICE page | Modelled on. We use a direct ratio, not a correlation model: *our choice* | | S6 | Futures availability | Futures change signal live Sunday 18:00 to Friday 17:00 New York, except the daily 17:00–18:00 break | **CME Group**, ES and NQ contract specifications, "Trading hours → CME Globex": "Sunday 6:00 p.m. - Friday - 5:00 p.m. ET … with a daily maintenance period from 5:00 p.m. - 6:00 p.m. ET" | Lifted (fact). The weekend gap is our reading of those hours | | S7 | Overnight sessions in the underlying | Row 2a, 5-minute maximum age | **Blue Ocean ATS** FAQ: "8:00 PM ET- 4:00 AM ET (Sunday-Thursday)"; trades "reported to the FINRA Trade Reporting Facility". **Robinhood** 24 Hour Market: "Sunday 8 PM ET through Friday 8 PM ET". **SEC** Release 34-101777 (27 Nov 2024) approving 24X; Release 34-104894 (25 Feb 2026), p.3–5: 24X Market Session 21:00–04:00 ET, overnight SIP support projected Nov/Dec 2026. **Pyth**, "Market Hours": a separate Overnight row. **Chainlink** v11 schema: market status "Overnight" | Modelled on. On 5 Aug 2024 Blue Ocean suspended overnight trading (CNBC, secondary), so the session can vanish; row 2a has no special standing | | S8 | Token trades over 15 minutes | 15-minute VWAP, §5.3 screen | **WMR** v30, p.12: 5-minute window. **CF** BRR: 60 minutes. No precedent for 15 minutes | **Our choice. Founder decision** | | S9 | Order-book depth bound | P clamped to bid/ask at size S | **CF** RTI v17.0 §4.1.1, p.8–9 and §4.2 "Utilized Depth", p.15: the index is built from order books, using the "mid price-volume curve and mid spread-volume curve" within a depth limit | Adapted: CF prices from depth; we only bound with it. S is **our choice** | | S10 | Cross-listed instruments | Row 5, ratio k set at the last common trading instant | As S5 (ETFs as proxies) | Modelled on; the ratio method is **our choice** | | S11 | Issuer primary level only 24/5 | Row 6 is a bound, and absent on weekends | **xStocks**, *How xStocks work*, "Primary and Secondary Markets": "Primary issuance and redemption operate 24/5"; FAQ "How do xStocks operate during market off-hours?"; *Market flow*, "Key Parameters": minimum $5,000 | Lifted (fact) | | S12 | Stablecoin FX always applied | Row 7 multiplier | No published precedent found | **Our choice** | | S13 | Corporate actions and the multiplier | Adjust the anchor at ex-date / issuer activation; pause while terms are not final | **FTSE Russell**, *Corporate Actions and Events Guide* v7.1 (Sep 2026): §1, p.3, adjustment "on the ex date"; §4.1, p.7, split factor; §4.2, p.7, special dividends deducted "before the open on the ex date". **S&P DJI**, *Equity Indices Policies & Practices* (Aug 2026, read via a Wayback copy), p.19 special dividends, p.24 splits. **xStocks**, *Dividends and stock splits*: dividends reinvested "reflected through a multiplier increase", activation "00:30 UTC on the day immediately following the Ex-Date". **Chainlink** v10: `currentMultiplier`, `newMultiplier`, `activationDateTime`; *Tokenized Equity Feeds*, "Pause confirmation for corporate actions" | Modelled on | | S14 | Band grows with √time | z · σ · √τ term | **Basel Committee**, *Amendment to the Capital Accord to Incorporate Market Risks* (Jan 1996), §B.4(c), printed p.44: VaR "scaled up to ten days by the square root of time". **Pyth**, "Best practices", "Confidence Intervals": price ± interval "intended to achieve 95% coverage" | Modelled on (scaling and the idea of a published interval). The formula and every parameter are **our choice. Founder decision**. Unlike Pyth's stated 95% target, our coverage is unmeasured until back-tested (§3A.5) | | S15 | Insufficient data → NO FIXING | Fewer than two live inputs of distinct signal types | **Chainlink**, *Selecting Quality Data Feeds*, "ETF and Forex feeds": "Do not use these feeds outside those windows". **Pyth**, "Best practices", "Price Availability": outside market hours "it's not clear what an equity's price is". **CF** Criteria v8.5 §2: two constituents | Modelled on | | S16 | Last good value shown with its age; consumers check staleness | §3A.7 rule 4 | **Chainlink**, *Getting Historical Data*: `updatedAt` "The timestamp when the answer was computed"; *Tokenized Equity Feeds*: "Implement staleness detection by monitoring the feed's last update timestamp". **Pyth**: SDKs apply "a staleness check by default" | Modelled on | | S17 | EXCEPTIONAL moves are flagged, not halted | Y = 10%, flag and notify | **CME Group**, *S&P 500 Price Limits: FAQ* (22 Sep 2020), Q3: "a hard upside and downside limit of 7% from 5:00 p.m. to 8:30 a.m." (CT). **NYSE** Rule 7.12 (SEC Release 34-106380, 91 FR 59278, 18 Sep 2026): 7%, 13%, 20% market-wide levels | Adapted: those venues halt or limit trading; a fixing cannot stop a market, so it flags. Y is **our choice. Founder decision** | | S18 | Halts → NO FIXING | §3A.7 rule 6 | **Chainlink**, *Tokenized Equity Feeds*, corporate-action pause: "the feed freezes at the last known good token value during the pause window". **LULD Plan** (SEC-approved 31 May 2012, luldplan.com) | Adapted: we publish `NO FIXING` rather than freeze, so no consumer mistakes a frozen value for a fresh one. *Our choice* | | S19 | Fixed times 00:00 / 08:00 / 16:00 UTC | Three a day, weekends included | No verified precedent for these times was found. Chainlink's tokenized-equity feeds are 24/5 and continuous, not fixed-time | **Our choice. Founder decision** (8-hourly or hourly, §14) | | S20 | Mixed baskets on the NYSE calendar; linear band sum | §3A.8 | FTSE Russell, *Closing Prices* p.3: a closed market carries its last close. No precedent for the band sum | Modelled on (calendar); **our choice** (band) | ### 3A.10 Worked examples Worked example C (§5.7) takes SPYx through a weekend fixing (futures closed) and a Sunday-night one (futures live). ### 3A.11 What exists in code, and what does not Summarised here; the build list is in §13.2. **Phase 1 was built on 5 Oct 2026.** **Before phase 1:** - Layer 1 for BTC and ETH (internal only, never displayed publicly while its sources are not licensed for publication). - An unsigned indicative basket NAV. - One OFFICIAL strike per instrument per day, the `nyse` calendar and the intersection rule for baskets. - The crypto OFFICIAL strike is 16:00 London **every calendar day, weekends and holidays included**. On the DevNet pilot desk the OFFICIAL strike runner is switched off, so no OFFICIAL strike is made on any day there. **Built in phase 1:** - **Schedule:** slots at 00:00, 08:00 and 16:00 UTC every day, with a 15-minute window and a cut-off at the slot + 10 minutes. - The home market's state is computed at each slot (NYSE regular session, early closes and holidays). - Where a slot is the instrument's OFFICIAL strike, the slot points to it. - **Determination:** - crypto by the §5.3 determination on the 15-minute window; - tokenised equity by the class-C waterfall: anchor, signals by priority, screen, depth bound, band, `NO FIXING`; - baskets by Σ units × leg value with the linear band. Any leg `NO FIXING` makes the basket `NO FIXING`. - **Anchor:** the instrument's last OFFICIAL committee fixing at a home-market close. It is stale once a newer close passes with no OFFICIAL fixing. The home market's licensed closing price is not used. - **σ** comes from the OFFICIAL fixings. With fewer than 20 daily returns, a default of 200 bp a day is used and flagged. - **Seats' off-hours submissions** (protocol v4.1): the venue window and the book at size; the lender's mark against the tolerance it declared in advance; the issuer's snapshot (96 h for a custodial reserve), multiplier, primary level and corporate-action flag. - **Gates, applied at the cut-off:** K signatures with a venue among them, the lender gate, the issuer gate, and the halts. - **The issuer weekend rule (founder decision):** for a tokenised equity whose home market is shut at the slot, "redemptions closed: primary market closed" is the expected state, not a gate failure. - It is flagged `PRIMARY-CLOSED`. - Reserves must still cover supply, and the freshness, mint/burn and corporate-action rules still apply. - The same reason while the home market is open is a halt. - **The minimum of two signal types is kept.** It is a published parameter. - **The TOKEN-CONSENSUS fallback (§3A.5a) is built and switched off on the live desk.** With no hard signal live, it takes the median move of at least three issuer families' tokens (two of them independent of the priced token's issuer), each from its most liquid eligible venue, flagged `TOKEN-CONSENSUS` ("tokens only, lower confidence"), tier 0. - Public, read-only readers exist for xStocks on Kraken and bStocks on Binance (USDT converted at a public USDT/USD rate over the same window). Robinhood, Ondo and Dinari have no reader yet (§3A.5a says why). - The per-family figures are disclosed to members only. - The sandbox runs it on, with scripted inputs, and says so on every record. - **Publication:** `GET /api/offhours` and `GET /api/offhours/{id}`, the desk, the benchmark pages and the publication record. Each is labelled `OFF-HOURS SIGNED · pilot — not attested · not a NAV · uncalibrated band`. - Each record carries a SHA-256 digest. - Per-venue figures are withheld from the public view until each venue consents. - An on-chain relay refuses an off-hours value as a NAV. **Not yet:** - a ledger slot, so phase 1 signatures are the seats' recorded submissions with the published rule applied; - every licensed class-C input (home-market live, futures, overnight sessions, cross-listed instruments, token trades and books off Canton, stablecoin FX, corporate-action calendar); - for TOKEN-CONSENSUS: a V_0 capture at each close, readers for Robinhood Chain and Ondo, each venue's terms for publishing a derived value, and the founder's approval to switch it on; - the band back-test; - attested (above tier 0) off-hours values; - linked corrections and the 24-hour challenge; - custodian corroboration of the weekend issuer rule. --- ## 3B. Tokenised equities, corporate actions and baskets of tokens **Why this section exists.** Type E (a token that represents a share) and type F (a basket or index of tokens) need the rules an index provider publishes for shares and indexes: which close is the reference, what happens when a stock is halted, how a split or a dividend reaches the token, and how a basket keeps its level continuous when its legs change. This section writes those rules down. It is modelled on the published methodologies of S&P Dow Jones Indices, FTSE Russell, MSCI and CF Benchmarks (§3B.9; Appendix A, A11, A35 and A38–A40). It does not change §3, §3A or §5: the input hierarchy, the off-hours family and the determination stay as they are, and §3A's off-hours rules apply unchanged to every token priced here. > **Status, stated plainly (6 Oct 2026).** Most of this section is **written, not built**. No tokenised equity is on the live desk's roster, no OFFICIAL equity fixing has been made, and no official closing price is licensed or wired. What is built is listed in §3B.0, row by row; everything else is marked *written*. Nothing here makes a value easier to publish: every rule either defines a reference, adds a halt, or keeps a level continuous. ### 3B.0 What is built and what is written | Rule | Status (6 Oct 2026) | |---|---| | NYSE calendar for any instrument or basket with an equity leg: OFFICIAL strike at 16:00 New York on NYSE days only; a basket strikes only when every leg strikes (the intersection rule) | **Built** | | NYSE early closes (13:00 New York) | **Built for the off-hours schedule and the close-window recorder only.** The OFFICIAL strike schedule does not yet know early closes: on 27 Nov 2026 and 24 Dec 2026 it would strike at 16:00. *Written* (§3B.1; §13.2 item 19) | | Issuer's share ratio change (`multiplier`, `multiplierNext`, `multiplierActivatesAt`) adjusting the off-hours anchor; `corporateActionPending` halting the off-hours fixing | **Built** (off-hours only, §3A.11) | | Official closing price of the primary listing × share ratio (§3B.1) | *Written.* Needs a licensed closing-price source (§13.2 items 7 and 18) | | Home-market halt or suspension detected automatically (§3B.2) | *Written.* No home-market status feed is wired; a halt reaches the desk today only through the issuer's `corporateActionPending` or a paused mint/burn | | Corporate-action table, notices, ex-date handling and the disagreement halt (§3B.3) | *Written.* No corporate-action calendar or issuer-notice record exists in code | | Basket legs as fixed units per share (`unitsPerShare`); a percentage weight converted to units once, at creation, from a stated NAV per share and the legs' marks | **Built** (the fund definition and the create-an-ETP assistant) | | Basket NAV = Σ units × each leg's fixing − accrued fees; no leg value, no NAV | **Built** (the ledger's NAV arithmetic and fee accrual; the EVM vault's fee multiplier) | | Scheduled rebalance with an announced, cancellable waiting period before a new basket applies | **Built in the EVM vault only** (proposal, at least 1 day, default 2 days, then apply; the vault is paused while the set of legs changes). Not built on Canton: the Daml basket has no rebalance choice | | Equal weight, capped weight, an index level with a divisor, rebalance reference prices, unscheduled removals (§3B.4–§3B.6) | *Written* | ### 3B.1 A single tokenised stock: the reference **Reference.** For a type E token, the reference at an OFFICIAL strike is `R = C × r` - **C** is the **official closing price** of the underlying share on its **primary listing**, as published by that exchange for the strike day. On US exchanges this is the closing auction price, which is what FTSE Russell uses for every US exchange ("Official Closing Price (Auction)", *Closing Prices used for Index Calculation* v5.3, p.6). Where the exchange's own rules set the official close by another method (for example when no auction prints), the exchange's published official close is used as published, never a price the desk derives. - **r** is the token's **share ratio**: shares of the underlying represented by one token, as stated in the issuer's terms and in force at the strike. xStocks call it the multiplier (A33). A ratio change that activates after the strike applies from the next strike. **Where R is used.** R is the type E **level (c)** input of §3 (the hierarchy is unchanged: the token's own Canton trades and quotes come first, levels (a) and (b)); the **anchor** of every off-hours value (§3A.4 row 1, §3A.5 step 1); and the value published beside each OFFICIAL equity fixing so a reader sees the token's basis to the share. Like every level (c) input, it **requires a licensed source** (§3.1): exchange closing prices are licensed market data. Until one is licensed, level (c) is unavailable for publication, and the phase-1 off-hours anchor stays the last OFFICIAL committee fixing (§3A.11). **What counts as the primary listing.** 1. The listing the token's terms name as the underlying. 2. Otherwise, the exchange on which the share is **listed**, not one on which it merely trades under unlisted trading privileges. For a US share that is its listing exchange (for example NYSE, Nasdaq, NYSE American, NYSE Arca or Cboe). 3. A token on a depositary receipt references the receipt's listing, not the foreign share. 4. A share with more than one primary listing: the listing named in the terms; if none is named, the listing with the highest traded value over the past 12 months, decided when the instrument is admitted (§3B.8) and changed only under §9.6. A non-USD primary listing also needs a named, licensed FX rate at its close; none is approved, so only USD listings are admissible today (*written*). **The strike.** The OFFICIAL equity strike is the primary listing's close: 16:00 New York on NYSE days, **13:00 New York on an NYSE early close** (the observation window ends at the early close), and no strike on an NYSE holiday (§1, §3A.8). *Written for early closes; built otherwise.* On an unscheduled closure, the exchange's own guidance decides whether a close exists, as S&P DJI follows exchange guidance and SEC Rule 123C closing contingency procedures (*Equity Indices Policies & Practices*, p.41). A day the primary listing declares closed is not a strike day. ### 3B.2 Halts, suspensions, holidays | Situation | Single token (OFFICIAL) | Basket or index level | Off-hours (§3A) | |---|---|---|---| | Halted intraday, reopens and an official close is published | Normal: R uses that close | Normal | Normal | | Halted or suspended at the close; no official close for the day | **No OFFICIAL fixing** for the token that day, published as a gap with the reason `HOME-HALTED` | **Index level:** the leg carries its last OFFICIAL value, flagged `CARRIED`, as index providers carry the last close of a suspended stock. **NAV:** none (§3.1 F, a missing leg means no NAV) | `NO FIXING` (§3A.7 rule 6, unchanged) | | Suspension lasting more than **5 NYSE trading days** | Still no fixing | The leg is reviewed as an unscheduled change (§3B.6) | `NO FIXING` | | Delisted | The token's benchmark is reviewed for cessation (§9.7) | Removed under §3B.6 | `NO FIXING` | | Scheduled NYSE holiday or weekend | No strike (not a gap) | No strike; a mixed basket strikes only on NYSE days (§3A.8) | Off-hours values continue (§3A) | *Precedents:* S&P DJI "carries forward the last available official closing price of suspended stocks" and reviews them after 60 business days (*Policies & Practices*, p.34); FTSE Russell keeps a suspended constituent "for a period of up to 20 business days at its last traded price" (*Corporate Actions and Events Guide* v7.1, §4.18, p.24); MSCI "carries forward the market price prior to the suspension" (*Corporate Events Methodology*, Feb 2026, §5.1, p.61). Those are index levels, not fund NAVs; our NAV rule stays stricter. The 5-day review trigger is **our choice** (shorter than every precedent, because a token that cannot be priced is collateral that cannot be valued); *founder decision* (§14). ### 3B.3 Corporate actions on a token **Principle.** A corporate action changes what one token is worth in shares; it must never change the price series by itself. Every action is applied **on its ex-date, before the first strike of that day**, as index providers do (FTSE Russell: "subject to an adjustment on the ex date", *Corporate Actions and Events Guide*, §1, p.3; MSCI applies a price adjustment factor "to neutralize ... the price movement due to the event", *Corporate Events Methodology*, §1, p.5). For a token, the adjustment is a change to the ratio r, or a cash or token distribution, **as the issuer's token terms say**; the desk never chooses the treatment. | Event | Effect on the token | Effective | Rule | |---|---|---|---| | **Split / reverse split** | r × (new shares / old shares); C falls (or rises) in proportion, so R is unchanged | Ex-date (the split's effective date on the primary listing). Where the issuer re-denominates tokens instead (more tokens, same r), the token count changes and r does not | FTSE Russell §4.1, p.7; MSCI §3.1, p.44; S&P DJI p.24 | | **Cash dividend** | Per the token terms, declared by the issuer for each token: **reinvest** (r rises by dividend ÷ the ex-date reference close, net of any withholding the issuer applies; xStocks activate it at 00:30 UTC the day after the ex-date, A33); **distribute** (cash or stablecoin paid to holders; r unchanged; the token trades ex-dividend from the ex-date); or **accrue** (r unchanged; the accrued amount is a separate, stated claim until paid) | Ex-date; for reinvest, the issuer's activation time | The issuer's terms decide. A token whose terms do not say which applies is not admitted (§3B.8) | | **Special dividend** | As a cash dividend, under the same declared treatment | Ex-date | FTSE Russell §4.2, p.7: special dividends deducted "before the open on the ex date"; S&P DJI p.19 | | **Stock dividend / bonus issue** | Same stock: r × (1 + bonus ratio). Different stock: as a spin-off | Ex-date | FTSE Russell §4.7, p.9; MSCI §3.2, p.44 | | **Spin-off** | Per the token terms: the issuer delivers the spun-off shares as a **new token** (holders receive it; the parent token's r is unchanged and C falls on the ex-date, so the token's value falls by the spun-off value), or **sells and reinvests** (r rises by the proceeds ÷ the parent's reference close). A spun-off share that is not yet trading is valued at zero until it trades, flagged | Ex-date | S&P DJI adds a spin-off "at a zero price at the market close of the day before the ex-date" (*Policies & Practices*, p.8); MSCI §2.8, p.35 | | **Merger or acquisition, cash** | The token converts to cash per the terms; the benchmark ceases (§9.7) or is restated as a cash claim | The completion date; the last OFFICIAL fixing is the last primary-listing close | S&P DJI: deletions at "the security's closing price on the deletion date" (p.6) | | **Merger, stock or mixed** | r becomes r × exchange ratio into the acquirer's share, and the primary listing becomes the acquirer's; the cash part is distributed or reinvested per the terms | Completion | **MSCI** §2.1, p.7; **S&P DJI** p.6; **FTSE Russell** §2.1.5, p.4 | | **Tender offer** | No change while the offer is open. Applied only if the issuer tenders the underlying (the terms say whether it may); then as a cash merger for the tendered part | Final results | S&P DJI p.8: implemented "only after the final results" are announced | | **Rights issue** | Per the terms: the issuer **sells the rights and reinvests** (r rises by proceeds ÷ reference close), **exercises and reinvests**, or **lets them lapse** (no change; the dilution falls on the token) | Ex-date | S&P DJI p.10; MSCI §3.6, p.48 | | **Delisting** | The reference ends at the last primary-listing close. Redemption follows the terms | Last trading day | S&P DJI: removed "at the primary exchange price, if available, or at a zero price" (p.5) | | **Symbol, name, CUSIP or ISIN change** | No price effect. The instrument's identifiers are updated on the record; the desk instrument id does not change | Effective date | No price effect, so no adjustment; *our choice* (no precedent cited) | **Sources and notice.