Two-Asset Surplus Settlement for Token Launches
Historical proposal: This article explores a price-preserving Surplus candidate. The implemented settlement policy uses a reduced-pay second quote and Surplus top-ups; it preserves the direct user payout but can change relative pool prices. See Quote Engine for current behavior.
Multiswap pools can hold protocol-owned token inventory in a Surplus account. For a token-launch pool containing a pay asset and a launched receive asset , the protocol would like to sell available Surplus without changing the user's direct quote. Some of the user's can enter Reserve, and the rest can be divided between Rewards and Treasury.
The allocation cannot be chosen independently of pool safety. Protecting the Reserve changes the physical Reserve endpoint. Preserving the direct relative prices then requires a common price gauge, and that gauge changes the LP Token's total scale.
For a two-asset pool, the resulting allocation problem has a simple solution:
- available Surplus inventory determines the fraction of paid by Reserve;
- LP safety determines the minimum fraction of that must enter Reserve;
- an optional configured floor may increase that pay-side Reserve fraction;
- Rewards and Treasury divide the remainder equally; and
- an infeasible Surplus attempt uses ordinary direct settlement instead.
The minimum pay allocation is closed form for every . When , the direct receive quote and the complete receive-side safety boundary are also closed form.
This article derives that candidate from first principles. It is not current implemented protocol behavior.
1. State and elasticity
Consider a fee-free Multiswap pool with exactly two Reserve Assets, and . Reserve Asset has:
- Reserve amount ;
- scale ; and
- marginal price .
The LP Token has scale
The derived opening scale share of is
Because there are only two assets, the derived share of is
The absolute scale unit will cancel from every allocation condition. The candidate needs , not and separately. The weight is a derived ratio, not an independent state variable.
Let the scale and price elasticities satisfy
The elasticity coefficient of Reserve Asset is
The coefficient-order safety conditions are
for each Reserve Asset and
for the LP Token.
The candidate keeps LP Token supply fixed. LP safety is therefore equivalent to
2. Calculate the ordinary direct quote first
For an swap, let the direct Reserve multipliers be
The direct Post-Trade Elasticity prices are
Post-trade value-flow balance gives
The direct quote determines the user's token amounts. Surplus settlement does not change those amounts. It changes only the accounts that fund and receive them.
Ordinary direct settlement is always available. It keeps every Reserve Asset coefficient fixed. Its normalized final LP scale is
Post-trade balance makes this equal to
Jensen's inequality shows that the common value is at least one. If the scale-weighted average of the logarithmic Reserve multipliers is nonnegative, the positive-exponent expression is at least one. If it is nonpositive, the equal negative-exponent expression is at least one. The inequality is strict for a nonzero trade. Ordinary direct settlement is therefore the safe fallback.
3. Define the two settlement fractions symmetrically
Let
be the fraction of the user's payment credited to Reserve.
Let
be the fraction of the user's output paid from Reserve.
The endpoints have direct interpretations:
- : all pay enters Reserve;
- : no pay enters Reserve;
- : Reserve supplies all receive tokens; and
- : Surplus supplies all receive tokens.
The actual Reserve multipliers are
Thus
and
4. Available inventory determines the receive fraction
The user receives
If the available protocol Surplus balance is , the maximum amount that Surplus can supply is
Reserve supplies the remainder. Therefore
This choice attempts to use as much available Surplus as the user can receive. It is an inventory rule, not a safety proof. The pay-side calculation must still determine whether that receive allocation is feasible.
5. Preserve the direct relative-price endpoint
The candidate requires the final price vector to be one common positive multiple of the direct post-trade price vector:
The common factor does not change relative prices:
It also preserves post-trade value-flow balance for the unchanged user amounts:
At the candidate endpoint, the Reserve Asset coefficient multiplier is
The receive asset has the largest endpoint distortion. Choosing
keeps the coefficient fixed:
For the pay asset,
so
Reserve Asset safety is therefore satisfied by construction. The remaining condition is LP Token safety.
6. Derive the two-asset LP condition
The final scales are
After dividing by , LP safety becomes
For a fixed , every quantity in this inequality is known except . The condition is linear in . That observation determines the pay allocation directly.
7. Calculate the minimum safe pay allocation
Solving the LP condition for gives
Since
the minimum safe pay-side Reserve fraction is
The interpretation is immediate:
- if the result is at most zero, zero pay allocation is sufficient;
- if it lies in , it is the unique minimum safe pay allocation; and
- if it exceeds one, the proposed receive allocation is infeasible.
At the exact interior minimum,
Every larger pay allocation remains safe and gives the LP Token additional scale.
8. Apply an optional configured Reserve floor
A pool may require a minimum pay allocation for reasons beyond endpoint safety, including future Reserve depth. Let that configured floor be
The final pay allocation is
Setting the floor to zero uses exactly the minimum required for safety and automatically replaces a negative calculated minimum with zero. It therefore maximizes the non-Reserve proceeds. A positive floor preserves at least the configured fraction for Reserve.
