Skip to main contentSkip to data table
Pharos

Redemption Backstop Changelog

Full version history of Redemption Backstop methodology decisions, from v1.0 to v4.35.

What This Controls

Redemption Backstop Changelog version history

Use this changelog to trace how Pharos changed the related scoring, data-source, threshold, or interpretation rules over time. The latest card below is the current public contract; older entries are retained so historical charts and citations can be read against the rules active at the time.

Latest Version

v4.35Aug 12, 2026

The residual queue clears: dEURO remodel, USDp basket sum, and valued redemption outputs

The final pass of the exit-credit campaign remodels dEURO onto its real StablecoinBridge rail, gives USDp a live proportional-basket bound, and values USD3 and eUSD redemption outputs at same-run on-chain NAV so their baskets no longer wait on external price rows. Scoring weights, ladders, and the exit engine are unchanged; routes move only through better evidence.

Impact Snapshot

  • dEURO replaces its false collateral-redemption model with live-only, fee-free StablecoinBridge basket telemetry across nine identity-pinned Ethereum bridges (EURT, EURS, VEUR, EURC, EURR, EUROP, EURI, EURE, EURA — each verified to burn dEURO 1:1 into its underlying with no fee). Capacity sums the idle EUR inventory (456,293 EUR at Ethereum block 25737329, almost entirely on the EURC bridge), converts it to USD through the protocol price feed rather than a false EUR=USD assumption, fails closed with no fallback, and leaves the output basket honestly unresolved because only five of the nine underlyings are tracked
  • USDp (Parallel) gains live capacity from the Parallelizer diamond's per-collateral getIssuedByCollateral reads, summed across the frxUSD, sfrxUSD, USDe, and sUSDe branches ($845,693 at block 25737340). The verified source redeems a proportional basket rather than holder-selected collateral, so the sum is the honest executable bound; the escrow-balance adapter gains a bounded multi-read mode for it and the documented full-supply model is dropped with no fallback
  • USD3 and eUSD redemption outputs are now valued at same-run on-chain NAV bound into the reserve snapshot, following the cUSD (Cap) precedent: ERC-4626 legs through convertToAssets and verified Compound wrappers through exchangeRate, with per-leg weights and a unit value published only when the live basket exactly matches the configured outputs ($1.1037 per USD3 and $1.0000 per eUSD at the review reads). An unreadable leg or a rotated basket suppresses the valuation while capacity telemetry stays intact, so the routes no longer wait on external peg rows for legs like steakUSDC
  • FDUSD's transparency source remains fail-closed after a first-party-only investigation: every firstdigitallabs.com path serves a Cloudflare JavaScript challenge to automated clients, the app subdomain exposes no transparency API, and the reachable copy is a Webflow mirror serving a scanned unparseable PDF — recorded so the staleness is a documented condition rather than a silent gap
v4.35Aug 12, 2026

The residual queue clears: dEURO remodel, USDp basket sum, and valued redemption outputs

The final pass of the exit-credit campaign remodels dEURO onto its real StablecoinBridge rail, gives USDp a live proportional-basket bound, and values USD3 and eUSD redemption outputs at same-run on-chain NAV so their baskets no longer wait on external price rows. Scoring weights, ladders, and the exit engine are unchanged; routes move only through better evidence.

  • dEURO replaces its false collateral-redemption model with live-only, fee-free StablecoinBridge basket telemetry across nine identity-pinned Ethereum bridges (EURT, EURS, VEUR, EURC, EURR, EUROP, EURI, EURE, EURA — each verified to burn dEURO 1:1 into its underlying with no fee). Capacity sums the idle EUR inventory (456,293 EUR at Ethereum block 25737329, almost entirely on the EURC bridge), converts it to USD through the protocol price feed rather than a false EUR=USD assumption, fails closed with no fallback, and leaves the output basket honestly unresolved because only five of the nine underlyings are tracked
  • USDp (Parallel) gains live capacity from the Parallelizer diamond's per-collateral getIssuedByCollateral reads, summed across the frxUSD, sfrxUSD, USDe, and sUSDe branches ($845,693 at block 25737340). The verified source redeems a proportional basket rather than holder-selected collateral, so the sum is the honest executable bound; the escrow-balance adapter gains a bounded multi-read mode for it and the documented full-supply model is dropped with no fallback
  • USD3 and eUSD redemption outputs are now valued at same-run on-chain NAV bound into the reserve snapshot, following the cUSD (Cap) precedent: ERC-4626 legs through convertToAssets and verified Compound wrappers through exchangeRate, with per-leg weights and a unit value published only when the live basket exactly matches the configured outputs ($1.1037 per USD3 and $1.0000 per eUSD at the review reads). An unreadable leg or a rotated basket suppresses the valuation while capacity telemetry stays intact, so the routes no longer wait on external peg rows for legs like steakUSDC
  • FDUSD's transparency source remains fail-closed after a first-party-only investigation: every firstdigitallabs.com path serves a Cloudflare JavaScript challenge to automated clients, the app subdomain exposes no transparency API, and the reachable copy is a Webflow mirror serving a scanned unparseable PDF — recorded so the staleness is a documented condition rather than a silent gap
Details

Impact Notes

  • dEURO replaces its false collateral-redemption model with live-only, fee-free StablecoinBridge basket telemetry across nine identity-pinned Ethereum bridges (EURT, EURS, VEUR, EURC, EURR, EUROP, EURI, EURE, EURA — each verified to burn dEURO 1:1 into its underlying with no fee). Capacity sums the idle EUR inventory (456,293 EUR at Ethereum block 25737329, almost entirely on the EURC bridge), converts it to USD through the protocol price feed rather than a false EUR=USD assumption, fails closed with no fallback, and leaves the output basket honestly unresolved because only five of the nine underlyings are tracked
  • USDp (Parallel) gains live capacity from the Parallelizer diamond's per-collateral getIssuedByCollateral reads, summed across the frxUSD, sfrxUSD, USDe, and sUSDe branches ($845,693 at block 25737340). The verified source redeems a proportional basket rather than holder-selected collateral, so the sum is the honest executable bound; the escrow-balance adapter gains a bounded multi-read mode for it and the documented full-supply model is dropped with no fallback
  • USD3 and eUSD redemption outputs are now valued at same-run on-chain NAV bound into the reserve snapshot, following the cUSD (Cap) precedent: ERC-4626 legs through convertToAssets and verified Compound wrappers through exchangeRate, with per-leg weights and a unit value published only when the live basket exactly matches the configured outputs ($1.1037 per USD3 and $1.0000 per eUSD at the review reads). An unreadable leg or a rotated basket suppresses the valuation while capacity telemetry stays intact, so the routes no longer wait on external peg rows for legs like steakUSDC
  • FDUSD's transparency source remains fail-closed after a first-party-only investigation: every firstdigitallabs.com path serves a Cloudflare JavaScript challenge to automated clients, the app subdomain exposes no transparency API, and the reachable copy is a Webflow mirror serving a scanned unparseable PDF — recorded so the staleness is a documented condition rather than a silent gap
  • Route-family totals are unchanged at 148 offchain-issuer, 67 stablecoin-redeem, 38 collateral-redeem, 39 queue-redeem, 14 psm-swap, and 9 basket-redeem
Commit provenance not recorded
    v4.34Aug 12, 2026

    A consensus-enforced fee bound, the USDPT issuer rail, live USSD escrow, and documented skips

    A third exit-credit pass bounds ZSD's redemption fee at the rate its own consensus code enforces, configures Western Union's USDPT on the Anchorage issuer rail, moves USSD onto live escrow telemetry, and records routes that primary sources declined to support — including one route this registry had been modeling without documentation. Scoring weights, ladders, and the exit engine are unchanged; routes move only through better evidence.

    • ZSD (Zephyr) replaces its dynamic-fee marker with a fixed 10 bps bound: the pinned RingCT source deducts `exchange_128 / 1000` from the ZSD/ZEPH rate on every REDEEM_STABLE, and because Zephyr mainnet has run hard fork 11 since block 536000 the pre-fork 200 bps path is unreachable. This is the same consensus source that bounded ZYS in v4.33, read on the sibling conversion
    • USDPT (Western Union) gains an offchain-issuer route, so coverage rises to 315 configured coins and the offchain-issuer family grows from 147 to 148. Anchorage Digital Bank N.A. is the federally regulated issuer and its Covered Stablecoin Terms redeem presented tokens at Par Value, but the route is client-gated — the terms redeem 'exclusively from Clients' — and settlement is modeled as days rather than the issuer default of same-day because the terms promise only 'commercially reasonable efforts' with no published timeframe and reserve the discretion to refuse, suspend, or limit any request
    • USSD (Sonic) consumes live escrow telemetry as its executable exit bound and drops the documented-bound full-supply model with no fallback, so an unavailable read leaves the route unrated instead of assuming immediacy. At Sonic block 77432523 the BrandedCustodian's totalAssets() and the custodian's frxUSD balance both read 2,081,316.47, confirming the escrow measured is the asset the redemption pays out; its redeemFee() is still 0 and paused() reverts, so the verified source exposes no pause surface
    • satUSD (River) takes no static fee bound — `maxRedemptionFee` is a per-branch governance parameter capped only at 100%, two orders of magnitude above the admissible ceiling — but its cost model is corrected from undisclosed to the documented `min(redemptionFeeFloor + baseRate, maxRedemptionFee)` formula, and its live adapter now reads each branch's getRedemptionRateWithDecay() so the current cost comes from telemetry instead. Capacity moves onto per-chain trove debt read through the Satoshi app's getGlobalSystemBalances(), gated on debtToken() still round-tripping to this coin's own satUSD deployment and on the global TCR clearing each branch MCR. The documented-bound full-supply model is dropped with no fallback: satUSD is largely bridged or Smart-Vault-minted rather than trove-backed, so total supply never described what the redemption engine could honor
    Details

    Impact Notes

    • ZSD (Zephyr) replaces its dynamic-fee marker with a fixed 10 bps bound: the pinned RingCT source deducts `exchange_128 / 1000` from the ZSD/ZEPH rate on every REDEEM_STABLE, and because Zephyr mainnet has run hard fork 11 since block 536000 the pre-fork 200 bps path is unreachable. This is the same consensus source that bounded ZYS in v4.33, read on the sibling conversion
    • USDPT (Western Union) gains an offchain-issuer route, so coverage rises to 315 configured coins and the offchain-issuer family grows from 147 to 148. Anchorage Digital Bank N.A. is the federally regulated issuer and its Covered Stablecoin Terms redeem presented tokens at Par Value, but the route is client-gated — the terms redeem 'exclusively from Clients' — and settlement is modeled as days rather than the issuer default of same-day because the terms promise only 'commercially reasonable efforts' with no published timeframe and reserve the discretion to refuse, suspend, or limit any request
    • USSD (Sonic) consumes live escrow telemetry as its executable exit bound and drops the documented-bound full-supply model with no fallback, so an unavailable read leaves the route unrated instead of assuming immediacy. At Sonic block 77432523 the BrandedCustodian's totalAssets() and the custodian's frxUSD balance both read 2,081,316.47, confirming the escrow measured is the asset the redemption pays out; its redeemFee() is still 0 and paused() reverts, so the verified source exposes no pause surface
    • satUSD (River) takes no static fee bound — `maxRedemptionFee` is a per-branch governance parameter capped only at 100%, two orders of magnitude above the admissible ceiling — but its cost model is corrected from undisclosed to the documented `min(redemptionFeeFloor + baseRate, maxRedemptionFee)` formula, and its live adapter now reads each branch's getRedemptionRateWithDecay() so the current cost comes from telemetry instead. Capacity moves onto per-chain trove debt read through the Satoshi app's getGlobalSystemBalances(), gated on debtToken() still round-tripping to this coin's own satUSD deployment and on the global TCR clearing each branch MCR. The documented-bound full-supply model is dropped with no fallback: satUSD is largely bridged or Smart-Vault-minted rather than trove-backed, so total supply never described what the redemption engine could honor
    • USDai moves onto its live PYUSD float with no fallback, gated on baseToken() still resolving to that same PYUSD deployment. For a KYC-gated burn-and-withdraw route the float is the only honest bound, and the point is not academic: at the 2026-08-12 read the contract held 174,318,300.42 PYUSD against a USDai supply near 172.6M, so the float currently exceeds supply and no fixed fraction of supply could stand in for it
    • DOC (Money On Chain) consumes MoCState.freeDoc() — the DOC currently redeemable through redeemFreeDoc — identity-bound to the tracked DOC token through the MoC connector, with a 95% documented ratio retained as fallback because DOC is also deployed on Arbitrum and Ethereum while only the Rootstock-local balance is redeemable, and Rootstock exposes a single public RPC. At the 2026-08-12 read freeDoc() returned 2,874,833.75 with the connector identity resolving and the pause target false
    • USDz (Anzen) is corrected from whitelisted to permissionless access, read from the deployed source rather than the docs: redeem() gates only on pause, collateral rate, sufficient SPCT reserve, and a caller blacklist, with no holder whitelist. The SPCT whitelist sits one level down and covers the USDz contract itself, which is what calls spct.redeem() — on-chain, SPCT isWhitelist() reads true for the USDz contract and false for an ordinary address. Anzen's Qualified-Market-Maker framing describes the primary mint rail, not a restriction on who may redeem
    • USDz also moves onto live telemetry with no fallback. `redeem()` pays USDC out of the USDz contract after pulling it from the SPCT pool, so the pool's own USDC is the depth rather than full supply, and the whole surface is withheld when USDz's pinned usdc(), spct(), or oracle() identities stop resolving or paused() reads true. Its fee is also read live: the route charges USDz's redeemFeeRate() first and SPCT's rate on the remainder, so the two compose rather than add
    • USDz's first live capacity read is an honest negative of the kind the DOLA correction established. At Ethereum mainnet on 2026-08-12 the SPCT pool held 6,695 raw USDC units — 0.006695 USDC, under a cent — against a USDz supply of 806,422.80, and the source makes that ceiling exact rather than approximate: redeem() requires spct.reserveUSD() * 1e12 >= _amount, capping any single redemption at 0.006695 USDz. The route is open and unpaused but drained to a rounding error, so the earlier full-supply model was crediting a reserve it could not pay
    • eUSD (Electronic Dollar) migrates to the Reserve DTF adapter and becomes live-only with no fallback, the same treatment USD3 took in v4.33: the route reads the RToken's own redemptionAvailable() throttle, which refills over time and shrinks as it is drawn, so no static supply figure represents it. At Ethereum block 25737172 the throttle returned exactly 5,000,000.00 against a supply of 22,834,920.56 with the basket handler reporting SOUND — binding at roughly 22% of supply, which is what the full-supply model had been overstating
    • HONEY (Berachain) moves from documented full supply to live-direct vault telemetry: the gated probe enumerates the HoneyFactory's registered assets and their collateral vaults, verifying the factory's own honey() resolves to the tracked token first, and bounds the route by what those vaults hold. Its documented asset-specific fee schedule is now bounded by live redeemRates() as well. At Berachain block 24750999 basket mode was off for both mint and redeem, all four registered assets read isPegged() true, the vaults held 7,831,557.70 against a supply of 7,831,365.98, and live rates were 0 bps on three assets and exactly 5 bps on the fourth
    • Two routes are deliberately left unmodeled after live investigation. USBD (BIMA) stays documented-bound because immediate capacity is trove-set-dependent: a pinned system-debt view would overstate the executable exit as troves churn. xUSD (BabelFish) stays as-is because the deployed v5 aggregator manager departs from its documented interface, so executable capacity cannot be bounded safely from either source
    • dEURO keeps no fee bound and is flagged for a route remodel. Re-reading the primary docs found no holder-exercisable redemption into position collateral at all — the positions page documents owner minting plus a permissionless challenge auction, which liquidates rather than redeems — so the modeled route has no documented fee to bound. The one exit dEURO does document is a different rail: StablecoinBridge burns dEURO 1:1 into a single source Euro stablecoin at no fee, but bounded by that bridge's idle inventory rather than by supply, which at Ethereum block 25737044 was 456,236.35 EURC on the EURC bridge
    • ZeUSD (Zoth) stays unconfigured: the documented route belongs to the ZeDP position NFT holder burning that position's own debt for the exact collateral deposited, not to a secondary ZeUSD holder, and the shared V1 router is recorded paused. bnUSD (Balanced) stays unconfigured: the tracked asset is the v1 ICON token whose maintained documentation has narrowed to wind-down tasks, and the 1:1 Stability Fund swap runs through SODAX on token identities distinct from the tracked contract
    • CJPY (Yamato) moves onto live telemetry with no fallback: the priority registry's own getRedeemablesCap() — identity-gated on the registry round-tripping to the pinned Yamato core — is converted JPY to ETH through the protocol oracle and ETH to USD through the shared reference price, retiring both the documented full-supply model and the now-stale policy that recorded the adapter as capacity-less
    • AID (GAIB) moves onto live telemetry with no fallback: the redeemer's USDC payout float capped by the remaining daily redemption allowance, identity-gated on stablecoin()/aid() and the pinned beacon implementation, read at $239,938.89 against the whitelisted burn-and-withdraw rail on 2026-08-12; its 10 bps fee is confirmed by the deployed redemptionFeeBps()
    • iUSD (InfiniFi) gains live queue telemetry: the Gateway's RedeemController is identity-chained and read for queue length and total enqueued redemptions (both zero with gates open on 2026-08-12), lifting the route's evidence above the blind 15% heuristic that previously carried it alone; the direct controller buffer stays unscored because hook-driven liquidity is not statically readable
    • Route-family totals are now 148 offchain-issuer, 67 stablecoin-redeem, 38 collateral-redeem, 39 queue-redeem, 14 psm-swap, and 9 basket-redeem
    Commit provenance not recorded
      v4.33Aug 12, 2026

      Three new PSM routes, four more fee bounds, and live capacity telemetry

      A second exit-credit pass configures three previously unconfigured PSM rails, bounds four more redemption fees against primary sources, records two routes as still unconfigurable, and switches four routes onto live capacity telemetry — including one correction that removes credit a drained contract could never have honored. Scoring weights, ladders, and the exit engine are unchanged; routes move only through better evidence.

