Skip to main content
Unlisted page
This page is unlisted. Search engines will not index it, and only users having a direct link can access it.

Surplus Settlement: Safe Composition, Coefficient Order, and Permanent Liquidity

· 26 min read
Eric Forgy
Founder of CavalRe

Scope: This research article compares Surplus candidates and safety conditions. The current implementation uses a reduced-pay second quote with direct-payout top-ups, described in Quote Engine. Counter-swaps and LP Token burning discussed here are not the deployed settlement policy.

Multiswap Surplus is exogenous protocol inventory. When a user receives an asset held in Surplus, the protocol can use that inventory to settle the user's output and convert it into reserve growth, Rewards, Treasury revenue, or an ongoing CAV token sale.

The economic purpose is straightforward. The safety question is not.

A compound action can look harmless when examined as an immediate round trip and still leave the pool in a state from which later transactions transfer value unexpectedly. The correct test is therefore not merely whether the first user can reverse the transaction without profit. The resulting state must remain inside the coefficient-order admissible set under every later supported action.

This article develops that test from first principles. It reaches four conclusions:

  1. the original price-preserving Surplus transformation does not remain inside the Post-Trade Elasticity coefficient order;
  2. the counter-swap model is a composition of supported state transitions and does remain inside that order;
  3. LP Token burning is coefficient-order admissible, although it creates a distinct temporary-liquidity allocation issue;
  4. coefficient safety can be verified token by token, while value-flow entropy provides an aggregate summary of those local certificates.

The analysis assumes exact arithmetic, positive reserves and scales, and homogeneous scale elasticity

0<es<1,0<e_s<1,

with price elasticity

eP=1es.e_P=1-e_s.

The exact boundary es=0e_s=0 is discussed separately.

1. Multiswap state and coefficient order

Let the pool contain n>1n>1 Reserve Assets. Reserve Asset ii has reserve ai>0a_i>0, scale si>0s_i>0, and marginal price

Pi=siai.P_i=\frac{s_i}{a_i}.

Its elasticity coefficient is

ci=siaies.\boxed{c_i=\frac{s_i}{a_i^{e_s}}.}

Equivalently,

si=ciaiess_i=c_i a_i^{e_s}

and

Pi=ciaieP.P_i=c_i a_i^{-e_P}.

The LP Token has reserve a0a_0, scale

s0=i=1nsi,\boxed{s_0=\sum_{i=1}^{n}s_i,}

price

P0=s0a0,P_0=\frac{s_0}{a_0},

and coefficient

c0=s0a0es.c_0=\frac{s_0}{a_0^{e_s}}.

The Post-Trade Elasticity safety results use a one-sided coefficient order:

cici\boxed{c_i'\le c_i}

for every Reserve Asset, and

c0c0\boxed{c_0'\ge c_0}

for the LP Token.

Ordinary swaps keep every Reserve Asset coefficient fixed and increase the LP Token coefficient through finite-step divergence. Supported single-asset liquidity actions keep the active Reserve Asset coefficient and LP Token coefficient fixed while contracting every nonparticipating Reserve Asset coefficient by one common multiplier 0<λ<10<\lambda<1. An LP Token burn leaves Reserve Asset state fixed and increases the LP Token coefficient.

These directions matter because they compose. If every primitive action moves every coefficient in its permitted direction, no later sequence of supported actions can reverse the partial order.

2. Post-trade settlement

For a signed reserve change daida_i, define

ri=daiai,ri>1.r_i=\frac{da_i}{a_i}, \qquad r_i>-1.

An ordinary Reserve Asset swap leg remains on its elastic curve:

ai=ai(1+ri)a_i'=a_i(1+r_i)

and

si=si(1+ri)es.s_i'=s_i(1+r_i)^{e_s}.

Its final marginal price is

Pi=Pi(1+ri)eP.P_i'=P_i(1+r_i)^{-e_P}.

Post-trade value flow is

Σi=daiPi=siri(1+ri)eP.\boxed{ \Sigma_i =da_iP_i' =s_i\frac{r_i}{(1+r_i)^{e_P}}. }

The general post-trade value-flow identity couples the LP Token leg to the Reserve Asset legs:

Σ0=i=1nΣi.\boxed{ \Sigma_0 = \sum_{i=1}^{n}\Sigma_i. }

An ordinary reserve-only swap has no LP Token flow, so

Σ0=0\Sigma_0=0

and the general identity reduces to

i=1nΣi=0.\sum_{i=1}^{n}\Sigma_i=0.