** Every action needs two records before it is applied: 1. **The issuer's notice**: the action, its ex-date or activation time, the treatment under the token terms, and the new r (or the distribution). It is the issuer seat's signed submission (`multiplierNext`, `multiplierActivatesAt`, `corporateActionPending`), published on the record. 2. **The announcement source**: the company's own public announcement (its filing with its regulator, or its press release) and the primary listing's notice of the ex-date. The administrator records both, each with its URL, time read and SHA-256. The issuer's notice is due **at least 2 NYSE trading days before the ex-date** (FTSE Russell recognises "a minimum two-day notice requirement" for actionable events, §2.1.5, p.4; S&P DJI finalises merger changes with "at least one (1) business days' notice" for US-listed stocks, p.6). A late notice does not stop the adjustment if the terms are final and the sources agree; it is flagged `LATE-NOTICE`. **When the issuer's notice and the exchange's record disagree** (a different ex-date, ratio, amount or treatment from the company's announcement or the listing's notice), or either is missing by the ex-date: - **halt**: the token's OFFICIAL and off-hours fixings are `NO FIXING` with the reason `CA-DISAGREEMENT`, from the ex-date until they agree (the same halt as `corporateActionPending`, §3A.7 rule 6); - **flag**: the disagreement is published on the issuer's sources-and-agreement record (§4.3, §7) and goes to the oversight function's review (§9.1); - **never pick a side**: the desk applies neither version. A basket holding the token follows §3B.2 (index level carried and flagged; no NAV). ### 3B.4 Baskets and indexes: eligibility and weighting **Constituent eligibility.** A token may be a leg of a basket or index only if, at admission and at every rebalance: 1. it has a **valid committee fixing** (a fixing of its own, under its own committee), or a **fallback approved for that leg** in the basket's terms and named on the record; 2. its token terms state the treatment of every corporate action in §3B.3 (type E); 3. its committee is constituted and its strike calendar is known. A leg that loses its fixing is handled under §3B.6; it is never priced by the desk instead. **Weighting schemes.** Each basket states one scheme in its terms. The fixing arithmetic is always **fixed units between rebalances**: NAV or level = Σ units × leg value. The scheme decides only how the units are set at each rebalance. | Scheme | Units set at a rebalance | Between rebalances | Status | |---|---|---|---| | **Fixed units** | Units per share are the basket's definition; they change only by a basket change | Weights drift with prices | **Built** (`unitsPerShare`) | | **Fixed weights converted once** | units_i = w_i × NAV per share ÷ value_i, from a stated NAV per share and each leg's reference value | Weights drift | **Built** at creation (the create-an-ETP assistant shows the calculation); at a rebalance, *written* | | **Equal weight** | w_i = 1/n, then as above | Weights drift; reset at each rebalance | *Written* | | **Capped market-capitalisation weight** | w_i proportional to the leg's market value (free-float shares × price for an equity; circulating supply × price for a crypto asset), then any w_i above the cap c is set to c and the excess spread pro rata over the uncapped legs, repeated until none exceeds c | Weights drift; a cap is restored only at the next rebalance (fixed-frequency capping) unless the terms adopt an emergency rebalance trigger | *Written*. The cap is per basket (for example 20%, or 10/40); a basket with n legs and cap c needs n × c ≥ 100% | *Precedents:* S&P DJI's equal weighted index "must be rebalanced from time to time to re-establish the proper weighting" (*Index Mathematics*, Sep 2026, p.16), and its capped indexes are reweighted at rebalancings (p.10). CF Benchmarks caps "at rebalance points" for fixed-frequency capping, or by "emergency rebalances" for dynamic capping (*Multi Asset Series Ground Rules* v4.4, §4.6.1–4.6.2, p.27). ### 3B.5 Keeping the level continuous: units, divisor and rebalancing **Two kinds of basket value.** - **A fund NAV per share** (type F) is Σ units per share × each leg's fixing − accrued fees and liabilities (§3.1 F). It falls by the fee every day, by design: it is what a share is worth. The fund's holdings change only by creation, redemption, a fee or a rebalance, and a rebalance delivers new units, so the NAV is continuous by construction. **Built.** - **An index level** (an unfunded benchmark of tokens, if one is published) is `I = Σ (q_i × P_i) / D`, where q_i are the index units, P_i each leg's fixing and D the **divisor**. It deducts no fees. *Written; no index level is published.* **Divisor maintenance.** Whenever anything other than prices changes the index's market value (a leg added or removed, a rebalance, a corporate action not already neutral in r), the divisor is reset **after the close** so that the level is the same before and after: `D_new = D_old × (Σ q_new × P) / (Σ q_old × P)`, both sums at the same closing prices. This is S&P DJI's method: the divisor exists "to maintain the continuity of an index level following the implementation of corporate actions, index rebalancing events, or other non-market driven actions", and adjustments are made "after the close" (*Index Mathematics*, p.5 and p.8). A corporate action handled through r (§3B.3) is already neutral for the token's value and needs no divisor change; a cash distribution that leaves r unchanged does, unless the index is a total-return variant that reinvests it. **Scheduled rebalancing.** - **Calendar:** stated in each basket's terms (for example quarterly, effective after the close on the third Friday of March, June, September and December). A rebalance takes effect only on a day every leg strikes (the intersection rule). - **Announcement:** the new units or weights, the reference date and the effective date are published at least **5 NYSE trading days** before the effective date, and the basket is frozen to further changes from the announcement. On the EVM vault the same proposal sits in its timelock, at least 1 day and by default 2, and can be cancelled in that window (**built**). *Our choice for 5 days*, longer than the one or two business days' notice S&P DJI gives when it finalises a merger change (*Policies & Practices*, p.6); *founder decision*. - **Reference prices:** units are computed from each leg's **OFFICIAL fixing on the reference date**, the strike at least 2 NYSE trading days before the effective date, so the announced units can be traded before they apply. A leg with no OFFICIAL fixing on the reference date uses its last one, flagged; a leg with none at all is not admitted. - **Effective:** after the close of the effective date. The last NAV or level under the old units is struck at that close; the new units apply from the next strike. ### 3B.6 Unscheduled changes | Trigger | Action | Notice | |---|---|---| | A leg is **delisted**, its token ceases, or its fixing is withdrawn | The leg is removed at its last OFFICIAL fixing (for a delisting: its last primary-listing close; S&P DJI uses the primary exchange price "if available, or ... a zero price", p.5). Its value is redistributed to the remaining legs pro rata, or to a named replacement if the basket's terms name one. For an index, the divisor keeps the level unchanged | At least 2 NYSE trading days where the event is announced in advance; otherwise as soon as it is known, flagged `UNSCHEDULED` | | A leg **loses its fixing** (no committee fixing and no approved fallback) for more than **5 strike days**, or is halted for more than 5 NYSE trading days (§3B.2) | Reviewed by the administrator and, once constituted, the oversight function: keep and wait, or remove as above | The review and its outcome are published; removal with at least 2 NYSE trading days' notice | | A **corporate action** on a leg (§3B.3) | Handled in the leg's r; the basket's units do not change. A spin-off delivered as a new token joins the basket at the units received, until the next rebalance | As §3B.3 | | A **disagreement halt** on a leg (§3B.3) | The basket follows §3B.2: index level carried and flagged; no NAV | — | On the EVM vault, a change to the set of legs is applied while the vault is paused, so no creation or redemption straddles two definitions (**built**). CF Benchmarks gives the precedent for an exceptional removal of a crypto constituent: a review dated "the 7th day immediately preceding" the removal, communicated to licensees (*Multi Asset Series Ground Rules*, §3.8, p.18). ### 3B.7 Mixed crypto and equity baskets Unchanged from §1 and §3A.8, and stated here so the rules read together: - **any basket with an equity leg strikes OFFICIAL at the home-market close**, 16:00 New York on NYSE days (13:00 on an early close, §3B.1), and only on days every leg strikes; - each leg enters at **its own OFFICIAL fixing of that day**: an equity leg at its home close, a crypto leg at its 16:00 London fixing. The basket waits until every leg's fixing is settled, and a missing one means no NAV. This is how index providers treat a market that closes earlier, using each market's own close (FTSE Russell, *Closing Prices used for Index Calculation*, p.3), and it means a crypto leg is about five hours older than the equity close; the gap is disclosed with every such NAV. **Built** (the basket waits for its components and reads their fixings); - off-hours, the basket has OFF-HOURS SIGNED values under §3A.8, never a NAV; - rebalance reference prices (§3B.5) are the OFFICIAL fixings at the basket's own strike, for every leg. ### 3B.8 Corrections and governance **Corrections.** An OFFICIAL equity fixing, a basket NAV and an index level are corrected only under §6.5 (materiality 1 bp, `RestatementProposal`, two business days). A corporate action applied with the wrong r or on the wrong date is an error under §6.5, and every value it touched is restated, each pointing back to the original. Off-hours values are never restated (§3A.7 rule 7). **Who approves what.** These hooks use the existing governance; they add no new body. - **A new tokenised stock** is admitted by the administrator when §3B.4's eligibility holds, its committee is seated (§4), and its token terms and primary listing are recorded; the admission is published. Once the oversight function exists (§9.1), admissions are in its remit ("review every gate refusal, exclusion and fallback"). - **A new basket or index** is defined by its sponsor's terms (legs, scheme, cap, calendar, fallbacks) and admitted on the same basis; its rules are published before its first strike. - **A material change** to a published basket's rules (the scheme, the cap, the rebalance calendar, a fallback) or to any rule of this section follows §9.6: a consultation of at least 30 days and at least 30 days' notice. Scheduled rebalances under published rules are not methodology changes; they follow §3B.5's notice. - **Cessation** of a token's benchmark or a basket follows §9.7. - The **annual review** (§9.8) covers this section: how many corporate actions were applied, flagged late or halted for disagreement, and the halts and removals in baskets. ### 3B.9 Design choices and their precedents Same conventions as §5.0 and §3A.9. ETP Foundry does not claim compliance with any of them. | # | Design choice | Our rule | Precedent (source, section, page) | How used | |---|---|---|---|---| | E1 | Reference is the official closing auction price | R = C × r, C from the primary listing | **FTSE Russell**, *Closing Prices used for Index Calculation* v5.3, p.6: US exchanges, "Official Closing Price (Auction)" (A11) | Lifted | | E2 | Suspended stock carries its last close in an index | §3B.2; no NAV for a fund | **S&P DJI**, *Equity Indices Policies & Practices* (Aug 2026), p.34; **FTSE Russell**, *Corporate Actions and Events Guide* v7.1, §4.18, p.24; **MSCI**, *Corporate Events Methodology* (Feb 2026), §5.1, p.61 | Modelled on (index level); stricter for NAV, *our choice*. The 5-day review is *our choice* | | E3 | Corporate actions on the ex-date, neutral to the series | §3B.3 | **FTSE Russell** §1, p.3 and §4.1–4.7, p.7–9; **MSCI** §1, p.5 (price adjustment factor) and §3, p.44–48; **S&P DJI** p.8–10, p.19, p.24 | Modelled on. The token's treatment comes from the issuer's terms, not ours | | E4 | Two-day notice of actionable events; halt when sources disagree | §3B.3 | **FTSE Russell** §2.1.5, p.4; **S&P DJI** p.6; **MSCI** §8.1, p.68: changes "announced to clients prior to their implementation" | Modelled on (notice). The disagreement halt is *our choice*, as Chainlink pauses a feed for corporate actions (A31) | | E5 | Divisor keeps the level continuous | §3B.5 | **S&P DJI**, *Index Mathematics* (Sep 2026), p.5 and p.8 | Lifted (method) | | E6 | Equal and capped weights, reset at rebalance | §3B.4 | **S&P DJI**, *Index Mathematics*, p.10 and p.16; **CF Benchmarks**, *CF Digital Asset Index Family, Multi Asset Series, Ground Rules* v4.4 (31 Aug 2026), §4.5–4.6, p.25–27 | Modelled on | | E7 | Exceptional removal of a leg | §3B.6 | **CF Benchmarks**, *Ground Rules* v4.4, §3.8, p.18; **S&P DJI**, *Policies & Practices*, p.5 | Modelled on | | E8 | Rebalance announced 5 trading days ahead; reference prices 2 days before effective | §3B.5 | **S&P DJI**, *Policies & Practices*, p.6 (one or two business days' notice of a merger change); the EVM vault timelock (built) | *Our choice; founder decision* | --- ## 4. What each seat submits **Principle: each seat contributes what only it holds.** Every seat submits numbers from its own systems, signed and timestamped. The administrator validates the form, applies the rule and records the result. A **malformed** submission is refused with HTTP 422, naming the field. A **well-formed** submission that fails its gate is recorded as that seat's **refusal**, with the numbers. Nothing is signed on-ledger for a refusal. Every accepted submission is recorded with: - a SHA-256 digest of the fields as received; - the protocol version; - the seat's identity. This makes the stored record verifiable later. The wire names below are exact. They are served by `GET /api/signer-protocol` and enforced by the desk before anything is submitted. **Who produces the submission: two modes, labelled on every value** (29 Sep 2026, §10). - **Own checker (own cloud or own machine).** The seat runs the reference checker, `signer-service`, reads its own systems and signs with a key it holds (an HSM or cloud KMS key, or a key file). This is the only mode whose signatures can count toward tier 1. - **Hosted by ETP Foundry.** For the pilot, a seat may instead connect its data sources in the dashboard ("Connect your data": a public reserve source, a REST JSON endpoint with a read-only key, or manual status flags) and let the administrator's hosted runner build and submit the same v4 submission, with the same builder and the same desk validation. **The administrator then chooses and fetches the inputs, so a hosted submission is administrator-operated for §6.4 condition 3 and never counts toward K or tier 1, whatever key signs it**, including the seat's own Google Cloud KMS key at L2. It is labelled "Hosted by ETP Foundry — pilot, counts as operator-run (tier 0)" in the dashboard and the API. ### 4.1 Venue: price contributor (condition `window-trades`, required) *Only the venue holds its own trade tape.* This is the price input. Nobody else can supply it. | Field | Type | Unit | Precision | Rule | |---|---|---|---|---| | `windowStart` | instant | UTC | — | Start of the window the figures cover. Not before the observation window opens | | `windowEnd` | instant | UTC | — | After `windowStart`. Not after the confirmation window closes, and not in the future | | `tradeCount` | integer | trades | 0 dp | ≥ 0 | | `volume` | number | units of the instrument | ≤ 10 dp | ≥ 0. Equals 0 exactly when `tradeCount` = 0 | | `vwap` | number | USD per unit | ≤ 10 dp | Required when `tradeCount` > 0. `low` ≤ `vwap` ≤ `high` | | `low` | number | USD per unit | ≤ 10 dp | Required when `tradeCount` > 0. > 0 | | `high` | number | USD per unit | ≤ 10 dp | Required when `tradeCount` > 0. ≥ `low` | | `haltSeconds` | integer | seconds | 0 dp | 0 ≤ value ≤ the window's length | | `bidTwap` | number | USD per unit | ≤ 10 dp | With `askTwap`, when `tradeCount` = 0 and the venue quoted. > 0, ≤ `askTwap` | | `askTwap` | number | USD per unit | ≤ 10 dp | As above | | `quotedSeconds` | integer | seconds | 0 dp | Required with quotes. Time the book was two-sided, ≤ the window's length | | `selfTradesExcluded` | boolean | — | — | **Required (built).** The venue attests that the figures exclude self-matched trades, trades between affiliated accounts, and trades with the venue or its affiliates as principal. `false`, or absent once the field is required, makes the window ineligible for level (a) | **Window convention.** `windowStart` is exclusive and `windowEnd` is inclusive: a trade at exactly the strike belongs to the window that ends at the strike. This matches CF Benchmarks' partition convention (methodology v17.4 §4.1.1). ### 4.1a Venue: data-sharing, audit right and surveillance (conditions of eligibility) A venue's windows count toward a level (a) value **above tier 0** only while all of the following hold. Without them the venue may still enter a determination, which is then held at tier 0 and names the venue and the missing condition (§6.4 condition 4); the code applies exactly this rule. Each condition is modelled on the CF Constituent Exchange Criteria v8.5 §3 (criteria 2–5, from pdf p.5: market integrity, KYC/AML, regulatory compliance, and data-sharing with CME). The specific terms are **our choice**. 1. **Data-sharing and audit right.** The venue has signed the committee terms' data-sharing clause. It gives the administrator, and the oversight function once constituted, the right to receive the trade-level records behind any submission within **5 business days** of a request. A venue that does not produce them is suspended from level (a) until it does. 2. **Self-trade and wash-trade exclusion.** The venue excludes the trades listed under `selfTradesExcluded` and attests to it on every submission. 3. **Surveillance.** The venue runs market surveillance over the token's book (at least spoofing, layering, wash and marking-the-close alerts), and reports any alert that touches an observation window to the administrator within 1 business day. 4. **Admission.** Before first use, the venue must show 90 days of trading history in the token. The administrator publishes its share of total window volume across eligible venues. The CF test, more than 3% of the reference rate's average daily window volume over 90–180 days (criterion 1, p.5), is the model. The threshold is a **founder decision**. *Status:* none of these is contracted. They are conditions of any tier 1 value at level (a) (§6.4). The desk keeps a record per venue, and the record counts only once a majority of the independent oversight members have countersigned it from their own authenticated accounts (built, 29 Sep 2026); an entry made by the administrator alone does not satisfy the condition. **Ledger mapping.** The deployed Daml package (`crossdesk 3.2.0`, `Governance.checkEvidence`) requires a confirming venue to state a traded range, and refuses a proposed value outside it. - **Trades in the window:** `low` and `high` become the on-ledger `observedLow` and `observedHigh`. - **No trades:** the confirmation carries `no-prints-attested`, with the time-weighted bid and ask checked by the desk. - **Range excludes the proposed value:** the submission is **recorded without a signature**. It still feeds the determination (§5.5). ### 4.2 Lender: risk-side challenge (condition `independent-mark`, required) *Only the lender knows its own mark, its eligible-collateral schedule and its haircut. It is the seat that loses money if the value is too high.* Its function is a **risk-side challenge**: the value must agree with the number the lender's own risk system uses. **What this check is, stated plainly.** A lender's collateral engine for a wrapped BTC token will usually mark it off a public BTC price. Where it does, the check tests that the fixing is within the lender's tolerance of that public reference. It is then a **cap on the token's basis to the underlying**, not an independent valuation of the token, and it is disclosed as such on every fixing. Only a mark derived from the lender's own executed transactions or liquidations in the token counts as independent price evidence. "Independent" in the IPV sense (CRR Art. 105(8)) means independent of the party that benefits; it does not mean an independent source of information. | Field | Type | Unit | Precision | Rule | |---|---|---|---|---| | `mark` | number | USD per unit | ≤ 10 dp | > 0. From the lender's own risk or collateral system | | `markAsOf` | instant | UTC | — | Not in the future. **At most 60 minutes before the submission itself** (built) | | `eligible` | boolean | — | — | Is the asset on its eligible-collateral schedule today. `false` is a refusal | | `haircutPct` | number | percent | ≤ 2 dp | Required when `eligible`. 0 ≤ h < 100 | | `markSource` | string | — | ≤ 200 chars | **Required** (built). The method behind the mark, e.g. `risk engine: BRR × 0.998` or `own liquidations, 7-day VWAP`. Recorded, not checked | | `markFromPublicReference` | boolean | — | — | **Required (built).