      • DOLA is corrected downward: its reviewed 8% PSM-share capacity was a phantom. At Ethereum block 25736814 the deployed Inverse PSM reads supply() and getTotalReserves() of zero with zero token balances and a hard-reverting sell(), the contract having been drained on 2025-12-10 and stripped of its 200k DOLA Fed float on 2025-12-11. Capacity is now live-only with no fallback, so an unavailable read leaves the route unrated instead of resurrecting the static bound; the 20 bps fee is unchanged and now confirmed by the contract's own sellFeeBps()
      • OUSG consumes live InstantManager router capacity as its immediate redeemable bound, replacing the full-supply model; Ondo's published $50M global instant-redemption limit across all investors in a rolling 24-hour window becomes the fallback when the router read is unavailable
      • USD3 (Reserve) consumes the RToken's own redemptionAvailable() throttle read and drops its documented-bound full-supply model entirely — the throttle refills over time, so no static figure represents it. Capacity is withheld when the collateral basket is not SOUND and the route is left unrated when the throttle cannot be read
      • USDD consumes the live Tron PSM GemJoin USDT balance, keeping the reviewed 16% PSM-share bound as fallback; its 0 bps fee is now confirmed by the module's on-chain tout()
      Details

      Impact Notes

      • DOLA is corrected downward: its reviewed 8% PSM-share capacity was a phantom. At Ethereum block 25736814 the deployed Inverse PSM reads supply() and getTotalReserves() of zero with zero token balances and a hard-reverting sell(), the contract having been drained on 2025-12-10 and stripped of its 200k DOLA Fed float on 2025-12-11. Capacity is now live-only with no fallback, so an unavailable read leaves the route unrated instead of resurrecting the static bound; the 20 bps fee is unchanged and now confirmed by the contract's own sellFeeBps()
      • OUSG consumes live InstantManager router capacity as its immediate redeemable bound, replacing the full-supply model; Ondo's published $50M global instant-redemption limit across all investors in a rolling 24-hour window becomes the fallback when the router read is unavailable
      • USD3 (Reserve) consumes the RToken's own redemptionAvailable() throttle read and drops its documented-bound full-supply model entirely — the throttle refills over time, so no static figure represents it. Capacity is withheld when the collateral basket is not SOUND and the route is left unrated when the throttle cannot be read
      • USDD consumes the live Tron PSM GemJoin USDT balance, keeping the reviewed 16% PSM-share bound as fallback; its 0 bps fee is now confirmed by the module's on-chain tout()
      • FXD (Fathom), HOLLAR (Hydration), and USDH (Hubble) gain psm-swap routes, so coverage rises to 314 configured coins and the psm-swap family grows from 11 to 14
      • USDai's route is bounded at the 10 bps redemption fee its issuer notice publishes, and access is corrected from permissionless to whitelisted because the same notice restricts contract-level mint and redeem to KYC'd market makers and approved institutional depositors
      • ZYS (Zephyr) replaces its undisclosed-fee marker with a fixed 10 bps bound taken from the consensus RingCT source, which deducts a 0.1% conversion fee on every REDEEM_YIELD
      • USDnr (Nerona) is bounded at 0 bps for the modeled USDnr -> M leg: Nerona documents no protocol mint or redeem fee on USDnr itself, and the 0.01% figure belongs to the downstream wM/USDC pool rather than to the modeled route
      • FXD carries a 25 bps whitepaper fee with whitelisted access and an unresolved xUSDT output; USDH carries its documented 50 bps PSM fee but routeStatus unknown, because no current Hubble source proves the module still executes; HOLLAR deliberately keeps no fee bound, since its buy-back fee is a per-collateral on-chain Permill with no documented ceiling and no adapter to read it
      • MAI (QiDao) stays unconfigured: its Peg Stability Module, fee, and contract-address pages now return HTTP 404, so the queue route cannot be read from a live primary source. iUSD (Initia) stays unconfigured: the maintained bridge documentation does not mention iUSD at all
      • Route-family totals are now 147 offchain-issuer, 67 stablecoin-redeem, 38 collateral-redeem, 39 queue-redeem, 14 psm-swap, and 9 basket-redeem
      Commit provenance not recorded
        v4.32Aug 12, 2026

        Live route-openness, live fees, and exit-credit route upgrades

        Live reserve adapters now assert current route openness and fees where the chain proves them, several routes gain live-direct capacity or documented fee bounds, and two routes are corrected against current primary sources. Scoring weights, ladders, and the exit engine are unchanged; routes move only through better evidence.

        • ERC-4626 wrapper adapters emit routeStatus open/paused from same-run evidence: positive redemption liquidity plus an opportunistic paused()/isShutdown() probe, so ~20 wrapper routes previously stuck at routeStatus unknown now carry current-open attribution and their producer observations become score-eligible
        • Mento V3 FPMM pools (JPYm, CHFm) read the pool's lpFee()+protocolFee() live (30 bps today, contract-capped at 200 bps combined), replacing the undisclosed-fee marker that ceilinged their exit credit
        • USDe gains live-direct redemption capacity from the EthenaMinting contract's own USDT/USDC balances, capped by per-asset and global max-redeem-per-block config read in the same pass; the prior 0.5% reviewed heuristic remains only as fallback
        • Reservoir routes read the USDC PSM on-chain (underlying identity, balance, pause state) instead of trusting API telemetry with unknown route status; base rUSD gains its own PSM redemption route (coverage rises to 311 configured), while srUSD/wsrUSD deliberately keep no fee bound because the deployed SavingModule exit fee is governance-settable with no ceiling under the 200 bps policy limit
        Details

        Impact Notes

        • ERC-4626 wrapper adapters emit routeStatus open/paused from same-run evidence: positive redemption liquidity plus an opportunistic paused()/isShutdown() probe, so ~20 wrapper routes previously stuck at routeStatus unknown now carry current-open attribution and their producer observations become score-eligible
        • Mento V3 FPMM pools (JPYm, CHFm) read the pool's lpFee()+protocolFee() live (30 bps today, contract-capped at 200 bps combined), replacing the undisclosed-fee marker that ceilinged their exit credit
        • USDe gains live-direct redemption capacity from the EthenaMinting contract's own USDT/USDC balances, capped by per-asset and global max-redeem-per-block config read in the same pass; the prior 0.5% reviewed heuristic remains only as fallback
        • Reservoir routes read the USDC PSM on-chain (underlying identity, balance, pause state) instead of trusting API telemetry with unknown route status; base rUSD gains its own PSM redemption route (coverage rises to 311 configured), while srUSD/wsrUSD deliberately keep no fee bound because the deployed SavingModule exit fee is governance-settable with no ceiling under the 200 bps policy limit
        • USTB is remodeled from the same-day fiat issuer rail to the atomic on-chain RedemptionIdle USDC rail its live adapter already measures (whitelisted access, 0 bps documented fee)
        • IST's PSM route status is set to unknown following Inter Protocol's governance-approved sunset; eUSD and USD3 (Reserve) gain documented 0 bps redemption-fee ceilings from Reserve's closed fee schedule
        • Route-family totals are now 147 offchain-issuer, 67 stablecoin-redeem, 38 collateral-redeem, 39 queue-redeem, 11 psm-swap, and 9 basket-redeem
        Commit provenance not recorded
          v4.31Aug 8, 2026

          Minimum-redeem ladder matches at-or-above

          The redemption backstop's minimum-redeem penalty ladder matched its thresholds strictly above, while the queue-backlog ladder matched at-or-above. A route whose reviewed minimum landed exactly on a boundary therefore took the gentler band. Both ladders now match at-or-above, and the comparison mode is no longer a parameter of the shared exit engine's band resolver.

          • A reviewed minimum redemption of exactly $1,000,000 now applies the 0.75 capacity multiplier instead of 0.9; exactly $10,000 applies 0.9 instead of no penalty
          • Only routes whose reviewed minimum sits exactly on a ladder threshold can move; all other route scores are unchanged
          • The queue-backlog ladder is unchanged — it already matched at-or-above
          • Band thresholds and multipliers, component subscores, capacity semantics, model confidence, route status, and the exit-route observation envelope are unchanged
          Details

          Impact Notes

          • A reviewed minimum redemption of exactly $1,000,000 now applies the 0.75 capacity multiplier instead of 0.9; exactly $10,000 applies 0.9 instead of no penalty
          • Only routes whose reviewed minimum sits exactly on a ladder threshold can move; all other route scores are unchanged
          • The queue-backlog ladder is unchanged — it already matched at-or-above
          • Band thresholds and multipliers, component subscores, capacity semantics, model confidence, route status, and the exit-route observation envelope are unchanged
          Commit provenance not recorded
            v4.3Aug 7, 2026

            One exit engine: the legacy effective exit score retires

            Exit was scored by two engines over the same route evidence. The route-scoring tables that the redemption backstop score and the Safety Score V9 Exit pillar each maintained a copy of are now a single definition, validated in CI against the V9 policy artifact. The legacy `effectiveExitScore` blend and its unshipped same-notional shadow engine are deleted; same-notional exit is published by the V9 Exit pillar alone. Redemption route scores themselves are unchanged.

            • The exit scoring tables — component weights, coverage and absolute-capacity breakpoints, settlement-delay, queue-backlog and minimum-redeem bands, holder-eligibility multipliers, confidence factors, route-family caps, and the stress-request policy — live once in `shared/lib/exit-route-scoring.ts`; the V9 policy JSON is asserted against that source rather than pinned to a second authored copy
            • Both published views now compose the same engine primitives and differ only in their request: the redemption score measures a route against the supply-denominator notional, the V9 Exit pillar against the same notional snapped to the reviewed stress grid
            • `effectiveExitScore` is removed from `GET /api/redemption-backstops` rows, from the snapshot and history writes, and from the detail-page and coverage surfaces; `methodology.effectiveExitModel` is removed from the endpoint and from `v4ScoringParametersHash`
            • `score`, `dexLiquidityScore`, `eventualRedeemabilityScore`, every component subscore, capacity semantics, model confidence, route status, and the exit-route observation envelope are unchanged — no redemption route score moves
            Details

            Impact Notes

            • The exit scoring tables — component weights, coverage and absolute-capacity breakpoints, settlement-delay, queue-backlog and minimum-redeem bands, holder-eligibility multipliers, confidence factors, route-family caps, and the stress-request policy — live once in `shared/lib/exit-route-scoring.ts`; the V9 policy JSON is asserted against that source rather than pinned to a second authored copy
            • Both published views now compose the same engine primitives and differ only in their request: the redemption score measures a route against the supply-denominator notional, the V9 Exit pillar against the same notional snapped to the reviewed stress grid
            • `effectiveExitScore` is removed from `GET /api/redemption-backstops` rows, from the snapshot and history writes, and from the detail-page and coverage surfaces; `methodology.effectiveExitModel` is removed from the endpoint and from `v4ScoringParametersHash`
            • `score`, `dexLiquidityScore`, `eventualRedeemabilityScore`, every component subscore, capacity semantics, model confidence, route status, and the exit-route observation envelope are unchanged — no redemption route score moves
            • Consumers of the retired blend read the published V9 Exit pillar instead: the Selector now sources its exit input from `pillars.exit` only, and no longer fetches the redemption payload at all
            • The unshipped `sameNotionalScoringMode: "active"` shadow engine — its observation eligibility, capacity-point resolution, pairwise request matching, and correlation classification — is deleted; the V9 Exit pillar performs that work in production
            • The `redemption_backstop*` `effective_exit_score` columns remain in D1 and simply stop being written; the entry schema keeps the key declared but inert so Safety Score V9 compiler inputs captured before this version stay replayable
            • Discovery's Curve provider check is scoped to the eight chains that credit Curve as a registered discovery provider and honors Curve's chain-path mapping, so deployment-census outcomes are always attributable to a named provider and the guaranteed-failing Gnosis request is gone
            Commit provenance not recorded
              v4.21Jul 30, 2026

              DUSD live queue capacity and issuer-discretionary route status

              DUSD now uses same-block Makina AsyncRedeemer telemetry to measure only the currently usable Ethereum USDC queue buffer. The route fails closed when the on-chain proxy, Machine token wiring, or queued-share liability proof cannot be validated, and an enabled redemption whitelist is represented as issuer-discretionary access rather than a route impairment.

              • `dusd-dialectic` moves from a static $0 queue placeholder to reserve-sync live-queue capacity backed by the Machine's idle Ethereum USDC minus `convertToAssets(DUSD.balanceOf(AsyncRedeemer))`
              • The Makina strategy adapter validates the AsyncRedeemer beacon implementation, Machine `accountingToken()`/`shareToken()` values, and redeemer `machine()` binding at one pinned Ethereum block before publishing capacity
              • DUSD no longer publishes the AsyncRedeemer minimum finalization delay as score-bearing `settlementDelaySec`; the 12-hour floor remains visible in `redemptionQueue.minimumFinalizationDelaySec`
              • Whitelist-enabled DUSD redemption remains `routeStatus: "open"` with `holderEligibility: "issuer-discretionary"`; `cohort-limited` remains reserved for explicit current route impairment beyond the modeled eligible cohort
              Details

              Impact Notes

              • `dusd-dialectic` moves from a static $0 queue placeholder to reserve-sync live-queue capacity backed by the Machine's idle Ethereum USDC minus `convertToAssets(DUSD.balanceOf(AsyncRedeemer))`
              • The Makina strategy adapter validates the AsyncRedeemer beacon implementation, Machine `accountingToken()`/`shareToken()` values, and redeemer `machine()` binding at one pinned Ethereum block before publishing capacity
              • DUSD no longer publishes the AsyncRedeemer minimum finalization delay as score-bearing `settlementDelaySec`; the 12-hour floor remains visible in `redemptionQueue.minimumFinalizationDelaySec`
              • Whitelist-enabled DUSD redemption remains `routeStatus: "open"` with `holderEligibility: "issuer-discretionary"`; `cohort-limited` remains reserved for explicit current route impairment beyond the modeled eligible cohort
              • No fallback ratio, full-supply, AUM, deployed-position, or reserve-weight capacity is used when the live queue proof is unavailable
              Commit provenance not recorded
                v4.20Jul 23, 2026

                sBOLD Stability Pool capacity and bounded opaque-fee evidence

                sBOLD now measures same-run BOLD withdrawability from its Liquity V2 Stability Pool positions instead of treating the vault's near-zero idle BOLD balance as its executable buffer. Reviewed full-supply routes with an undisclosed fee can also publish capacity evidence tagged as bounded-unknown cost, while remaining ineligible for current redemption scoring without a numeric cost bound.

                • `sbold-k3-capital` reads the BOLD amount returned by the vault's `calcFragments()` liquidity view and caps live capacity at the amount the vault can withdraw from its Stability Pool positions
                • sBOLD's live capacity uses documented-bound confidence and a strategy-buffer basis because collateral gains are excluded and K3 can temporarily restrict withdrawals when collateral exposure breaches its operational threshold
                • A failed sBOLD liquidity read fails closed instead of falling back to full NAV or the vault's total assets
                • Reviewed `undisclosed-reviewed` supply-model routes retain modeled capacity in `exitRouteObservations` with `feeEvidence: "undisclosed-reviewed"`, but the producer keeps them non-score-eligible until a fixed fee or reviewed numeric ceiling bounds same-notional cost
                Details

                Impact Notes

                • `sbold-k3-capital` reads the BOLD amount returned by the vault's `calcFragments()` liquidity view and caps live capacity at the amount the vault can withdraw from its Stability Pool positions
                • sBOLD's live capacity uses documented-bound confidence and a strategy-buffer basis because collateral gains are excluded and K3 can temporarily restrict withdrawals when collateral exposure breaches its operational threshold
                • A failed sBOLD liquidity read fails closed instead of falling back to full NAV or the vault's total assets
                • Reviewed `undisclosed-reviewed` supply-model routes retain modeled capacity in `exitRouteObservations` with `feeEvidence: "undisclosed-reviewed"`, but the producer keeps them non-score-eligible until a fixed fee or reviewed numeric ceiling bounds same-notional cost
                • Current opaque-fee redemption scores and effective-exit blending remain unchanged; downstream candidate models may consume the tagged capacity only under their own explicit opaque-fee ceiling
                Commit provenance not recorded
                  v4.19Jul 18, 2026

                  Fail-closed capacity for mixed reserve buckets

                  Live reserve metadata now qualifies as executable redemption capacity only when the adapter isolates assets that are immediately available to the holder route. Ethena's aggregate Liquid Cash accounting bucket does not make that distinction, so USDe retains its reviewed 0.5% hot-buffer fallback instead of treating the full mixed bucket as current capacity.