Scale change is not value flow. For each leg,

dsi=Σi+Γi,ds_i=\Sigma_i+\Gamma_i,

where

Γi=ai(PiPi)\Gamma_i=a_i(P_i'-P_i)

is the revaluation of the opening reserve. Equivalently,

dsi=esΣi+Di,ds_i=e_s\Sigma_i+\mathcal D_i,

where the finite-step divergence Di\mathcal D_i satisfies

Di0.\mathcal D_i\ge0.

Summing across the Reserve Asset legs gives

ds0=esΣ0+i=1nDi.\boxed{ ds_0 = e_s\Sigma_0 + \sum_{i=1}^{n}\mathcal D_i. }

For a nontrivial finite reserve-only swap with 0<es<10<e_s<1, Σ0=0\Sigma_0=0, so

s0s0=i=1nDi>0.s_0'-s_0 =\sum_{i=1}^{n}\mathcal D_i >0.

The LP Token reserve a0a_0 does not change during a Reserve Asset swap, so c0c_0 increases. Every Reserve Asset coefficient remains fixed.

3. The purpose of Surplus

Consider a user swap

AB.A\longrightarrow B.

When BB is CAV, the user is buying CAV. Surplus can supply the CAV sold to the user, allowing protocol inventory to enter circulation organically through ordinary demand. CAV supply is finite, so CAV will eventually cease to be a Surplus asset. Until then, this mechanism can operate as an ongoing CAV token sale.

The pool, Surplus, Rewards, and Treasury are distinct protocol accounts. A correct analysis follows both the pool state and the inventory transferred among those accounts.

Two different Surplus constructions have been considered:

  1. a direct price-preserving state adjustment;
  2. an ordinary Surplus counter-swap composed after the user swap.

They give the user the same ordinary swap quote, but they do not leave the pool in the same state.

4. The original price-preserving construction

Let the user's receive change be

daB<0.da_B<0.

The amount sent to the user is daB>0-da_B>0.

If the pool settled the ordinary swap directly, its hypothetical post-swap BB reserve would be

aB=aB+daB,a_B^*=a_B+da_B,

where

0<aB<aB.0<a_B^*<a_B.

The original Surplus construction instead supplied the user's BB from exogenous inventory and left the pool reserve at

aBPP=aB.a_B^{\mathrm{PP}}=a_B.

Here the superscript PP\mathrm{PP} denotes the price-preserving state. Scale was adjusted so that the final marginal price equaled the ordinary hypothetical price:

PBPP=PB.P_B^{\mathrm{PP}}=P_B^*.

This preserves one price point, but it does not preserve the future quote curve.

The ordinary swap remains on the initial BB curve, so

PB=cB(aB)eP.P_B^*=c_B(a_B^*)^{-e_P}.

The price-preserving state has the same price at the restored reserve:

PBPP=cBPPaBeP.P_B^{\mathrm{PP}} =c_B^{\mathrm{PP}}a_B^{-e_P}.

Equating the two prices gives

cBPPcB=(aBaB)eP>1.\boxed{ \frac{c_B^{\mathrm{PP}}}{c_B} = \left(\frac{a_B}{a_B^*}\right)^{e_P} >1. }

The receive coefficient expands. The state prices BB as though it were scarce while retaining the full reserve as pricing depth.

This violates the Reserve Asset coefficient direction immediately:

cBPP>cB.c_B^{\mathrm{PP}}>c_B.

The failure does not depend on whether an immediate ABAA\rightarrow B\rightarrow A reversal is profitable. The endpoint itself lies outside the coefficient order used by the subsequent-action composition result.

4.1 A concrete subsequent-trade comparison

The following numerical comparison applies the original price-preserving transformation to the Post-Trade Elasticity equations. It does not analyze the abandoned target-scale model in which the historical implementation was written.

Let the initial state be:

AssetReserveScalePrice
AA1010660.60.6
BB0.650.650.390.390.60.6

Let

es=0.9,eP=0.1.e_s=0.9, \qquad e_P=0.1.

The user pays

daA=0.8399290565da_A=0.8399290565

and receives

daB=0.6175.-da_B=0.6175.

