Skip to main content

Externally Owned Surplus

· 6 min read
Eric Forgy
Founder of CavalRe

Surplus is externally owned CAV held by the Protocol for sale. CavalRe owns the CAV, authorizes its use, and receives the sale proceeds in CavalRe Treasury. CavalRe and the Protocol are distinct accounting entities.

The mechanism can route independent fractions of the user's pay and receive legs through Reserve. The remaining amounts execute as a CavalRe-owned CAV sale. A pure sale bypasses Reserve and leaves Multiswap prices unchanged. A mixed settlement is accepted when its complete Reserve endpoint passes the gauge-invariant safety condition.

1. Direct quote

Consider a user exchanging AA for CAV. First calculate the ordinary direct Multiswap quote

daAD>0,daCAVD<0,da_A^D>0, \qquad da_{\mathrm{CAV}}^D<0,

with

daADPAD+daCAVDPCAVD=0.da_A^D P_A^D +da_{\mathrm{CAV}}^D P_{\mathrm{CAV}}^D=0.

The user receives the same quoted CAV amount under Surplus settlement. Surplus changes the sources and destinations of the token legs, not the user's quote.

2. Ownership journal

When CavalRe places CAV in Surplus, the CAV ledger posts

DebitCredit
Surplus CAVCavalRe Payable CAV

The asset and liability are equal amounts of the same token. At any CAV price their net Protocol-equity contribution is zero:

aCAVSurplusPCAVaCAVSurplusPCAV=0.a_{\mathrm{CAV}}^{\mathrm{Surplus}}P_{\mathrm{CAV}} -a_{\mathrm{CAV}}^{\mathrm{Surplus}}P_{\mathrm{CAV}}=0.

Repricing changes both marked values equally, so the cancellation remains exact.

3. Settlement fractions

Let

0πApay10\le\pi_A^{\mathrm{pay}}\le1

be the fraction of the user's AA routed to Reserve, and let

0πCAVrec10\le\pi_{\mathrm{CAV}}^{\mathrm{rec}}\le1

be the fraction of the user's CAV supplied by Reserve. The fractions are independent. Multiswap does not require them to be equal.

The Reserve endpoint is

aAS=aA+πApaydaAD,a_A^S=a_A+\pi_A^{\mathrm{pay}}da_A^D, aCAVS=aCAV+πCAVrecdaCAVD.a_{\mathrm{CAV}}^S =a_{\mathrm{CAV}} +\pi_{\mathrm{CAV}}^{\mathrm{rec}}da_{\mathrm{CAV}}^D.

Surplus supplies

(1πCAVrec)(daCAVD)(1-\pi_{\mathrm{CAV}}^{\mathrm{rec}})(-da_{\mathrm{CAV}}^D)

CAV, and CavalRe Treasury receives the corresponding non-Reserve AA amount. Reserve coefficients remain fixed and LP Token supply does not change.

4. Pure Surplus sale

When

πApay=πCAVrec=0,\pi_A^{\mathrm{pay}} =\pi_{\mathrm{CAV}}^{\mathrm{rec}} =0,

the sale posts two separate same-token journals.

On the AA ledger:

DebitCredit
CavalRe Treasury AACavalRe Payable AA

On the CAV ledger:

DebitCredit
CavalRe Payable CAVSurplus CAV

Every debit and credit is matched within its own token ledger. There is no cross-token journal.

No Reserve Asset amount or scale changes, and neither the LP Token amount nor its derived scale changes. Therefore

ciSc0S=cic0\frac{c_i^S}{c_0^S}=\frac{c_i}{c_0}

for every Reserve Asset ii. The pure sale is projectively neutral and produces no price impact.

Economically, CavalRe has sold some of its finite CAV inventory for AA. The Protocol has provided quotation, custody, and settlement without selling Protocol-owned CAV.

5. General safety condition

Because Reserve coefficients and LP Token supply are fixed, the projective condition

ciSc0Scic0\frac{c_i^S}{c_0^S}\le\frac{c_i}{c_0}

for every Reserve Asset is equivalent here to

s0Ss0,\boxed{s_0^S\ge s_0,}

where

s0S=cA(aA+πApaydaAD)es+cCAV(aCAV+πCAVrecdaCAVD)es+iA,CAVsi.s_0^S =c_A(a_A+\pi_A^{\mathrm{pay}}da_A^D)^{e_s} +c_{\mathrm{CAV}} (a_{\mathrm{CAV}}+\pi_{\mathrm{CAV}}^{\mathrm{rec}}da_{\mathrm{CAV}}^D)^{e_s} +\sum_{i\ne A,\mathrm{CAV}}s_i.