                  • `usde-ethena` no longer promotes Ethena's mixed Liquid Cash aggregate into live-proxy executable capacity
                  • USDe continues to use the reviewed 0.5% hot-buffer fallback and documented fixed 10 bps fee; its reserve composition remains visible as backing evidence
                  • The generic reserve-sync contract is unchanged for adapters that isolate route-executable assets; aggregate accounting categories must now remain contextual rather than scoring capacity
                  Details

                  Impact Notes

                  • `usde-ethena` no longer promotes Ethena's mixed Liquid Cash aggregate into live-proxy executable capacity
                  • USDe continues to use the reviewed 0.5% hot-buffer fallback and documented fixed 10 bps fee; its reserve composition remains visible as backing evidence
                  • The generic reserve-sync contract is unchanged for adapters that isolate route-executable assets; aggregate accounting categories must now remain contextual rather than scoring capacity
                  Commit provenance not recorded
                    v4.18Jul 13, 2026

                    Bounded exit-route observations for documented full-supply routes

                    Resolved full-supply redemption routes that quantify no immediate capacity now publish an explicitly-bounded exit-route observation derived from the row's own reviewed model: documented-terms evidence at the review timestamp, capacity bounded by the documented full-supply basis, and a cost bound only when the fee model is a documented fixed bps fee. Atomic settlement projects onto the same-notional exit request; every slower settlement model publishes diagnostic eventual-redemption evidence that is never score-eligible.

                    • Open, resolved `supply-full` routes with documented-bound capacity confidence and a reviewed docs timestamp emit one `exitRouteObservations` row where they previously emitted none
                    • Only atomic-settlement routes with a documented fixed-bps fee at or under the 200 bps same-notional cost bound are score-eligible; immediate, same-day, days, and queued settlement models publish `eventual-redemption` diagnostic observations with conservative settlement-horizon ceilings (1h/1d/14d/30d)
                    • Routes with formula, variable, or undisclosed fee models carry a zero executable bound because the published row states no defensible cost bound
                    • Redemption scores, capacity scores, effective-exit blending, and eventual redeemability are unchanged; this adds observation evidence only
                    Details

                    Impact Notes

                    • Open, resolved `supply-full` routes with documented-bound capacity confidence and a reviewed docs timestamp emit one `exitRouteObservations` row where they previously emitted none
                    • Only atomic-settlement routes with a documented fixed-bps fee at or under the 200 bps same-notional cost bound are score-eligible; immediate, same-day, days, and queued settlement models publish `eventual-redemption` diagnostic observations with conservative settlement-horizon ceilings (1h/1d/14d/30d)
                    • Routes with formula, variable, or undisclosed fee models carry a zero executable bound because the published row states no defensible cost bound
                    • Redemption scores, capacity scores, effective-exit blending, and eventual redeemability are unchanged; this adds observation evidence only
                    Commit provenance not recorded
                      v4.17Jul 9, 2026

                      Live-direct capacity tranche: Mento family, USTB, PUSD, cUSD fee, savings-vault cohort

                      A verified batch of routes moves onto same-run live redemption telemetry: the 13-coin Mento family reads Broker/BiPoolManager pool depth and spread, the GBPm Liquity-v2-fork branch, or Mento-v3 FPMM pool depth on Celo; Superstate USTB capacity becomes the on-chain RedemptionIdle USDC buffer with a documented 0 bps fee; Polymarket PUSD scores its verified backing-vault unwrap capacity; Cap cUSD's flat redeem fee is read live from the vault's Minter; and the atomic-full-backing savings-vault cohort extends to sUSDD and sDOLA after per-vault redemption-simulation review.

                      • All 13 Mento stablecoins (cUSD, cEUR, and the FX m-stables) move from documented-bound full-supply heuristics to live-direct on-chain capacity: broker coins score counter-asset bucket depth with the pool's on-chain spread as a live formula fee, `gbpm-mento` scores its fork's ActivePool debt with the Liquity-style `getRedemptionRateWithDecay()` fee, and `jpym-mento`/`chfm-mento` score FPMM pool depth (capacity only; the FPMM fee getter is unverified)
                      • `ustb-superstate` capacity of record is now the USDC balance of Superstate's RedemptionIdle contract read in the same run (the liquidity API remains context), and its fee model moves from undisclosed to the documented current 0 bps protocol redemption fee
                      • `pusd-polymarket` moves from documented full-supply to reserve-sync live-direct capacity: unwrap pulls USDC from the verified immutable backing vault, so the vault balance (~101% of supply) is current executable capacity with a documented 0 bps fee
                      • `cusd-cap` fee evidence moves from undisclosed to a live on-chain formula: the vault's inherited Minter exposes `getRedeemFee()` (currently 0 bps), emitted as current-fee telemetry each run
                      Details

                      Impact Notes

                      • All 13 Mento stablecoins (cUSD, cEUR, and the FX m-stables) move from documented-bound full-supply heuristics to live-direct on-chain capacity: broker coins score counter-asset bucket depth with the pool's on-chain spread as a live formula fee, `gbpm-mento` scores its fork's ActivePool debt with the Liquity-style `getRedemptionRateWithDecay()` fee, and `jpym-mento`/`chfm-mento` score FPMM pool depth (capacity only; the FPMM fee getter is unverified)
                      • `ustb-superstate` capacity of record is now the USDC balance of Superstate's RedemptionIdle contract read in the same run (the liquidity API remains context), and its fee model moves from undisclosed to the documented current 0 bps protocol redemption fee
                      • `pusd-polymarket` moves from documented full-supply to reserve-sync live-direct capacity: unwrap pulls USDC from the verified immutable backing vault, so the vault balance (~101% of supply) is current executable capacity with a documented 0 bps fee
                      • `cusd-cap` fee evidence moves from undisclosed to a live on-chain formula: the vault's inherited Minter exposes `getRedeemFee()` (currently 0 bps), emitted as current-fee telemetry each run
                      • `usde-ethena` fee evidence moves to the documented fixed 10 bps from Ethena's public fees API and terms; capacity remains live-proxy because no public redeemable-buffer endpoint exists
                      • `susdd-tron-dao-reserve` and `sdola-inverse-finance` join the atomic-full-backing cohort after contract-source review plus state-override redemption simulations (sUSDD is an sDAI-fork pot/join exit; sDOLA unstakes from a fully liquid DolaSavings module); `sbold-k3-capital` was reviewed and deliberately excluded because its collateral-health gate and BOLD-only withdrawal cap make exits constrainable, and `eearn-ember`'s operator-batched request/settle exits keep the near-zero idle probe honest
                      • Scoring formulas, weights, and confidence gates are unchanged; this tranche changes capacity and fee evidence sources only
                      Commit provenance not recorded
                        v4.16Jun 26, 2026

                        Yearn V3 strategy-queue capacity for verified vault exits

                        Reviewed Yearn V3 ERC-4626 vault exits now use same-run on-chain strategy-queue withdrawability instead of the idle underlying balance when the default queue proves strategy-backed assets are redeemable by the vault.

                        • `ybold-yearn` and `yvusdc-yearn` no longer score near-zero direct exit capacity solely because the vault contracts hold little or no idle BOLD/USDC; the adapter measures `totalIdle()` plus each funded default-queue strategy's `min(currentDebt, convertToAssets(maxRedeem(vault)))`
                        • The new `redemptionLiquidity: { source: "yearn-v3-withdrawable", settlementDelaySec: 0 }` mode is reviewer-configured and re-probes Yearn V3 strategy liquidity every reserve sync, so it is narrower than treating generic ERC-4626 `convertToAssets(totalSupply)` as executable capacity
                        • Unconfigured ERC-4626 wrappers remain conservative: idle underlying, reviewed Morpho vault liquidity, or explicit atomic-full-backing modes are still the only scoring capacity sources
                        • If a funded Yearn strategy's debt, maxRedeem, or conversion probe is unavailable, the live reserve snapshot degrades and the route fails closed instead of falling back to full NAV
                        Details

                        Impact Notes

                        • `ybold-yearn` and `yvusdc-yearn` no longer score near-zero direct exit capacity solely because the vault contracts hold little or no idle BOLD/USDC; the adapter measures `totalIdle()` plus each funded default-queue strategy's `min(currentDebt, convertToAssets(maxRedeem(vault)))`
                        • The new `redemptionLiquidity: { source: "yearn-v3-withdrawable", settlementDelaySec: 0 }` mode is reviewer-configured and re-probes Yearn V3 strategy liquidity every reserve sync, so it is narrower than treating generic ERC-4626 `convertToAssets(totalSupply)` as executable capacity
                        • Unconfigured ERC-4626 wrappers remain conservative: idle underlying, reviewed Morpho vault liquidity, or explicit atomic-full-backing modes are still the only scoring capacity sources
                        • If a funded Yearn strategy's debt, maxRedeem, or conversion probe is unavailable, the live reserve snapshot degrades and the route fails closed instead of falling back to full NAV
                        Commit provenance not recorded
                          v4.15Jun 25, 2026

                          Atomic-full-backing capacity for external savings-module vaults

                          ERC-4626 savings vaults whose redemption is atomic and unconstrained — because the underlying is released on demand from an external savings module rather than held as an idle vault balance — now score their full convertible backing as current executable redemption capacity instead of the near-zero idle-underlying probe.

                          • `sdai-sky` no longer scores ~$0 instant-exit capacity: the legacy Sky DSR routes redeemed DAI through the Maker pot, so `DAI.balanceOf(sDAI)` is ~0 even though sDAI→DAI redemption is atomic and unconstrained against the full ~$175M backing
                          • A reviewer-asserted `redemptionLiquidity: { source: "atomic-full-backing" }` adapter flag treats the supply-equivalent convertible backing (ratio 1.0) as live-direct same-run on-chain capacity; it is set only where the unconstrained-redemption property is verified, since the default idle-balance telemetry understates such vaults to ~0
                          • sDAI's redemption backstop score rises 69→93 and its effective-exit liquidity dimension 62→93 as the capacity component moves from 0 to 97
                          • Sky's modern `susds-sky`/`stusds-sky` savings vaults are unaffected: they hold their underlying in-contract, so the existing idle-balance probe already measured full backing — only the legacy pot-routed sDAI needed the flag
                          Details

                          Impact Notes

                          • `sdai-sky` no longer scores ~$0 instant-exit capacity: the legacy Sky DSR routes redeemed DAI through the Maker pot, so `DAI.balanceOf(sDAI)` is ~0 even though sDAI→DAI redemption is atomic and unconstrained against the full ~$175M backing
                          • A reviewer-asserted `redemptionLiquidity: { source: "atomic-full-backing" }` adapter flag treats the supply-equivalent convertible backing (ratio 1.0) as live-direct same-run on-chain capacity; it is set only where the unconstrained-redemption property is verified, since the default idle-balance telemetry understates such vaults to ~0
                          • sDAI's redemption backstop score rises 69→93 and its effective-exit liquidity dimension 62→93 as the capacity component moves from 0 to 97
                          • Sky's modern `susds-sky`/`stusds-sky` savings vaults are unaffected: they hold their underlying in-contract, so the existing idle-balance probe already measured full backing — only the legacy pot-routed sDAI needed the flag
                          • The scoring formula and confidence gates are unchanged; this only corrects capacity measurement for vaults whose backing is verifiably redeemable in full but invisible to an idle-balance read
                          Commit provenance not recorded
                            v4.14Jun 23, 2026

                            Morpho V1/V2 vault liquidity for curated vault exits

                            Steakhouse, Smokehouse, and Gauntlet Morpho vault-token reserve-sync telemetry now uses reviewed Morpho V1/V2 vault liquidity as current executable redemption capacity after validating the exact vault, underlying asset, listed status, and chain.

                            • `steakusdt-steakhouse`, `steakusdc-steakhouse`, `gtusdcp-gauntlet`, `bbqusdc-steakhouse`, and `gtusdc-gauntlet` no longer score their instant-exit paths from idle underlying alone when the vault has withdrawable Morpho liquidity available
                            • Morpho V2 `liquidity` and Morpho V1 `liquidity.underlying` are treated as live-direct same-run API capacity and capped by the ERC-4626 asset base before entering the effective-exit blend
                            • Morpho V2 `forceDeallocatableLiquidity` is retained as context only; it does not inflate scoring capacity
                            • The standalone DEX liquidity score remains a DEX-market measure and does not count Morpho lending-vault liquidity directly
                            Details

                            Impact Notes

                            • `steakusdt-steakhouse`, `steakusdc-steakhouse`, `gtusdcp-gauntlet`, `bbqusdc-steakhouse`, and `gtusdc-gauntlet` no longer score their instant-exit paths from idle underlying alone when the vault has withdrawable Morpho liquidity available
                            • Morpho V2 `liquidity` and Morpho V1 `liquidity.underlying` are treated as live-direct same-run API capacity and capped by the ERC-4626 asset base before entering the effective-exit blend
                            • Morpho V2 `forceDeallocatableLiquidity` is retained as context only; it does not inflate scoring capacity
                            • The standalone DEX liquidity score remains a DEX-market measure and does not count Morpho lending-vault liquidity directly
                            Commit provenance not recorded
                              v4.13Jun 15, 2026

                              Live reserve telemetry for medium-confidence follow-ups

                              Verified Redemption Backstop follow-ups now use same-run reserve-sync capacity for eligible Liquity-style, M0-wrapper, and Re Protocol routes, while entries whose live evidence is paused, zero, queue-only, or reserve-incomplete remain deliberately unpromoted.

                              • `cdp-enosys` now binds the Flare Liquity V2 branch telemetry path, measuring FXRP, WFLR, stXRP, and sFLR branch collateral plus branch debt and current redemption-fee evidence from the 4-hourly live reserve snapshot
                              • `meusd-mezo` now uses a dedicated Mezo native ActivePool adapter that reads live collateral balance, protocol debt, TCR/MCR route health, and current redemption-rate telemetry directly from Mezo contracts
                              • `wm-m0` and `usdsc-startale` now use an M0 wrapper-underlying adapter for current M balance capacity; USDSC additionally verifies the Soneium SwapFacility route and approved swapper before emitting whitelisted-primary direct capacity
                              • `reusd-re-protocol` now parses Re Protocol's official metrics payload for instant redemption vault capacity instead of relying only on reviewed fallback ratios, while retaining the queued-route fallback because excess redemptions can still spill to the queue
                              Details

                              Impact Notes

                              • `cdp-enosys` now binds the Flare Liquity V2 branch telemetry path, measuring FXRP, WFLR, stXRP, and sFLR branch collateral plus branch debt and current redemption-fee evidence from the 4-hourly live reserve snapshot
                              • `meusd-mezo` now uses a dedicated Mezo native ActivePool adapter that reads live collateral balance, protocol debt, TCR/MCR route health, and current redemption-rate telemetry directly from Mezo contracts
                              • `wm-m0` and `usdsc-startale` now use an M0 wrapper-underlying adapter for current M balance capacity; USDSC additionally verifies the Soneium SwapFacility route and approved swapper before emitting whitelisted-primary direct capacity
                              • `reusd-re-protocol` now parses Re Protocol's official metrics payload for instant redemption vault capacity instead of relying only on reviewed fallback ratios, while retaining the queued-route fallback because excess redemptions can still spill to the queue
                              • Review-time adapter dry run at 2026-06-15 10:09 UTC measured $120.9M of current live-direct capacity across the upgraded routes: $84.2M wM, $25.4M Re Protocol reUSD, $4.8M USDSC, $3.5M Mezo meUSD, and $3.0M Enosys CDP
                              • Aster asUSDF, Hyperbeat hbUSDT, Inverse DOLA, and Piku USP remain unpromoted because the verified live route is unavailable, paused/zero-capacity, or queue-only; DUSD Alto and Lista lisUSD have verified PSM candidates but need a clean reserve-composition plus live-capacity side-channel before promotion
                              Commit provenance not recorded
                                v4.12Jun 15, 2026

                                Verified fee evidence and direct Sky LitePSM capacity

                                A reviewed redemption-backstop upgrade tranche replaces undisclosed-fee placeholders with sourced fixed or formula fee models where public evidence supports them, and Sky DAI/USDS capacity now reads the LitePSM USDC pocket directly on-chain.