** `true` when the mark is derived from a public reference price for the underlying (for example BRR × factor). Published with the fixing, so every reader knows which kind of check was made | **Gate.** |proposed value − mark| / proposed value ≤ the lender's **declared tolerance**. The deviation is measured against the value being confirmed, which after a restrike is the determination. The tolerance is set in advance in its seat settings (`tolerances.markBps`, default **25 bp**) and never per submission. Outside the band is a refusal: *"your mark 64 700 is 43.1 bp from the proposed value 64 980; your declared tolerance is 25 bp"*. **Publication.** The fixing is published only if at least one lender's mark on the proposal passed (§6.2). **When level (a) and a reference-derived mark disagree.** Where eligible level (a) prints and a mark with `markFromPublicReference = true` differ by more than the lender's tolerance, the refusal is recorded with both numbers and escalated to the oversight function (*planned*: the escalation step is not built, and no oversight function exists yet, so today the administrator records and reviews it, §9.1). The fixing is not forced to the reference. **A lender's mark must not come from a contributor.** A mark taken from a contributing venue's own prints (for example the token's last trade on a venue that submits to the same fixing) makes the check circular. `markSource` must name such a source, and a mark that is a token price on a public venue is not a public reference price for the underlying, so its `markFromPublicReference` is `false`. ### 4.3 Issuer: peg-integrity gate (condition `reserve-snapshot`, required for W and E) *The issuer does not price anything.* Its seat is a gate: the wrapper is worth its underlying only while reserves cover supply and holders can redeem. | Field | Type | Unit | Precision | Rule | |---|---|---|---|---| | `reserves` | number | units of the underlying (e.g. BTC) | ≤ 10 dp | ≥ 0 | | `supply` | number | tokens outstanding | ≤ 10 dp | > 0 | | `asOf` | instant | UTC | — | Not in the future. Age ≤ the asset's freshness limit (default 24 h, set per instrument) | | `evidenceRef` | string | — | ≤ 500 chars | The evidence behind the numbers. **Attested:** the proof-of-reserve report URL, reserve address list or auditor report reference. **On-chain:** the contract address(es) and block number read. **Custodial:** the custodian statement reference | | `redemptionsOpen` | boolean | — | — | Redemptions open to holders now | | `mintBurnPaused` | boolean | — | — | Minting or burning paused now | **Gate.** All four must hold, or the snapshot is a refusal naming each failure: - `reserves` ≥ `supply`; - the snapshot is fresh; - `redemptionsOpen` = true; - `mintBurnPaused` = false. The desk records `coverageRatio` = reserves / supply to 6 dp, and the snapshot's age in hours. **What is public, and why the signature still matters.** Much of this is observable. BitSafe and onRails publish reserve and supply information, and supply is readable on-ledger. The signed snapshot adds four things a public web page does not: 1. **Accountability.** A named party states the numbers, under the committee terms, on a permanent record. 2. **A timestamped as-of snapshot.** The fixing is gated on reserves *at that time*, not whenever a page was last updated. 3. **Contractual liability.** A knowingly false submission breaches the terms and is grounds for removal (terms §11.7). No seat has signed the terms yet, so this liability does not exist today. 4. **Non-public status.** Only the issuer can state the redemption and mint/burn status authoritatively in real time. A proof-of-reserve is point-in-time and covers assets, not liabilities or encumbrances. Chainlink's documentation says self-reported reserve data "carries additional risks … Users must do their own risk assessment" (Appendix A18; Circle's July 2026 examination report asserts coverage at two stated dates, A19). The gate inherits that limitation, and this document says so. The issuer's signed snapshot is its own statement, not an audit, an examination or agreed-upon procedures. **Independent corroboration (amended 5 Oct 2026; built).** The issuer's snapshot is **one input, not the authority**. A snapshot that passes the gate above is then checked, before its signature can reach the ledger, against sources the issuer does not control. The desk reads them itself as **administrator corroboration reads**: deterministic reads of public data, logged with their source, time and SHA-256 digest so that anyone can repeat them. They can only stop or label a value. They never count toward K and never stand in for a seat's signature (§6.4 condition 3 is unchanged). | Check | What the desk reads | Independent of the issuer? | Outcome | |---|---|---|---| | **Reserves** | On-chain holdings at the issuer's disclosed reserve addresses. For CBTC: BitSafe's published address list, each address's confirmed balance read from the Bitcoin chain and summed at the tip height | Yes (a reproducible public read; the address list is BitSafe's own, and this is disclosed) | Issuer `reserves` and the read differ by more than **50 bp**: **refused**, value withheld | | **Supply** | The supply the desk reads itself: the Canton CIP-56 registry's `totalSupply`, and `totalSupply()` on each configured chain, summed | Yes | Issuer `supply` and the sum differ by more than **10 bp**: **refused** | | **Evidence** | When `evidenceRef` contains an https URL, the document is fetched (public hosts only, no redirects) and its SHA-256 recorded | **No.** It is the issuer's own document: a consistency check, never independent corroboration | A `sha256:` digest cited in `evidenceRef` that the document does not match, or a JSON document whose `reserves`/`supply`/`totalSupply` contradicts the snapshot: **refused**. A document that cannot be fetched is recorded as missing | Outcomes, in order: - **Disagreement** beyond tolerance: the snapshot is recorded as the issuer seat's refusal, with the agreement table, and nothing is signed. The value is withheld; the fallback rules of §6.2 apply, as for any issuer refusal. - **Corroborated:** every configured independent reserve read agreed. Label "reserves independently corroborated" (plus "supply not independently read" where no supply source agreed). - **Not corroborated:** no independent reserve source exists for the asset, or it could not be read in time. The snapshot is accepted under the gate above and labelled **"reserves not independently corroborated"**. The administrator never fills the gap with its own judgement. Whether a value with this label may be published above tier 0 is §6.4's business; condition 5 (independent reserve corroboration) is proposed, not adopted (decision 9, G7). Every assessment is appended to the event log (`corroboration.issuer`) and published per strike without figures (§7). Today the configured independent sources are BitSafe's reserve addresses for CBTC and, where its registry address is configured, CBTC's Canton registry supply. Custodian statements and security or verification agent confirmations are not inputs yet (decision 9, G3 and G4: they need those parties to agree to provide them). The tolerances are methodology parameters (§9.6). ### 4.4 Custodian: holdings reconciliation (condition `custody-reconciliation`, required, funds) | Field | Type | Unit | Precision | Rule | |---|---|---|---|---| | `holdings` | number | units of the asset | ≤ 10 dp | ≥ 0. Units held in custody for the fund | | `ledgerHoldings` | number | units of the asset | ≤ 10 dp | ≥ 0. Units the ledger shows the fund holding at the strike | | `encumbered` | number | units of the asset | ≤ 10 dp | ≥ 0. Pledged, lent or otherwise encumbered | | `statementAsOf` | instant | UTC | — | Fresh (default 24 h), not in the future | **Gate:** `holdings` = `ledgerHoldings` and `encumbered` = 0. The difference is recorded. ### 4.5 Transfer agent: register reconciliation (condition `register-reconciliation`, required, funds) | Field | Type | Unit | Precision | Rule | |---|---|---|---|---| | `registerShares` | number | shares | ≤ 10 dp | ≥ 0 | | `ledgerShares` | number | shares | ≤ 10 dp | ≥ 0. Shares outstanding on the ledger at the strike | | `registerAsOf` | instant | UTC | — | Fresh (default 24 h), not in the future | **Gate:** `registerShares` = `ledgerShares`. The difference is recorded. ### 4.6 Administrator (ETP Foundry): proposes and computes, never attests The administrator: - opens the proposal; - computes the determination; - applies the gates; - publishes. It is not a committee member. The Daml package refuses a committee that includes the administrator (`admin notElem members`). The administrator does not trade the instruments it prices. ### 4.7 Earlier protocol versions - **v3 (yes/no answers)** and **v2 (numeric conditions)** remain known conditions, accepted as optional additions to a v4 submission. - A v3 or earlier confirmation is read under the version stamped on it (`protocolRef`). - A v4 desk refuses a confirmation that omits its seat's required submission, with a 422 naming it. --- ## 5. Calculation ### 5.0 Design choices and their precedents Every rule below is either **modelled on** a published practice, cited to the section and page of its source, or marked as **our choice**, with the precedent range and the reason. ETP Foundry does not claim compliance with any standard; nothing here has been audited. The rules for the 24/7 family (OFF-HOURS SIGNED fixings) have their own precedent table, rows S1–S20 in §3A.9. Page references: "pdf p." is the viewer page; "printed p." is the page number on the document. IOSCO FR07/13 printed page = pdf page − 3. Full references are in Appendix A. | # | Design choice | Our rule | Precedent (source, section, page) | How used | |---|---|---|---|---| | 1 | Order of inputs | (a) transactions → (b) executable quotes → (c) reference × par → (d) carry-forward / judgement | **IOSCO** FR07/13 Principle 8, printed p.21: (a) the submitter's own transactions, (b) observed transactions in the underlying, (c) transactions in related markets, (d) firm bids and offers, (e) other information and expert judgement; the order may be varied. **BMR** Art. 11(1)(a): "transaction data, if available and appropriate". **WMR** FX methodology v30 §4.3, p.11: trades, then orders, then bank quotes | **Adapted.** Related-market transactions (level c) are ranked below the token's own quotes because of wrapper basis (**our choice**, §3) | | 2 | Anchor in transactions | Level (a) is preferred and published as such | **IOSCO** Principle 7, printed p.20: anchored in observable arm's-length transactions in an active market | Modelled on | | 3 | Observation window | 60 minutes ending at the strike (crypto: 15:00–16:00 London) | **CME CF RR Methodology** v17.4 §8, pdf p.19: BRR observation window (CF: "TWAP Period") 60 minutes, 15:00–16:00 London | **Lifted** (strike 16:00 London, adopted 28 Sep 2026) | | 4 | Strike time | **16:00 Europe/London** (crypto), adopted 28 Sep 2026 | **CME CF** §8: BRR effective 16:00 London. **WMR** v30: 16:00 London closing fix | **Lifted.** A US ETP's natural reference would be BRRNY at 16:00 New York (A17); London was chosen to align with the BRR and WMR | | 5 | Aggregation | Volume-weighted median of venue VWAPs | **CME CF** §4.1.1, pdf p.10: volume-weighted median of pooled trades per partition. **NY Fed**, SOFR "Calculation Methodology": volume-weighted median | **Adapted.** CF applies it to pooled trades in twelve 5-minute partitions, averaged. We apply it to one window VWAP per venue, because a Canton venue submits aggregates, not a tape. Measured on real public data (§5.6; figures on request): most of the difference from the reference rate comes from collapsing each venue to one number. Twelve per-partition submissions per venue close most of it, and are *planned* | | 6 | Outlier rule | Exclude a venue > **300 bp** from the **simple median** of venue VWAPs (three or more venues). Two venues further apart than that: level (a) unavailable | **CME CF** §5.3, pdf p.15: an exchange whose VWM deviates from the median of exchange VWMs by more than the Potentially Erroneous Data parameter (**5%** for BRR, §8) has all its trades disregarded, and the Oversight Committee is informed. **WMR** v30 §4.4, p.12: rates validated against currency-specific tolerance thresholds (values not published) | **Adapted.** CF anchors on an unweighted median across at least five constituents and reports each exclusion to its Oversight Committee; ETP has no oversight function yet (§9.1). The simple-median anchor is built (§5.3). **Threshold is our choice**: the only published figure is 500 bp (CF, BTC); we set 300 bp because a thin Canton venue can be moved more cheaply than a CF constituent. **Founder decision** | | 7 | Minimum contributors | `minVenues` = 1 in the pilot, flagged single-source, **never above tier 0**. Two venues run by independent operators are **a condition** of any value above tier 0 | **CF Constituent Exchange Criteria** v8.5 §2, pdf p.4: no fewer than two constituent exchanges at launch | The precedent is 2. The pilot falls short, and says so on every value. **Founder decision** | | 7a | Weight cap and tie rule | No venue's weight in the VWM above 50% when **three or more venues remain after the outlier step and the share floor**; the excess is redistributed to the others in proportion to their volume. At an exact half, the value is the **weight-proportional interpolation** of the two straddling VWAPs, not their midpoint. With two venues remaining there is no cap: the value (the larger venue's VWAP) must lie within both venues' ranges, and the two within `outlierBps` of each other | No published precedent for a per-venue weight cap in a crypto reference rate was found. **IOSCO** Principle 6(d), printed p.20: design should take into account "the distribution of trading among Market Participants (market concentration)"; Principle 11(h), printed p.23: disclose "the possible concentration of inputs". Proportional redistribution of capped weight resembles capped equity-index practice (for example 10/40 capped indexes); that source was not opened for this document and no rule relies on it | **Our choice. Founder decision.** Without the cap, the venue reporting the most volume sets the value alone. Without the interpolation, a capped venue's adjacent venue would set half the value whatever its size (§5.3) | | 7b | Share floor | After the outlier step, a venue below **10%** of the remaining venues' window volume (`minSharePct`) is recorded as below the share floor and does not enter the median | Nearest precedent: **CF Criteria** §3 criterion 1, pdf p.5: > 3% of the reference rate's average daily window volume, an admission test over 90–180 days, not a per-window floor | **Our choice. Founder decision.** It stops a minimum-size venue (one USD 1,000 trade) from moving a capped value | | 8 | Venue eligibility | ≥ `minTrades` trades and ≥ `minNotionalUsd` in the window, plus the §4.1a admission, data-sharing and self-trade conditions | **CF Criteria** §3 criterion 1, pdf p.5: > 3% of the reference rate's average daily window volume over 180 days (90 for an addition), an **admission** test; criteria 2–5 cover integrity, KYC/AML, compliance and data-sharing. **BoE** SONIA key features (ii): only trades ≥ £25m. **WMR** v30 §4.4.2, p.12: a minimum number of valid trades set by expert judgement, not published | **Adapted.** CF's test is for admission over months; ours adds per-window thresholds. **Thresholds are our choice** until Canton volumes exist. **Founder decision** | | 9 | Quote fallback | Time-weighted mid; spread ≤ 200 bp; two-sided ≥ 50% of the window | **WMR** v30 §4.4.2, p.12–13: orders are used when trades are insufficient; §4.4.1, p.12: non-trade currencies are snapshotted every 15 s across the window | Mechanism adapted. **Thresholds are our choice. Founder decision** | | 10 | Halted venue | Excluded from (a) if halted > 50% of the window | **CME CF** §5.1, pdf p.14: delayed or missing data is disregarded; empty partitions are dropped. No halt threshold is published | **Our choice. Founder decision** | | 11 | Lender validation band | The value must sit within the lender's pre-declared tolerance of its own mark (default 25 bp) | **CRR** (EU) 575/2013 Art. 105(8): independent price verification by a unit independent of those who benefit. **Delegated Reg. (EU) 2016/101** (UK onshored text) Art. 19(3)(e): "a formal IPV process based on prices independent from the relevant trading desk". **BCBS** fair-value guidance (Apr 2009) Principles 1 and 4, p.2–6: explicit quantitative thresholds that trigger a challenge. **SEC Rule 2a-5**(a)(4): price challenges to pricing services | The mechanism, a check against a threshold declared in advance, is modelled on IPV. Where the lender's mark derives from a public reference, the check is a basis cap, not an independent valuation (§4.2). **No regulator publishes the number**; banks set their own. 25 bp is our default, and each lender declares its own. **Founder decision** | | 12 | Issuer reserve snapshot | Reserves ≥ supply, as of a stated time, with a reference to the evidence | **Circle** USDC Examination Report, July 2026: a point-in-time assertion at stated dates (23:59 UTC), examined with reasonable assurance under AICPA attestation standards. **Chainlink** Proof of Reserve docs, "Types of Proof of Reserve Feeds": third-party, custodian and self-reported off-chain reserves; wallet address lists | Modelled on the as-of assertion and its evidence reference. **The issuer's signed statement is not an audit or an examination**, and is not described as one | | 13 | Snapshot freshness | 24 h default, per instrument | **Circle**: monthly examinations, weekly disclosures. **Chainlink** PoR: per-feed heartbeat and deviation thresholds (values vary; not verified per feed) | **Our choice. Founder decision** | | 14 | Transparency of each determination | Level, method, venues used and excluded, volumes, digests | **IOSCO** Principle 9, printed p.22 | Modelled on | | 15 | Restatement | 1 bp of the published value (relative); two business days | **CME CF** §6.1, pdf p.17: same day, only if > 0.10% (10 bp of the price, relative). **NY Fed**, SOFR "Rate Revisions": same day, only if > 1 bp. **BoE**, SONIA "Republication policy": ≥ 2 bp, by 12:00 | The only like-for-like precedent is CF's 10 bp relative threshold; our 1 bp is tighter. The SOFR and SONIA thresholds are **absolute** basis points of an interest rate (at a 4% rate, 1 bp absolute is 25 bp relative), so they are cited for process only, not for the number. The two-business-day window is longer than every precedent's same-day rule. **Founder decision** | | 16 | Methodology changes | ≥ 30 days' consultation and ≥ 30 days' notice | **FTSE Russell** Policy for Benchmark Methodology Changes v2.9 §2.3.1, p.6: consultations typically open no less than four weeks (a shorter window is reserved); at least one month's notice. **IOSCO** Principle 12, printed p.23. **BMR** Art. 13(2) | Modelled on | | 17 | Cessation notice | ≥ 60 days, enforced on-ledger | **IOSCO** Principle 13, printed p.24: a written cessation policy proportionate to use; no number | **Our choice** | | 18 | Annual review | At least every 12 months | **BMR** Art. 5(3)(a). **CME CF** §10, pdf p.47. **FTSE Russell** Policy §2.1, p.4 | Modelled on | | 19 | Records | 5 years | **IOSCO** Principle 18, printed p.28 | Lifted | | 20 | Equity closing price | Official close of the primary listing (auction where one exists); last close when the market is shut | **FTSE Russell**, *Closing Prices used for Index Calculation* v5.3, p.3–6 | Lifted | | 21 | Fallback when the benchmark is unavailable | Tiers 3–5 | **Bitwise Bitcoin ETF** prospectus (424B3, 1 Aug 2025): if BRRNY is unavailable, a secondary source, then the principal-market price, then the sponsor's fair value. **NY Fed** SOFR contingency | Modelled on | ### 5.1 Sequence **Implemented today** (transitional, because the deployed package fixes one price per proposal): 1. **Propose.** At the strike, the desk opens a proposal at a **pre-fill value** (reference × par), on-ledger. The pre-fill is a starting point for the seats to test, not a level (c) value: while no reference is licensed for publication, it is computed from the desk's internal exchange composite, it is never published, and it can never become the fixing (level (c) is unavailable, §3.1). It is visible to the committee's seats on the proposal; whether that is within the source venues' terms is an open licensing question (§14). 2. **Submit.** Each venue submits its window (§4.1). - Range contains the pre-fill: the submission is a signed confirmation. - Range excludes the pre-fill: the submission is recorded without a signature. 3. **Determine.** The desk computes the determination from **every venue's latest submission for the strike** (instrument, session, as-of date), under §5.2 to §5.4. 4. **Restrike.** If the determination is level (a) or (b), and the on-ledger value differs from it by more than the determination tolerance (default **0 bp**), the desk does two things: - withdraws the proposal (`WithdrawFixing`); - proposes the determined value exactly. This happens once every venue seat has submitted, or when K is reached, whichever comes first. The default limit is **one restrike per strike**. Submissions are filed by strike, so they carry over. 5. **Validate and gate.** Seats confirm the proposal on-ledger with their v4 submissions. The desk checks the lender band, the issuer gate and the reconciliations (§4, §6.2). 6. **Finalise.