The amount outside Reserve is divided equally:
The earlier 70/15/15 allocation is therefore not fundamental. It occurs when the final pay fraction is .
9. Safe direct fallback
If
the inventory-selected receive allocation cannot satisfy the constraints. The transaction does not revert for this reason. It uses ordinary direct settlement:
The user receives the original direct quote either way. The optional Surplus path changes settlement accounts only when its endpoint is admissible.
10. Closed forms at half elasticity
Suppose
The normalized direct pay value flow is
Balance gives
The direct receive multiplier is then
No numerical inversion is required.
There is an exact one-step constant-product coincidence when . In that case,
This identity follows from post-trade execution. It does not make the complete Multiswap state transition equivalent to constant product because the scales generally evolve differently.
At half elasticity, LP safety is
Introducing is useful here because the condition becomes the quadratic
This quadratic explains why receive-side safety need not be monotone. Depending on the opening state and pay allocation, safe allocations can occur near full Surplus funding, near direct Reserve funding, or in both regions with an unsafe interval between them. The candidate does not rely on monotonicity because it tests the inventory-selected endpoint and derives the pay minimum at that exact endpoint.
11. A concrete token-launch example
Take a two-asset pool with
and
The derived opening share is
A user pays units of , so
The direct post-trade quote gives
so the user receives approximately
units of .
Suppose Surplus holds at least that much . Then
The minimum safe pay allocation is
With no higher configured floor, the user's units of are allocated as follows:
- approximately to Reserve;
- approximately to Rewards; and
- approximately to Treasury.
Surplus supplies the full units of . The final scales are
so
The coefficient remains fixed, the coefficient contracts, and the LP Token lies exactly on its safety boundary. The final relative price equals the direct post-trade relative price.
If the pool instead configures a pay-side floor, the final pay allocation is . Reserve receives units of , while Rewards and Treasury each receive . The endpoint remains safe and gives the LP Token positive scale slack.
12. Why the two-asset scope matters
The gauge acts on every asset in a pool. In a pool with nonparticipating assets, protecting the receive Reserve forces the same downward gauge onto those unrelated scales. That can make useful Surplus allocations difficult or impossible.
This does not require Multiswap to abandon Surplus settlement. Multiswap is a network of pools with different cardinalities, including two-asset pools. The launch candidate enables this mechanism only for proven two-asset pools. Pools with more than two Reserve Assets continue using ordinary direct settlement unless a separate construction is established.
13. The boundary
At
direct settlement keeps both Reserve scales fixed. Any receive protection forces a downward gauge, while diverting any pay amount prevents the pay leg from restoring the lost scale. LP safety then requires
Only ordinary direct settlement remains. Burning LP Tokens cannot help because when . Nontrivial Surplus settlement therefore requires .
14. Candidate transaction
For an eligible two-asset pool, an atomic transaction follows this sequence:
- Calculate the ordinary direct Post-Trade Elasticity quote.
- Read the live receive-asset Surplus balance.
- Calculate the inventory-supported .
- Calculate .
- Calculate the minimum safe .
- Apply the configured pay-side Reserve floor, if any.
- If the required pay allocation exceeds one, discard the optional Surplus endpoint and use ordinary direct settlement.
- Otherwise calculate the common gauge and explicit scale updates.
- Credit the selected pay fraction to Reserve.
- Divide the remaining pay amount equally between Rewards and Treasury.
- Fund the receive amount from Reserve and Surplus according to .
- Apply every account and scale update atomically.
The quote does not search over allocations. Inventory fixes the receive fraction, and the safety equation fixes the minimum pay fraction.
15. Implementation status and remaining work
This article specifies a research candidate. The current executable Surplus adjustment does not implement this gauge-equivalent two-asset mechanism.
Before implementation, the candidate still needs:
- fixed-point rounding rules that round the pay minimum upward;
- exact ledger journals for Reserve, Surplus, Rewards, Treasury, LP, and user movements;
- tests at the feasibility boundary and around direct fallback;
- randomized repeated-action tests as scale shares evolve;
- authorization rules for Surplus debits and scale-accumulator changes; and
- an explicit pool-level enablement rule restricting launch support to proven two-asset configurations with .
Conclusion
Two-asset Multiswap pools admit a focused Surplus mechanism suitable for token launches. The direct quote determines the user's amounts and relative price endpoint. Available Surplus inventory determines how much of the receive leg Reserve must fund. The LP safety condition then gives the minimum fraction of the pay leg that must enter Reserve. Any configured Reserve floor can raise that fraction, and Rewards and Treasury divide what remains.
The result is a deterministic allocation rule:
When the optional endpoint is infeasible, the transaction executes its ordinary direct quote. The mechanism therefore adds protocol-owned token distribution and revenue allocation to eligible two-asset pools without making user execution depend on Surplus feasibility.