                                • Twenty-six live-direct wrapper, queue, and collateral routes now use fixed or formula fee evidence instead of `undisclosed-reviewed`, including Frax sfrxUSD, Spark sUSDC/sUSDT, Yearn yvUSDC/yBOLD, Aave sGHO/stkGHO, Jupiter JupUSD, Maple syrupUSDC, GAIB sAID, f(x) fxSAVE, and selected Gauntlet, Steakhouse, Curve, Noon, OpenEden, Ethena, dTRINITY, and Ebisu routes
                                • Additional reviewed fee evidence was added for YieldFi yUSD, Hyperbeat hbUSDT, and Re Protocol reUSD, but those rows still depend on their existing capacity evidence and do not imply new live-direct buffer telemetry
                                • Admin-configurable or still-undisclosed fee routes such as Ember eEarn, Maple syrupUSDT, Asymmetry asUSDF, Avant/Rings/Reservoir candidates, and several buffer-locator candidates remain unpromoted until public numeric fee or direct-capacity evidence exists
                                • The `sky-makercore` adapter now validates Sky LitePSM `gem()` and `pocket()` on Ethereum and reads `USDC.balanceOf(pocket)` as same-run live-direct redemption capacity; if the on-chain probe is unavailable, DAI/USDS retain their existing reviewed fallback rather than failing open
                                Details

                                Impact Notes

                                • Twenty-six live-direct wrapper, queue, and collateral routes now use fixed or formula fee evidence instead of `undisclosed-reviewed`, including Frax sfrxUSD, Spark sUSDC/sUSDT, Yearn yvUSDC/yBOLD, Aave sGHO/stkGHO, Jupiter JupUSD, Maple syrupUSDC, GAIB sAID, f(x) fxSAVE, and selected Gauntlet, Steakhouse, Curve, Noon, OpenEden, Ethena, dTRINITY, and Ebisu routes
                                • Additional reviewed fee evidence was added for YieldFi yUSD, Hyperbeat hbUSDT, and Re Protocol reUSD, but those rows still depend on their existing capacity evidence and do not imply new live-direct buffer telemetry
                                • Admin-configurable or still-undisclosed fee routes such as Ember eEarn, Maple syrupUSDT, Asymmetry asUSDF, Avant/Rings/Reservoir candidates, and several buffer-locator candidates remain unpromoted until public numeric fee or direct-capacity evidence exists
                                • The `sky-makercore` adapter now validates Sky LitePSM `gem()` and `pocket()` on Ethereum and reads `USDC.balanceOf(pocket)` as same-run live-direct redemption capacity; if the on-chain probe is unavailable, DAI/USDS retain their existing reviewed fallback rather than failing open
                                • The scoring formula and confidence gates are unchanged; the update only improves route evidence quality where the required fee and capacity proof was verified
                                Commit provenance not recorded
                                  v4.11Jun 10, 2026

                                  Documented immediate buffers for top fiat issuers

                                  Top fiat issuers with documented routine same-day or next-day par redemption for verified customers and monthly-attested fully highly-liquid reserves move from eventual-only supply-full capacity to documented-bound immediate hot-buffer ratios under a uniform conservative haircut.

                                  • An offchain issuer route qualifies only when both criteria hold: issuer terms document routine T+0/T+1 (or intraday) par redemption for verified customers, and the latest attestation or transparency disclosure quantifies a highly liquid reserve share (cash, overnight reverse repos, US Treasury bills of three months or less, or government money market funds)
                                  • Uniform haircut rule: the documented immediate ratio is the attested highly liquid share multiplied by 0.25 (a 75% haircut), rounded down to the nearest 0.05, reflecting banking-rail, wire-cutoff, and compliance-processing throughput rather than asset liquidity; issuer-specific stricter reserve-slice bounds (USDC's 7% cash slice, USDtb's 10% USDC buffer) keep precedence over the generic rule
                                  • PYUSD, USDP, USDG, and GUSD now use `supply-ratio` 0.25 with `documented-bound` confidence on a hot-buffer basis, with dual sources reviewed 2026-06-10: redemption terms (Paxos USD stablecoin terms and conditions; Gemini Dollar redemption commitments) plus the issuer attestation hubs (Paxos PYUSD/USDP/USDG transparency, Gemini GUSD attestations)
                                  • USDT stays eventual-only because Tether's terms commit to no routine settlement timeframe and retain broad discretionary delay and suspension rights; RLUSD and FDUSD stay eventual-only because their public terms document par redemption but no routine T+0/T+1 settlement window; USD1 stays eventual-only because no public issuer redemption terms with a documented settlement window exist
                                  Details

                                  Impact Notes

                                  • An offchain issuer route qualifies only when both criteria hold: issuer terms document routine T+0/T+1 (or intraday) par redemption for verified customers, and the latest attestation or transparency disclosure quantifies a highly liquid reserve share (cash, overnight reverse repos, US Treasury bills of three months or less, or government money market funds)
                                  • Uniform haircut rule: the documented immediate ratio is the attested highly liquid share multiplied by 0.25 (a 75% haircut), rounded down to the nearest 0.05, reflecting banking-rail, wire-cutoff, and compliance-processing throughput rather than asset liquidity; issuer-specific stricter reserve-slice bounds (USDC's 7% cash slice, USDtb's 10% USDC buffer) keep precedence over the generic rule
                                  • PYUSD, USDP, USDG, and GUSD now use `supply-ratio` 0.25 with `documented-bound` confidence on a hot-buffer basis, with dual sources reviewed 2026-06-10: redemption terms (Paxos USD stablecoin terms and conditions; Gemini Dollar redemption commitments) plus the issuer attestation hubs (Paxos PYUSD/USDP/USDG transparency, Gemini GUSD attestations)
                                  • USDT stays eventual-only because Tether's terms commit to no routine settlement timeframe and retain broad discretionary delay and suspension rights; RLUSD and FDUSD stay eventual-only because their public terms document par redemption but no routine T+0/T+1 settlement window; USD1 stays eventual-only because no public issuer redemption terms with a documented settlement window exist
                                  • Offchain-issuer route-family caps (65) and severe-depeg unscoreability for non-live documented-bound routes are unchanged
                                  Commit provenance not recorded
                                    v4.07Jun 10, 2026

                                    Conservative confidence defaults and final-state depeg gating

                                    Conservative confidence defaults in the effective-exit blend, live-proxy unknown-route-status rolls up low confidence, and the severe-depeg exemption is re-evaluated against the final resolved capacity state.

                                    • A v4 effective-exit blend invoked without model confidence now applies the low (0.35) confidence factor instead of full redemption weight
                                    • Live-proxy capacity with unknown route status always rolls up low model confidence; only live-direct telemetry or source-reviewed documented bounds keep unknown route status above low
                                    • The strong live-direct severe-depeg exemption is asserted against the final resolved capacity state, so live routes downgraded to fallback or heuristic capacity are impaired during severe active depegs
                                    • Output-asset impairment rows now flag over-leveraged dependency compositions whose reserve-derived weights sum above 100% of supply while keeping the impaired share clamped at 100%
                                    Details

                                    Impact Notes

                                    • A v4 effective-exit blend invoked without model confidence now applies the low (0.35) confidence factor instead of full redemption weight
                                    • Live-proxy capacity with unknown route status always rolls up low model confidence; only live-direct telemetry or source-reviewed documented bounds keep unknown route status above low
                                    • The strong live-direct severe-depeg exemption is asserted against the final resolved capacity state, so live routes downgraded to fallback or heuristic capacity are impaired during severe active depegs
                                    • Output-asset impairment rows now flag over-leveraged dependency compositions whose reserve-derived weights sum above 100% of supply while keeping the impaired share clamped at 100%
                                    Commit provenance not recorded
                                      v4.06May 27, 2026

                                      fxSAVE uses live ERC-4626 capacity

                                      fxSAVE redemption capacity now uses fresh ERC-4626 reserve-sync telemetry from the vault's idle fxSP balance instead of a heuristic strategy-buffer ratio.

                                      • `fxsave-f-x-protocol` moves from a static 20% heuristic capacity model to `reserve-sync-metadata`
                                      • Fresh clean snapshots resolve as live-direct current capacity and can produce medium model confidence despite the reviewed variable-fee route
                                      • The route fails closed as unrated when live ERC-4626 telemetry is stale, missing, or degraded, avoiding heuristic Safety Score uplift
                                      Details

                                      Impact Notes

                                      • `fxsave-f-x-protocol` moves from a static 20% heuristic capacity model to `reserve-sync-metadata`
                                      • Fresh clean snapshots resolve as live-direct current capacity and can produce medium model confidence despite the reviewed variable-fee route
                                      • The route fails closed as unrated when live ERC-4626 telemetry is stale, missing, or degraded, avoiding heuristic Safety Score uplift
                                      Commit provenance not recorded
                                        v4.05May 25, 2026

                                        ZCHF bridge capacity follows CHFAU

                                        Frankencoin ZCHF redemption capacity now uses the active CHFAU StablecoinBridge instead of the expired VCHF bridge, restoring live bridge-buffer telemetry for permissionless ZCHF exits.

                                        • `zchf-frankencoin` now probes the CHFAU bridge at `0x3e445ff4dddf0ff8ae7458c9746ed80bd664f6c1` and CHFAU token `0xbd4dfc058eb95b8de5ceaf39966a1a70f5556f78`
                                        • The old VCHF bridge remains documented historically but no longer supplies current capacity because its inventory is zero and its horizon expired on April 15, 2026
                                        • Until Frankencoin's price API publishes CHFAU directly, bridge telemetry values CHFAU at the existing VCHF CHF-price proxy and keeps a conservative 0.85% fallback buffer
                                        Details

                                        Impact Notes

                                        • `zchf-frankencoin` now probes the CHFAU bridge at `0x3e445ff4dddf0ff8ae7458c9746ed80bd664f6c1` and CHFAU token `0xbd4dfc058eb95b8de5ceaf39966a1a70f5556f78`
                                        • The old VCHF bridge remains documented historically but no longer supplies current capacity because its inventory is zero and its horizon expired on April 15, 2026
                                        • Until Frankencoin's price API publishes CHFAU directly, bridge telemetry values CHFAU at the existing VCHF CHF-price proxy and keeps a conservative 0.85% fallback buffer
                                        Commit provenance not recorded
                                          v4.04May 17, 2026

                                          Documented-bound confidence and live wrapper capacity

                                          Documented-bound redemption capacity can retain medium model confidence when route status is unknown, ERC-4626 wrappers can use live idle-underlying balances as direct capacity, and source-reviewed RWA, fiat, and wrapper coverage expands.

                                          • Resolved routes with `routeStatus: unknown` and `capacityConfidence: documented-bound` now keep medium model confidence when the rest of the evidence gates pass
                                          • `routeStatus: unknown` remains a low-confidence signal for live-proxy, dynamic, heuristic, and unresolved capacity evidence
                                          • This lets source-reviewed bounded routes avoid being downgraded solely because explicit route-status telemetry is unavailable, without treating proxy liquidity as current direct redemption evidence
                                          • ERC-4626 single-asset wrappers can now score fresh idle underlying ERC-20 balances as direct redemption capacity; the Spark, Sky, Curve, Frax, and Cap wrapper configs use that live path instead of full-supply immediate capacity
                                          Details

                                          Impact Notes

                                          • Resolved routes with `routeStatus: unknown` and `capacityConfidence: documented-bound` now keep medium model confidence when the rest of the evidence gates pass
                                          • `routeStatus: unknown` remains a low-confidence signal for live-proxy, dynamic, heuristic, and unresolved capacity evidence
                                          • This lets source-reviewed bounded routes avoid being downgraded solely because explicit route-status telemetry is unavailable, without treating proxy liquidity as current direct redemption evidence
                                          • ERC-4626 single-asset wrappers can now score fresh idle underlying ERC-20 balances as direct redemption capacity; the Spark, Sky, Curve, Frax, and Cap wrapper configs use that live path instead of full-supply immediate capacity
                                          • Source-reviewed coverage adds active Spiko, Anemoy, Securitize, Hamilton Lane, MXNe, Ripio wFIAT, and EUR0 routes while keeping pre-launch USDPT, USDB Bridge, USDF Flipcash, and FIUSD deferred until runtime eligibility is clearer
                                          • Coverage rises to 304 configured redemption routes, with route-family totals now at 148 offchain-issuer, 60 stablecoin-redeem, 41 collateral-redeem, 36 queue-redeem, 10 psm-swap, and 9 basket-redeem
                                          Commit provenance not recorded
                                            v4.03May 14, 2026

                                            RWA NAV route source review

                                            Source-reviewed coverage adds documented NAV, wrapper, and commodity redemption routes for the latest RWA expansion batch while leaving unsupported private-credit direct deals unmodeled.

                                            • JAAA, ACRDX, STAC, HLSCOPE, SAFO, EURSAFO, GBPSAFO, UKTBL, SPKCC, EURSPKCC, mF-ONE, mGLOBAL, mHYPER, mMEV, and mAPOLLO now carry documented-bound offchain issuer redemption routes at NAV
                                            • asUSDF now carries a queued wrapper exit back into USDF, XNK now carries a commodity issuer exchange route for physical gold, and USDF's Aster redemption config reflects the reviewed fee and settlement terms
                                            • Tradable private-credit direct-deal tokens remain intentionally unmodeled until a public issuer redemption route can be verified
                                            • Coverage rises to 297 configured redemption routes, with route-family totals now at 142 offchain-issuer, 60 stablecoin-redeem, 41 collateral-redeem, 36 queue-redeem, 10 psm-swap, and 8 basket-redeem
                                            Details

                                            Impact Notes

                                            • JAAA, ACRDX, STAC, HLSCOPE, SAFO, EURSAFO, GBPSAFO, UKTBL, SPKCC, EURSPKCC, mF-ONE, mGLOBAL, mHYPER, mMEV, and mAPOLLO now carry documented-bound offchain issuer redemption routes at NAV
                                            • asUSDF now carries a queued wrapper exit back into USDF, XNK now carries a commodity issuer exchange route for physical gold, and USDF's Aster redemption config reflects the reviewed fee and settlement terms
                                            • Tradable private-credit direct-deal tokens remain intentionally unmodeled until a public issuer redemption route can be verified
                                            • Coverage rises to 297 configured redemption routes, with route-family totals now at 142 offchain-issuer, 60 stablecoin-redeem, 41 collateral-redeem, 36 queue-redeem, 10 psm-swap, and 8 basket-redeem
                                            Commit provenance not recorded
                                              v4.02May 13, 2026

                                              Follow-up redemption coverage expansion

                                              Source-reviewed follow-up coverage adds documented Mento local-FX CDP routes, Enosys CDP redemptions, Blast USDB bridge exit, Metal Dollar basket redemption, MoveUSD issuer redemption, and Solomon USDv whitelisted reserve-buffer redemption.

                                              • AUDm, BRLm, CADm, COPm, GHSm, KESm, PHPm, and ZARm now carry documented-bound Mento CDP collateral-redeem routes with explicit notes that current per-symbol CDP telemetry is not modeled yet
                                              • CDP Enosys now carries a Liquity-style collateral-redeem route, while USDB and USDv add stablecoin-redeem coverage and XMD adds whitelisted basket-redeem coverage
                                              • MoveUSD now carries a source-reviewed offchain issuer redemption route through CFX designated channels for verified customers
                                              • Coverage rises to 280 configured redemption routes, with route-family totals now at 126 offchain-issuer, 60 stablecoin-redeem, 41 collateral-redeem, 35 queue-redeem, 10 psm-swap, and 8 basket-redeem
                                              Details

                                              Impact Notes

                                              • AUDm, BRLm, CADm, COPm, GHSm, KESm, PHPm, and ZARm now carry documented-bound Mento CDP collateral-redeem routes with explicit notes that current per-symbol CDP telemetry is not modeled yet
                                              • CDP Enosys now carries a Liquity-style collateral-redeem route, while USDB and USDv add stablecoin-redeem coverage and XMD adds whitelisted basket-redeem coverage
                                              • MoveUSD now carries a source-reviewed offchain issuer redemption route through CFX designated channels for verified customers
                                              • Coverage rises to 280 configured redemption routes, with route-family totals now at 126 offchain-issuer, 60 stablecoin-redeem, 41 collateral-redeem, 35 queue-redeem, 10 psm-swap, and 8 basket-redeem
                                              Commit provenance not recorded
                                                v4.01May 12, 2026

                                                Yearn yBOLD wrapper redemption coverage

                                                yBOLD now has a reviewed Yearn ERC-4626 wrapper redemption route into BOLD, keeping the wrapper exit separate from BOLD's downstream Liquity collateral-redemption route.