** When K-of-N is reached and the gate passes, the desk finalises (`FinalizeFixing`). It records the determination (level, method, venues used and excluded, submission digests). **Target** (proposed Daml `crossdesk 3.3.0`, a written proposal, not built): - a submission phase *before* the proposal; - the determination and each venue's submission digest carried on-ledger; - no candidate value, and so no restrike. ### 5.2 Eligibility for level (a) A venue's window is eligible only if **all** of the following hold: | Test | Parameter | Pilot default | |---|---|---| | Trades in the window | `minTrades` | ≥ 1 | | Notional traded (VWAP × volume) | `minNotionalUsd` | ≥ USD 1,000 | | Halted for no more than | `maxHaltPct` of the window | 50% | | Self-trade exclusion attested | `selfTradesExcluded` = true (§4.1) | Required; `false` or absent makes the window ineligible (built) | | Share of eligible volume | `minSharePct` | **10%**: after the outlier step (§5.3), a venue whose window volume is below 10% of the remaining venues' volume is recorded and published as below the share floor, and does not enter the median (built, 29 Sep 2026) | | Data-sharing, audit right, surveillance in force | §4.1a | Recorded per venue and countersigned by a majority of the independent oversight members from their own accounts. A venue without a countersigned record may enter a tier-0 determination, where it is named; **any value above tier 0 requires every venue used to have it** (§6.4 condition 4; built) | **Tier 1 notional floor.** `minNotionalUsd` is 1,000 in the pilot. For any value above tier 0, **every venue in the median must have traded at least USD 10,000 (CBTC) or USD 5,000 (cETH, CC)** in the window. This is a condition of tier 1, not a recommendation (§14). Built (29 Sep 2026): the determination records each venue's window notional, and the tier assignment holds a value at tier 0 when any venue in the median is under the floor (`TierConditions`, `fixing.determination.tier1-min-notional-usd`). ### 5.3 Volume-weighted median and the outlier rule **Rule** (this version; built in the desk, amended 29 Sep 2026): 1. Take the eligible venues' VWAPs (§5.2), weighted by volume. 2. **Outlier step, with three or more eligible venues:** - compute the **simple (unweighted) median** of their VWAPs as the outlier anchor; - exclude any venue whose VWAP is more than **`outlierBps` (300 bp)** from that anchor. This is adapted from CF Benchmarks' rule (methodology v17.4 §5.3, pdf p.15), which excludes a constituent exchange whose median deviates from the simple median of exchange medians by more than a "Potentially Erroneous Data" parameter (5% for BRR). A simple-median anchor means the largest venue cannot become the anchor against which it is itself tested. Our threshold is tighter because Canton venue depth is thinner. The threshold, the floor and the cap are founder decisions (§5.0 rows 6, 7a and 7b). 3. **Share floor.** Of the venues that remain, any venue whose window volume is below **`minSharePct` (10%)** of their total volume is recorded as below the share floor and does not enter the median (§5.0 row 7b). It is applied **after** the anchor on purpose: applied before, a dominant venue far from the market would push the honest small venues under the floor and be left as the only venue, which is exactly what the simple-median anchor exists to prevent (our choice; the second bank review proposed "before the anchor", and the unit test `simpleMedianAnchor` shows why that order fails). 4. **Count again.** "Three or more" and "exactly two" below mean the venues **remaining after the outlier step and the share floor**, not the number that were eligible. Three eligible venues of which one is excluded are treated as two. 5. **Three or more remaining:** - **cap weights:** no venue may carry more than **50%** of the total weight. A venue above the cap is set to 50%, and the excess is redistributed to the others in proportion to their volume (`maxWeightPct` = 50); - take the VWM with the capped weights (definition below). 6. **Exactly two remaining:** there is no cap. - If their VWAPs are more than `outlierBps` apart, neither can be preferred: level (a) is not available, and the determination falls to (b), (c) or (d) with a dispersion note. - Otherwise the VWM is the **larger venue's VWAP** (with exactly equal volumes, the interpolation of the two, which is then their midpoint), and it must also lie **within both venues' reported ranges** (`low`–`high`). If it does not, level (a) is not available (built). With two venues the larger one sets the value, constrained only by the other's range; this is disclosed (§9.2). 7. **One remaining:** the determination is computed and flagged **single source**, but it is **never published above tier 0** (§6.4). A single venue cannot set a tier 1 value. 8. Level (a) holds when at least **`minVenues`** venues remain. **VWM definition:** - Sort the VWAPs, with their (capped) weights. - The VWM is the smallest VWAP at which cumulative weight reaches half the total weight. Otherwise it is one venue's reported window VWAP, not re-rounded. - **Exactly half:** when the cumulative weight equals exactly half the total at one VWAP (v_i, weight w_i), the VWM is the **weight-proportional interpolation** of that VWAP and the next one (v_j, w_j): (w_i · v_i + w_j · v_j) / (w_i + w_j), with the capped weights, rounded half-even to 10 dp. **Why the interpolation, and not the midpoint (our choice).** When the cap binds, the capped venue holds exactly 50%, so an exact half is the normal case, not an edge case. The conventional midpoint would then give the adjacent venue as much say as the capped venue, whatever its own size: a venue with one USD 1,000 trade next to the dominant venue could move the value halfway towards itself. Interpolating by weight gives each of the two straddling venues pull in proportion to its own capped weight, and the share floor keeps any venue under 10% out of the median altogether. Together they replace the earlier midpoint rule (replaced 29 Sep 2026). No published precedent for this interpolation was found; it is **our choice**, and Example A shows its effect. The volume-weighted median is the aggregation used by SOFR (volume-weighted median of repo transactions) and by the CME CF reference rates within each partition. It resists a single venue printing a distorted price in a way a mean does not. It does **not** resist a venue that reports more than half the volume, which is why the cap exists. *Planned refinement:* each venue submits **twelve per-partition aggregates** (VWAP and volume for each 5-minute partition), and the determination averages the twelve partition VWMs, as the CME CF BRR does with pooled trades. It is not built. §5.6 describes the measurement (figures on request). ### 5.4 Levels (b), (c), (d) **(b) Executable quotes.** A venue qualifies when all of these hold: - it reports `bidTwap` ≤ `askTwap`; - its spread is ≤ **`maxSpreadBps` (200 bp)** of the mid; - it was two-sided for ≥ **`minQuotedPct` (50%)** of the window. The determination is the median of qualifying mids, weighted by `quotedSeconds`. It needs `minVenues`. WM/Reuters practice is similar: it falls back from trades to orders when valid trades are insufficient. **(c)** Reference × par, from a **licensed** reference named per instrument (§3.1). **Requires a licensed reference:** until one is licensed, level (c) is unavailable, and the determination falls to (d) or to a gap. A level (c) value is **never tier 1 or tier 2**. It is published at tier 3, and the committee's role at level (c) is limited to attesting the par factor (§6.4). **(d)** The prior published committee value, flagged. Tier 4 when published automatically. **None available:** a gap is published as a gap (tier 5). The administrator never estimates to fill a gap. ### 5.5 Worked example A: the full v4 sequence (hypothetical numbers) This example uses invented numbers, to show the share floor, the two-venue rule, the restrike and the gates in one pass, with a variant for the outlier anchor, the cap and the tie rule. Example B (§5.6) uses real public data. CBTC, strike 16:00 London, observation window 15:00–16:00 London. The pre-fill on the proposal is BTC-USD 65 010 × par 1.0 = **65 010** (hypothetical). | Venue | Trades | Volume (CBTC) | VWAP | Low / High | Notional (USD) | Eligible | |---|---|---|---|---|---|---| | V1 | 42 | 3.1 | 64 980 | 64 700 / 65 210 | 201 438 | yes | | V2 | 15 | 0.9 | 65 040 | 64 900 / 65 150 | 58 536 | yes | | V3 | 3 | 0.2 | 66 950 | 66 900 / 67 000 | 13 390 | yes, then below the share floor | The steps under §5.2 and §5.3 as built (amended 29 Sep 2026): 1. **Eligibility.** All three meet `minTrades`, `minNotionalUsd` (pilot 1,000), the halt limit and `selfTradesExcluded`. 2. **Anchor.** Three venues are eligible, so the outlier step runs. The simple median of 64 980, 65 040 and 66 950 is **65 040**. V3 is (66 950 − 65 040) / 65 040 = 293.7 bp away, inside 300 bp, so it is **not** excluded as an outlier. 3. **Share floor.** The three hold 4.2 in total. V3 holds 0.2 / 4.2 = **4.8%**, below the 10% floor, so V3 does not enter the median. It is recorded as below the share floor. V1 holds 73.8% and V2 21.4%. 4. **Count again.** Two venues remain, so there is no cap (§5.3 steps 4 and 6). 5. **Two-venue tests.** The gap between 64 980 and 65 040 is 9.2 bp (4.6 bp each side of the midpoint), inside 300 bp. The VWM is the larger venue's VWAP: total 4.0, half 2.0, and V1's 3.1 reaches it first, so the VWM is **64 980**. It lies inside V1's range (64 700–65 210) and V2's (64 900–65 150). Level (a), from two venues, total volume 4.0. 6. **Restrike.** The pre-fill, 65 010, is 4.6 bp from 64 980, so the desk restrikes at **64 980**. V1 and V2 confirm with their ranges, which contain 64 980. V3's range, 66 900–67 000, excludes it, so V3's submission is recorded without a signature; its data and its exclusion are on the record. 7. **Lender.** Mark 64 950, at 15:58:30, eligible, haircut 15%, `markSource` "risk engine: licensed BTC reference × 0.998", `markFromPublicReference` = true. The deviation is 4.6 bp, within the declared 25 bp: **pass**. Because the mark is reference-derived, the check is a basis cap (§4.2), and the fixing says so. 8. **Issuer.** Reserves 1 250.0 BTC, supply 1 248.5 CBTC, coverage 1.001201. As of 15:00 (1 h old), with a PoR report reference. Redemptions open; mint/burn not paused: **pass**. 9. **Finalise.** With K-of-N reached, the fixing is **64 980**, input level (a), with the venues used and excluded, and the submission digests. It is tier 1 only if every §6.4 condition holds, including the tier 1 notional floor: V1 (USD 201 438) and V2 (USD 58 536) both exceed USD 10,000. **What this shows.** With two venues, the larger one sets the value, and the smaller one constrains it only through its range (disclosed, §9.2). V3's single distant print cannot move anything: it is under the share floor. **The same inputs with a larger V3 (a variant, to show the cap and the tie rule).** Suppose V3 had traded 0.5 CBTC at the same VWAP, so the total is 4.5: 1. **Anchor.** As above: 65 040, and V3 at 293.7 bp is **not** excluded. 2. **Share floor.** V1 68.9%, V2 20.0%, V3 11.1%: all three enter. 3. **Cap.** Three venues remain, so the cap applies. V1 (68.9%) is set to 50%; V2 and V3 share the other 50% in proportion to 0.9 : 0.5, that is 32.14% and 17.86%. In exact weights: V1 70, V2 45, V3 25 (total 140). 4. **VWM.** Sorted, V1's 64 980 brings the cumulative weight to exactly 70 of 140, one half. The value is the weight-proportional interpolation of V1 and the next VWAP, V2: (70 × 64 980 + 45 × 65 040) / 115 = **65 003.4782608696**. 5. **Comparison.** The earlier midpoint rule would have given (64 980 + 65 040) / 2 = 65 010, giving V2 (20% of volume) the same pull as V1. The interpolation moves the value 23.5 USD (3.6 bp) from V1 instead of 30 USD (4.6 bp). V3's distant print still does not move this result, because it is not adjacent to the half-way point. The 300 bp threshold, the 10% floor, the cap and the tie rule interact, and the founder decisions on them (§14) should be taken with this example in view. ### 5.6 Worked example B: real public data, BTC-USD, 25 September 2026 (illustrative) **Purpose.** This applies §5.3 to real trades from public exchange APIs, so a reviewer can re-run it. It then compares the result with the published CME CF Bitcoin Reference Rate for the same hour. **Status.** It is illustrative. It is not an ETP Foundry fixing: CBTC has no Canton venue data yet. ETP Foundry does not license or redistribute the BRR. **Where to find it.** The scripts, the raw responses with their SHA-256 hashes, the results and the caveats are available to reviewers on request from committee@etpfoundry.com. **Illustrative reconstruction on 25 Sep 2026 public exchange data. The figures are available to reviewers on request under the source venues' research terms. They are not reproduced here.** **The method, without the figures.** 1. **Window.** 15:00:00–16:00:00 London (14:00:00–15:00:00 UTC in British Summer Time), the BRR observation window. 2. **Inputs.** Five public exchange trade endpoints. Four gave exact trades; one gave only 1-minute candles, used as a proxy (Σ((H+L+C)/3 × volume) / Σ volume) and flagged as such. 3. **Rule.** §5.3 applied to one window VWAP per venue: total volume, the VWM, each venue's deviation, and the outlier test. No venue was near the 300 bp limit. 4. **Comparison.** The same trades were also aggregated as the CME CF BRR is (pooled trades in twelve 5-minute partitions, the VWM of each, averaged), and compared with the published BRR for that day. ETP Foundry does not license or redistribute the BRR, so neither the published value nor the differences from it are reproduced here. **What this shows, stated plainly (in words).** - Collapsing each venue to one window number, not the single window itself, explains most of the gap to the reference rate: with one number per venue, the median snaps to whichever venue holds the middle of the volume. - The headline figure came from the one venue whose number was an estimate from candles, not trades. - Twelve per-partition aggregates per venue recover most of the gap without needing a trade tape, which is why §5.3 lists them as the planned refinement. - The differences were small relative to the lender tolerance, but not zero. ### 5.7 Worked example C: an equity token on a weekend (hypothetical numbers) **Status.** Every price below is **invented** to show the rules and the arithmetic of §3A.4 and §3A.5, except two real facts: the SPYx multiplier (1.005714560286254, xStocks public API, read 28 Sep 2026, A33) and the CME Globex hours (A27). No ETP Foundry OFF-HOURS SIGNED fixing exists. SPY is not an ETP Foundry instrument. **Instrument.** SPYx. Home market NYSE. OFFICIAL: 16:00 New York on NYSE days. OFF-HOURS SIGNED: 00:00, 08:00 and 16:00 UTC. #### C1. Sunday 27 September 2026, 08:00 UTC: futures closed **Anchor (row 1).** SPY official close on Friday 25 Sep, 16:00 New York (20:00 UTC): **600.00** (hypothetical). No corporate action is pending. A = 600.00 × 1.005714560286254 = **603.4287**. **Which inputs are live at 08:00 UTC Sunday.** | Row | Input | State | Why | |---|---|---|---| | 0 | Home market | closed | Weekend | | 2 | ES futures | **stale** | Globex closed from Friday 17:00 New York (21:00 UTC) to Sunday 18:00 New York (22:00 UTC) | | 2a | Overnight session | closed | Blue Ocean runs 20:00–04:00 New York, Sunday to Thursday; it opens at 00:00 UTC Monday | | 5 | Cross-listed ETFs | closed | Weekend in every region | | 3 | Token trades, 07:45–08:00 UTC | **live** | Two venues traded (one signal type) | | 4 | Order book at USD 25,000 | live | Bid 603.90, ask 608.10 (USD) | | 6 | Issuer primary level | absent | xStocks primary issuance is 24/5 | | 7 | Stablecoin FX | live | USDT/USD 0.9998, USDC/USD 0.9999 | **Token trades (row 3), 15-minute window ending 08:00 UTC.** | Venue | Operator | Trades | Volume (SPYx) | VWAP (quote) | Low / High (quote) | VWAP (USD) | Low / High (USD) | |---|---|---|---|---|---|---|---| | A (CEX) | operator 1 | 12 | 41.5 | 605.80 USDT | 605.20 / 606.40 | 605.6788 | 605.0790 / 606.2787 | | B (DEX) | operator 2 | 5 | 9.2 | 606.30 USDC | 605.90 / 606.70 | 606.2394 | 605.8394 / 606.6393 | | C (Canton venue) | operator 3 | 0 | 0 | quotes: bid 604.00 / ask 608.50 USD | — | — | — | Both A and B are seats and attest `selfTradesExcluded` = true. Venue C quoted but did not trade. **Step 1: is there a value to compute? No: `NO FIXING`.** Under the rules as written and built, C1 fails three separate tests: 1. **Signal types (§3A.4).** Only one signal type is live: token trades. Futures, the overnight session and cross-listed ETFs are closed or stale. Token trades on two venues are still **one** input, so the minimum of two live inputs of distinct signal types is not met. 2. **Size floor (§3A.4).** Venue A: 12 trades and USD 25,136 (41.5 × 605.6788), which meets the floor of 5 trades and USD 10,000. Venue B: 5 trades but USD 5,577 (9.2 × 606.2394), below USD 10,000, so B's window does not count. 3. **Two-venue rule (§5.3), even if both had met the floor.** Two venues remain, so there is **no weight cap** (the cap applies only with three or more). Total volume 50.7, half 25.35; venue A (41.5) reaches half first, so the VWM is A's VWAP, **605.6788**. That lies outside B's USD range, 605.8394–606.6393, so level (a) is **not available** for the token-trade signal. **Published.** > SPYx · OFFHOURS · 2026-09-27T08:00Z · **NO FIXING** · reason: one live signal type (token trades); venue B below the off-hours size floor; two-venue range test failed (A's VWAP 605.6788 outside B's range 605.8394–606.6393) · last good: 2026-09-27T00:00Z, 605.80, 8 h old · stale: ES futures (last 2026-09-25T21:00Z), overnight session, cross-listed ETFs · not a NAV **Under the rules as written, a weekend with two token venues whose ranges do not overlap the larger venue's VWAP is `NO FIXING`.** An earlier draft of this example capped each of the two venues at 50% and took their midpoint, 605.9591. The rules do not do that (the cap needs three or more venues), and the code does not either. The draft's published value, 606.2894 ± 6.92, was wrong and is withdrawn. **Lost futures information (open question).** ES traded until 21:00 UTC on Friday, one hour after the anchor, and that move is dropped on the weekend because the input is stale. Whether the last futures print may be used as a stale-but-informative hard signal is listed in §14. **The band arithmetic, as an illustration only.** Had a second signal type been live, and had the token-trade determination been V_t = 605.9591 (hypothetical), the steps of §3A.5 would give: | Quantity | Value | |---|---| | A (anchor) | 600.00 × 1.005714560286254 = 603.4287 | | V_0 (Friday 19:45–20:00 UTC, hypothetical) | 603.10, which is 5.45 bp below A | | M = A × V_t / V_0 | 603.4287 × 605.9591 / 603.10 = **606.2894** | | Bound | 603.90 ≤ 606.2894 ≤ 608.10: not bounded | | σ | 90 bp (60-day daily volatility of SPY closes, hypothetical) | | τ | Friday 21:00 UTC (last ES print) to Sunday 08:00 UTC = 35 h = 1.4583 days | | Volatility term, z = 1 | 90 × √1.4583 = 90 × 1.2076 = **108.7 bp** | | D | each venue's deviation from V_t: A −4.63 bp, B +4.63 bp, so **4.63 bp** | | s | (608.10 − 603.90) / 2 / 606.2894 = **34.64 bp** | | b = √(108.69² + 4.63² + 34.64²) | **114.2 bp = ± 6.92 USD** at z = 1 (about 68% nominal coverage, uncalibrated; at the recommended z = 2 the volatility term doubles and b is about 220 bp) | | Venue A's high vs P | 606.2787, 0.0107 below P: A would be recorded without a signature | **Seats, had a value been determined** (K = 3 of N = 5). Nothing is signed for `NO FIXING`; this shows how each check would have read. - **Lender:** mark 606.00 at 07:58 UTC, eligible, haircut 20%. Deviation 4.77 bp. The lender has declared **`markBpsOffHours` = 50 bp** in its seat settings in advance, twice its weekday `markBps` of 25 bp, because its own weekend liquidation policy accepts a wider gap; the declared value is published with every fixing. 4.77 bp ≤ 50 bp: the check would pass. **The band (114 bp) plays no part in the gate:** it never widens the lender's tolerance (§3A.6). Its `markSource` is "CEX SPYx last trade × 1", a **token** price on a public venue, not a public reference price for the underlying, so **`markFromPublicReference` = false**; and because that CEX is venue A, a contributor, the check would be circular with A's own prints. A lender sourcing its mark that way is told so, and the fixing discloses it (§4.2). - **Issuer:** a custodial snapshot from the Friday custodian statement, 36 h old (≤ 96 h), SPY held ≥ SPYx outstanding × 1.0057145603, requests accepted, mint/burn not paused, `multiplier` 1.005714560286254, no action pending: the gate would pass. - **Venues:** B's range contains 606.2894 and C's quote (604.00–608.50) contains it; A's range excludes it. At least one venue signature is required among the K (§3A.1). #### C2. Monday 28 September 2026, 00:00 UTC (Sunday 20:00 New York): futures live ES reopened at 22:00 UTC. The ES contract's mid at the Friday anchor instant (16:00 New York) was **6,050.00**, and at 23:59:30 UTC Sunday it is **6,080.25** (both hypothetical). - **Signal types.** Futures are live (a hard signal) and token trades are live on venues that meet the off-hours floor (hypothetical): two distinct signal types, so the minimum is met. Blue Ocean opens at 00:00 UTC, the fixing instant, so it has no 5-minute VWAP yet and is **not** a third signal. - **M** = 603.4287 × 6,080.25 / 6,050.00 = 603.4287 × 1.0050000 = **606.4459** (futures are first in priority). - **Cross-check.** The token-trade implied value is 606.60: D = 2.54 bp, well inside X = 5%, so it is kept. - **Band.** τ is the age of the freshest hard signal: F_t is stamped 23:59:30, so τ = **30 seconds** = 0.000347 days, and the volatility term is 90 × √0.000347 = **1.7 bp**. With D = 2.54 bp and s = 20 bp (hypothetical, a tighter book), b = √(1.68² + 2.54² + 20²) = **20.2 bp**, which is **± 1.23 USD** at z = 1 (uncalibrated). **What the two cases show.