The output is 95%95\% of the initial BB reserve. The ordinary hypothetical state is:

AssetReserveScalePrice
AA10.839929056510.83992905656.45171309576.45171309570.59518038010.5951803801
BB0.03250.03250.02631101550.02631101550.80956970860.8095697086

Suppose the price-preserving allocation retains 80%80\% of the paid AA in Reserves and directs the remainder outside the pool. The adjusted state is:

AssetReserveScalePrice
AA10.671943245210.67194324526.35173123676.35173123670.59518038010.5951803801
BB0.650.650.52622031060.52622031060.80956970860.8095697086

The ordinary and adjusted states have the same marginal prices. The adjusted BB state has twenty times the ordinary reserve and scale at that price. Its coefficient is higher by the factor

cBPPcB=200.11.349282848.\frac{c_B^{\mathrm{PP}}}{c_B} =20^{0.1} \approx1.349282848.

Now consider a later holder selling

2.518512 B.2.518512\ B.

The later sale produces approximately:

First settlementLater AA receivedCombined result at the initial equal prices
Ordinary pool settlement2.1656462.1656460.575295-0.575295 AA-equivalent
Price-preserving Surplus state2.8349542.834954+0.094013+0.094013 AA-equivalent

The combined result includes both transactions. In the price-preserving case, the participant's net token changes are

(2.8349540.8399290565)A+(0.61752.518512)B.\left(2.834954-0.8399290565\right)A + \left(0.6175-2.518512\right)B.

Because the initial prices of AA and BB are equal, the initial-price AA-equivalent result is

2.8349540.8399290565+0.61752.5185120.094013.2.834954 -0.8399290565 +0.6175 -2.518512 \approx0.094013.

The corresponding ordinary-settlement calculation is approximately 0.575295-0.575295 AA-equivalent.

The sequence requires the later seller to bring pre-existing external BB. It is not a closed pool-only cycle. The comparison establishes a narrower but relevant result: the adjusted state can quote a subsequent external inventory sale more favorably than the ordinary Post-Trade Elasticity state by enough to reverse the combined initial-value result.

For a token such as CAV that is held outside the pool and traded externally, that is a material safety boundary. Preserving the marginal price did not preserve the economic depth associated with that price.

5. The counter-swap construction

The new construction uses only ordinary state transitions:

  1. the user executes ABA\rightarrow B;
  2. from the resulting state, Surplus executes BAB\rightarrow A;
  3. the protocol allocates the actual AA received by Surplus.

The user receives the ordinary quoted output. Surplus does not modify the user's swap. It executes a second ordinary swap from the actual post-user state.

For full settlement, Surplus pays exactly the amount of BB required to restore the pool's BB reserve:

daBuser+daBSurplus=0.da_B^{\mathrm{user}}+da_B^{\mathrm{Surplus}}=0.

Both swaps preserve cBc_B. Restoring aBa_B therefore restores

sBs_B

and

PB.P_B.

Surplus receives less AA than the user paid. The difference remains in the pool as round-trip gain. The pool's AA reserve is therefore higher after full settlement; the complete pool state is not restored, and the model does not claim price preservation.

That distinction is essential. The counter-swap reaches a different price through a path of supported actions. It does not manufacture a price-preserving endpoint by changing a Reserve Asset coefficient.

5.1 Partial settlement

Surplus can supply any amount between zero and the complete user output. The user swap still executes normally. Surplus then sells the amount it supplies through an ordinary finite swap calculated from the actual post-user state.

Partial settlement does not interpolate reserves, scales, or prices after the fact. It changes only the size of the ordinary counter-swap.

5.2 Multi-asset settlement

For an atomic multi-asset user swap, all receive assets supplied by Surplus form the pay side of one ordinary multi-asset Surplus sale. The counter-action obeys the general value-flow identity:

Σ0=i=1nΣi.\Sigma_0 = \sum_{i=1}^{n}\Sigma_i.

Because the counter-action is reserve-only, Σ0=0\Sigma_0=0 and therefore

i=1nΣi=0.\sum_{i=1}^{n}\Sigma_i=0.

It also preserves

ci=cic_i'=c_i

for every participating Reserve Asset.

If the counter-action realizes several proceeds assets, their later reserve allocations use sequential supported single-asset liquidity actions. An arbitrary partial multi-asset liquidity action is not substituted for those sequential actions unless its dispersion boundary has been enforced.

5.3 Counter-actions do not recurse

The Surplus counter-action is an underlying ordinary action, not a new user action eligible for another Surplus counter-action.

This matters because both the pay asset and proceeds asset may be Surplus assets. If a Surplus BAB\rightarrow A sale could invoke Surplus again merely because AA is also held in Surplus, the protocol would create a recursive action chain. The execution boundary must disable Surplus processing inside its own counter-action.