This is the complete endpoint test for independent settlement fractions. Inventory availability, positive reserves, and exact journal balance are separate admissibility requirements.

6. An always-safe path

Equal fractions are not required, but they give a useful proof that nontrivial safe mixed settlements always exist. Set

πApay=πCAVrec=π,0π1.\pi_A^{\mathrm{pay}} =\pi_{\mathrm{CAV}}^{\mathrm{rec}} =\pi, \qquad 0\le\pi\le1.

Along this line,

s0S(π)=cA(aA+πdaAD)es+cCAV(aCAV+πdaCAVD)es+iA,CAVsi.s_0^S(\pi) =c_A(a_A+\pi da_A^D)^{e_s} +c_{\mathrm{CAV}}(a_{\mathrm{CAV}}+\pi da_{\mathrm{CAV}}^D)^{e_s} +\sum_{i\ne A,\mathrm{CAV}}s_i.

For 0<es<10<e_s<1, this function is strictly concave for a nonzero trade, and

ds0Sdπ=es(daADPAS+daCAVDPCAVS).\frac{d s_0^S}{d\pi} =e_s\left(da_A^D P_A^S +da_{\mathrm{CAV}}^D P_{\mathrm{CAV}}^S\right).

At the direct endpoint,

ds0Sdππ=1=0\left.\frac{d s_0^S}{d\pi}\right|_{\pi=1}=0

by the direct post-trade value-flow equation. Strict concavity makes the derivative positive for 0π<10\le\pi<1. Hence

s0S(π)s0s_0^S(\pi)\ge s_0

for the entire interval, with equality at the pure-sale endpoint. Equal fractions are therefore a sufficient safe subfamily inside the larger independently allocated mechanism.

7. Round trips

Consider a pure ACAVA\rightarrow\mathrm{CAV} Surplus sale followed by an ordinary CAVA\mathrm{CAV}\rightarrow A Reserve swap. The first leg has no Multiswap price impact. The second adds CAV to Reserve and removes AA, so the Multiswap CAV price moves down and the AA price moves up.

This is not a closed-state round trip. Surplus CAV has decreased, CavalRe Treasury AA has increased, Reserve CAV has increased, and Reserve AA has decreased. The user is an intermediary through which CavalRe sells CAV into the Reserve for AA.

Repeated loops can continue only while authorized Surplus remains. If no other action removes CAV from Reserve, the finite inventory bounds the absolute CAV price response by

PCAVfPCAV(1+aCAVSurplusaCAV)eP>0.\frac{P_{\mathrm{CAV}}^f}{P_{\mathrm{CAV}}} \ge \left( 1+\frac{a_{\mathrm{CAV}}^{\mathrm{Surplus}}}{a_{\mathrm{CAV}}} \right)^{-e_P}>0.

The CAV-to-AA relative price also reflects the simultaneous change in the AA Reserve. CavalRe controls tolerated sale pressure by limiting authorized Surplus relative to live Reserve depth.

Splitting is not an accounting exploit. It can change the execution path and reduce finite-trade price impact, so Surplus sizing and execution policy should assume users can split across transactions.

8. Atomic settlement requirements

An implementation must:

  1. calculate the direct user quote from live Reserve state;
  2. choose authorized independent settlement fractions;
  3. verify sufficient CavalRe-owned CAV in Surplus;
  4. post every same-token Reserve, Surplus, Treasury, payable, and user entry;
  5. update the Reserve endpoint once for the complete atomic action;
  6. preserve exact matched Surplus and CavalRe payable balances;
  7. enforce the projective endpoint condition, positive Reserve balances, and pool-favorable rounding; and
  8. apply cumulative endpoint accounting to compatible split calls inside one transaction.

Conclusion

Surplus is a finite, externally owned CAV sale facility. CavalRe supplies CAV and receives AA in CavalRe Treasury. Exact matched asset--liability postings remove the externally owned inventory from Protocol-equity repricing.

The pure sale is price-neutral because it does not touch price-forming state. Mixed settlement may use independent pay and receive fractions. The complete Reserve endpoint is accepted exactly when it satisfies

ciSc0Scic0i.\boxed{ \frac{c_i^S}{c_0^S}\le\frac{c_i}{c_0} \quad\forall i. }