** The anchor is the same. With futures live, there are two signal types, a value, and a band of about 20 bp. With futures closed on a weekend and only token trades live, there is **no value**: one signal type is not enough, however many venues print. Had a second signal existed, the band would have been about 114 bp at z = 1, most of it the √τ term. A lender reading the tape sees both the gap and the band; it sets its haircut from them, and never widens its declared tolerance because of them. --- ## 6. Validation, gates and the tier waterfall ### 6.1 K-of-N The on-ledger committee quorum is unchanged: - K signatures of N members; - K ≥ 2, K ≤ N; - the administrator is not a member; - one fixing per series per day (`FixingSeries`). Every signature carries a `SignerCheck`: member, role, protocol version, named conditions, and the venue's range. The published `NavFixing` carries them all. ### 6.2 Gates at finalisation (desk, off-ledger) A proposal on which any seat submitted under v4 is finalised only if all of these hold: 1. **Determination.** If level (a) or (b) is available, the on-ledger value equals the determination within the determination tolerance (default 0 bp). 2. **Lender** (types W, N and E). At least one lender confirmed with an `independent-mark` inside its declared band. 3. **Issuer** (types W and E, reserve model not `native`). An issuer confirmed with a `reserve-snapshot` that passed its gate **and was not contradicted by an independent source** (§4.3, "Independent corroboration"). A snapshot that an independent read contradicts beyond tolerance is recorded as a refusal and never signed, so this gate cannot pass on it. A snapshot with no independent corroboration available passes this gate and carries the label "reserves not independently corroborated". 4. **Funds.** The NAV arithmetic is the ledger's. The custodian and transfer agent confirm with reconciliations that passed. If K is reached but a gate fails, the desk records `fixing.gate-refused` with the reasons and does not finalise. The confirmation window then runs to its fallback. **If the failed gate is the issuer's peg-integrity gate, tier 3 is not available for that strike.** The value is tier 4 (prior fixing, flagged "peg gate failed") only if the prior fixing is less than 24 hours old; otherwise it is tier 5, a gap. A tier 3 value (reference × par) is never published while the issuer's latest snapshot for the instrument is a refusal: that would publish BTC × 1.0 at exactly the moment the issuer's data says the wrapper may not be worth its underlying. Built: the fallback reads the issuer gate (§13). **A silent issuer is treated like a refusal.** Tier 3 also requires a **passing** issuer snapshot younger than the instrument's freshness limit (default 24 h). An issuer that has simply stopped submitting therefore blocks tier 3 exactly as a refusal does, and the fallback proceeds to tier 4 (under the same 24-hour rule) or tier 5 (built, 29 Sep 2026). **Tier 3 requires a licensed reference.** Tier 3 is reference × par, and the reference must be licensed for publication (§3.1). Until one is, tier 3 is unavailable and the fallback proceeds to tier 4 or 5 (built, 29 Sep 2026: `marketdata.public-display` = false). A proposal with no v4 submission on it (a v3 record) is read under v3, unchanged. ### 6.3 Why an issuer or lender refusal is not a veto on the truth - **Issuer refusal.** A refusal on reserves or redemptions means the wrapper may not be worth its underlying. Publishing "the underlying price" as the wrapper's fixing would then be wrong, which is why the fallback cannot do it either (§6.2). - **Lender refusal.** A mark outside its band is a disagreement between the value and the lender's risk-system number. Where that number is reference-derived, it is a disagreement about basis (§4.2). It is resolved openly, by restrike or fallback, not by averaging it away. Both refusals are recorded with their numbers and are visible to every member. ### 6.4 Tier and input level Two independent labels are published with every value: - the **tier**: who stood behind it; - the **input level**: what data it came from. | Tier | Meaning | Input levels possible | Attested? | |---|---|---|---| | **0** | Not attested. Computed by the desk, attested by nobody; or a committee fixing that does not meet the four conditions below ("pilot"). A tier 0 value derived from unlicensed exchange data is never published: the public surfaces say "not published, awaiting a licensed source" | any level | No | | **1** | Committee fixing (attested): K-of-N inside the window, gates passed, and every condition below met | (a), (b); (d) only with a written rationale | **Yes** | | **2** | Committee fixing after escalation: as tier 1, reached after reminders at ½ window and alternates at ¾. A description of how K was reached, not a lower quality grade | (a), (b) | **Yes** | | **3** | Fallback: reference × par (**not a committee price**): a licensed reference × the last attested par factor, automatic. Also any committee confirmation at level (c): the committee attests the par factor only. **Requires a licensed reference** (unavailable today, §3.1). **Never while the issuer's gate is refused or the issuer is silent** (§6.2) | (c) | Par factor only | | **4** | Fallback: prior committee value carried forward, flagged | (d) | No | | **5** | `NO FIXING`: no value. A gap is published as a gap | — | — | **Level (c) is never tier 1 or tier 2.** Attesting "reference × par" as a committee fixing is the v3 design that §0 calls a rubber stamp. At level (c), the committee's signatures stand behind the par factor, and the value is published at tier 3. **Conditions for any value above tier 0** (a hard precondition, not a recommendation). No value is published at tier 1 or tier 2, and no OFF-HOURS SIGNED fixing (§3A) is published as attested, unless all of the following hold on the strike date. Until they hold, an OFF-HOURS SIGNED fixing is published at tier 0 with the label `pilot — not attested`, and the licence forbids its use for liquidation. 1. **Oversight.** An oversight function of at least three members, a majority independent of the administrator and of every seat holder, has been constituted and has approved this methodology version (§9.1). **The approval is countersigned by each approving independent member from that member's own authenticated account, and published with the members' names and declared affiliations; an entry made by the administrator alone does not satisfy this condition.** The venue-condition records of condition 4 count only once a majority of the independent members have countersigned them the same way. 2. **Own keys.** At least K of the signatures are made by third parties at trust level **L2** or above, meaning with keys the seat holds itself. 3. **No administrator seats.** No seat counted toward K is operated by the administrator or its affiliates (ETP Foundry, Lucilla, Inc., CrossDesk), **whatever its trust level**. Each seat carries an **operator of record**: the legal entity that controls the signing key. A seat whose operator is the administrator or an affiliate, or which is flagged operator-run, never counts toward K, at L1, L2 or L3. (An administrator-run L2 seat, such as the test seat used to prove L2, fails this condition.) **A signature produced by the administrator's hosted checker also fails it**, at any level and with any key, because the administrator fetched the inputs it attests: the runner records each hosted submission in the audit log before it submits, and a seat's signatures on any day its checker was hosted are treated the same way; switching to its own checker later does not change them (§10). 4. **Venues.** The venue conditions of §4.1a, §5.2 and §5.3 are met: at least **two venues run by independent operators** for level (a) (with one venue every value is tier 0, published and labelled), every venue used has a countersigned §4.1a record, and every venue in the median meets the tier 1 notional floor (§5.2). **Disclosure of the pilot, stated plainly.** In the DevNet pilot the administrator operates every seat and holds every seat's L1 key: at L1, the administrator could have produced any signature itself. Until the four conditions hold, every value is tier 0, and pilot attestations by administrator-operated seats are labelled "pilot — administrator-operated seats", never tier 1. Built: the tier assignment checks these conditions (with oversight and venue records countersigned by the members' own accounts, each seat's operator of record, and the hosted-checker record), so today every value is tier 0 by design (§13). **Signing keys today.** L2 (the seat's own key signs; the administrator's participant cannot sign for it through the Ledger API) is built and was proven on DevNet on 26 Sep 2026. **It is switched off on the running desk today**, and will be on before the first seat onboards. At L2 the administrator can still refuse or delay a submission, and a participant running modified software is the one remaining path to a signature the seat did not make; L3 (the seat's own participant) closes it. ### 6.5 Errors and restatement These rules carry forward from v0.1 §6: - **Materiality threshold:** 1 bp of the published value, or any error that changes a settlement obligation. - **Correction:** by `RestatementProposal` under the same K-of-N. The corrected value must differ, and a reason is mandatory. The original stays on the record, and the correction points back to it. - **Window:** two business days. This is policy, not enforced on-ledger. For comparison: the CME CF BRR is restated only above 0.10% of the price and on the same day (methodology §6.1, pdf p.17), the only like-for-like comparison. SOFR is revised the same day only if the change exceeds 1 bp (NY Fed, "Rate Revisions"), and SONIA is republished at 2 bp or more (Bank of England, "Republication policy"); those are absolute basis points of an interest rate, not relative to a price. Our two-business-day window is longer than all three (§5.0 row 15, founder decision). **What happens to trades settled at a superseded value** is not yet decided: unwound, adjusted in cash, or left standing. Creations and redemptions settle against the fixing atomically, so this must be decided before any tier 1 value (**founder decision**, §14). A restatement never applies to an OFF-HOURS SIGNED fixing: one that proves wrong is corrected by a new, linked record, and consumers decide what to do with liquidations made against it (§3A.7). --- ## 7. Publication (transparency of determinations) IOSCO Principle 9 asks for a concise explanation of each determination: the number and volume of transactions, the range, the mix of input types, and the extent of any expert judgement. **What the public surfaces carry (licensing).** Exchange-sourced prices (Coinbase, Kraken, Bitstamp, Gemini, Crypto.com and CF Benchmarks data, and anything derived from them) **never appear on a public surface**. This is a founder decision of 28 Sep 2026, and the desk enforces it with the setting `marketdata.public-display` = false (built, 29 Sep 2026): - the public and unauthenticated API (`/api/benchmarks`, `/api/series`, `/api/etps`, CSV and JSON downloads), the benchmark pages and tiles, and the test-ETP cards carry **committee-derived values** where they exist, and otherwise no price and the words **"not published, awaiting a licensed source"**. A series day with no committee value carries a status row: `NO PUBLIC VALUE — internal reference only (source not licensed for publication)`; - the MCP tools and the in-console assistant that read those values are **signed-in only and labelled internal**; - level (c) and tier 3 are unavailable until a licensed reference exists (§3.1, §6.2); - the publication record keeps its history unchanged (it is a hash chain); a dated notice row (29 Sep 2026) records that its earlier observed prices were derived from exchange data not licensed for publication and withdraws them. The raw record still carries them, because history is not edited, so **the raw record is no longer published** (founder decision, 29 Sep 2026). `/record` shows a redacted public view, generated at each site deploy: every row keeps its date, status, tier, digest and previous digest; each exchange-derived figure reads "withheld (source not licensed for publication)" and is published as a salted SHA-256 commitment (in those rows the observation timestamps are withheld too, so a price cannot be recovered by searching the row digest). Anyone can check the chain's linkage and the full digest of every row with nothing withheld; the digests of redacted rows and the commitments can be checked only with the private record, which is available to auditors, regulators and the oversight function on request. From the notice row on, the record states only whether a value was published, never the number. Each fixing record carries: | Item | Where | Status | |---|---|---| | Value, strike, session, as-of date | `NavFixing` on-ledger; `GET /api/series/{id}` | Implemented | | Tier | Series row | Implemented | | Input level, method, venues used and excluded (with reasons), total volume, single-source flag | `fixing.determined` event; proposal view `determination` | Implemented in the record. **On the public series: planned** | | Each venue's trade count, volume, VWAP, low/high, halt seconds; SHA-256 per submission | Confirmation and submission events | Implemented (record). Public disclosure of per-venue figures needs each venue's consent: *planned, per venue* | | Signers, role, protocol version, named conditions, venue range | `SignerCheck` on the `NavFixing` | Implemented | | Signature trust level mix (L1 hosted / L2 own key) | Series row disclosure | Implemented | | Layer label (`LIVE` / `OFFHOURS` / `OFFICIAL`); for `OFFHOURS`, the band (and "uncalibrated band" until back-tested), inputs used, inputs stale, each lender's declared `markBpsOffHours`, and flags (`NO FIXING`, `BOUNDED`, `EXCEPTIONAL`, `PRIMARY-DIVERGENCE`, `PRIMARY-CLOSED`, `EVENT-`) | `GET /api/offhours`, `GET /api/offhours/{id}`; `offHours` on `GET /api/benchmarks/{id}` | **Built, phase 1** (5 Oct 2026; desk-side records, tier 0). Per-venue figures withheld on the public view until each venue consents. `EVENT-`: *planned* | | `markFromPublicReference` and `markSource` for each lender | Confirmation event; public series | *Planned* | | Lender deviation in bp; issuer coverage ratio and snapshot age | Confirmation event | Implemented (record) | | **Sources and agreement** for the issuer's reserve snapshot: per source, its name, type, whether it is independent of the issuer, its time, its SHA-256 digest and agree / disagree / missing; the outcome and label ("reserves independently corroborated", "reserves not independently corroborated", or withheld) | `corroboration.issuer` event; public `GET /api/series/{id}/sources`; the `/record` page | **Implemented** (5 Oct 2026). Statuses only on the public surfaces; the figures behind each status stay in the event log, available to auditors and the oversight function | | Fetched evidence documents (`evidenceRef` URLs) and their SHA-256 | `corroboration.issuer` event; public panel | **Implemented** (5 Oct 2026) | | Gate outcome, refusals and their reasons | `fixing.gate-refused`, `proposal.refused` | Implemented (record) | Reading a published fixing needs no licence. Referencing it in a contract needs one. Tier labels, in words: tier 1 "committee fixing (attested)"; tier 2 "committee fixing after escalation"; tier 3 "fallback: reference × par (not a committee price)"; tier 4 "prior value carried forward, flagged"; tier 5 "NO FIXING"; tier 0 "not attested" or "pilot". --- ## 8. What is public, and what each seat uniquely provides | Seat | Already public (anyone can read it) | Only this seat can provide | What its submission does | |---|---|---|---| | **Venue** | Its displayed order book, if it publishes one; spot prices on other markets | **Its executed trades in the window** (count, volume, VWAP, range) and its halt record, signed | **Sets the price** (levels a, b) | | **Lender** | Nothing about its book | **The mark its own risk system uses**, with its declared source, its eligible-collateral decision and its haircut, stated against its own exposure | **Challenges the price from the risk side.** Outside its band, nothing publishes. Where its mark is reference-derived, this is a basis cap (§4.2) | | **Issuer** | Reserve reports and addresses it publishes; token supply on-ledger | **A signed, timestamped reserves/supply snapshot tied to this strike**; the **real-time** redemption and mint/burn status; contractual accountability for both | **Gates publication** on peg integrity | | **Custodian** | Nothing | **The units actually in custody** and any encumbrance, per its statement | **Gates** a fund NAV | | **Transfer agent** | Nothing | **The shares on the register** | **Gates** a fund NAV | | **Administrator** | This methodology; every rule. (Its internal exchange composite is not public, §7) | Nothing it may attest | **Computes** the determination and publishes. Never signs | ### Why this is not rubber-stamping 1. **The price comes from the committee's data, not from outside it**, with one qualification. Under v1.0 the fixing is the volume-weighted median of the venues' own signed window VWAPs. The external reference is a fallback (level c), published at tier 3 and labelled as such, and only from a licensed source; today it is unavailable. **The qualification:** while the lender's mark is derived from a public reference, the venues' data can move the fixing only inside the lender's band around that reference (§4.2). The disclosure `markFromPublicReference` says when that is the case. 2. **Every submission is a number that can be wrong in a checkable way.** - A venue's VWAP must lie within its own low and high. - Its range must contain the value it signs; the ledger refuses otherwise. - A lender's mark must fall within a tolerance it declared in advance. - An issuer's reserves must cover supply, as of a stated time, with a reference to the evidence. A yes/no cannot be checked like this. A number with a timestamp and a digest can. 3. **The seats are independent checks on each other**, in opposed directions: - the venues set the price from trades; - the lender, which is harmed by an overstated value, challenges it against its own risk-system mark (off-hours, a lender that liquidates gains from a low value instead: a disclosed conflict, §3A.1); - the issuer, which would prefer par, cannot move the price at all and can only stop publication. 4. **Disagreement is visible, not averaged.** - An excluded venue, a lender outside its band and an issuer gate failure are each recorded with the numbers. - A value no longer publishes when a seat's data says it should not. 5. **The administrator cannot fill the gap.** It computes and publishes, but it cannot sign, and the ledger refuses it as a member. If the gates fail, the result is a fallback or a gap, labelled. **What this does not solve**, stated plainly: - The desk cannot audit a seat's source systems. A seat that submits a false number has made a false statement on a permanent record, under its name. This is the residual trust, and it is disclosed to every seat. - Canton venue liquidity for CBTC and cETH is unproven. Until venues submit, level (a) is a design, not a demonstrated fact (IOSCO Principle 7, §11). --- ## 9. Governance and oversight ### 9.1 Oversight function **Target composition** (IOSCO Principle 5; EU/UK BMR Art. 5, where applicable): - at least **three members**, a majority **independent** of the administrator and of any seat holder; - for example: a former benchmark or index professional, a market-structure or risk practitioner, and a lawyer experienced in tokenised securities; - a chair who is independent. **Remit:** - review this methodology at least annually; - approve material changes after consultation; - oversee the cessation process; - review every gate refusal, exclusion and fallback, and every disagreement or missing source on the issuer's sources-and-agreement record (§4.3, §7); - monitor seat conduct; - receive complaints escalated from the administrator; - report suspected misconduct or manipulation to the relevant authority where one exists. **Status: not constituted.** There is no oversight function today. Its charter is written (three independent members, no seat holder or contributor eligible, quorum, cadence, remit, appointment and removal, conflict declarations), together with the candidate profile and invitation, but no member has been appointed. The committee of seats is **not** an oversight function. Its members hold positions, which is why their role is limited to supplying and checking data. Until an independent oversight function exists, the administrator performs the reviews listed above, publishes them, and says that it does so. **A constituted oversight function is a hard precondition** for any tier 1 or tier 2 value and for any attested OFF-HOURS SIGNED fixing (§6.4). Its constitution and its approval of each methodology version count only when countersigned by the independent members themselves from their own authenticated accounts (built, 29 Sep 2026); the administrator cannot enter them alone. Until it exists, every value is tier 0. ### 9.2 Conflicts of interest - **Administrator:** - does not trade, hold or lend the instruments it prices; - is not a committee member (enforced on-ledger); - does not accept payment contingent on a fixing's level. - **Disclosed conflicts.