6. Allocating realized proceeds

After the counter-swap, Surplus owns the actual AA received from the pool. Let the allocation send portions of that realized amount to:

  • Reserves;
  • Rewards;
  • Treasury.

Transfers from Surplus to Rewards or Treasury do not change pool state. The reserve allocation does.

6.1 Single-asset permanent-liquidity allocation

The reserve portion is supplied through a supported single-asset liquidity action:

ALP.A\longrightarrow LP.

The active Reserve Asset AA and LP Token remain on their elastic curves:

cA=cAc_A'=c_A

and

c0=c0.c_0'=c_0.

Every nonparticipating Reserve Asset jj keeps the same reserve and receives the common scale multiplier

0<λ<1.0<\lambda<1.

Therefore

cj=λcj<cj.c_j'=\lambda c_j<c_j.

This is the permitted Reserve Asset coefficient direction.

6.2 Burning the minted LP Tokens

Let a0a_0 be LP Token supply immediately before the reserve allocation. Suppose ALPA\rightarrow LP mints

Δa0>0\Delta a_0>0

LP Tokens. Immediately after the liquidity action,

a0+=a0+Δa0.a_0^+=a_0+\Delta a_0.

The liquidity action preserves c0c_0, so

s0+=c0(a0+Δa0)es.s_0^+ =c_0(a_0+\Delta a_0)^{e_s}.

Burning exactly the minted LP Tokens restores

a0=a0a_0'=a_0

while leaving Reserve Asset state and s0+s_0^+ unchanged. Consequently,

c0=s0+a0es=c0(1+Δa0a0)es>c0.\boxed{ c_0' = \frac{s_0^+}{a_0^{e_s}} = c_0 \left(1+\frac{\Delta a_0}{a_0}\right)^{e_s} >c_0. }

The burn moves the LP Token coefficient in the permitted direction. It does not expand any Reserve Asset coefficient.

Burning is therefore safe for pool state under the coefficient-order theorem.

MEV qualification: Coefficient safety does not make the burn neutral to transaction ordering. Burning converts the reserve allocation into a pro-rata benefit for whoever holds LP Tokens at that moment. A temporary liquidity provider can enter before the Surplus allocation and remove afterward, receiving part of the added reserve. Minimum receive protects the swap user's execution but does not prevent this LP ownership strategy. Section 10.3 derives the transfer exactly. The protocol must therefore choose between burning, retaining, distributing, or locking the minted LP Tokens based on the intended recipient of the allocation.

6.3 Holding or distributing LP Tokens

Burning is not required for coefficient safety. The protocol can instead:

  • retain the minted LP Tokens as protocol-owned liquidity;
  • distribute them to Rewards;
  • distribute them to Treasury;
  • place them in an irrevocable or time-controlled account.

After the supported ALPA\rightarrow LP action, transferring the resulting LP Tokens among external accounts does not change pool state. Their eventual redemption must occur through an ordinary supported liquidity action.

The choice among holding, distributing, locking, and burning is therefore an allocation-policy question rather than a pool-state admissibility question.

7. Individual coefficient safety certificates

The coefficient order can be checked token by token.

For each token ii, define its coefficient multiplier

χi=cici=sisi(aiai)es.\boxed{ \chi_i = \frac{c_i'}{c_i} = \frac{s_i'}{s_i} \left(\frac{a_i}{a_i'}\right)^{e_s}. }

The individual safety conditions are

χi1\boxed{\chi_i\le1}

for every Reserve Asset, and

χ01\boxed{\chi_0\ge1}

for the LP Token.

For a sequence of actions indexed by tt, coefficient multipliers telescope:

cifinalciinitial=tχi,t.\frac{c_i^{\mathrm{final}}}{c_i^{\mathrm{initial}}} = \prod_t\chi_{i,t}.

If every primitive action satisfies the individual conditions, every finite composition satisfies the endpoint coefficient order automatically.

This is the precise reason the new Surplus model can be analyzed compositionally. It is not merely a sequence of actions that have looked safe in isolated round-trip tests. Each intermediate state carries the same local certificate required by the subsequent-action theorem.

7.1 Surplus certificates by step

StepReserve Asset multipliersLP Token multiplier
User swapχi=1\chi_i=1 for every Reserve Assetχ0>1\chi_0>1
Surplus counter-swapχi=1\chi_i=1χ0>1\chi_0>1
Single-asset ALPA\rightarrow LPχA=1\chi_A=1 and χj=λ<1\chi_j=\lambda<1 for jAj\ne Aχ0=1\chi_0=1
Burn minted LP Tokensχi=1\chi_i=1χ0>1\chi_0>1
Hold or distribute minted LP Tokensno pool-state changeno pool-state change

Every step stays inside the coefficient order.