                                                • `ybold-yearn` now carries a source-reviewed stablecoin-redeem route using documented-bound supply-full capacity semantics
                                                • Coverage rises to 267 configured redemption routes, with route-family totals now at 125 offchain-issuer, 58 stablecoin-redeem, 32 collateral-redeem, 35 queue-redeem, 10 psm-swap, and 7 basket-redeem
                                                • The route notes clarify that yBOLD exits into BOLD at the Yearn vault exchange rate, while final par exit quality still inherits BOLD's Liquity collateral-redemption path
                                                Details

                                                Impact Notes

                                                • `ybold-yearn` now carries a source-reviewed stablecoin-redeem route using documented-bound supply-full capacity semantics
                                                • Coverage rises to 267 configured redemption routes, with route-family totals now at 125 offchain-issuer, 58 stablecoin-redeem, 32 collateral-redeem, 35 queue-redeem, 10 psm-swap, and 7 basket-redeem
                                                • The route notes clarify that yBOLD exits into BOLD at the Yearn vault exchange rate, while final par exit quality still inherits BOLD's Liquity collateral-redemption path
                                                Commit provenance not recorded
                                                  v4.0May 12, 2026

                                                  Current-capacity scoring and evidence-aware route quality

                                                  Redemption Backstop v4 separates current executable capacity from eventual redeemability, adds fixed-USD capacity and size-aware costs, and makes route status, confidence, and effective-exit blending more explicit and conservative.

                                                  • Standalone route scoring now uses current executable capacity while `eventualRedeemabilityScore` preserves long-tail legal or protocol route quality as separate context
                                                  • Capacity profiles expose immediate, daily-limited, queued, eventual, and scoring capacity fields; fixed public USD buffers can be modeled without encoding arbitrary supply ratios
                                                  • Effective-exit blending now scales redemption uplift by modeled exit size, current capacity, confidence, and DEX/redemption correlation, with diversification bonus reserved for plausibly independent issuer rails
                                                  • Route-status evidence remains a four-hour snapshot from live-reserve metadata, reviewed static policy, and market-implied depeg overlays; no new outbound route-status fetches are added to the redemption sync
                                                  Details

                                                  Impact Notes

                                                  • Standalone route scoring now uses current executable capacity while `eventualRedeemabilityScore` preserves long-tail legal or protocol route quality as separate context
                                                  • Capacity profiles expose immediate, daily-limited, queued, eventual, and scoring capacity fields; fixed public USD buffers can be modeled without encoding arbitrary supply ratios
                                                  • Effective-exit blending now scales redemption uplift by modeled exit size, current capacity, confidence, and DEX/redemption correlation, with diversification bonus reserved for plausibly independent issuer rails
                                                  • Route-status evidence remains a four-hour snapshot from live-reserve metadata, reviewed static policy, and market-implied depeg overlays; no new outbound route-status fetches are added to the redemption sync
                                                  • Registry validation now runs through a shared manifest/validator, emits deterministic audit reports, and is paired with v4 active-gap and heuristic-route coverage audit tooling
                                                  Commit provenance not recorded
                                                    v3.997May 12, 2026

                                                    Redemption coverage expansion and documented-bound upgrades

                                                    Reviewed redemption coverage expands across issuer rails, NAV wrappers, queue exits, PSM routes, collateral redemptions, and protocol conversions, while older reviewed routes with explicit terms are promoted from heuristic to documented-bound capacity.

                                                    • BENJI, WTGXX, VBILL, JTRSY, USTBL, EUTBL, bIB01, bC3M, CADD, MYRC, KRWQ, and SOFID now carry source-reviewed offchain issuer or platform redemption routes
                                                    • stUSDS, stcUSD, sBOLD, msY, yUSD, sAID, and ZYS now carry source-reviewed wrapper, vault, or protocol-conversion routes
                                                    • ACRED, bUSD0, IST, uUSD, ZSD, hyUSD, and fUSD now carry source-reviewed queued, PSM, collateral, or protocol-conversion routes
                                                    • ZARP, CETES, CGO, DGLD, DUSD Alto, USSD, and USDP move from low-confidence heuristic capacity into documented-bound coverage based on reviewed public route terms
                                                    Details

                                                    Impact Notes

                                                    • BENJI, WTGXX, VBILL, JTRSY, USTBL, EUTBL, bIB01, bC3M, CADD, MYRC, KRWQ, and SOFID now carry source-reviewed offchain issuer or platform redemption routes
                                                    • stUSDS, stcUSD, sBOLD, msY, yUSD, sAID, and ZYS now carry source-reviewed wrapper, vault, or protocol-conversion routes
                                                    • ACRED, bUSD0, IST, uUSD, ZSD, hyUSD, and fUSD now carry source-reviewed queued, PSM, collateral, or protocol-conversion routes
                                                    • ZARP, CETES, CGO, DGLD, DUSD Alto, USSD, and USDP move from low-confidence heuristic capacity into documented-bound coverage based on reviewed public route terms
                                                    • Coverage rises to 264 configured redemption routes, with route-family totals now at 124 offchain-issuer, 57 stablecoin-redeem, 32 collateral-redeem, 34 queue-redeem, 10 psm-swap, and 7 basket-redeem
                                                    Commit provenance not recorded
                                                      v3.996May 12, 2026

                                                      Stablecoin audit route coverage expansion

                                                      Comprehensive review of recently added stablecoins adds source-reviewed redemption routes for audited wrappers, Nest vaults, DUSD, mRe7YIELD, DJED, and SMARDEX USDN while refreshing OnRe and Hyperbeat route terms.

                                                      • USDCx, Spark Savings USDT/USDC, Gauntlet USDC Core/Prime, Yearn yvUSDC, Aave sGHO, and the MEV Capital Falcon senior tranche now carry modeled protocol redemption or NAV-exit routes
                                                      • DUSD and mRe7YIELD now carry offchain/platform redemption routes; DJED and SMARDEX USDN now carry collateral-redemption routes; nTBILL, nBASIS, nOPAL, and nWISDOM now carry queued Nest redemption routes
                                                      • OnRe redemption terms now reflect weekly capacity up to 2.5% NAV and a 25 bps fee, while hbUSDT reflects instant 0.5% or classic no-fee redemption timing
                                                      • Coverage rises to 238 configured redemption routes, with route-family totals now at 112 offchain-issuer, 50 stablecoin-redeem, 28 collateral-redeem, 32 queue-redeem, 9 psm-swap, and 7 basket-redeem
                                                      Details

                                                      Impact Notes

                                                      • USDCx, Spark Savings USDT/USDC, Gauntlet USDC Core/Prime, Yearn yvUSDC, Aave sGHO, and the MEV Capital Falcon senior tranche now carry modeled protocol redemption or NAV-exit routes
                                                      • DUSD and mRe7YIELD now carry offchain/platform redemption routes; DJED and SMARDEX USDN now carry collateral-redemption routes; nTBILL, nBASIS, nOPAL, and nWISDOM now carry queued Nest redemption routes
                                                      • OnRe redemption terms now reflect weekly capacity up to 2.5% NAV and a 25 bps fee, while hbUSDT reflects instant 0.5% or classic no-fee redemption timing
                                                      • Coverage rises to 238 configured redemption routes, with route-family totals now at 112 offchain-issuer, 50 stablecoin-redeem, 28 collateral-redeem, 32 queue-redeem, 9 psm-swap, and 7 basket-redeem
                                                      Commit provenance not recorded
                                                        v3.995May 11, 2026

                                                        Non-USD and commodity coverage expansion

                                                        Seven newly tracked non-USD and commodity stablecoins now publish source-reviewed redemption routes, including Mento CDP collateral exits for GBPm, JPYm, and CHFm.

                                                        • GLDY, VNXAU, XAGm, and EUROe now carry documented-bound offchain issuer redemption routes with reviewed source links and access, fee, settlement, and capacity caveats
                                                        • GBPm, JPYm, and CHFm now carry collateral-redeem routes into USDm-backed Mento CDP collateral, aligned with the new Mento CDP reserve-sync mode
                                                        • Coverage rises to 202 configured redemption routes, with route-family totals now at 106 offchain-issuer and 26 collateral-redeem
                                                        Details

                                                        Impact Notes

                                                        • GLDY, VNXAU, XAGm, and EUROe now carry documented-bound offchain issuer redemption routes with reviewed source links and access, fee, settlement, and capacity caveats
                                                        • GBPm, JPYm, and CHFm now carry collateral-redeem routes into USDm-backed Mento CDP collateral, aligned with the new Mento CDP reserve-sync mode
                                                        • Coverage rises to 202 configured redemption routes, with route-family totals now at 106 offchain-issuer and 26 collateral-redeem
                                                        Commit provenance not recorded
                                                          v3.994May 10, 2026

                                                          Conservative queued coverage for stkGHO and USDRIF

                                                          Aave Umbrella stkGHO and RIF On Chain USDRIF now publish source-reviewed queued redemption routes with eventual-only capacity semantics.

                                                          • stkGHO is modeled as a queued wrapper exit into GHO through Aave Umbrella's cooldown and withdrawal-window process, with slashing risk retained in route notes
                                                          • USDRIF is modeled as a queued RIF-collateral redemption route because broad holder redemption is settlement-cycle based, while outside-settlement redemption is limited to free USDRIF
                                                          • Both routes use documented-bound eventual-only capacity, so they remain visible as reviewed coverage without creating immediate live-capacity evidence for Safety Score liquidity uplift
                                                          Details

                                                          Impact Notes

                                                          • stkGHO is modeled as a queued wrapper exit into GHO through Aave Umbrella's cooldown and withdrawal-window process, with slashing risk retained in route notes
                                                          • USDRIF is modeled as a queued RIF-collateral redemption route because broad holder redemption is settlement-cycle based, while outside-settlement redemption is limited to free USDRIF
                                                          • Both routes use documented-bound eventual-only capacity, so they remain visible as reviewed coverage without creating immediate live-capacity evidence for Safety Score liquidity uplift
                                                          Commit provenance not recorded
                                                            v3.993May 10, 2026

                                                            Live redemption telemetry gating and constraints

                                                            Live redemption capacity now carries adapter-declared capacity/freshness context through the API, fails closed on unverified nested freshness unless explicitly allowlisted, and applies live daily limits as scoring capacity constraints.

                                                            • Reserve-sync redemption routes now persist and expose live capacity kind, freshness kind, source timestamp/URLs, settlement delay, queue depth, daily limit, minimum redeem size, and live holder eligibility when adapters emit them
                                                            • Nested live redemption freshness marked `unverified` is no longer scoreable by default; only route-specific allowlisted lower-bound cases can continue to score while retaining the unverified context
                                                            • Adapter-emitted daily redemption limits cap scoring capacity while raw immediate capacity remains visible for context
                                                            Details

                                                            Impact Notes

                                                            • Reserve-sync redemption routes now persist and expose live capacity kind, freshness kind, source timestamp/URLs, settlement delay, queue depth, daily limit, minimum redeem size, and live holder eligibility when adapters emit them
                                                            • Nested live redemption freshness marked `unverified` is no longer scoreable by default; only route-specific allowlisted lower-bound cases can continue to score while retaining the unverified context
                                                            • Adapter-emitted daily redemption limits cap scoring capacity while raw immediate capacity remains visible for context
                                                            Commit provenance not recorded
                                                              v3.992Apr 22, 2026

                                                              Tracked wrapper routes inherit severe parent depegs

                                                              Configured tracked wrappers now inherit a severe active-depeg impairment from their parent stablecoin when their peg is explicitly authored through that same parent link.

                                                              • Wrapper routes whose metadata keeps `pegReferenceId === variantOf` now reuse the parent's severe active-depeg exercisability gate instead of remaining scoreable when only the parent has the open depeg row
                                                              • This inherited impairment is scoped only to wrappers that already have a redemption-backstop config in the registry; the rollout does not add new route coverage by itself
                                                              • Safety Score active-depeg caps and Redemption Backstop route impairment now stay aligned for tracked wrappers on the same quarter-hourly/4-hourly runtime clocks
                                                              Details

                                                              Impact Notes

                                                              • Wrapper routes whose metadata keeps `pegReferenceId === variantOf` now reuse the parent's severe active-depeg exercisability gate instead of remaining scoreable when only the parent has the open depeg row
                                                              • This inherited impairment is scoped only to wrappers that already have a redemption-backstop config in the registry; the rollout does not add new route coverage by itself
                                                              • Safety Score active-depeg caps and Redemption Backstop route impairment now stay aligned for tracked wrappers on the same quarter-hourly/4-hourly runtime clocks
                                                              Commit provenance not recorded
                                                                v3.991Apr 21, 2026

                                                                AUDF and DOC route coverage

                                                                Forte AUD and Dollar on Chain now publish reviewed redemption routes, extending modeled coverage to one additional offchain issuer rail and one additional BTC-collateral redemption rail.

                                                                • AUDF now carries a documented-bound offchain-issuer redemption route sourced from Forte's PDS, legal terms, and reserve-report page
                                                                • DOC now carries a permissionless collateral-redeem route into RBTC sourced from Money On Chain protocol docs
                                                                • Coverage rises to 179 configured redemption routes, with route-family totals now at 93 offchain-issuer and 23 collateral-redeem
                                                                Details

                                                                Impact Notes

                                                                • AUDF now carries a documented-bound offchain-issuer redemption route sourced from Forte's PDS, legal terms, and reserve-report page
                                                                • DOC now carries a permissionless collateral-redeem route into RBTC sourced from Money On Chain protocol docs
                                                                • Coverage rises to 179 configured redemption routes, with route-family totals now at 93 offchain-issuer and 23 collateral-redeem
                                                                Commit provenance not recorded
                                                                  v3.99Apr 20, 2026

                                                                  Flat/RWA issuer coverage expansion

                                                                  Six newly tracked flat/RWA issuer assets join modeled redemption coverage, including whitelisted collateral redemption for Alloy aUSDT and five documented issuer routes.

                                                                  • USDon, USDsui, BRLV, USDGLO, and AUDM now publish documented-bound offchain-issuer redemption routes with reviewed source links and access/settlement caveats
                                                                  • Alloy aUSDT now publishes a whitelisted collateral-redemption route into XAUT, while live reserve sync reads its Ethereum vault XAUT balance and aUSDT supply for reserve visibility
                                                                  • Jiritsu JUSD remains excluded because the priced CoinGecko/CMC JUSD asset resolves to a different token and the official Jiritsu token lacks a usable price/depeg source
                                                                  Details

                                                                  Impact Notes

                                                                  • USDon, USDsui, BRLV, USDGLO, and AUDM now publish documented-bound offchain-issuer redemption routes with reviewed source links and access/settlement caveats
                                                                  • Alloy aUSDT now publishes a whitelisted collateral-redemption route into XAUT, while live reserve sync reads its Ethereum vault XAUT balance and aUSDT supply for reserve visibility
                                                                  • Jiritsu JUSD remains excluded because the priced CoinGecko/CMC JUSD asset resolves to a different token and the official Jiritsu token lacks a usable price/depeg source
                                                                  Commit provenance not recorded
                                                                    v3.98Apr 16, 2026

                                                                    Capacity-over-supply clamp, coverage expansion, and runtime hardening

                                                                    Live reserve capacity is now clamped to current supply for scoring, 17 new stablecoins join modeled redemption coverage, and several lower-confidence supply-ratio routes are explicitly tagged as heuristic rather than silently relying on uncited ratios.

                                                                    • Live redemption capacity greater than current supply is now clamped to supply for scoring and surfaces an explicit note; previously only the ratio was clamped while the raw USD amount flowed through unchanged
                                                                    • 17 new stablecoins added to redemption coverage: dEURO, CJPY, wM, ftUSD, USDz, USDSC, Silk, USDAT, USDnr, BUCK, USDH, BRLA, ctUSD, XO, USDK, USDM, and USDKG, spanning collateral-redeem, stablecoin-redeem, basket-redeem, queue-redeem, and offchain-issuer families
                                                                    • Lower-confidence supply-ratio routes (dusd-dtrinity, yousd-yield-optimizer, uty-xsy) now carry explicit `confidence: heuristic` plus reviewed docs rather than silently defaulting to heuristic with no evidence trail
                                                                    • Fee-score breakpoints extracted to named constants and route notes deduplicated end-to-end
                                                                    Details

                                                                    Impact Notes

                                                                    • Live redemption capacity greater than current supply is now clamped to supply for scoring and surfaces an explicit note; previously only the ratio was clamped while the raw USD amount flowed through unchanged
                                                                    • 17 new stablecoins added to redemption coverage: dEURO, CJPY, wM, ftUSD, USDz, USDSC, Silk, USDAT, USDnr, BUCK, USDH, BRLA, ctUSD, XO, USDK, USDM, and USDKG, spanning collateral-redeem, stablecoin-redeem, basket-redeem, queue-redeem, and offchain-issuer families
                                                                    • Lower-confidence supply-ratio routes (dusd-dtrinity, yousd-yield-optimizer, uty-xsy) now carry explicit `confidence: heuristic` plus reviewed docs rather than silently defaulting to heuristic with no evidence trail
                                                                    • Fee-score breakpoints extracted to named constants and route notes deduplicated end-to-end
                                                                    Commit provenance not recorded
                                                                      v3.97Apr 15, 2026

                                                                      Redemption backstop code deduplication and boundary test coverage

                                                                      The "strong live-direct route" predicate is now defined once and reused by both the report-card liquidity consumer and the backstop builder, with inline rationale on route family caps and new boundary test coverage.