** The licence fee includes a charge on AUM above a threshold (etpfoundry.com/licensing), and AUM rises with the fixing level. The administrator also runs the settlement desk and creation/redemption, and in the pilot it holds every seat's L1 key. These are disclosed conflicts. The "computes but never attests" controls do not address a fee linked to AUM or to the level of the fixing; the mitigations for that are the conditions of §6.4: an independent oversight function that approves the methodology, K signatures from third-party seats with their own keys, and no administrator-operated seat counted toward K. - **Seats hold positions by design.** The mitigations are: 1. inputs are the seat's own data, not opinion; 2. the seats' interests differ (issuer and lender are clearly opposed; a venue's interest depends on its inventory); 3. no single seat type can set the price alone once `minVenues` ≥ 2, and, under the 50% weight cap (§5.3), no single venue can either (**with three or more eligible venues; with two, the larger venue's VWAP is the value, if it lies inside the other's range**); 4. every submission is attributable and permanent. **Off-hours borrower side (disclosed).** For OFF-HOURS SIGNED fixings the lender, the only price-side validator, gains from a low value when it liquidates. At least one venue signature is required among the K, the depth bound limits the value, and the lender's tolerance is declared in advance and never widened (§3A.1, §3A.6). This mitigates the conflict; it does not remove it. - **Declarations.** Each seat declares, at appointment and on change, any position or arrangement that could bias its submissions. See the conflicts policy, etpfoundry.com/documents/conflicts-policy-v0.2.md. ### 9.3 Submitter code of conduct The model is IOSCO Principle 14 and BMR Art. 15. Every seat agrees to the following when it accepts a seat. 1. **Source.** Submit only data produced by its own systems for the stated window: executed trades, its own mark, its own reserve and custody records. 2. **No estimation in place of data.** Never submit an estimate or someone else's number as its own. If a figure cannot be produced, the checker halts, and no submission is sent. 3. **No discretion over tolerances at submission time.** Tolerances (`markBps`, and `markBpsOffHours` for off-hours fixings) are declared in advance in seat settings. Widening one to make a check pass is prohibited, and no one else, including the administrator, widens a seat's tolerance for it: the off-hours band never does (§3A.6). 4. **Controls.** - An automated checker (§10), or a documented manual procedure, produces each submission. - Access is limited to named people and credentials. - Changes to the checker's data sources are recorded. 5. **Records.** Keep the data behind each submission for **five years** (IOSCO Principle 18) and produce it to the oversight function or an authority on request. 6. **Suspicious activity.** Report to the administrator any attempt to influence a submission, and any trading it believes was intended to move a window's prints. 7. **Separation.** Where the seat also trades the instrument, those who submit are not those who trade it, or the conflict is declared and managed. 8. **Refusal is normal.** A refusal is never held against a seat. A knowingly false submission is grounds for removal (committee terms §11.7). The administrator reviews adherence at least annually. ### 9.4 Record keeping - **On-ledger:** proposals, attestations (`SignerCheck`), fixings, restatements, cessation notices. These are immutable by construction. - **Off-ledger:** an append-only event log. - It holds every submission with its SHA-256 digest, every refusal with its numbers, every determination and gate outcome, every restrike and every fallback. - The durable store is required in production. - **Who can see submissions, stated truthfully.** Submissions are sent to the administrator's desk over its REST API and kept in this **off-ledger** log, not on the ledger. They are shown to the committee and its auditor, and published per seat only with that seat's consent. That is the administrator's access policy under the committee terms, enforced by the desk's authentication and roles; it is **not** a property of the ledger, and the administrator can read every submission. On-ledger, a signature's `SignerCheck` shows only the seat's role, conditions and range. - **Retention:** at least **five years**. - **What is not yet in place:** the durable store exists, but independent backup verification against the retention policy does not. ### 9.5 Complaints - **How to complain:** in writing to committee@etpfoundry.com. Anyone may complain about a fixing, a submission or this methodology. - **Timing:** acknowledged within 2 business days; answered within 20 business days, with the reasoning. - **Escalation:** unresolved complaints go to the oversight function once one exists. - **Records:** complaints and responses are kept for five years (IOSCO Principle 16). - **Status:** no complaint has been received. ### 9.6 Methodology changes and consultation - **Material changes include:** - the input hierarchy; - any §5 parameter (`minVenues`, `minTrades`, `minNotionalUsd`, `minSharePct`, `outlierBps`, `maxWeightPct`, the tie rule, `maxSpreadBps`, `maxHaltPct`, `minQuotedPct`, determination tolerance, observation window); - the strike time; - the gates; - K or N; - the materiality threshold. - for the 24/7 family (§3A): the fixing times, every maximum age, the change-signal priority, the signal-type rule and size floors, the band formula and its parameters (z, b_min, b_max, S), X, Y, and the off-hours issuer freshness. - **Process for a material change:** - a public consultation of at least **30 days**, with the rationale and draft text; - a published summary of comments and responses, unless a respondent asks for confidentiality; - then at least **30 days' notice** before the change takes effect. This is modelled on FTSE Russell's published policy (v2.9 §2.3.1, p.6): consultations typically open at least four weeks, with a shorter window reserved, and at least one month's notice. IOSCO Principle 12 (printed p.23) and BMR Art. 13(2) ask for advance notice and a clear timeframe. - **Non-material changes** (clarifications, typographical corrections) take effect on publication. - **Versions:** every version is retained, and a fixing is read under the version in force at its strike. - **Status:** no consultation has been run. v1.0 is the first version published under this policy. The 29 Sep 2026 amendment (§16) was made before any fixing was published for commercial use and before any third party held a seat, so no referencing contract needed notice. The 5 Oct 2026 amendment (independent corroboration of the issuer's snapshot, §4.3, §6.2, §7) was made on the same basis; it only adds refusals and labels, and never makes a value easier to publish. ### 9.7 Cessation - A benchmark is ceased with **at least 60 days'** published notice. The notice is enforced on-ledger (`CessationNotice`) and names the final strike and any successor. - Three consecutive tier 3 or tier 4 strikes trigger a review of whether it should cease. - Users are encouraged to hold contractual fallbacks (IOSCO Principle 13). ### 9.8 Annual review At least once every 12 months, the administrator (and, once constituted, the oversight function) reviews: - whether the inputs still represent the market: venue count, volumes, exclusion and fallback rates; - the §5 parameters; - seat conduct; - complaints; - the independent-corroboration record: how often each issuer's snapshot was corroborated, not corroborated or refused, and whether the tolerances (§4.3) still fit; - this document. The review is published. The first review is due by **30 September 2027**. The checklist the review follows is written (annual-review checklist, kept with the committee's governance documents). ### 9.9 Audit There is no external audit today (IOSCO Principle 17). An independent review of the administrator's adherence to this methodology is *planned* before any fixing is used by a third party for settlement. A readiness checklist of what an assurance firm will test (controls, evidence, records, change management, independence) is written; no firm has been engaged. --- ## 10. Automation: how each seat's checker works A seat's checker runs in one of two modes. Onboarding offers them in this order: | Mode | Who runs it | Key | Counts toward tier 1? | Label | |---|---|---|---|---| | **Hosted** ("no install") | ETP Foundry's hosted runner, from the sources the seat connects in the dashboard | the seat's hosted party (L1), or the seat's own Google Cloud KMS Ed25519 key (L2), used through a signing permission the seat grants on that one key and can revoke | **No, never** (§6.4 condition 3): the administrator fetches the inputs | "Hosted by ETP Foundry — pilot, counts as operator-run (tier 0)" | | **Own cloud** ("upgrade for official, tier 1, values") | the seat, running `signer-service` in its own Google Cloud (Cloud Run) or AWS (ECS Fargate) account from one-click templates, or on its own machine | the seat's own key: Google Cloud KMS `EC_SIGN_ED25519`, AWS KMS `ECC_NIST_EDWARDS25519` (`ED25519_SHA_512`, raw message), or a key file | Yes, when the other §6.4 conditions hold | "Own cloud — your checker, your key (tier 1 eligible)" | In both modes the checker: - reads the seat's systems (hosted: only the sources the seat connected; credentials are write-only, encrypted at rest and audit-logged); - builds the v4 submission with the same builder (the hosted runner's is tested against `signer-service`'s on shared vectors); - submits it through the same desk validation. At L2 the seat's own key signs. **Pre-strike readiness.** Fifteen minutes before each strike the desk checks each seat: a hosted seat's sources must be reachable and its KMS permission valid; an own-cloud checker must have checked in within the last 30 minutes. A seat that is not ready is alerted by webhook, and by e-mail where enabled, and the alert is audit-logged. Three rules: - The checker **never** reads the proposed value to build a submission. The only exception is the lender's comparison, which the desk performs. - It **never** widens a tolerance. - It **halts** (sends nothing and escalates) when a source cannot be read. | Seat | Typical source systems | What the adapter does | |---|---|---| | **Venue** | Matching-engine trade database or a trade-history API; FIX drop copy; market-data service for the book; exchange status or halt log | Selects trades with timestamps in the window. Computes count, Σqty, Σ(px·qty)/Σqty, min and max. Sums halt seconds from the status log. If no trades, computes time-weighted best bid and ask from book snapshots, and the seconds the book was two-sided | | **Lender** | Risk engine or collateral-management system (the mark and eligibility schedule); haircut table | Reads the mark the lender's own book uses at the strike, its timestamp, the eligibility flag and the haircut | | **Issuer** | Reserve attestation system: PoR feed, custodian API, on-chain read of the lock or reserve addresses. Token supply from the registry. Redemption desk and mint/burn controls | Reads reserves and supply at the same instant, the evidence reference (report URL, address list, block number), and the redemption and mint/burn status flags | | **Custodian** | Custody statement (e.g. an ISO 20022 statement of holdings, or a portal API); encumbrance or pledge register | Reads units held for the fund and units encumbered at the statement time. The ledger holdings come from the desk's read-only API | | **Transfer agent** | Shareholder register system | Reads shares outstanding at the register time. The ledger shares come from the desk's read-only API | Example configurations ship with `signer-service` for every seat. Its stub adapter **halts** until the seat wires a real source, so no placeholder is ever submitted. --- ## 11. IOSCO Principles: implementation map Source: IOSCO, *Principles for Financial Benchmarks, Final Report*, FR07/13, July 2013 (Appendix A1; principle texts on printed p.15–29). "Implemented" means built and tested in this codebase. None of it has been exercised with a third party, and nothing has been audited. This is a self-assessment, not a statement of compliance. | # | Principle | State | What exists / what is missing | |---|---|---|---| | 1 | Overall responsibility of the administrator | **Partial** | The administrator is named, and the methodology and rules are published. There is no regulated entity and no formal control framework | | 2 | Oversight of third parties | **Partial** | Sources are named. The internal exchange composite (Coinbase, Kraken, Bitstamp) is not licensed for publication and is used internally only (§3.1, §7); Scan is read for CC. There are no agreements with data providers or seats yet | | 3 | Conflicts of interest for administrators | **Partial** | The administrator does not trade and is not a member (ledger-enforced); a conflicts policy is written. A one-person administrator is itself a concentration risk | | 4 | Control framework | **Partial** | Automated controls: 422 validation, gates, ledger constraints, append-only log. There is no independent control function | | 5 | Internal oversight | **Not implemented** | No independent oversight function (§9.1). Constituting one, countersigned by its independent members, is a hard precondition for any value above tier 0 (§6.4) | | 6 | Benchmark design | **Partial** | The design is documented, including the 24/7 family (§3A), the tokenised-equity, corporate-action and basket rules (§3B, written, mostly not built) and the market-concentration controls (weight cap, §5.3). The underlying market (Canton venues for CBTC, cETH, CC) is not yet shown to be active. Off-hours, the token's own market is thin by nature, which is why the band exists | | 7 | Data sufficiency | **Not demonstrated** | The hierarchy is designed to anchor on transactions. No venue has submitted, and no exchange-derived value is published (§7). OFF-HOURS SIGNED fixings anchor on the home market's closing transactions and extrapolate from related markets, which P7 allows ("extrapolations from prior transactions", printed p.20), and refuse to publish below two live inputs of distinct signal types (§3A.4, §3A.5). None of their inputs is wired | | 8 | Hierarchy of data inputs | **Implemented (code)** for OFFICIAL; **specified** for OFF-HOURS SIGNED | Levels (a) to (d) in the desk; not yet exercised. The off-hours waterfall and change-signal priority (§3A.4) are specified, not built. Related-market transactions rank below the token's own quotes for OFFICIAL, and above token trades off-hours, because off-hours the related market is deeper (§3, §3A.4) | | 9 | Transparency of determinations | **Partial** | The determination, exclusions and digests are recorded. Input level on the public series is planned. Each OFF-HOURS SIGNED fixing is specified to carry its band, the inputs used, the inputs stale, and its flags (§3A.5, §3A.7); not built | | 10 | Periodic review | **Planned** | Annual review committed (§9.8); first due 30 Sep 2027 | | 11 | Content of the methodology | **Implemented** | This document, including the extrapolation method for off-hours values (P11(b), printed p.23: "any models or extrapolation methods") and the limits of the design (P11(h)) | | 12 | Changes to the methodology | **Policy only** | §9.6; no consultation run yet | | 13 | Transition (cessation) | **Implemented** | 60-day `CessationNotice` enforced on-ledger (§9.7) | | 14 | Submitter code of conduct | **Written** | §9.3; no seat has signed it | | 15 | Internal controls over data collection | **Partial** | Validation of form, units, windows and digests; issued seats and credentials; L2 external signing. There is no verification of seats' source data | | 16 | Complaints procedures | **Policy only** | §9.5 | | 17 | Audits | **Not implemented** | Planned before third-party settlement use (§9.9) | | 18 | Audit trail | **Implemented** | Ledger plus append-only event log; five-year retention is policy (§9.4) | | 19 | Cooperation with regulatory authorities | **Policy only** | The administrator is not supervised. It will provide records on request | --- ## 12. Regulatory position - **Not authorised.** ETP Foundry is not authorised, registered, recognised or endorsed as a benchmark administrator under the EU Benchmarks Regulation (EU) 2016/1011 or the UK Benchmarks Regulation, or in any other jurisdiction. This methodology does not claim otherwise. - **Classification.** A fixing determined from Canton venue submissions is based on **input data contributed by contributors** (BMR Art. 3(1)(8)–(9)). Canton venues are not trading venues within MiFID II / UK MiFIR, so it is not a regulated-data benchmark (Art. 3(1)(24)), and the contributor code-of-conduct and supervised-contributor provisions (Art. 15, 16) are the relevant model. Whether a fixing is a "benchmark" within BMR Art. 3(1)(3) depends on how it is used, not on ETP Foundry's status. ETP Foundry does not assert that its fixings, OFFICIAL or OFF-HOURS SIGNED, fall outside that definition. - **Canada (question for counsel).** The administrator operates from Ontario. No ETP Foundry fixing is designated under Multilateral Instrument 25-102 *Designated Benchmarks and Benchmark Administrators*. Designation, if sought or imposed, would bring MI 25-102's governance, oversight-committee and assurance requirements. Counsel's view is required on whether any use of a fixing could lead to designation. - **United States (question for counsel).** No benchmark-administrator regime applies. But a fixing referenced by a registered fund, an ETP or a CFTC-regulated contract brings the fund's Rule 2a-5 pricing-source oversight, and the anti-manipulation provisions of the Commodity Exchange Act, to its inputs. An OFF-HOURS SIGNED fixing used by a lender for liquidations may raise the same questions. Counsel's view is required before any such use. - **EU scope change.** Regulation (EU) 2025/914, applicable from 1 January 2026, narrows the EU BMR to critical, significant (≥ EUR 50 bn), EU Climate and certain commodity benchmarks. It lets EU supervised entities use out-of-scope third-country benchmarks without equivalence, recognition or endorsement. Whether and how that applies to a given fixing is a legal question for counsel, not an assumption of this document. - **UK.** The UK BMR is supervised by the FCA. Its reform under FSMA 2023 is pending. We have not verified the current timetable. - **Before a regulated entity references a fixing.** Before any EU- or UK-supervised entity references a fixing in a regulated product, the administrator will obtain legal advice and resolve the applicable route. --- ## 13. Ledger: what is enforced where | Rule | Enforced by | |---|---| | K-of-N, K ≥ 2, administrator not a member, one fixing per series per day, forgery impossible | Daml `crossdesk 3.2.0` | | Venue range contains the value; range only from the venue; no-prints attested explicitly | Daml `checkEvidence` | | v4 submission form, units, precision, windows; lender band; issuer, custodian and transfer-agent gates | Desk, before submission | | Determination (VWM, eligibility, outliers), restrike, finalisation gate | Desk, at determination and finalisation | | Truth of a seat's source data | **Nobody.** The seat's own systems, and its accountability on a permanent record | | **Built in this version** (§13.1): simple-median outlier anchor; 50% weight cap; two-venue range test; midpoint tie rule (since replaced); single venue never above tier 0; `selfTradesExcluded`, `markFromPublicReference`, required `markSource`, mark age from submission; no tier 3 while the issuer gate is refused; level (c) never tier 1; the §6.4 conditions for any value above tier 0 (oversight and venue-condition records) | Desk, before submission and at finalisation; unit-tested. Not on-ledger | | **Built by the 29 Sep 2026 amendment** (§13.1, second table): crypto strike 16:00 Europe/London; 10% share floor; weight-proportional tie rule; two-venue test on the count after the outlier step; silent issuer blocks tier 3; no public exchange-derived values, with level (c) and tier 3 unavailable without a licensed reference; seat operator of record for condition 3; oversight and venue records countersigned by the independent members' own accounts | Desk, unit-tested. Not on-ledger | | **24/7 family (§3A), phase 1, built 5 Oct 2026:** the 00/08/16 UTC schedule, class-C determination and band, v4.1 off-hours submissions, seat gates and halts, the issuer weekend rule, publication, mixed baskets, the sandbox path (§3A.11) | Desk, unit-tested. **Not on-ledger**: the Daml change (§13.2 item 1) is not built | The Daml changes that would move the determination and the submissions on-ledger are written up as a **proposal**. They are not built. ### 13.1 Desk changes this version required (built) Every row below is built and unit-tested in the desk. One consequence, by design: until an oversight function is on record and K signatures come from L2 third-party seats, every pilot value is published at tier 0. The strike-zone row was settled on 28 Sep 2026 (16:00 London) and set in code on 29 Sep 2026. | Rule | Change | |---|---| | Simple-median outlier anchor (§5.3 step 2) | Replace the preliminary `weightedMedian(...)