7.2 Conditions that remain global

Individual coefficient certificates do not replace transaction consistency.

Every resulting state must satisfy

s0=i=1nsi.\boxed{s_0'=\sum_{i=1}^{n}s_i'.}

Every value-flow-coupled action must also satisfy

Σ0=i=1nΣi.\boxed{ \Sigma_0 = \sum_{i=1}^{n}\Sigma_i. }

For a reserve-only swap, Σ0=0\Sigma_0=0 and the identity specializes to

i=1nΣi=0.\sum_{i=1}^{n}\Sigma_i=0.

The coefficient conditions establish state admissibility. Post-trade value-flow balance establishes properly coupled consideration. A valid action requires both.

8. Value-flow entropy

Coefficient order admits an aggregate logarithmic monotone. Its change can be written without fixed reference coefficients as

ΔH=logc0c01n1i=1nlogcici.\boxed{ \Delta\mathcal H = \log\frac{c_0'}{c_0} - \frac{1}{n-1} \sum_{i=1}^{n} \log\frac{c_i'}{c_i}. }

Define the LP Token contribution

h0=logχ0h_0=\log\chi_0

and each Reserve Asset contribution

hi=logχi.h_i=-\log\chi_i.

When every individual coefficient condition holds,

h00h_0\ge0

and

hi0.h_i\ge0.

Entropy then decomposes into the individual safety margins:

ΔH=h0+1n1i=1nhi0.\boxed{ \Delta\mathcal H = h_0 + \frac{1}{n-1} \sum_{i=1}^{n}h_i \ge0. }

For an ordinary swap,

ΔH=logc0c0>0.\Delta\mathcal H = \log\frac{c_0'}{c_0} >0.

For a supported single-asset liquidity action,

ΔH=logλ>0.\Delta\mathcal H=-\log\lambda>0.

For an LP Token burn that reverses a relative mint r0=Δa0/a0>0r_0=\Delta a_0/a_0>0 while retaining scale,

ΔHburn=eslog(1+r0)>0.\Delta\mathcal H_{\mathrm{burn}} =e_s\log(1+r_0) >0.

If the LP Tokens are held or distributed rather than burned, the burn contribution is absent. The completed sequence remains entropy-nondecreasing.

8.1 Entropy is a summary, not the primary condition

A positive aggregate entropy change does not prove that every Reserve Asset coefficient moved safely. One Reserve Asset coefficient could expand while sufficiently large contractions elsewhere keep the scalar sum positive.

The primary tests are therefore

χi1for every Reserve Asset\chi_i\le1 \quad\text{for every Reserve Asset}

and

χ01.\chi_0\ge1.

Entropy is the aggregate audit value. The individual coefficient multipliers are the local certificates.

The original price-preserving receive leg illustrates the distinction. It fails locally because

χB>1,\chi_B>1,

regardless of whether coefficient motion elsewhere could make total entropy nonnegative.

9. Which actions remain inside the coefficient-order admissible set?

The coefficient analysis gives the following classification for 0<es<10<e_s<1.

Here, “Supported” means supported by the mathematical action set analyzed in this article. It does not claim that the action is already exposed by the current implementation.

ActionCoefficient resultStatus
Ordinary Reserve Asset swapReserve coefficients fixed; c0c_0 increasesSupported
Full or partial Surplus counter-swapOrdinary swap resultSupported
Ordinary multi-asset counter-swapReserve coefficients fixed; c0c_0 increasesSupported
Transfer proceeds to Rewards or TreasuryNo pool-state changeSupported
Single-asset ALPA\rightarrow LPActive coefficient fixed; complement coefficients contractSupported
Hold or distribute realized LP TokensNo additional pool-state changeSupported
Burn protocol-owned LP Tokens without withdrawing reservesReserve coefficients fixed; c0c_0 increasesSupported
Proportional all-Reserve-Asset liquidityEvery coefficient fixedSupported
Arbitrary partial multi-asset liquidityλ\lambda depends on dispersion and may leave the admissible domainNot initially supported
Direct scale adjustment used only to preserve a chosen priceCan expand a Reserve Asset coefficientNot supported
Transfer tokens into Reserves without a defined liquidity transitionCoefficient motion is undefinedNot supported
Recursive Surplus processing inside the counter-actionDoes not define a finite primitive compositionNot supported

Any ordinary Reserve Asset swap has the same pool-state status regardless of who owns the external accounts. For example,

BCAVB\rightarrow CAV

or

ACAVA\rightarrow CAV

is a supported state transition when executed as an ordinary swap. Whether buying CAV from one protocol account only to return it to another advances the intended allocation policy is a separate question.