                                                                      • `isStrongLiveDirectRoute` is now a single shared predicate in `shared/lib/redemption-backstop-scoring.ts` consumed by both `scoreLiquidity` and `buildRedemptionBackstopEntry`, removing the prior drift-prone duplicate definitions
                                                                      • Severe-depeg exclusion behavior is now locked in at the exact 2499 / 2500 bps boundary, live-proxy routes are explicitly confirmed not to survive severe depegs even with permissionless atomic execution, and all capacity-score and route-family cap breakpoints are covered by assertions
                                                                      • No coin-facing scoring semantics changed; this release is test coverage, documentation, and code deduplication only
                                                                      Details

                                                                      Impact Notes

                                                                      • `isStrongLiveDirectRoute` is now a single shared predicate in `shared/lib/redemption-backstop-scoring.ts` consumed by both `scoreLiquidity` and `buildRedemptionBackstopEntry`, removing the prior drift-prone duplicate definitions
                                                                      • Severe-depeg exclusion behavior is now locked in at the exact 2499 / 2500 bps boundary, live-proxy routes are explicitly confirmed not to survive severe depegs even with permissionless atomic execution, and all capacity-score and route-family cap breakpoints are covered by assertions
                                                                      • No coin-facing scoring semantics changed; this release is test coverage, documentation, and code deduplication only
                                                                      Commit provenance not recorded
                                                                        v3.96Apr 15, 2026

                                                                        Redemption telemetry validation and route-status fail-closed hardening

                                                                        Live reserve redemption telemetry now fails closed more consistently, and shared config/documentation provenance no longer leaks across expanded route groups.

                                                                        • Paused, degraded, or cohort-limited live route-status telemetry now marks the redemption row impaired instead of publishing a current standalone score
                                                                        • Nested and legacy redemption telemetry fields are validated independently before persistence, preventing malformed nested values from being masked by valid legacy fields
                                                                        • Adapters that are not declared as redemption-capacity sources no longer emit unsupported capacity metadata, and expanded shared route configs now receive per-asset reviewed docs
                                                                        Details

                                                                        Impact Notes

                                                                        • Paused, degraded, or cohort-limited live route-status telemetry now marks the redemption row impaired instead of publishing a current standalone score
                                                                        • Nested and legacy redemption telemetry fields are validated independently before persistence, preventing malformed nested values from being masked by valid legacy fields
                                                                        • Adapters that are not declared as redemption-capacity sources no longer emit unsupported capacity metadata, and expanded shared route configs now receive per-asset reviewed docs
                                                                        Commit provenance not recorded
                                                                          v3.95Apr 15, 2026

                                                                          USTB live Superstate liquidity capacity

                                                                          USTB now combines its existing on-chain NAV reserve proof with Superstate's current public liquidity endpoint for bounded redemption-capacity telemetry.

                                                                          • The `ustb-superstate` route now uses reserve-sync metadata instead of the static full-supply eventual model
                                                                          • The `superstate-liquidity` adapter preserves USTB NAV reserve slices while adding current Circle USD and USDC RedemptionIdle liquidity as capacity
                                                                          • If the Superstate liquidity payload is missing or malformed, USTB remains visible but unrated for redemption capacity rather than using NAV/AUM as immediate liquidity
                                                                          Details

                                                                          Impact Notes

                                                                          • The `ustb-superstate` route now uses reserve-sync metadata instead of the static full-supply eventual model
                                                                          • The `superstate-liquidity` adapter preserves USTB NAV reserve slices while adding current Circle USD and USDC RedemptionIdle liquidity as capacity
                                                                          • If the Superstate liquidity payload is missing or malformed, USTB remains visible but unrated for redemption capacity rather than using NAV/AUM as immediate liquidity
                                                                          Commit provenance not recorded
                                                                            v3.94Apr 15, 2026

                                                                            frxUSD live reserve capacity and route-status guardrails

                                                                            frxUSD now resolves redemption capacity from fresh Frax balance-sheet telemetry, and live redemption route status can flow from reserve adapters into redemption-backstop scoring.

                                                                            • The `frxusd-frax` route now uses reserve-sync metadata instead of the static full-supply eventual model
                                                                            • Frax balance-sheet redemption capacity emits a current stablecoin capacity amount without reusing reserve-composition ratios as supply-relative capacity
                                                                            • Live reserve redemption telemetry can carry route status and provenance so paused or degraded live routes do not silently score as open
                                                                            Details

                                                                            Impact Notes

                                                                            • The `frxusd-frax` route now uses reserve-sync metadata instead of the static full-supply eventual model
                                                                            • Frax balance-sheet redemption capacity emits a current stablecoin capacity amount without reusing reserve-composition ratios as supply-relative capacity
                                                                            • Live reserve redemption telemetry can carry route status and provenance so paused or degraded live routes do not silently score as open
                                                                            Commit provenance not recorded
                                                                              v3.93Apr 15, 2026

                                                                              Long-tail live redemption adapters

                                                                              Additional long-tail redemption routes now use current live reserve telemetry instead of static eventual-capacity assumptions where public APIs or on-chain reads expose bounded capacity.

                                                                              • Felix feUSD, Nerite USND, and Quill USDQ now use same-run Liquity v2 ActivePool debt as direct bounded redemption capacity
                                                                              • fxUSD now consumes f(x)'s protocol debt balances as live proxy capacity, while USDaf uses Asymmetry's timestamped protocol supply as direct current capacity
                                                                              • JupUSD now consumes its public transparency API for current USDC/USDtb holdings and route-status telemetry, retaining the reviewed 10% buffer only as fallback
                                                                              Details

                                                                              Impact Notes

                                                                              • Felix feUSD, Nerite USND, and Quill USDQ now use same-run Liquity v2 ActivePool debt as direct bounded redemption capacity
                                                                              • fxUSD now consumes f(x)'s protocol debt balances as live proxy capacity, while USDaf uses Asymmetry's timestamped protocol supply as direct current capacity
                                                                              • JupUSD now consumes its public transparency API for current USDC/USDtb holdings and route-status telemetry, retaining the reviewed 10% buffer only as fallback
                                                                              Commit provenance not recorded
                                                                                v3.92Apr 15, 2026

                                                                                BOLD live Liquity v2 branch debt capacity

                                                                                BOLD now uses the Liquity v2 branch adapter's same-run on-chain ActivePool debt as direct redemption-capacity telemetry.

                                                                                • The `bold-liquity` live reserve config now uses `liquity-v2-branches`, which reads branch collateral balances plus ActivePool branch debt
                                                                                • `bold-liquity` now resolves redemption capacity from fresh reserve-sync metadata instead of the static full-supply model
                                                                                • When the Liquity v2 branch snapshot is unavailable or stale, BOLD remains visible but unrated for redemption capacity rather than falling back to an immediate full-supply estimate
                                                                                Details

                                                                                Impact Notes

                                                                                • The `bold-liquity` live reserve config now uses `liquity-v2-branches`, which reads branch collateral balances plus ActivePool branch debt
                                                                                • `bold-liquity` now resolves redemption capacity from fresh reserve-sync metadata instead of the static full-supply model
                                                                                • When the Liquity v2 branch snapshot is unavailable or stale, BOLD remains visible but unrated for redemption capacity rather than falling back to an immediate full-supply estimate
                                                                                Commit provenance not recorded
                                                                                  v3.91Apr 15, 2026

                                                                                  LUSD live direct capacity telemetry

                                                                                  LUSD now uses the Liquity v1 live reserve adapter's same-run on-chain system debt as direct redemption-capacity telemetry.

                                                                                  • The `liquity-v1` adapter now publishes nested `metadata.redemption` capacity from `TroveManager.getEntireSystemDebt()` alongside the existing live redemption fee
                                                                                  • `lusd-liquity` now resolves redemption capacity from fresh reserve-sync metadata instead of the static full-supply model
                                                                                  • When the Liquity on-chain snapshot is unavailable or stale, LUSD remains visible but unrated for redemption capacity rather than falling back to an immediate full-supply estimate
                                                                                  Details

                                                                                  Impact Notes

                                                                                  • The `liquity-v1` adapter now publishes nested `metadata.redemption` capacity from `TroveManager.getEntireSystemDebt()` alongside the existing live redemption fee
                                                                                  • `lusd-liquity` now resolves redemption capacity from fresh reserve-sync metadata instead of the static full-supply model
                                                                                  • When the Liquity on-chain snapshot is unavailable or stale, LUSD remains visible but unrated for redemption capacity rather than falling back to an immediate full-supply estimate
                                                                                  Commit provenance not recorded
                                                                                    v3.9Apr 15, 2026

                                                                                    Normalized redemption telemetry and live capacity adapters

                                                                                    Live reserve adapters can now publish normalized redemption telemetry, and Cap cUSD now uses direct vault-capacity telemetry instead of full-supply eventual assumptions.

                                                                                    • Reserve-sync redemption routes prefer nested `metadata.redemption` capacity, fee, freshness, and route-status fields while keeping legacy flat metadata readable
                                                                                    • Live reserve validation rejects malformed or unsupported redemption telemetry before it can reach redemption-backstop scoring
                                                                                    • Cap cUSD now scores against current unpaused available vault balances through the new cap-vault adapter rather than treating full eventual basket redeemability as immediate capacity
                                                                                    Details

                                                                                    Impact Notes

                                                                                    • Reserve-sync redemption routes prefer nested `metadata.redemption` capacity, fee, freshness, and route-status fields while keeping legacy flat metadata readable
                                                                                    • Live reserve validation rejects malformed or unsupported redemption telemetry before it can reach redemption-backstop scoring
                                                                                    • Cap cUSD now scores against current unpaused available vault balances through the new cap-vault adapter rather than treating full eventual basket redeemability as immediate capacity
                                                                                    Commit provenance not recorded
                                                                                      v3.8Apr 14, 2026

                                                                                      Active-depeg exercisability gate

                                                                                      Severe active depegs now impair static or non-live-direct redemption routes unless current live-open redemption evidence is available.

                                                                                      • Open depeg rows at or above 2500 bps now mark static, documented-bound, live-proxy, issuer/API, queue, and estimated redemption routes as impaired instead of publishing a normal current score
                                                                                      • Impaired rows keep route metadata visible but set score and effectiveExitScore to null, lower model confidence, and carry a market-implied route-status reason
                                                                                      • Live-direct, dynamic, permissionless, atomic or immediate redemption routes can remain scoreable during severe active depegs because they provide current direct exercisability evidence
                                                                                      Details

                                                                                      Impact Notes

                                                                                      • Open depeg rows at or above 2500 bps now mark static, documented-bound, live-proxy, issuer/API, queue, and estimated redemption routes as impaired instead of publishing a normal current score
                                                                                      • Impaired rows keep route metadata visible but set score and effectiveExitScore to null, lower model confidence, and carry a market-implied route-status reason
                                                                                      • Live-direct, dynamic, permissionless, atomic or immediate redemption routes can remain scoreable during severe active depegs because they provide current direct exercisability evidence
                                                                                      Commit provenance not recorded
                                                                                        v3.7Apr 7, 2026

                                                                                        Best-path effective exit model replaces weighted blend

                                                                                        The effective exit score now uses max(dex, redemption) + diversification bonus instead of a weighted blend that penalized coins with one strong exit path and one weak one.

                                                                                        • Effective exit formula changed from `max(dex, dex × 0.55 + redemption × 0.45)` to `max(dex, redemption) + min(dex, redemption) × 0.10` — the best exit path dominates and a second path earns a modest diversification bonus
                                                                                        • Redemption-only coins now use the raw redemption backstop score with no cap or discount, removing the previous `min(70, score × 0.75)` penalty; route family caps (offchain-issuer ≤ 65, queue-redeem ≤ 70) remain as guardrails
                                                                                        • Coins with strong permissionless redemption (DAI, GHO, frxUSD, LUSD, BOLD) see the largest uplift; DEX-only coins are unaffected; CeFi offchain-issuer coins see modest improvement bounded by route family caps
                                                                                        Details

                                                                                        Impact Notes

                                                                                        • Effective exit formula changed from `max(dex, dex × 0.55 + redemption × 0.45)` to `max(dex, redemption) + min(dex, redemption) × 0.10` — the best exit path dominates and a second path earns a modest diversification bonus
                                                                                        • Redemption-only coins now use the raw redemption backstop score with no cap or discount, removing the previous `min(70, score × 0.75)` penalty; route family caps (offchain-issuer ≤ 65, queue-redeem ≤ 70) remain as guardrails
                                                                                        • Coins with strong permissionless redemption (DAI, GHO, frxUSD, LUSD, BOLD) see the largest uplift; DEX-only coins are unaffected; CeFi offchain-issuer coins see modest improvement bounded by route family caps
                                                                                        Commit provenance not recorded
                                                                                          v3.6Apr 6, 2026

                                                                                          ZCHF VCHF bridge route added with live bridge-capacity telemetry

                                                                                          Frankencoin ZCHF now models its permissionless onchain StablecoinBridge exit into VCHF instead of remaining uncovered in redemption backstops.

                                                                                          • `zchf-frankencoin` now uses a reviewed `stablecoin-redeem` route for the public ZCHF -> VCHF burn-and-withdraw bridge contract
                                                                                          • The existing Frankencoin collateral-positions reserve adapter now emits the bridge's live VCHF inventory as immediate redeemable capacity telemetry, so fresh hourly reserve sync can drive current bridge-buffer sizing directly
                                                                                          • When live bridge telemetry is temporarily unavailable, the route falls back to a conservative reviewed 1.4% bridge-buffer ratio instead of disappearing entirely
                                                                                          Details

                                                                                          Impact Notes

                                                                                          • `zchf-frankencoin` now uses a reviewed `stablecoin-redeem` route for the public ZCHF -> VCHF burn-and-withdraw bridge contract
                                                                                          • The existing Frankencoin collateral-positions reserve adapter now emits the bridge's live VCHF inventory as immediate redeemable capacity telemetry, so fresh hourly reserve sync can drive current bridge-buffer sizing directly
                                                                                          • When live bridge telemetry is temporarily unavailable, the route falls back to a conservative reviewed 1.4% bridge-buffer ratio instead of disappearing entirely
                                                                                          Commit provenance not recorded
                                                                                            v3.5Apr 5, 2026

                                                                                            Telemetry-aware freshness gate for reserve-sync capacity

                                                                                            Adapters that declare capacity telemetry (direct or proxy) or physically emit capacity metadata no longer require scoring-grade freshness evidence to use live capacity data for scoring. The temporal quality is already validated by the isFresh gate.

                                                                                            • iUSD-infiniFi now resolves live-proxy capacity confidence from the infiniFi protocol API instead of falling back to the heuristic 15% ratio, restoring medium model confidence and re-enabling backstop contribution to effective exit scoring
                                                                                            • Any reserve-sync-metadata route whose adapter provides capacity telemetry but uses unverified freshness mode now scores against live capacity data instead of being silently downgraded to a heuristic fallback
                                                                                            • Adapters without declared capacity telemetry or physical capacity metadata still require scoring-grade freshness evidence, preserving the original gate for inferred-capacity routes
                                                                                            Details

                                                                                            Impact Notes

                                                                                            • iUSD-infiniFi now resolves live-proxy capacity confidence from the infiniFi protocol API instead of falling back to the heuristic 15% ratio, restoring medium model confidence and re-enabling backstop contribution to effective exit scoring
                                                                                            • Any reserve-sync-metadata route whose adapter provides capacity telemetry but uses unverified freshness mode now scores against live capacity data instead of being silently downgraded to a heuristic fallback
                                                                                            • Adapters without declared capacity telemetry or physical capacity metadata still require scoring-grade freshness evidence, preserving the original gate for inferred-capacity routes
                                                                                            Commit provenance not recorded
                                                                                              v3.4Apr 4, 2026

                                                                                              USD.AI base-token and sUSDai route split

                                                                                              USD.AI no longer overloads the base token and yield token onto one redemption model: base USDai keeps the direct PYUSD-side rail, while sUSDai now has its own documented queued exit.