` used as the outlier anchor with an unweighted median of eligible VWAPs | | 50% weight cap (§5.3) | Cap any weight share above `Rules.maxWeightPct` (new, default 50) and rescale the rest, before the final VWM | | Midpoint at exactly half (§5.3) | Return the midpoint of the value at which cumulative weight equals exactly half and the next value. **Replaced on 29 Sep 2026** by the weight-proportional interpolation (second table) | | Two-venue range test (§5.3 step 3) | With two eligible venues, require the value to lie within both `low`–`high` ranges; else level (a) unavailable | | Single venue never above tier 0 (§5.3 step 4, §6.4) | Treat a single-source determination as tier 0 whatever K is reached | | `selfTradesExcluded` (§4.1) | New boolean; `false` makes the window ineligible | | Lender fields (§4.2) | Make `markSource` required; add the boolean; measure `markAsOf` against the submission time, not `w.opens()` | | No tier 3 while the issuer gate is refused (§6.2) | Skip tier 3; allow tier 4 only if the prior fixing is < 24 h old; else tier 5 | | Level (c) never tier 1 (§6.4) | When the determination is `Level.REFERENCE`, do not finalise as a committee fixing; publish tier 3 with the attested factor | | Conditions above tier 0 (§6.4) | Refuse tier 1/2 unless K signatures are L2 third-party seats not operated by the administrator, and an oversight approval of the methodology version is on record | | Strike zone (§1, §14) | Europe/London in both backends (29 Sep 2026; see the second table) | **Amendment of 29 Sep 2026 (built, unit-tested in the desk):** | Rule | Change | |---|---| | Crypto strike 16:00 Europe/London (§1) | `UTC` → `Europe/London`, matching `backend-devnet` | | Share floor (§5.2, §5.3 step 3) | After the outlier step, a venue below 10% of the remaining volume is recorded and left out of the median | | Weight-proportional tie (§5.3) | At an exact half, (w_i·v_i + w_j·v_j) / (w_i + w_j) with capped weights, in place of the midpoint | | Two-venue test after the outlier step (§5.3 steps 4 and 6) | The cap and the two-venue rules use the count remaining after the outlier step and the floor; three eligible venues that drop to two are range-tested | | Silent issuer blocks tier 3 (§6.2) | No passing issuer snapshot inside the freshness limit is treated as a refusal | | No public exchange-derived values (§7) | Public routes carry committee-derived values or "not published, awaiting a licensed source"; the tier-0 composite seed is not published | | Level (c) and tier 3 need a licensed reference (§3.1, §6.2) | Without a licensed reference, no level (c) candidate and no tier 3; the fallback goes to tier 4 or 5 | | Operator of record (§6.4 condition 3) | A seat operated by the administrator or an affiliate, or flagged operator-run, never counts toward K, whatever its level | | Countersigned governance records (§6.4 conditions 1 and 4) | Oversight and venue-condition records count only once a majority of the independent members have countersigned them from their own accounts | | Tier 1 notional floor (§5.2, §6.4 condition 4) | Every venue in the median must have traded USD 10,000 (CBTC) / 5,000 (others) in the window for any value above tier 0 | ### 13.2 Build list for the 24/7 family (§3A) and the equity and basket rules (§3B), prioritised Estimates are engineer-days for one engineer who knows this codebase, excluding data-licence procurement. The last column gives the status at **5 Oct 2026** (phase 1, §3A.11). | # | Priority | Item | Effort | Status (5 Oct 2026) | |---|---|---|---|---| | 1 | P0 blocker | **Ledger slot for three fixings a day.** New sessions (e.g. `I00`, `I08`, `I16`) or an `IndicativeFixing` template with its own series slot per fixing time, carrying the value, band, label and an input digest. Needs a Daml package upgrade and a Daml SDK, which is not installed here | 5–8 | **Not built.** Records are desk-side events | | 2 | P0 | **Off-hours schedule** at 00:00 / 08:00 / 16:00 UTC, every day, with cut-off T+10 min, window T+30 min, and `NO FIXING` in place of tiers 3–5 | 3–4 | **Built**: slots, cut-off T+10, `NO FIXING`, no tiers 3–5. K is counted at the cut-off; the T+30 window is not built | | 3 | P0 | **Class-C determination** as a pure, tested function: anchor, change signals and priority, screen X, depth bound, band, `NO FIXING` / `BOUNDED` / `EXCEPTIONAL` | 3–4 | **Built** | | 4 | P0 | **Protocol v4.1 fields**: venue 15-minute window, `quoteCurrency`, depth-at-size, `bookAsOf`, `selfTradesExcluded`; lender 15-minute mark age and the declared `markBpsOffHours` gate; issuer 96-hour custodial freshness, `multiplier`, `multiplierNext`, `primaryLevel`, `corporateActionPending` | 3–5 | **Built in the desk**. Not built in `signer-service` or the hosted runner | | 5 | P1 | **Token secondary trades** off Canton (CEX and DEX), 15-minute VWAP per venue, and **order-book depth at size** | 4–6 | **Partly, for §3A.5a only** (off on the live desk): public readers for Kraken xStocks, Binance bStocks, and pinned DEX pools (Robinhood Chain, Ethereum, Solana). No order-book depth off Canton; Canton venue seats submit their own windows and depth | | 6 | P1 | **Stablecoin FX** (USDC/USD, USDT/USD) | 1 | **Partly, for §3A.5a only:** Kraken USDT/USD, USDC/USD and USDG/USD over the same window convert the Binance, Ethereum and Solana, and Robinhood Chain windows. Other non-USD windows are excluded | | 7 | P1 | **Home close, multiplier and corporate actions**: official close from a licensed vendor; xStocks multiplier poller (`api.xstocks.fi/api/v2/public/assets/{symbol}/multiplier`); ex-date calendar | 3–4 | **Partly.** The anchor is the last OFFICIAL fixing; issuer `multiplier`/`multiplierNext` adjust it. No licensed close, poller or calendar | | 8 | P1 | **Index futures** ES and NQ, contract roll calendar. Needs a CME market-data licence | 2–3 | **Not built** (no licence) | | 9 | P1 | **Publication**: `GET /api/offhours/{id}` and series rows labelled `OFFHOURS` with band, inputs used and stale; webhooks for `NO FIXING` and `EXCEPTIONAL` | 2–3 | **Built**: `GET /api/offhours`, `/api/offhours/{id}`, `offHours` on the benchmark API, webhooks `offhours.exceptional` and `offhours.no-fixing` | | 10 | P2 | **Mixed baskets**: OFF-HOURS SIGNED basket value with the linear band sum; extend the unsigned `GET /api/basket/nav/indicative` to carry bands | 2 | **Built** for the signed basket value (linear band). The unsigned indicative NAV is unchanged | | 11 | P2 | **Layer 1 for equities**: the live composite from the class-C inputs | 1–2 | **Not built** | | 12 | P2 | **Overnight sessions** (Blue Ocean, 24X once on the SIP). Needs a data licence; no consolidated overnight tape before the projected Nov/Dec 2026 SIP support | 2 | **Not built** (no licence) | | 13 | P2 | **Cross-listed ETFs** with the daily ratio k. Needs exchange data licences | 2–3 | **Not built** (no licence) | | 14 | P2 | **Issuer primary level** feed, once an issuer seat provides it | 1 | **Partly.** `primaryLevel` is accepted from the issuer seat. No adapter | | 15 | P0 | **Band back-test**: 12 months of Friday-close → Monday-open and holiday gaps per asset; realised coverage at z; published before any attested off-hours fixing | 3–5 | **Not built.** Every band is labelled uncalibrated | | 16 | P0 | **Signal-type rule and venue signature among K**: count inputs by signal type with the off-hours size floors; refuse K without a venue signature | 1 | **Built** (signal types counted with the off-hours floors; K without a venue signature gives `NO FIXING`) | | 17 | P1 | **TOKEN-CONSENSUS fallback** (§3A.5a): ≥ 3 issuer families, 2 independent of the priced token's issuer, median of per-family moves, flagged, tier 0; public readers; V_0 capture at the close for recent-only venues; Robinhood Chain and Ondo readers | 3–5 | **Built, switched off on the live desk** (5 Oct 2026): the rule, the flag, the sandbox path; readers for Kraken, Binance, Robinhood Chain (9 pools), Ondo on Ethereum (3 pools) and xStocks on Solana (3 pools); **the close-window recorder, running on the live desk** (V_0 at each NYSE close, V_t at off-hours slots for venues with no history, each response's SHA-256 kept). On the 3 Oct 2026 data at most two families qualified at any slot (three possible for NVDA at 00:00 UTC with the recorder running). **Not done:** licences for publishing derived values; no reader for Dinari or MEXC | | 18 | P0 (before any equity OFFICIAL) | **Licensed official closing price** of the primary listing, and the reference R = C × r on the record for every OFFICIAL equity fixing (§3B.1) | 2–3 + licence | **Not built** (no licence) | | 19 | P0 | **NYSE early closes in the OFFICIAL schedule** (13:00 strike, window ending at the early close) | 1 | **Not built.** Known to the off-hours schedule and the recorder only | | 20 | P0 | **Home-market status**: halts, suspensions and delistings of the primary listing, `HOME-HALTED`, the 5-day review trigger (§3B.2) | 2 | **Not built** | | 21 | P0 | **Corporate-action record**: the issuer's notice and the announcement sources (company, primary listing) with SHA-256, the 2-day notice check, `LATE-NOTICE`, and the `CA-DISAGREEMENT` halt for OFFICIAL and off-hours (§3B.3) | 3–4 | **Partly.** The issuer's `multiplier`, `multiplierNext`, `multiplierActivatesAt` and `corporateActionPending` are accepted and act off-hours. No announcement sources, notice check or disagreement halt | | 22 | P1 | **Weighting and rebalancing on Canton**: equal and capped weights, rebalance announcement, reference-date units, effective-date switch (§3B.4–§3B.5) | 4–6 | **Not built on Canton.** Fixed units and a once-only weight-to-units conversion at creation are built; the EVM vault has a timelocked, cancellable rebalance | | 23 | P2 | **Index level with a divisor**, `CARRIED` legs, unscheduled removal at the last fixing (§3B.5–§3B.6) | 2–3 | **Not built.** No index level is published | Total: about **35–50 engineer-days** for items 1–17 (items 2, 3, 4 (desk), 9, 10 and 16 are built: roughly 12–16 of them), and about **14–20** more for items 18–23, plus licences for CME futures, a US closing-price source, and (for rows 12–13) overnight and non-US exchange data. The §13.1 items are separate and already built. --- ## 14. Parameters awaiting a founder decision Every row is a methodology parameter. The precedent for each is in §5.0 (the row number is given). | Parameter | Pilot default | Recommendation before an OFFICIAL fixing | |---|---|---| | **Crypto strike zone** (rows 3–4) | **16:00 Europe/London** (set 29 Sep 2026) | **Decided: 16:00 Europe/London, adopted 28 Sep 2026**, aligning the window with the CF BRR TWAP Period and the WMR 16:00 London fix. It replaces the 16:00 UTC of rulebook v0.2 §5.1. No fixing had been published under either, so no referencing contract needed notice. The off-hours times stay 00:00, 08:00 and 16:00 UTC | | `minVenues` (row 7) | 1 (single source flagged, **tier 0 only**) | **2 venues run by different operators**, not affiliated with the issuer or the administrator. This is a **condition** for any tier 1 or tier 2 value, not a recommendation (CF Criteria v8.5 §2: two at launch) | | Weight cap and tie rule (row 7a) | **50%**, weight-proportional tie (built) | **50%** of total weight when three or more venues remain after the outlier step and share floor; with two, the value must lie within both ranges | | Share floor (row 7b) | **10%** (built) | 10% of total eligible window volume | | `minTrades` per venue (row 8) | 1 | 5. No public precedent gives a number (WMR sets it by expert judgement) | | `minNotionalUsd` per venue (row 8) | 1,000 (pilot eligibility) | **10,000 (CBTC) / 5,000 (cETH, CC) is a condition of any tier 1 value, not a recommendation** (§5.2). For scale, SONIA admits only trades ≥ £25m, and CF requires > 3% of the reference rate's average daily window volume over 90–180 days (an admission test) | | Venue admission (§4.1a) | none | 90 days' history; data-sharing and audit right (5 business days); self-trade exclusion attested; surveillance; the record countersigned by the independent oversight members | | `outlierBps` (row 6) | 300 | 300 for CBTC and cETH; 500 for CC (thinner). The published precedent is 500 bp (CF BRR, §5.3) | | `maxSpreadBps` / `minQuotedPct` | 200 / 50% | Unchanged until quote data exists | | Determination tolerance | 0 bp (the value must equal the determination) | Keep 0 | | Lender tolerance (`markBps`) (row 11) | 25 bp, declared per lender | 25 bp for CBTC and cETH; 50 bp for CC. IPV practice requires a pre-set threshold but no regulator publishes a number (BCBS 2009 P1, P4) | | Lender mark age (§4.2) | 60 min before the submission itself; `markSource` required; `markFromPublicReference` required (built) | Keep | | Issuer freshness (row 13) | 24 h | 24 h (attested); 1 h (on-chain) | | Observation window (rows 3, 5) | 60 min, one window (15:00–16:00 London) | Keep 60 min (CF BRR); move to 12 × 5-minute partitions when venues can submit per partition. The cost of one window was measured on 25 Sep 2026 (§5.6; figures on request) | | Restrikes per strike | 1 | 1 | | **24/7 family (§3A)** | | | | Fixing times (S19) | **00:00, 08:00, 16:00 UTC (built 5 Oct 2026)** | 00:00, 08:00, 16:00 UTC every day. Ask the first lenders whether their liquidation engines need hourly (15 Sep draft, question 5) | | Which assets first | none | SPYx and QQQx only (index tokens, where futures are the strong signal); single-stock tokens later, with wider bands | | Maximum ages (§3A.4) | — | Home live 1 min; futures 5 min; overnight session 5 min; token trades 15 min; order book 1 min; cross-listed 5 min; stablecoin FX 5 min; issuer primary since publication | | Token-trade window (S8) | — | 15 minutes | | Change-signal priority | — | futures → overnight session → cross-listed → token trades; first eligible sets the value | | Band (S14) | — | σ = 60-day close-to-close daily volatility; τ from the last hard signal; b_min = 5 bp; b_max = 1,000 bp (above it, `NO FIXING`); D includes the dispersion of V_0. **z = 2 recommended** for haircuts (about 95% nominal; z = 1 is about 68% nominal). Decide the coverage target (90% or 95%) that the 12-month back-test must show (§3A.5) | | Depth size S (S9) | — | USD 25,000, set per asset from observed books | | Source disagreement X (§3A.5) | — | 5% (rulebook v0.2 §7.4) | | EXCEPTIONAL Y (S17) | — | 10%, flag only (rulebook v0.2 §7.5); CME's overnight ES limit of 7% is the nearest reference | | Minimum independent live inputs | **2** (built, `offhours.min-signal-types`). The sandbox keeps 2 and runs the TOKEN-CONSENSUS fallback (§3A.5a) on, flagged `TOKEN-CONSENSUS`. Setting 1 on the desk publishes weekend equity values from token trades alone, at tier 0 | 2, of **distinct signal types** (rulebook v0.2 §5.2 as tightened by §3A.4); token trades are one type; off-hours size floor per token venue: `minTradesOffHours` 5, `minNotionalOffHoursUsd` 10,000, `selfTradesExcluded` = true | | TOKEN-CONSENSUS fallback (§3A.5a) | **Off on the live desk** (`offhours.token-consensus-enabled` = false); on in the sandbox. 3 issuer families minimum (`token-consensus-min-families`, never below 3), 2 independent of the priced token's issuer | Founder decision to switch on, after each venue's terms for publishing a derived value are confirmed (or licensed) and the bStocks issuer is verified. Tier 0 always | | Issuer weekend rule (G9, D4) | **Built:** `redemptionsClosedReason` = `primary-market-closed` is accepted while the home market is shut; reserves ≥ supply, freshness, mint/burn and corporate actions still gate | Add corroboration by the latest custodian or agent statement (≤ 96 h) | | σ when history is short | **200 bp a day, flagged `SIGMA-DEFAULT`, below 20 daily returns** (built) | Set per asset from the back-test | | Stale futures as information | — | Open: whether the last ES/NQ print after the anchor (Friday up to 21:00 UTC) may be used as a stale-but-informative hard signal on weekends (Example C1) | | Off-hours issuer freshness | **96 h custodial, 24 h otherwise (built)** | 96 h for a custodial snapshot, so a Friday statement covers a weekend and a Monday holiday | | Off-hours lender gate | — | **`markBpsOffHours`, declared per lender** in advance (default its `markBps`), published with every fixing; the band never widens it; mark ≤ 15 min old | | Single-stock tokens without futures | — | Index futures not used as a beta proxy | | Mixed-basket band | — | Linear sum of leg bands (conservative) | | **Equity and baskets (§3B)** | | | | Suspended leg in an index level | — | Carry the last OFFICIAL value, flagged `CARRIED`; review after **5 NYSE trading days** (precedents carry 20 to 60 days; shorter here because the token is collateral). Never in a NAV | | Corporate-action notice from the issuer | — | At least **2 NYSE trading days** before the ex-date; late notice flagged, not refused, if the sources agree | | Rebalance notice and reference date | EVM vault: timelock ≥ 1 day, default 2 (built) | Announce **5 NYSE trading days** before the effective date; reference prices = OFFICIAL fixings 2 trading days before it | | Default cap for capped baskets | — | Per basket; none by default. A cap c needs n × c ≥ 100% | | Non-USD primary listings | not admissible | Admit only with a named, licensed FX rate at the listing's close | | Data licences | none | **A licensed reference for level (c) and tier 3** (unavailable until one is licensed, §3.1); whether the internal pre-fill may be shown to seats on the proposal (§5.1); who pays for CME futures, a US closing-price source and overnight data; approved venue list for token trades | | Package pricing | — | Close only / close + off-hours / 24/7 (packaging and prices on request; not published) | | Oversight function | none | **Condition, not recommendation** (§6.4): three members, majority independent, constituted and approving this version by countersignature from their own accounts, before any tier 1/2 value or attested OFF-HOURS SIGNED fixing | | Signing keys | administrator holds every seat's L1 key; L2 built and proven on DevNet 26 Sep 2026, switched off on the running desk | K signatures from third-party seats at **L2** (own keys), none operated by the administrator or an affiliate (operator of record), before any tier 1/2 value. L2 on before the first seat onboards | | Trades settled at a restated value (§6.5) | undecided | Decide: unwind, cash adjustment, or leave standing | --- ## 15. Appendix A: Evidence pack Each source below was opened and read for this document. Where a primary text could not be reached, the row says so, and no rule relies on it. | # | Publisher | Title, version, date | URL | What we took from it | |---|---|---|---|---| | A1 | IOSCO | *Principles for Financial Benchmarks, Final Report*, FR07/13, July 2013 | https://www.iosco.org/library/pubdocs/pdf/IOSCOPD415.pdf | The 19 principles. Taken from them: data sufficiency (P7, printed p.20), input hierarchy (P8, p.21), transparency (P9, p.22), periodic review (P10, p.22), change consultation (P12, p.23), cessation (P13, p.24), submitter code of conduct (P14, p.25–26), complaints (P16, p.27), audit and a 5-year audit trail (P17–18, p.28), oversight (P5, p.18) | | A2 | UK legislation (onshored EU text) | Regulation (EU) 2016/1011 (Benchmarks Regulation) | https://www.legislation.gov.uk/eur/2016/1011/contents | Definitions: input, transaction and regulated data, Art. 3(1)(14), (15), (24). Oversight function, Art. 5(1), (3)(a), (4). Input data "transaction data, if available and appropriate", Art. 11(1). Methodology transparency and consultation, Art. 13(1)–(2). Code of conduct, Art. 15(1)–(2). Supervised contributors, Art. 16 | | A3 | EU / CMS (secondary) | Regulation (EU) 2025/914 amending the BMR, applicable 1 January 2026. CMS, *EU Benchmarks Regulation Overhaul Published*, 21 May 2025 | https://cms.law | Scope narrowed to critical, significant, EU Climate and certain commodity benchmarks. The primary EUR-Lex text was not reachable; cite it only after counsel confirms | | A4 | CF Benchmarks | *CME CF Cryptocurrency Reference Rates Methodology Guide*, v17.4, 24 Aug 2026 | https://docs.cfbenchmarks.com/CME%20CF%20Reference%20Rates%20Methodology.pdf | 60-minute window and 12 × 5-minute partitions (§8, pdf p.19–20). VWM per partition with an equal-weight mean (§4.1.1, p.10). Delayed and erroneous data (§5.1–5.2, p.14–15). Potentially Erroneous Data exclusion at 5% (§5.3, p.15). No day-to-day expert judgement (§5.5). Restatement only if > 0.10% and on the same day (§6.1, p.17). Annual review, changes under UK BMR Art. 13 (§10, p.47) | | A5 | CF Benchmarks | *Constituent Exchange Criteria*, v8.5, 11 May 2026; *Constituent Exchanges List*, v13.7, 24 Aug 2026 | https://docs.cfbenchmarks.com/CME%20CF%20Constituent%20Exchanges%20Criteria.pdf | At least two constituents at launch (§2, p.4). Eligibility of > 3% of window volume over 180 or 90 days, plus market-integrity criteria (§3, p.5). The BTC constituent list | | A6 | FTSE Russell (LSEG) | *WMR FX Benchmarks: Spot, Forward, NDF and Metal Rates*, v30, Jan 2026 | https://www.lseg.com/content/dam/ftse-russell/en_us/documents/ground-rules/wmr-fx-methodology.pdf | A 5-minute window, ±2m30s around the fix (p.12). Fallback from trades to orders to quotes (§4.3, p.11; §4.4.2, p.12–13). 