10. Subsequent actions and transaction ordering

The coefficient-order result addresses the original concern about latent state damage. After the counter-swap sequence, later supported actions begin from another state inside the same coefficient-order admissible set.

It does not make Multiswap resistant to transaction ordering.

10.1 User minimum receive

A transaction builder can attempt to buy an asset before a large user purchase and sell after the user's transaction. This is ordinary sequential-price ordering around a public DEX transaction.

The user controls that boundary through a minimum receive amount. If prior state changes reduce the output below that minimum, the user transaction reverts. The complete user swap and Surplus counter-action must be atomic so no transaction can be inserted between them.

Backrunning the final state remains possible. A backrunner must trade through the ordinary Post-Trade Elasticity curve from that state.

10.2 Surplus availability

An all-or-nothing Surplus threshold creates a discontinuity when inventory is nearly exhausted. Transaction ordering can determine which user consumes the remaining eligible inventory.

Partial settlement with a deterministic continuous coverage rule removes the sharp full-settlement threshold. It does not change the user quote or the coefficient-order proof because the covered amount is still sold through an ordinary counter-swap.

10.3 Temporary-liquidity capture around a burn

Burning the LP Tokens minted by the reserve allocation is state-safe. Economically, it converts the supplied AA into a benefit for whoever owns LP Tokens at the burn moment.

A temporary liquidity provider can attempt to:

  1. enter through proportional liquidity before a large Surplus allocation;
  2. own a fraction of the LP Token supply when the protocol burns its minted LP Tokens;
  3. remove liquidity afterward;
  4. receive part of the allocation through that removal.

The reserve-level transfer can be shown exactly in the fee-free model. Let rJ>0r_J>0 be the temporary provider's proportional relative liquidity increase. Before the Surplus transaction, proportional entry changes every reserve and LP Token supply by the same factor:

aientry=(1+rJ)aia_i^{\mathrm{entry}}=(1+r_J)a_i

and

a0entry=(1+rJ)a0.a_0^{\mathrm{entry}}=(1+r_J)a_0.

Let dA>0d_A>0 be the Reserve Asset AA amount added by the later Surplus allocation. After the allocation mints and burns its own LP Tokens, the temporary provider's LP Tokens are still rJa0r_Ja_0, total LP Token supply remains (1+rJ)a0(1+r_J)a_0, and the AA reserve contains

(1+rJ)aA+dA.(1+r_J)a_A+d_A.

Burning the temporary provider's rJa0r_Ja_0 LP Tokens has relative LP Token change

r0exit=rJa0(1+rJ)a0=rJ1+rJ.r_0^{\mathrm{exit}} = -\frac{r_Ja_0}{(1+r_J)a_0} = -\frac{r_J}{1+r_J}.

A proportional all-Reserve-Asset removal uses that same relative change for every reserve. The amount of AA returned to the temporary provider is therefore

daAexit=rJ1+rJ[(1+rJ)aA+dA]=rJaA+rJ1+rJdA.\boxed{ -da_A^{\mathrm{exit}} = \frac{r_J}{1+r_J} \left[(1+r_J)a_A+d_A\right] = r_Ja_A + \frac{r_J}{1+r_J}d_A. }

The first term returns the temporary provider's original AA contribution. The second term is a positive portion of the Surplus reserve allocation. Ignoring fees and rounding, increasing rJr_J lets temporary liquidity capture an increasing fraction of dAd_A.

The proportional entry and removal preserve every coefficient, so both have

ΔH=0.\Delta\mathcal H=0.

The allocation and burn between them increase entropy. The entire sequence remains inside the safe coefficient order even though the temporary LP receives value intended for incumbent LP holders.

Minimum receive on the user's swap does not directly prevent this allocation capture. The issue concerns ownership at the LP Token burn, not whether the user received an acceptable swap output.

This produces a policy choice:

  • burning rewards LP Token holders present at the burn;
  • retaining the minted LP Tokens creates protocol-owned liquidity;
  • distributing them assigns liquidity claims directly to Rewards or Treasury;
  • placing them in an irrevocable account makes the associated liquidity nonredeemable without creating an immediate pro-rata donation to active LP Token holders.