                                                                                              • Base `usdai-usd-ai` remains a permissionless atomic stablecoin-redeem route scoped to the liquid base token rather than to the yield product
                                                                                              • New `susdai-usd-ai` now models the documented 30-day queued unstake flow back into USDai instead of inheriting base-token semantics
                                                                                              • Because public USD.AI materials do not publish a trustworthy numeric instant-liquidity bound for sUSDai, the new route is scored as documented-bound eventual capacity rather than as a measured immediate buffer
                                                                                              Details

                                                                                              Impact Notes

                                                                                              • Base `usdai-usd-ai` remains a permissionless atomic stablecoin-redeem route scoped to the liquid base token rather than to the yield product
                                                                                              • New `susdai-usd-ai` now models the documented 30-day queued unstake flow back into USDai instead of inheriting base-token semantics
                                                                                              • Because public USD.AI materials do not publish a trustworthy numeric instant-liquidity bound for sUSDai, the new route is scored as documented-bound eventual capacity rather than as a measured immediate buffer
                                                                                              Commit provenance not recorded
                                                                                                v3.3Apr 4, 2026

                                                                                                Selective lower-bound recovery for GHO and Reservoir fallback hardening

                                                                                                Two reserve-backed redemption routes now recover from the v3.1 trust-boundary tightening without weakening reserve-sync scoring globally.

                                                                                                • GHO can again use tracked live GSM backing as an immediate redemption lower bound when reserve sync is degraded only because residual issuance outside the configured GSM set remains aggregated
                                                                                                • wsrUSD now falls back to Reservoir's reviewed 25 bps minimum USDC PSM balance when the live balance-sheet API lacks scoring-grade freshness evidence, instead of remaining unrated
                                                                                                • Reserve-sync fallback ratios can now preserve reviewed `documented-bound` confidence and basis metadata instead of being forced into the generic heuristic bucket
                                                                                                Details

                                                                                                Impact Notes

                                                                                                • GHO can again use tracked live GSM backing as an immediate redemption lower bound when reserve sync is degraded only because residual issuance outside the configured GSM set remains aggregated
                                                                                                • wsrUSD now falls back to Reservoir's reviewed 25 bps minimum USDC PSM balance when the live balance-sheet API lacks scoring-grade freshness evidence, instead of remaining unrated
                                                                                                • Reserve-sync fallback ratios can now preserve reviewed `documented-bound` confidence and basis metadata instead of being forced into the generic heuristic bucket
                                                                                                Commit provenance not recorded
                                                                                                  v3.2Apr 3, 2026

                                                                                                  USD.AI redemption rail wording correction

                                                                                                  USD.AI's reviewed redemption route now explicitly reflects the live PYUSD-only base-token rail instead of broader multi-stable wording inherited from older docs phrasing.

                                                                                                  • USD.AI still models base USDai as a permissionless atomic stablecoin-redeem route, but the reviewed route notes and fee text now state that direct mint and redeem are against PYUSD specifically rather than generic supported stablecoins
                                                                                                  • The slower queue remains scoped to sUSDai unstaking only, preserving the existing base-token route semantics while tightening the evidence trail to the live app flow and current issuer guidance
                                                                                                  • No live redemption-capacity telemetry is added here because USD.AI's public API does not currently expose a trustworthy base-token redeemable-buffer or redemption-limit feed
                                                                                                  Details

                                                                                                  Impact Notes

                                                                                                  • USD.AI still models base USDai as a permissionless atomic stablecoin-redeem route, but the reviewed route notes and fee text now state that direct mint and redeem are against PYUSD specifically rather than generic supported stablecoins
                                                                                                  • The slower queue remains scoped to sUSDai unstaking only, preserving the existing base-token route semantics while tightening the evidence trail to the live app flow and current issuer guidance
                                                                                                  • No live redemption-capacity telemetry is added here because USD.AI's public API does not currently expose a trustworthy base-token redeemable-buffer or redemption-limit feed
                                                                                                  Commit provenance not recorded
                                                                                                    v3.1Mar 30, 2026

                                                                                                    Live-capacity truth-boundary hardening and registry cleanup

                                                                                                    Reserve-backed redemption routes now use stricter live-metadata eligibility, explicit live-direct vs live-proxy confidence, and reviewed source-link guardrails.

                                                                                                    • Reserve-sync capacity now requires fresh `ok` snapshots, no degrading reserve warnings, scoring-grade freshness evidence, and an adapter that explicitly exposes redeemable-capacity telemetry
                                                                                                    • Live-backed routes now distinguish `live-direct` from `live-proxy`, and only direct live capacity can resolve high confidence; `pUSD Plume` is corrected back to a reviewed documented-bound issuer rail instead of a fake dynamic route
                                                                                                    • Reviewed documented-bound and reserve-sync routes now require explicit `docs[]`, unreviewed routes are closed or downgraded, and stored/API snapshot details preserve richer fidelity metadata including capacity basis and live-capacity classification
                                                                                                    Details

                                                                                                    Impact Notes

                                                                                                    • Reserve-sync capacity now requires fresh `ok` snapshots, no degrading reserve warnings, scoring-grade freshness evidence, and an adapter that explicitly exposes redeemable-capacity telemetry
                                                                                                    • Live-backed routes now distinguish `live-direct` from `live-proxy`, and only direct live capacity can resolve high confidence; `pUSD Plume` is corrected back to a reviewed documented-bound issuer rail instead of a fake dynamic route
                                                                                                    • Reviewed documented-bound and reserve-sync routes now require explicit `docs[]`, unreviewed routes are closed or downgraded, and stored/API snapshot details preserve richer fidelity metadata including capacity basis and live-capacity classification
                                                                                                    Commit provenance not recorded
                                                                                                      v3.0Mar 24, 2026

                                                                                                      Issuer and route-review medium-confidence tranche

                                                                                                      A final low-effort tranche upgrades the remaining easy issuer-style and route-reviewed assets from heuristic defaults to documented-bound redemption coverage.

                                                                                                      • EURS, GYEN, CADC, the reviewed VNX fiat tokens, TRYB, tGBP, JPYC, AxCNH, IDRT, EUROP, and EURAU now use reviewed documented-bound issuer redemption semantics instead of generic heuristic issuer defaults
                                                                                                      • FPI and GYD now use reviewed documented-bound collateral-redemption semantics rather than remaining low-confidence placeholder routes
                                                                                                      • This tranche adds medium-confidence coverage without introducing new adapter work or changing the route bar for the harder semantics-blocked assets
                                                                                                      Details

                                                                                                      Impact Notes

                                                                                                      • EURS, GYEN, CADC, the reviewed VNX fiat tokens, TRYB, tGBP, JPYC, AxCNH, IDRT, EUROP, and EURAU now use reviewed documented-bound issuer redemption semantics instead of generic heuristic issuer defaults
                                                                                                      • FPI and GYD now use reviewed documented-bound collateral-redemption semantics rather than remaining low-confidence placeholder routes
                                                                                                      • This tranche adds medium-confidence coverage without introducing new adapter work or changing the route bar for the harder semantics-blocked assets
                                                                                                      Commit provenance not recorded
                                                                                                        v2.9Mar 24, 2026

                                                                                                        Semantics correction for non-deterministic HOLLAR exit

                                                                                                        A route-semantics review removes one overstated redemption path and explicitly leaves several harder assets outside medium-confidence coverage until a credible holder backstop is established.

                                                                                                        • HOLLAR is no longer modeled as a `psm-swap` redemption route because the Hydration Stability Module only guarantees buying HOLLAR from the facility, while protocol buybacks of HOLLAR remain opportunistic rather than holder-deterministic
                                                                                                        • The harder follow-up set led to no new medium-confidence additions for crvUSD, sUSD, MIM, or USDU Finance because current public materials still do not establish a primary redemption rail comparable to the existing modeled route families
                                                                                                        • This keeps redemption coverage honest by preferring uncovered or low-coverage states over overstated direct-exit semantics
                                                                                                        Details

                                                                                                        Impact Notes

                                                                                                        • HOLLAR is no longer modeled as a `psm-swap` redemption route because the Hydration Stability Module only guarantees buying HOLLAR from the facility, while protocol buybacks of HOLLAR remain opportunistic rather than holder-deterministic
                                                                                                        • The harder follow-up set led to no new medium-confidence additions for crvUSD, sUSD, MIM, or USDU Finance because current public materials still do not establish a primary redemption rail comparable to the existing modeled route families
                                                                                                        • This keeps redemption coverage honest by preferring uncovered or low-coverage states over overstated direct-exit semantics
                                                                                                        Commit provenance not recorded
                                                                                                          v2.8Mar 24, 2026

                                                                                                          Second medium-confidence redemption cleanup tranche

                                                                                                          A second cleanup tranche upgrades the best non-top-100 low-confidence routes where Pharos already had sufficient issuer, reserve, or queue-redemption evidence to stop relying on heuristics.

                                                                                                          • cUSD, cEUR, ALUSD, and AZND now use reviewed eventual or reserve-backed redemption semantics instead of heuristic capacity ratios
                                                                                                          • USDA now carries a reviewed issuer-redemption route, while pUSD Plume now uses live reserve metadata with a documented 1:1 USDC fallback instead of a generic low-confidence issuer assumption
                                                                                                          • Names whose route semantics are still genuinely unresolved, such as crvUSD, sUSD, MIM, and HOLLAR, remain outside this tranche rather than being promoted on weak evidence
                                                                                                          Details

                                                                                                          Impact Notes

                                                                                                          • cUSD, cEUR, ALUSD, and AZND now use reviewed eventual or reserve-backed redemption semantics instead of heuristic capacity ratios
                                                                                                          • USDA now carries a reviewed issuer-redemption route, while pUSD Plume now uses live reserve metadata with a documented 1:1 USDC fallback instead of a generic low-confidence issuer assumption
                                                                                                          • Names whose route semantics are still genuinely unresolved, such as crvUSD, sUSD, MIM, and HOLLAR, remain outside this tranche rather than being promoted on weak evidence
                                                                                                          Commit provenance not recorded
                                                                                                            v2.7Mar 24, 2026

                                                                                                            Buffer-backed medium-confidence redemption tranche

                                                                                                            A follow-up tranche promotes the remaining cleanest heuristic routes by tying their capacity bounds to already-curated stable redemption buffers or direct full-reserve rails.

                                                                                                            • USDD, LISUSD, reUSD, USR, USDF, DUSD, USP, and BUCK now use reviewed documented-bound capacity instead of generic heuristic ratios because Pharos already tracks explicit stable redemption buffers for those routes
                                                                                                            • msUSD and fxUSD now carry reviewed direct-redemption semantics rather than unresolved low-confidence defaults, reflecting Main Street's full USDC reserve rail and f(x)'s documented collateral redemption path
                                                                                                            • Routes whose reserve stack still lacks a clearly bounded redeemable stable buffer, such as YUSD, USN, and UTY, intentionally remain low-confidence until the evidence improves
                                                                                                            Details

                                                                                                            Impact Notes

                                                                                                            • USDD, LISUSD, reUSD, USR, USDF, DUSD, USP, and BUCK now use reviewed documented-bound capacity instead of generic heuristic ratios because Pharos already tracks explicit stable redemption buffers for those routes
                                                                                                            • msUSD and fxUSD now carry reviewed direct-redemption semantics rather than unresolved low-confidence defaults, reflecting Main Street's full USDC reserve rail and f(x)'s documented collateral redemption path
                                                                                                            • Routes whose reserve stack still lacks a clearly bounded redeemable stable buffer, such as YUSD, USN, and UTY, intentionally remain low-confidence until the evidence improves
                                                                                                            Commit provenance not recorded
                                                                                                              v2.6Mar 23, 2026

                                                                                                              Moderate-effort redemption confidence tranche

                                                                                                              A moderate-effort tranche reviews a final group of already-modeled lower-confidence routes where Pharos now has stronger primary redemption semantics, but not yet protocol-native live instant-buffer telemetry across the full set.

                                                                                                              • DOLA and JupUSD now treat their published stable-buffer bounds as reviewed documented-capacity inputs instead of leaving those ratios in the heuristic bucket
                                                                                                              • rwaUSDi, mTBILL, MUSD, USDN, and YZUSD now use reviewed redemption semantics with documented-bound capacity instead of generic low-confidence placeholders, while YUSD, USN, and UTY keep conservative bounded-capacity assumptions because their delta-neutral collateral stacks still lack explicit published live buffers
                                                                                                              • The documented-bound subset now contributes medium-confidence redemption evidence, while the reviewed delta-neutral routes stay visible-only until Pharos has explicit buffer bounds or live telemetry
                                                                                                              Details

                                                                                                              Impact Notes

                                                                                                              • DOLA and JupUSD now treat their published stable-buffer bounds as reviewed documented-capacity inputs instead of leaving those ratios in the heuristic bucket
                                                                                                              • rwaUSDi, mTBILL, MUSD, USDN, and YZUSD now use reviewed redemption semantics with documented-bound capacity instead of generic low-confidence placeholders, while YUSD, USN, and UTY keep conservative bounded-capacity assumptions because their delta-neutral collateral stacks still lack explicit published live buffers
                                                                                                              • The documented-bound subset now contributes medium-confidence redemption evidence, while the reviewed delta-neutral routes stay visible-only until Pharos has explicit buffer bounds or live telemetry
                                                                                                              Commit provenance not recorded
                                                                                                                v2.5Mar 23, 2026

                                                                                                                Reviewed docs-backed quick-win redemption tranche

                                                                                                                A docs-backed quick-win tranche upgrades nine existing low-confidence redemption routes where the remaining blocker was heuristic capacity or stale access and fee assumptions rather than missing telemetry.

                                                                                                                • avUSD, cUSD, USDu, cgUSD, HONEY, EUSD, AID, OUSD, and USBD now use reviewed documented-bound redemption capacity instead of staying low-confidence under heuristic supply models
                                                                                                                • USDu and AID now reflect whitelist-gated direct redemption access, while cgUSD and AID also disclose reviewed live fee assumptions from official docs
                                                                                                                • These routes still do not claim a separately measured live instant buffer, but they now contribute medium-confidence redemption evidence across roughly half a billion dollars of additional tracked market cap
                                                                                                                Details

                                                                                                                Impact Notes

                                                                                                                • avUSD, cUSD, USDu, cgUSD, HONEY, EUSD, AID, OUSD, and USBD now use reviewed documented-bound redemption capacity instead of staying low-confidence under heuristic supply models
                                                                                                                • USDu and AID now reflect whitelist-gated direct redemption access, while cgUSD and AID also disclose reviewed live fee assumptions from official docs
                                                                                                                • These routes still do not claim a separately measured live instant buffer, but they now contribute medium-confidence redemption evidence across roughly half a billion dollars of additional tracked market cap
                                                                                                                Commit provenance not recorded
                                                                                                                  v2.4Mar 23, 2026

                                                                                                                  Maple syrup withdrawal route correction

                                                                                                                  Maple's syrupUSDC and syrupUSDT routes now model the documented withdrawal queue instead of an overstated near-instant redemption buffer.

                                                                                                                  • syrupUSDC and syrupUSDT now use reviewed queue-redemption semantics with documented-bound eventual capacity rather than a heuristic 30% immediate buffer assumption
                                                                                                                  • Access is now modeled as whitelisted onchain, reflecting Maple's PoolPermissionManager gating for `requestRedeem` and `redeem` calls
                                                                                                                  • These routes now contribute medium-confidence redemption evidence while preserving Maple's documented FIFO processing and potential multi-day settlement delay
                                                                                                                  Details

                                                                                                                  Impact Notes

                                                                                                                  • syrupUSDC and syrupUSDT now use reviewed queue-redemption semantics with documented-bound eventual capacity rather than a heuristic 30% immediate buffer assumption
                                                                                                                  • Access is now modeled as whitelisted onchain, reflecting Maple's PoolPermissionManager gating for `requestRedeem` and `redeem` calls
                                                                                                                  • These routes now contribute medium-confidence redemption evidence while preserving Maple's documented FIFO processing and potential multi-day settlement delay
                                                                                                                  Commit provenance not recorded
                                                                                                                    v2.3Mar 23, 2026

                                                                                                                    Reviewed lower-cap redemption cleanup tranche

                                                                                                                    A small lower-cap cleanup tranche upgrades Pleasing and Apyx routes from generic heuristics to reviewed redemption semantics without adding new live telemetry assumptions.

                                                                                                                    • PUSD and PGOLD now use reviewed documented-bound redemption routes tied to Pleasing's published off-ramp and physical-delivery docs instead of generic heuristic issuer assumptions
                                                                                                                    • apxUSD now reflects the documented whitelist-gated mint/redeem rail rather than a generic permissionless stablecoin-redeem assumption
                                                                                                                    • These routes still do not claim a separately measured live instant buffer, but they now contribute medium-confidence redemption evidence instead of remaining low-confidence heuristics
                                                                                                                    Details

                                                                                                                    Impact Notes

                                                                                                                    • PUSD and PGOLD now use reviewed documented-bound redemption routes tied to Pleasing's published off-ramp and physical-delivery docs instead of generic heuristic issuer assumptions
                                                                                                                    • apxUSD now reflects the documented whitelist-gated mint/redeem rail rather than a generic permissionless stablecoin-redeem assumption
                                                                                                                    • These routes still do not claim a separately measured live instant buffer, but they now contribute medium-confidence redemption evidence instead of remaining low-confidence heuristics
                                                                                                                    Commit provenance not recorded
                                                                                                                      v2.2Mar 23, 2026

                                                                                                                      Live-buffer routes for Ethena and Falcon synthetics

                                                                                                                      USDe and USDf now reuse live reserve telemetry for current redeemable stable buffers, turning two large synthetic-dollar gaps into reviewed route coverage.