15-second snapshots for non-trade currencies (§4.4.1, p.12). Median of trades. A minimum number of valid trades by expert judgement (§4.4.2). Tolerance validation (§1.3.5 "Validation of data", p.4–5) | | A7 | ICE Benchmark Administration | *LBMA Gold Price and LBMA Silver Price Methodology*, Jan 2026 | https://www.ice.com/publicdocs/LBMA_Gold_Price_and_LBMA_Silver_Price_Calculation_Methodology.pdf | The price is formed from participants' orders, not their votes: 30-second rounds, and an imbalance threshold of 10,000 oz gold / 500,000 oz silver (¶6–8, p.1–2). Used as the contrast with a committee that votes on a price | | A8 | Federal Reserve Bank of New York | *Additional Information about Reference Rates* (web page) | https://www.newyorkfed.org/markets/reference-rates/additional-information-about-reference-rates | SOFR is a volume-weighted median of transactions ("Calculation Methodology"). Revision only if > 1 bp, same day ("Rate Revisions"). Data contingency | | A9 | Bank of England | *SONIA key features and policies* (web page) | https://www.bankofengland.co.uk/markets/sonia-benchmark/sonia-key-features-and-policies | Trimmed mean of the central 50%; only trades ≥ £25m ("(ii) Statement of methodology"). Insufficiency: ≥ 5 reporters fail AND volume < 70% of the 5-day mean. Republication ≥ 2 bp | | A10 | FTSE Russell (LSEG) | *Policy for Benchmark Methodology Changes*, v2.9, Jul 2026 | https://www.lseg.com/content/dam/ftse-russell/en_us/documents/policy-documents/ftse-russell-policy-for-benchmark-methodology-changes.pdf | Review at least annually (§2.1, p.4). Consultation typically ≥ 4 weeks, with a shorter window reserved, and ≥ 1 month's notice of a material change (§2.3.1 "Public consultation process", p.6) | | A11 | FTSE Russell (LSEG) | *Closing Prices used for Index Calculation*, v5.3, Aug 2026; *Corporate Actions and Events Guide*, v7.1, Sep 2026 (re-read 6 Oct 2026) | https://www.lseg.com/content/dam/ftse-russell/en_us/documents/policy-documents/closing-prices-used-for-index-calculation.pdf | The official closing price (auction) by exchange, US exchanges "Official Closing Price (Auction)" (p.6); a closed market carries the last close (p.3). Splits adjust without a divisor change (§4.1, p.7); two days' notice (§2.1.5, p.4) | | A12 | S&P Dow Jones Indices | *S&P U.S. Indices Methodology*, March 2025 (copy hosted outside spglobal.com) | cdn.prod.website-files.com/673b448cba170146346ba90f/682e130394819f969ae518c2_methodology-sp-us-indices.pdf | Divisor methodology (pdf p.17). ≥ 3 business days' notice (p.18). The Index Committee meets monthly and reviews annually (p.23). *Policies & Practices* was not reachable | | A13 | U.S. SEC | Rule 2a-5, 17 CFR 270.2a-5; adopting release IC-34128, 86 FR 748 (6 Jan 2021), rule text at 86 FR 807–808 | https://www.ecfr.gov/current/title-17/chapter-II/part-270/section-270.2a-5 | Valuation risks, methodologies, testing and pricing-service oversight with price challenges ((a)(1)–(4)). Segregation from portfolio management ((b)(2)). Definition of a readily available market quotation ((c)) | | A14 | UK legislation (onshored EU text) | Regulation (EU) No 575/2013 (CRR) Art. 105, as adopted | https://www.legislation.gov.uk/eur/2013/575/article/105/adopted | Independent price verification by a unit independent of the beneficiaries, at least monthly (Art. 105(8)); reporting lines independent of the front office (105(2)(b)). UK: moved to the PRA Rulebook from 1 Jan 2022; the PRA text was not opened | | A15 | UK legislation (onshored EU text; shown as prospectively revoked by FSMA 2023) | Commission Delegated Regulation (EU) 2016/101 (RTS on prudent valuation) | https://www.legislation.gov.uk/eur/2016/101/contents | Market-data sources used in IPV (Art. 3). A formal IPV process based on prices independent from the trading desk (Art. 19(3)(e)). Art. 19(3)(d) concerns thresholds for when valuation models are no longer robust, and is not relied on | | A16 | Basel Committee on Banking Supervision | *Supervisory guidance for assessing banks' financial instrument fair value practices*, 15 Apr 2009 | https://www.bis.org/publications/200904-guidelines-supervisory-guidance-assessing-banks-financial-instrument-fair-value-practices.pdf | Explicit quantitative thresholds that trigger a challenge (Principles 1 and 4, p.2–6). IPV definition (fn. 5, p.4). No reliance on a single pricing source (Principle 2). No numeric thresholds are published | | A17 | Bitwise (SEC filing) | Bitwise Bitcoin ETF prospectus, 424B3, 1 Aug 2025 | https://www.sec.gov/Archives/edgar/data/1763415/000121390025070105/ | NAV on CF BRRNY at 4pm ET. The fallback: a secondary source, then the principal-market price, then the sponsor's fair value | | A18 | Chainlink | *SmartData — Proof of Reserve* documentation; *Decentralized data model* | https://docs.chain.link/data-feeds/smartdata ; https://docs.chain.link/architecture-overview/architecture-decentralized-model | Types of reserve source: third-party, custodian, self-reported; wallet address lists. Deviation and heartbeat update triggers. Users are responsible for data quality | | A19 | Circle | *Transparency* page; *USDC Examination Report*, July 2026 (report dates 8 and 31 July 2026) | https://www.circle.com/transparency | A point-in-time assertion at stated dates, examined with reasonable assurance under AICPA attestation standards, monthly. A PoR covers assets against supply, not all liabilities | | A20 | AICPA (secondary: republished press release) | *2025 Criteria for Stablecoin Reporting*; Part II (controls) added 12 Jan 2026 | https://article.wn.com/view/2026/01/13/AICPA_Updates_Criteria_for_Stablecoin_Reporting_to_Address_C/ | The criteria exist. The primary text was not opened, so the criteria are **not** relied on for a rule | | A21 | ETP Foundry | Worked example B: BTC-USD, 25 Sep 2026, public trade data | On request (committee@etpfoundry.com) | Reproducible scripts, the raw responses with SHA-256 hashes, and results for §5.6. Figures are given to reviewers only, under the source venues' research terms | | A22 | CF Benchmarks | *CME CF Cryptocurrency Real Time Indices Methodology Guide*, v17.0, 21 Sep 2026 | https://docs.cfbenchmarks.com/CME%20CF%20Real%20Time%20Indices%20Methodology.pdf | BRTI "approximately every second … including weekends and holidays" (§7, p.24). "A robust, yet highly timely indication of the current price" (§4.2, p.15). Built from constituent order books (§4.1.1, p.8–9); Utilized Depth (§4.2, p.15) | | A23 | U.S. SEC | *Good Faith Determinations of Fair Value*, Release IC-34128, 86 FR 748 (6 Jan 2021) | https://www.govinfo.gov/content/pkg/FR-2021-01-06/pdf/2020-26971.pdf | Monitoring for significant events after a foreign market closes (§II.A.3(c), 86 FR 754). A stale foreign close is unreliable after an event, so the fund fair-values (§II.D, 86 FR 772–773, fn 355). Rule 2a-5(c) text (86 FR 808). Staff letters withdrawn on 8 Sep 2022 (§II.F, 86 FR 774–775) | | A24 | SEC Division of Investment Management | Letter to Craig S. Tyle (ICI) regarding valuation issues, 30 Apr 2001 | https://www.sec.gov/divisions/investment/guidance/tyle043001.htm | §I.C–I.D: evaluate significant events after the foreign market closes; triggers such as "a certain percentage change in a foreign futures index". **Withdrawn** (A23); historical only | | A25 | Investment Company Institute | *Fund Valuation Under the SEC's New Fair Value Rule*, Dec 2021 | https://www.ici.org/files/2021/21-ppr-fund-valuation-primer.pdf (read via a Wayback copy; 403 to scripts) | §V.C.3, p.23 and fn 77: time-zone fair-value adjustment factors from pricing services, using proxies and historical correlation | | A26 | Vanguard (SEC filing) | Vanguard International Equity Index Funds, Form N-CSRS, period to 30 Apr 2014 | https://www.sec.gov/Archives/edgar/data/857489/000093247114005891/intlequityindexfinal.htm | Note A: "foreign market proxies (for example, ADRs, futures contracts, or exchange-traded funds)" between the foreign close and the fund's pricing time | | A27 | CME Group | E-mini S&P 500 and E-mini Nasdaq-100 contract specifications (read 28 Sep 2026) | https://www.cmegroup.com/markets/equities/sp/e-mini-sandp500.contractSpecs.html ; https://www.cmegroup.com/markets/equities/nasdaq/e-mini-nasdaq-100.contractSpecs.html | "Sunday 6:00 p.m. - Friday - 5:00 p.m. ET … daily maintenance period from 5:00 p.m. - 6:00 p.m. ET" | | A28 | CME Group | *S&P 500 Price Limits: FAQ*, 22 Sep 2020; *US-Based Equity Index Futures Price Limits: FAQ*, 22 Sep 2020 | https://www.cmegroup.com/trading/equity-index/sp-500-price-limits-faq.html | Q3: "a hard upside and downside limit of 7% from 5:00 p.m. to 8:30 a.m." (CT); dynamic circuit breakers of 3.5% with a two-minute pause | | A29 | Blue Ocean Technologies; Robinhood; CNBC (secondary) | Blue Ocean ATS FAQ; Robinhood Help Center, "Robinhood 24 Hour Market"; CNBC, 5 Aug 2024 | https://blueocean-tech.io/faq/ ; https://robinhood.com/us/en/support/articles/24hour-market/ ; https://www.cnbc.com/2024/08/05/robinhood-no-24-hour-trading-monday-due-to-issue-at-third-party-venue.html | Blue Ocean 20:00–04:00 ET, Sunday–Thursday; trades reported to the FINRA TRF and CAT. Robinhood "Sunday 8 PM ET through Friday 8 PM ET". Blue Ocean suspended overnight trading on 5 Aug 2024 (secondary source) | | A30 | U.S. SEC | Release 34-101777 (27 Nov 2024), 24X National Exchange approval, 89 FR 97092; Release 34-104894 (25 Feb 2026), File S7-2026-06 | https://www.sec.gov/files/rules/other/2024/34-101777.pdf ; https://www.sec.gov/files/rules/other/2026/34-104894.pdf | 24X approved to trade NMS stocks "23 hours per day, five (5) days per week" (p.1, p.39). 24X Market Session 21:00–04:00 ET; the equity data plans project overnight support in Nov/Dec 2026 (p.3–5) | | A31 | Chainlink | *Tokenized Equity Feeds*; *Selecting Quality Data Feeds*; *Getting Historical Data* (read 28 Sep 2026) | https://docs.chain.link/data-feeds/tokenized-equity-feeds ; https://docs.chain.link/data-feeds/selecting-data-feeds ; https://docs.chain.link/data-feeds/historical-data | 24/5 feeds that "do not publish updates, including heartbeat updates, while markets are closed"; weekend data quality "N/A", update frequency "Stale"; the corporate-action pause "freezes at the last known good token value"; "Do not use these feeds outside those windows"; `updatedAt`; staleness detection. xStocks is not among the listed providers | | A32 | Pyth Network | *Market Hours*; *Best practices* ("Price Availability", "Confidence Intervals") | https://docs.pyth.network/price-feeds/market-hours ; https://docs.pyth.network/price-feeds/best-practices | US equity feeds follow market hours, with separate pre-market, post-market and overnight rows. Price ± confidence interval "intended to achieve 95% coverage". Staleness checks by default | | A33 | xStocks (Backed) | *How xStocks work*; *FAQ*; *Issuance and redemption: market flow*; *Dividends and stock splits*; *Multipliers*; public API (queried 28 Sep 2026) | https://docs.xstocks.fi/docs/how-xstocks-work ; https://docs.xstocks.fi/docs/dividends-and-stock-splits ; https://docs.xstocks.fi/developers/multipliers ; https://api.xstocks.fi/api/v2/public/assets/SPYx/multiplier?network=Ethereum | 1:1 backing; primary issuance and redemption 24/5, secondary 24/7; minimum $5,000; dividends reinvested through a multiplier, activated at 00:30 UTC the day after the ex-date; launch multiplier 1.0. **Live data, not methodology:** SPYx `currentMultiplier` 1.005714560286254; the API lists Chainlink (v10 schema) and Pyth feeds. The docs do not name an "official oracle" | | A34 | Chainlink | Data Streams *Report Schema* v8 (RWA Standard), v10 (Tokenized Asset), v11 (RWA Advanced) | https://docs.chain.link/data-streams/reference/report-schema-v8 (and -v10, -v11) | `marketStatus`: "Always use marketStatus to determine whether a market is open"; v11 statuses include Overnight and Closed; in v10, `tokenizedPrice` continues on weekends while `price` does not; `currentMultiplier`, `newMultiplier`, `activationDateTime` | | A35 | FTSE Russell (LSEG); S&P Dow Jones Indices | *Corporate Actions and Events Guide for Market Capitalisation Weighted Indices*, v7.1, Sep 2026; *Equity Indices Policies & Practices*, Aug 2026 (re-read 6 Oct 2026 for §3B via the Wayback capture of 3 Oct 2026) | https://www.lseg.com/content/dam/ftse-russell/en_us/documents/policy-documents/corporate-actions-and-events-guide.pdf ; https://www.spglobal.com/spdji/en/documents/methodologies/methodology-sp-equity-indices-policies-practices.pdf (read via the Wayback capture of 21 Aug 2026; 403 to scripts) | FTSE: adjustment on the ex date (§1, p.3); two-day notice of actionable events (§2.1.5, p.4); splits (§4.1, p.7); special dividends deducted before the open on the ex date (§4.2, p.7); scrip issues and stock distributions (§4.7, p.9); suspended constituents kept "for a period of up to 20 business days at its last traded price" (§4.18, p.24). S&P: delistings at "the primary exchange price, if available, or at a zero price" (p.5); merger finalisation notice (p.6); tender offers after final results (p.8); spin-offs at a zero price the day before the ex-date (p.8); rights offerings (p.10); special dividends (p.19); splits (p.24); suspended stocks carry the last official close (p.34); unexpected exchange closures and SEC Rule 123C (p.41) | | A36 | Basel Committee on Banking Supervision | *Amendment to the Capital Accord to Incorporate Market Risks*, Jan 1996 | https://www.bis.org/publications/199601-standards-amendment-capital-accord-incorporate-market-risks.pdf | §B.4(c), printed p.44: VaR "scaled up to ten days by the square root of time" | | A37 | U.S. SEC / NYSE; LULD Plan Participants | Release 34-106380 (SR-NYSE-2026-43), 91 FR 59278, 18 Sep 2026; Limit Up-Limit Down Plan | https://www.federalregister.gov/documents/2026/09/18/2026-19125/self-regulatory-organizations-new-york-stock-exchange-llc-notice-of-filing-and-immediate ; https://www.luldplan.com/ | Rule 7.12 market-wide circuit breakers at 7%, 13% and 20% of the prior S&P 500 close. LULD approved by the SEC on 31 May 2012 (plan text not opened) | | A38 | S&P Dow Jones Indices | *Index Mathematics Methodology*, September 2026 (read via the Wayback capture of 1 Oct 2026; 403 to scripts) | https://www.spglobal.com/spdji/en/documents/methodologies/methodology-index-math.pdf | The divisor exists "to maintain the continuity of an index level following the implementation of corporate actions, index rebalancing events, or other non-market driven actions" (p.5); divisor adjustments "after the close" (p.8); capped indexes (p.10); an equal weighted index "must be rebalanced from time to time" (p.16) | | A39 | MSCI | *MSCI Corporate Events Methodology*, February 2026 | https://www.msci.com/indexes/documents/methodology/0_MSCI_Corporate_Events_Methodology_20260210.pdf | A price adjustment factor "to neutralize ... the price movement due to the event" (§1, p.5); mergers (§2.1, p.7); spin-offs (§2.8, p.35); splits and stock dividends (§3.1–3.2, p.44); rights issues (§3.6, p.48); suspended securities: "carries forward the market price prior to the suspension" (§5.1, p.61); changes "announced to clients prior to their implementation" (§8.1, p.68) | | A40 | CF Benchmarks | *CF Digital Asset Index Family, Multi Asset Series, Ground Rules*, v4.4, 31 Aug 2026 | https://docs.cfbenchmarks.com/CF%20Digital%20Asset%20Index%20Family%20Multi%20Asset%20Series%20-%20Ground%20Rules.pdf | Exceptional constituent review dated "the 7th day immediately preceding" a removal, communicated to licensees (§3.8, p.18); alternative weights, equal and modified equal weighting (§4.5, p.25–26); capping "at rebalance points" or by "emergency rebalances" (§4.6, p.26–27); rebalance procedure (§6, p.29–30) | *Not verified from primary sources, and not relied on for any rule here:* - an ICE Data Services (FVIS) primary description of fair-value adjustment factors (product page 404; catalog behind login). A25 and A26 are used instead; - whether overnight ATS trades reported to the FINRA TRF reach the consolidated tape, and when; - whether LULD applies outside regular hours; - a precedent for fixed 00:00 / 08:00 / 16:00 UTC times; - the AICPA AT-C 215 (agreed-upon procedures) and AT-C 205 (examination) texts; - IAASB ISAE 3000 (Revised); - the date the WM/Reuters window moved to five minutes; - the current UK BMR reform timetable; - which Crypto.com instrument CF uses; - capped equity-index methodologies (for example 10/40 capped indexes), cited in §5.0 row 7a only as a resemblance. --- ## 16. Version history | Version | Date | Change | |---|---|---| | 1.0 (amended 6 Oct 2026, tokenised equities and baskets) | 6 Oct 2026 | New **§3B**: the reference for a tokenised stock (official closing auction price of the primary listing × the token's share ratio) and what counts as the primary listing; halts, suspensions, early closes and holidays; a corporate-action table (splits, cash and special dividends per the token terms, stock dividends, spin-offs, mergers, tender offers, rights issues, delisting, identifier changes) with the issuer's notice, the announcement sources, ex-date handling and a `CA-DISAGREEMENT` halt; basket and index rules (eligibility, fixed-unit, equal and capped weights, divisor, scheduled and unscheduled changes, mixed baskets, NAV versus index level, corrections, governance hooks); precedents E1–E8 from S&P DJI, FTSE Russell, MSCI and CF Benchmarks (A38–A40). §3B.0 says what is built and what is only written; §2, §3.1, §3A.4 row 8, §11 row 6, §13.2 items 18–23 and §14 updated. **No existing rule changed**; nothing makes a value easier to publish | | 1.0 (amended 5 Oct 2026, TOKEN-CONSENSUS readers and close recorder) | 5 Oct 2026 | §13.2 item 17 built: the **close-window recorder** (each public venue's 15-minute window at every NYSE close, and at off-hours slots for venues with no history, appended with each response's SHA-256; runs on the live desk, records only) and readers for **Robinhood stock tokens** (Robinhood Chain pools, USDG), **Ondo Global Markets** (Ethereum Uniswap v3, USDC) and **xStocks on Solana** (USDC); stablecoins converted at Kraken's USD trades over the same window, never assumed at par. §3A.5a venue table, "what this means today" (Saturday 3 Oct 2026 re-run) and licensing findings; §3A.4 rows 3 and 7, §3A.11, §13.2 items 5, 6 and 17. The fallback stays **off** on the live desk | | 1.0 (amended 5 Oct 2026, TOKEN-CONSENSUS) | 5 Oct 2026 | New §3A.5a, the **TOKEN-CONSENSUS fallback** (founder-approved direction): with no hard signal live, the median move of at least three issuer families' tokens (two independent of the priced token's issuer), each from its most liquid eligible venue, flagged `TOKEN-CONSENSUS` ("tokens only, lower confidence"), tier 0; fewer families give `NO FIXING`. **Off on the live desk**, on in the sandbox. Public readers for Kraken xStocks and Binance bStocks; the venue findings of 5 Oct 2026; §3A.4, §3A.5, §3A.7, §3A.11, §13.2 (items 5, 6, 17) and §14 updated | | 1.0 (amended 5 Oct 2026) | 5 Oct 2026 | OFF-HOURS SIGNED fixings, **phase 1 built** (§3A.11, §13.2 status column):
- desk-side schedule at 00/08/16 UTC for every scheduled instrument and Canton Coin;
- class-C determination and band; v4.1 off-hours submissions; seat gates, halts and `NO FIXING`;
- the issuer weekend rule (founder decision D4/G9);
- publication at `GET /api/offhours` and on the desk and public pages; the sandbox off-hours path;
- the anchor in phase 1 is the last OFFICIAL committee fixing;
- the two-signal-type minimum stays 2 (configurable);
- §3A.0 status, §7 publication row, §13 and §14 updated. No rule of §3A.4–§3A.8 was changed | | 1.0 (amended 29 Sep 2026) | 29 Sep 2026 | After the second bank review, before any commercial use:
- §4, §6.4, §10: two checker modes, **hosted** (administrator-operated, never tier 1, even with the seat's own KMS key) and **own cloud**; pre-strike readiness alerts;
- crypto OFFICIAL strike **16:00 Europe/London**, adopted 28 Sep 2026 (§1, §3A.0, §5.0 rows 3–4, §14); off-hours times stay UTC; the "coincide" rule now applies only in winter;
- licensing (§3.1, §7): no exchange-derived price on any public surface; level (c) and tier 3 require a licensed reference; example B figures removed from the public copies;
- §5.2–§5.3: 10% share floor; weight-proportional interpolation at an exact half (replaces the midpoint); "three or more" and "exactly two" counted after the outlier step and the floor (the floor is applied after the anchor); the two-venue caveat in §9.2; §4.1a and §5.2 aligned with the code; tier 1 notional floor a condition;
- §6.2: a silent issuer blocks tier 3;
- §6.4: condition 1 needs countersignature by the independent members' own accounts; condition 3 tests each seat's operator of record, whatever its level; L2 status stated (built, switched off on the running desk);
- §3A: layer 2 renamed **OFF-HOURS SIGNED** (`OFFHOURS`; formerly "signed INDICATIVE"); "indicative" now means unsigned only; tier 0 `pilot — not attested` until §6.4 holds; lender gate is the declared `markBpsOffHours`, never widened by the band; independent live inputs need distinct signal types and size floors; band calibration, z = 2 recommended, 12-month back-test; borrower-side conflict and a venue signature among K;
- `EXCEPTIONAL` has one meaning (a move above Y); chain events are `EVENT-`;
- worked example A recomputed; worked example C1 corrected to `NO FIXING`, C2 τ corrected to 30 s;
- tier labels aligned (tier 2 "committee fixing after escalation", tier 3 "fallback: reference × par (not a committee price)");
- §9.4 states who can read submissions (an off-ledger log under the administrator's access policy). | | 1.0 (amended) | 28 Sep 2026 | Before first publication:
- §3A, the 24/7 fixing family (live indicative, signed INDICATIVE fixings at 00/08/16 UTC with a data-quality band, OFFICIAL close), the class-C waterfall, per-seat off-hours submissions, mixed baskets, failure rules, precedent rows S1–S20; worked example C (§5.7);
- §0.1 precedence;
- manipulation controls specified (simple-median anchor, 50% weight cap, two-venue range test, midpoint tie rule, venue admission and data-sharing, self-trade attestation);
- lender role renamed a risk-side challenge, with `markFromPublicReference`;
- no tier 3 while the issuer gate is refused; level (c) never tier 1; conditions for any value above tier 0;
- §12 classification, Canada and US; citation corrections; §5.6 re-attribution with every figure printed by the evidence script.
Nothing in this amendment is built unless §13 says so | | 1.0 | 28 Sep 2026 | First version under this title:
- input hierarchy (a) to (d);
- determination by volume-weighted median of venue VWAPs, with eligibility and outlier rules;
- per-seat numeric submissions (`SIGNER_PROTOCOL v4`);
- lender validation band and issuer peg-integrity gate;
- governance, code of conduct, IOSCO map.
Supersedes Fixing Methodology v0.1 §3, §5 and §7 where they conflict | | 0.1 | 12 Aug 2026 | Fixing Methodology v0.1: waterfall, strike, restatement, cessation |