All four choices can remain inside the pool-state coefficient order. They differ in ownership and susceptibility to temporary-liquidity allocation capture.

10.4 MEV sensitivity by action

No permissionless DEX action is generally resistant to transaction ordering. The relevant question is which Surplus actions introduce sensitivity beyond an ordinary user trade and which limits apply.

ActionPrincipal ordering sensitivityRequired control
User Reserve Asset swapA transaction can execute before the user and worsen the user's outputUser-specified minimum receive or maximum pay
User liquidity removalPrior state changes can reduce the Reserve Asset outputUser-specified minimum receive
Surplus counter-swapA separately executable counter-action could be inserted around or separated from the user actionExecute the user action and counter-action atomically; apply an explicit minimum counter-swap receive when settlement rounding or fees make the result variable
Full-settlement inventory thresholdOrdering can determine which transaction consumes the last eligible Surplus inventoryPrefer deterministic partial coverage; otherwise make the all-or-nothing rule and inventory snapshot explicit
Multi-asset counter-swapA public, predictable basket sale creates several final price changes that can be backrunExecute atomically, use fixed allocation rules, and enforce minimum proceeds for every receive asset
Sequential reserve allocationsThe final state depends on the fixed order of single-asset liquidity actionsFix the order in protocol rules and enforce minimum LP Token receive for each provision
LP Token burnTemporary liquidity can enter before the burn and receive part of the allocation afterwardMinimum receive is insufficient; retain, distribute, or lock LP Tokens, or define time-based eligibility for burn benefits
Standalone protocol ACAVA\rightarrow CAV swapA known protocol purchase can be traded around like any predictable orderEnforce minimum CAV receive, maximum price movement, and an explicit execution-size rule
Surplus-assisted LPALP\rightarrow A removalThe user leg has ordinary removal exposure; allocating or burning the counter-provision's LP Tokens adds the ownership-at-allocation issueMinimum receive for the user removal and the same LP allocation policy used for swap Surplus

The compound user action and its counter-action must be indivisible. Atomicity prevents insertion between their intermediate states, while minimum receive limits adverse ordering around the complete transaction. Neither control prevents temporary LP ownership around an LP Token burn because that strategy targets allocation ownership rather than the user's execution price.

11. Extending Surplus to liquidity removal

The same compositional analysis applies to a user removing a single Reserve Asset:

LPA.LP\longrightarrow A.

Surplus can supply the received AA through the counter-action

ALP.A\longrightarrow LP.

The user removal and Surplus counter-provision are both supported single-asset liquidity actions. Let their complement multipliers be

0<λremove<10<\lambda_{\mathrm{remove}}<1

and

0<λprovide<1.0<\lambda_{\mathrm{provide}}<1.

Their combined entropy change before any LP Token burn is

ΔH=logλremovelogλprovide>0.\boxed{ \Delta\mathcal H = -\log\lambda_{\mathrm{remove}} -\log\lambda_{\mathrm{provide}} >0. }

Surplus realizes LP Tokens from the counter-provision. It can allocate those LP Tokens directly to Rewards and Treasury and burn, retain, or lock the remaining portion.

Every such choice is state-safe when:

  • both liquidity actions satisfy the supported single-asset equations;
  • every reserve and scale remains positive;
  • the LP Token burn, if any, removes only protocol-owned LP Tokens without withdrawing Reserve Assets.

The composition does not restore the entire pool. Although restoring aAa_A also restores the active AA state because cAc_A remains fixed, every nonparticipating Reserve Asset coefficient receives the product

λremoveλprovide<1.\lambda_{\mathrm{remove}} \lambda_{\mathrm{provide}} <1.

That contraction is the permitted safety direction. It is a real economic effect of the two liquidity actions, not an accounting error.

12. Boundaries that remain open

The coefficient result is strong, but it has a defined domain.

12.1 The exact boundary es=0e_s=0

At

es=0,e_s=0,

coefficient becomes scale:

ci=si.c_i=s_i.

Swaps and the stated liquidity equations remain defined, but the strict extraction proof for liquidity sequences uses the positive reserve sensitivity of

si=ciaies.s_i=c_i a_i^{e_s}.

That sensitivity disappears at es=0e_s=0. Entropy is constant rather than strictly increasing across the supported boundary operations.

The counter-swap portion remains an ordinary swap composition. A complete Surplus sequence containing liquidity allocation at es=0e_s=0 requires its own extraction-safety proof before receiving the same production status.