                                                                                                                      • USDe now models the whitelisted direct mint-and-redeem rail documented by Ethena, with fresh live Liquid Cash telemetry used as the current redeemable stable buffer and a conservative 0.5% fallback bound when telemetry is unavailable
                                                                                                                      • USDf now models Falcon's KYC-only queued redemption route with a live stablecoin-buffer input from Falcon's transparency feed and a reviewed zero protocol-fee assumption based on Falcon docs
                                                                                                                      • These routes materially expand medium-confidence redemption coverage without pretending either protocol has a permanently fixed instant-exit buffer
                                                                                                                      Details

                                                                                                                      Impact Notes

                                                                                                                      • USDe now models the whitelisted direct mint-and-redeem rail documented by Ethena, with fresh live Liquid Cash telemetry used as the current redeemable stable buffer and a conservative 0.5% fallback bound when telemetry is unavailable
                                                                                                                      • USDf now models Falcon's KYC-only queued redemption route with a live stablecoin-buffer input from Falcon's transparency feed and a reviewed zero protocol-fee assumption based on Falcon docs
                                                                                                                      • These routes materially expand medium-confidence redemption coverage without pretending either protocol has a permanently fixed instant-exit buffer
                                                                                                                      Commit provenance not recorded
                                                                                                                        v2.1Mar 23, 2026

                                                                                                                        Mid-cap route correction and review tranche

                                                                                                                        A mid-cap tranche adds missing USX, USDa, and M redemption configs while correcting USD.AI and NUSD onto reviewed routes that better match their protocol docs.

                                                                                                                        • USX, USDa, and M now carry reviewed redemption routes instead of remaining uncovered, and NUSD now uses reviewed documented-bound queue semantics rather than a generic 20% heuristic
                                                                                                                        • USD.AI now models the base token's direct burn-and-withdraw stablecoin rail instead of inheriting the slower sUSDai unstaking assumptions
                                                                                                                        • These routes still do not claim a separately measured live instant buffer, but they materially expand medium-confidence redemption coverage across the mid-cap queue
                                                                                                                        Details

                                                                                                                        Impact Notes

                                                                                                                        • USX, USDa, and M now carry reviewed redemption routes instead of remaining uncovered, and NUSD now uses reviewed documented-bound queue semantics rather than a generic 20% heuristic
                                                                                                                        • USD.AI now models the base token's direct burn-and-withdraw stablecoin rail instead of inheriting the slower sUSDai unstaking assumptions
                                                                                                                        • These routes still do not claim a separately measured live instant buffer, but they materially expand medium-confidence redemption coverage across the mid-cap queue
                                                                                                                        Commit provenance not recorded
                                                                                                                          v2.0Mar 23, 2026

                                                                                                                          Third lower-cap redemption review tranche

                                                                                                                          A third lower-cap review tranche upgrades more issuer-style routes from heuristic supply-full modeling to reviewed documented-bound capacity and corrects frxUSD onto its direct onchain stablecoin redemption rail.

                                                                                                                          • thBILL, XAUm, USDGO, and USA₮ now carry reviewed documented-bound eventual redemption capacity instead of generic heuristic supply-full modeling
                                                                                                                          • XAUm now discloses a reviewed 25 bps redemption fee and T+3 settlement expectations, while USDGO now uses the reviewed zero-fee StableHub exchange rail documented by OSL
                                                                                                                          • frxUSD now models the direct onchain USDC mint/redeem contract path as a reviewed stablecoin-redeem route instead of sitting in a generic offchain issuer bucket
                                                                                                                          Details

                                                                                                                          Impact Notes

                                                                                                                          • thBILL, XAUm, USDGO, and USA₮ now carry reviewed documented-bound eventual redemption capacity instead of generic heuristic supply-full modeling
                                                                                                                          • XAUm now discloses a reviewed 25 bps redemption fee and T+3 settlement expectations, while USDGO now uses the reviewed zero-fee StableHub exchange rail documented by OSL
                                                                                                                          • frxUSD now models the direct onchain USDC mint/redeem contract path as a reviewed stablecoin-redeem route instead of sitting in a generic offchain issuer bucket
                                                                                                                          Commit provenance not recorded
                                                                                                                            v1.9Mar 23, 2026

                                                                                                                            Second lower-cap issuer review tranche

                                                                                                                            A second lower-cap review tranche upgrades more issuer-backed routes from heuristic supply-full modeling to reviewed documented-bound redemption capacity, with targeted fee and settlement corrections.

                                                                                                                            • USDH, FIDD, AEUR, USDX, USDM, SBC, EURR, USDR, WUSD, and AUDD now carry reviewed documented-bound eventual redemption capacity instead of generic heuristic supply-full modeling
                                                                                                                            • USDM and AEUR now disclose reviewed non-instant settlement expectations from issuer materials, while USDH now carries an explicit fee-free reviewed route and SBC now uses reviewed pricing language instead of an undocumented fee assumption
                                                                                                                            • These routes remain eventual-only issuer exits without a separately measured immediate redeemable buffer, but they now qualify as medium-confidence redemption evidence instead of low-confidence heuristics
                                                                                                                            Details

                                                                                                                            Impact Notes

                                                                                                                            • USDH, FIDD, AEUR, USDX, USDM, SBC, EURR, USDR, WUSD, and AUDD now carry reviewed documented-bound eventual redemption capacity instead of generic heuristic supply-full modeling
                                                                                                                            • USDM and AEUR now disclose reviewed non-instant settlement expectations from issuer materials, while USDH now carries an explicit fee-free reviewed route and SBC now uses reviewed pricing language instead of an undocumented fee assumption
                                                                                                                            • These routes remain eventual-only issuer exits without a separately measured immediate redeemable buffer, but they now qualify as medium-confidence redemption evidence instead of low-confidence heuristics
                                                                                                                            Commit provenance not recorded
                                                                                                                              v1.8Mar 23, 2026

                                                                                                                              Expanded reviewed lower-cap issuer redemption coverage

                                                                                                                              A lower-cap review tranche now upgrades multiple issuer-backed and tokenized-cash routes from heuristic supply-full modeling to reviewed documented-bound redemption capacity.

                                                                                                                              • CASH, MNEE, USDP, GUSD, XUSD, XSGD, USDQ, EURQ, EURe, EURI, TBILL, EURCV, and USDCV now carry reviewed documented-bound eventual redemption capacity instead of generic heuristic supply-full modeling
                                                                                                                              • TBILL, EURI, EURCV, and USDCV now also disclose reviewed non-instant settlement constraints from issuer documentation
                                                                                                                              • These routes remain eventual-only and do not claim a separately measured immediate redeemable buffer, but they can now resolve medium confidence instead of low
                                                                                                                              Details

                                                                                                                              Impact Notes

                                                                                                                              • CASH, MNEE, USDP, GUSD, XUSD, XSGD, USDQ, EURQ, EURe, EURI, TBILL, EURCV, and USDCV now carry reviewed documented-bound eventual redemption capacity instead of generic heuristic supply-full modeling
                                                                                                                              • TBILL, EURI, EURCV, and USDCV now also disclose reviewed non-instant settlement constraints from issuer documentation
                                                                                                                              • These routes remain eventual-only and do not claim a separately measured immediate redeemable buffer, but they can now resolve medium confidence instead of low
                                                                                                                              Commit provenance not recorded
                                                                                                                                v1.7Mar 23, 2026

                                                                                                                                Sky LitePSM routes now use live PSM capacity

                                                                                                                                Sky DAI/USDS routes now score against fresh live PSM USDC capacity from reserve telemetry, and infiniFi IUSD now carries a fixed zero-fee redemption model.

                                                                                                                                • DAI and USDS use current Sky PSM USDC balance as dynamic immediate redemption capacity when fresh live reserve metadata is available
                                                                                                                                • When Sky live metadata is unavailable or stale, those routes fall back to the prior reviewed 33% heuristic instead of becoming unrated
                                                                                                                                • IUSD now uses a fixed zero-fee redemption model, allowing its existing dynamic-capacity queue route to resolve high confidence
                                                                                                                                Details

                                                                                                                                Impact Notes

                                                                                                                                • DAI and USDS use current Sky PSM USDC balance as dynamic immediate redemption capacity when fresh live reserve metadata is available
                                                                                                                                • When Sky live metadata is unavailable or stale, those routes fall back to the prior reviewed 33% heuristic instead of becoming unrated
                                                                                                                                • IUSD now uses a fixed zero-fee redemption model, allowing its existing dynamic-capacity queue route to resolve high confidence
                                                                                                                                Commit provenance not recorded
                                                                                                                                  v1.6Mar 23, 2026

                                                                                                                                  Reviewed full-supply redemption routes can now be documented-bound

                                                                                                                                  Reviewed issuer and direct-redeem routes can now use documented-bound eventual-only capacity when official terms establish full-supply redeemability without a separately measured immediate buffer.

                                                                                                                                  • Multiple issuer and direct-redeem routes now resolve capacity confidence as documented-bound instead of heuristic after source review
                                                                                                                                  • These routes stay eventual-only and do not claim a separately measured immediate redeemable buffer
                                                                                                                                  • Dynamic immediate-capacity telemetry is still required for high-confidence uplift on routes where current buffer size matters operationally
                                                                                                                                  Details

                                                                                                                                  Impact Notes

                                                                                                                                  • Multiple issuer and direct-redeem routes now resolve capacity confidence as documented-bound instead of heuristic after source review
                                                                                                                                  • These routes stay eventual-only and do not claim a separately measured immediate redeemable buffer
                                                                                                                                  • Dynamic immediate-capacity telemetry is still required for high-confidence uplift on routes where current buffer size matters operationally
                                                                                                                                  Commit provenance not recorded
                                                                                                                                    v1.5Mar 22, 2026

                                                                                                                                    Fresh live-metadata gating and clearer route provenance

                                                                                                                                    Reserve-backed redemption routes now stop scoring against stale live metadata, the API methodology envelope tracks stored snapshot rows, and detail surfaces disclose clearer source provenance.

                                                                                                                                    • Reserve-sync capacity now requires a fresh authoritative live snapshot; stale metadata falls back conservatively or leaves the route unrated
                                                                                                                                    • GHO normalizes current tracked GSM buy fees into redemption fee telemetry, while the API methodology version now reflects the latest stored row version instead of the live code constant
                                                                                                                                    • Detail pages now show reviewed-vs-fallback source provenance, and Honey is modeled as a basket exit under stress-state redemption semantics
                                                                                                                                    Details

                                                                                                                                    Impact Notes

                                                                                                                                    • Reserve-sync capacity now requires a fresh authoritative live snapshot; stale metadata falls back conservatively or leaves the route unrated
                                                                                                                                    • GHO normalizes current tracked GSM buy fees into redemption fee telemetry, while the API methodology version now reflects the latest stored row version instead of the live code constant
                                                                                                                                    • Detail pages now show reviewed-vs-fallback source provenance, and Honey is modeled as a basket exit under stress-state redemption semantics
                                                                                                                                    Commit provenance not recorded
                                                                                                                                      v1.4Mar 22, 2026

                                                                                                                                      Live Liquity fee telemetry for formula routes

                                                                                                                                      Formula-based Liquity redemption routes can now consume current on-chain fee telemetry from live reserve sync instead of relying only on the generic reviewed-formula bucket.

                                                                                                                                      • LUSD and BOLD live reserve adapters now record current redemption fee bps from official protocol contracts
                                                                                                                                      • Redemption backstop cost scoring uses live fee bps when that telemetry is available, while keeping the route labeled as a formula model
                                                                                                                                      • If live fee telemetry is missing, these routes fall back to the prior reviewed-formula scoring bucket
                                                                                                                                      Details

                                                                                                                                      Impact Notes

                                                                                                                                      • LUSD and BOLD live reserve adapters now record current redemption fee bps from official protocol contracts
                                                                                                                                      • Redemption backstop cost scoring uses live fee bps when that telemetry is available, while keeping the route labeled as a formula model
                                                                                                                                      • If live fee telemetry is missing, these routes fall back to the prior reviewed-formula scoring bucket
                                                                                                                                      Commit provenance not recorded
                                                                                                                                        v1.3Mar 22, 2026

                                                                                                                                        Documented-bound full-system redemption for Liquity routes

                                                                                                                                        Immutable Liquity-style routes can now be marked documented-bound when protocol mechanics establish full-system redeemability, while still preserving eventual-only capacity semantics.

                                                                                                                                        • LUSD and BOLD now resolve capacity confidence as documented-bound instead of heuristic
                                                                                                                                        • These routes stay eventual-only and do not claim a separately measured immediate redeemable buffer
                                                                                                                                        • Reviewed Liquity-style fee formulas remain dynamic formula inputs rather than fixed bps placeholders
                                                                                                                                        Details

                                                                                                                                        Impact Notes

                                                                                                                                        • LUSD and BOLD now resolve capacity confidence as documented-bound instead of heuristic
                                                                                                                                        • These routes stay eventual-only and do not claim a separately measured immediate redeemable buffer
                                                                                                                                        • Reviewed Liquity-style fee formulas remain dynamic formula inputs rather than fixed bps placeholders
                                                                                                                                        Commit provenance not recorded
                                                                                                                                          v1.2Mar 22, 2026

                                                                                                                                          Failure-safe snapshots and evidence-aware capacity semantics

                                                                                                                                          Redemption backstop snapshots now materialize failed rows safely, separate eventual redeemability from immediate capacity, and reuse more live reserve metadata.

                                                                                                                                          • Failed per-coin syncs now write fresh failed rows instead of leaving stale resolved rows live
                                                                                                                                          • `supply-full` routes no longer expose full current supply as immediate capacity on the detail surface
                                                                                                                                          • OpenEden USDO, GHO, and wsrUSD now reuse live reserve metadata for immediate redeemable capacity; infiniFi ratio now uses supply as the denominator
                                                                                                                                          Details

                                                                                                                                          Impact Notes

                                                                                                                                          • Failed per-coin syncs now write fresh failed rows instead of leaving stale resolved rows live
                                                                                                                                          • `supply-full` routes no longer expose full current supply as immediate capacity on the detail surface
                                                                                                                                          • OpenEden USDO, GHO, and wsrUSD now reuse live reserve metadata for immediate redeemable capacity; infiniFi ratio now uses supply as the denominator
                                                                                                                                          Commit provenance not recorded
                                                                                                                                            v1.1Mar 20, 2026

                                                                                                                                            Fee-source coverage expansion

                                                                                                                                            Expanded redemption-fee coverage with docs-backed fixed fees, conditional fee descriptions, and clearer handling of issuer routes without a single public fee schedule.

                                                                                                                                            • Redemption backstop entries now expose a fee description alongside bounded fee bps when available
                                                                                                                                            • Multiple assets now carry docs-backed fixed fee inputs instead of generic unknown-fee handling
                                                                                                                                            • Routes without a single public numeric fee now surface explicit variable or undisclosed fee descriptions instead of false precision
                                                                                                                                            Details

                                                                                                                                            Impact Notes

                                                                                                                                            • Redemption backstop entries now expose a fee description alongside bounded fee bps when available
                                                                                                                                            • Multiple assets now carry docs-backed fixed fee inputs instead of generic unknown-fee handling
                                                                                                                                            • Routes without a single public numeric fee now surface explicit variable or undisclosed fee descriptions instead of false precision
                                                                                                                                            Commit provenance not recorded
                                                                                                                                              v1.0Feb 28, 2026Reconstructed

                                                                                                                                              Initial redemption backstop scoring

                                                                                                                                              First operational release of the redemption backstop scoring framework with effective-exit assessment.

                                                                                                                                              • Introduced per-stablecoin redemption route configs with access, settlement, execution, and output-asset scoring
                                                                                                                                              • Effective-exit score combined capacity utilization with weighted route-family scores
                                                                                                                                              • Report card safety dimension now includes redemption backstop component
                                                                                                                                              Details

                                                                                                                                              Impact Notes

                                                                                                                                              • Introduced per-stablecoin redemption route configs with access, settlement, execution, and output-asset scoring
                                                                                                                                              • Effective-exit score combined capacity utilization with weighted route-family scores
                                                                                                                                              • Report card safety dimension now includes redemption backstop component
                                                                                                                                              Reconstructed from git commit history.Commit provenance not recorded