Skip to content

SHIELD

fact SHIELD is leg 1 of a series in NoteLegs (ERC-1155), id (seriesId << 1) | 1. One unit is one raw quote unit of matched notional (10⁻⁶ USDG); each 1 USDG of units (1e6 units) represents 1e6 × 1e12 × 1e8 / s0 Stock Token wei in escrow plus a share of the coupon prefund.

depositShield(seriesId, stockAmount, prefundQuote) transfers Stock Tokens and USDG into escrow during Subscription.

  • Stock is valued at the provisional reference price (OracleAdapter.latestPrice(feed)) for the prefund requirement and pro-rata matching bookkeeping. Final matching uses s0.
  • prefundQuote must be at least requiredPrefund(seriesId, stockAmount):
prefundRateBps = couponCapBps × (observations.length − 1) + notionalFeeBps requiredPrefund = stockNotional(provisional) × prefundRateBps / 1e4

For the worked example: (400 × 26 + 25) / 10,000 = 104.25% of notional, i.e. 104,250 USDG on 100,000 USDG of stock.

The coupon is unknown until strike. Escrowing the maximum possible coupon liability is what lets the protocol promise that every coupon can be paid without a liquidation engine. The cost is capital efficiency for SHIELD: with a 400 bps cap and 26 observations, more than the notional is locked. Governance can lower couponCapBps per series to reduce the prefund at the cost of a lower ceiling on the coupon.

At strike, S = stockToQuote(totalShieldStock, s0) and N = min(D, S, notionalCap, prefundCapacity). Matched stock is quoteToStockUp(N, s0), rounded up so COUPON holders are never short on physical settlement. The prefund is split into:

  • prefundMatched = N × prefundRateBps / 1e4 (rounded up), from which the notional fee is deducted immediately into accruedFees, leaving prefundRemaining.
  • prefundUnmatched, refundable at once via refund.

Unmatched stock is likewise refundable at once.

MomentConditionSHIELD paysSHIELD receives
Strikematchednotional fee (0.25% default) from prefundN_s units; unmatched stock and prefund refundable
Intermediate observationP >= barriergross coupon N × couponBps / 1e4 from prefundRemaining
Intermediate observationP < barriernothing
AutocallP >= autocallthat couponall matched stock back + prefundRemaining pro rata
MaturityP >= barrierfinal couponall matched stock back + prefundRemaining pro rata
MaturityP < barriernothing1 raw USDG unit per unit (par) from the COUPON escrow + prefundRemaining pro rata; stock delivered to COUPON holders

shieldUnusedPerUnit = prefundRemaining / N is fixed at the terminal observation and paid per unit on redeemShield.

SHIELD is long a down-and-in put struck at s0, knocked in only if the final observation is below the barrier, that switches off on autocall, financed by a coupon stream paid only while the barrier holds. Compared with buying a vanilla put:

Vanilla put at s0SHIELD
PremiumPaid up front, fixedPaid in instalments only while barrier holds; stops on autocall
Pays whenS_T < s0 at expiryS_T < barrier at maturity only (then pays intrinsic from s0)
Protection in a mild fall (barrier < S_T < s0)YesNo
Protection in a deep fallYesYes, full intrinsic from s0
Cost if the stock ralliesFull premium lostOnly coupons paid until autocall
  • Long-term Stock Token holders who fear a crash more than a drawdown.
  • Lenders holding Stock Tokens as collateral who want tail cover on their book.
  • Vaults and mandates that must remain invested but have a loss budget.

SHIELD units are transferable. There is no per-unit accrual to settle on transfer (SHIELD pays rather than receives during the life), but the onLegTransfer hook still runs to keep bookkeeping symmetric. Refunds of unmatched deposits belong to the original depositor and are not transferred with units.

  • If the barrier never breaks you pay every coupon and receive no payout; see Scenario B of the worked example.
  • Autocall removes your protection exactly when the stock is strong; you must re-enter a new series to stay covered.
  • Your Stock Tokens are locked until settlement. There is no early exit except by selling SHIELD units.