12.2 Fees

The analysis above is fee-free. Fee integration must specify whether the Surplus counter-action replaces gross or net user output, which account owns the fee, and how fee transfers affect reserve, scale, and coefficient accounting.

Fees cannot be added as an unexplained difference between token movement and the quoted state transition.

12.3 Rounding

Production arithmetic must round exact-input output down and exact-output input up in favor of the pool. Every intermediate action must independently preserve:

ai>0,si>0,a_i'>0, \qquad s_i'>0,

the aggregate scale identity, and the individual coefficient directions within the chosen numerical tolerance.

An implementation that preserves the final aggregate result while allowing repeated adverse per-leg rounding can accumulate state drift. The leg certificates expose that failure directly.

12.4 External sale policy

Pool-state safety does not determine whether CAV was sold at a desirable external price. Eligible assets, maximum sale size, timing, inventory limits, and any external-price controls belong to the Surplus execution policy.

The internal theorem establishes that a permitted sale leaves the pool inside the supported coefficient order. It does not replace token-sale policy.

13. Implementation invariants and property tests

Every primitive action and every randomized composition should verify:

Positive state

ai>0,si>0.a_i'>0, \qquad s_i'>0.

Aggregate scale

s0=i=1nsi.\boxed{s_0'=\sum_{i=1}^{n}s_i'.}

Value flow

Σ0=i=1nΣi.\boxed{ \Sigma_0 = \sum_{i=1}^{n}\Sigma_i. }

For a reserve-only swap, also verify

Σ0=0i=1nΣi=0.\Sigma_0=0 \quad\Longrightarrow\quad \sum_{i=1}^{n}\Sigma_i=0.

Reserve Asset coefficient direction

sisi(aiai)es1\boxed{ \frac{s_i'}{s_i} \left(\frac{a_i}{a_i'}\right)^{e_s} \le1 }

for every Reserve Asset.

LP Token coefficient direction

s0s0(a0a0)es1.\boxed{ \frac{s_0'}{s_0} \left(\frac{a_0}{a_0'}\right)^{e_s} \ge1. }

Entropy

ΔH0.\boxed{\Delta\mathcal H\ge0.}

Entropy is a diagnostic summary. The componentwise coefficient assertions remain authoritative.

The randomized sequence suite should include:

  • full and partial Surplus counter-swaps;
  • multi-asset Surplus sales;
  • sequential single-asset reserve allocations;
  • holding, distributing, locking, and burning realized LP Tokens;
  • user liquidity removal followed by Surplus counter-provision;
  • later swaps and liquidity actions from every resulting state;
  • temporary proportional liquidity around a permanent-liquidity allocation;
  • values near reserve positivity and λ\lambda boundaries;
  • integer conversion and pool-favorable rounding.

Conclusion

Surplus settlement remains coefficient-order admissible when it is built from actions that preserve the Post-Trade Elasticity coefficient order at every intermediate state.

The original price-preserving transformation fails that test on the receive leg:

cB>cB.c_B'>c_B.

It preserves a marginal price while replacing the depleted pricing reserve with full depth. A concrete later-inventory comparison shows why that distinction matters.

The counter-swap construction has a different structure:

ordinary user swapordinary Surplus counter-swapsupported allocation actions.\text{ordinary user swap} \longrightarrow \text{ordinary Surplus counter-swap} \longrightarrow \text{supported allocation actions}.

Every Reserve Asset coefficient remains fixed or contracts. The LP Token coefficient remains fixed or increases. Those directions survive composition and therefore remain valid under subsequent supported actions.

The local certificate is

χi=sisi(aiai)es.\boxed{ \chi_i = \frac{s_i'}{s_i} \left(\frac{a_i}{a_i'}\right)^{e_s}. }

Require

χi1\chi_i\le1

for every Reserve Asset and

χ01\chi_0\ge1

for the LP Token. Value-flow entropy then aggregates the nonnegative logarithmic margins of those individual certificates.

LP Token burning passes the state test. Whether to burn, retain, distribute, or lock the minted LP Tokens depends on who should own the permanent-liquidity allocation and how the protocol handles temporary liquidity around that allocation.

This separates three questions that should remain separate:

  1. state safety: does every token remain inside the coefficient order?
  2. transaction consistency: do scale and post-trade value flow balance exactly?
  3. allocation policy: who receives the economic benefit of Surplus inventory?

The counter-swap model answers the first two through supported composition. The third remains an explicit protocol choice.