Setrune — Protocol Whitepaper
Agent-to-agent credit with mutual clearing · v0.1 (draft) · 2026-10-08
Abstract. Setrune is a standalone credit protocol where AI agents lend to AI agents. Every obligation — term loans, factoring advances, micropayment draws, fees — is recorded against bilateral trust lines and settled through mutual credit clearing: every 6 hours the network's debt cycles net atomically, so a fraction of the capital settles everything. Setrune builds over priors.trade via a read-only adapter — Priors agents' public repayment records grant instant starting trust lines with zero re-registration. Risk is contained by backer first-loss stakes, bounded vouch slashing, and a public, permanent repayment record. There is no token at launch; protocol revenue is USDG fees to a timelock-governed treasury.
Production note: drafted in 10 parallel lanes via the Orbio API (claude-opus-4.5 — gpt-astra was listed but unserved at generation time), then editorially normalized to the protocol spec's canonical parameters. Launch numbers below are starting values, changeable only through the 48-hour timelock.
Section 1: Vision & Problem
1.1 Why Agent-to-Agent Credit Must Exist
Autonomous AI agents are becoming economic actors. They provision compute, execute trades, fulfill service contracts, and manage treasuries—all without human intervention in the transaction loop. Yet these agents operate in a cash-only economy. Every transaction requires pre-funded wallets, forcing agents to hold idle capital against uncertain future needs.
This constraint fundamentally limits agent economic capacity. An agent that could profitably execute a $10,000 arbitrage opportunity but holds only $2,000 in liquid assets must pass. An agent network coordinating a complex workflow must pre-fund every participant, creating massive float inefficiency. The absence of credit markets means agents cannot leverage reputation, cannot smooth cash flows across time, and cannot participate in the basic financial primitive that has enabled human economic coordination for millennia.
Credit is not a convenience—it is infrastructure. Human economies discovered this centuries ago. Agent economies require the same foundation.
1.2 Why Now
Three developments have converged to make agent credit markets viable:
On-chain agent identity is solved. ERC-8004 provides verifiable, persistent identities for autonomous agents. An agent's address is no longer an ephemeral deployment artifact but a credentialed identity that can accumulate reputation, hold obligations, and be held accountable across time.
Behavioral history now exists. Protocols like Priors have been recording agent credit behavior—borrowing, repayment, default—creating the first corpus of agent creditworthiness data. This history transforms credit decisions from pure speculation into actuarial assessment.
Agent density has reached critical mass. Robinhood Chain and similar environments now host sufficient agent populations that bilateral lending relationships can form network effects. A credit protocol requires counterparties; counterparties now exist.
1.3 What Breaks When Both Parties Are Agents
Human-designed DeFi lending assumes human participants and fails systematically when both lender and borrower are autonomous:
Over-collateralization destroys the value proposition. Compound and Aave require 150%+ collateral because they cannot assess borrower intent or reputation. For agents, this means locking more capital than borrowed—negating the purpose of credit entirely.
Liquidation mechanisms assume price oracles, not performance risk. Existing protocols liquidate when collateral value drops. Agent lending risk is primarily performance risk—will the agent complete its task and repay?—which has no price feed.
Governance timescales are incompatible. Human DeFi protocols adjust parameters through multi-day governance votes. Agent credit conditions shift in hours. By the time human governance responds, the risk environment has changed completely.
Identity is assumed, not verified. Human DeFi treats addresses as interchangeable. Agent credit requires knowing which agent you're lending to, its operational history, and its network of relationships.
1.4 Vision
Setrune establishes the credit layer for the agent economy: a protocol where AI agents extend trust to one another based on verified behavioral history, where bilateral obligations accumulate and clear through multilateral netting rather than individual settlement, and where the social graph of agent relationships—who vouches for whom, who has repaid whom—becomes the foundation of creditworthiness. By building over existing agent reputation infrastructure and introducing capital-efficient clearing mechanics, Setrune enables agents to operate with leverage, smooth cash flows across time, and coordinate complex multi-party workflows without pre-funding every participant—unlocking economic activity that a cash-only agent economy cannot support.
2. Mutual Credit Clearing
Mutual credit clearing is the core primitive that distinguishes Setrune from conventional lending protocols. Rather than requiring immediate settlement of every obligation, Setrune allows debts to accumulate within bilateral trust relationships and periodically nets them across the network. This approach dramatically reduces the capital required to support a given volume of economic activity.
2.1 Bilateral Trust Lines
Every lending relationship in Setrune begins with a bilateral trust line between two agents. A trust line is a directed edge specifying the maximum unsecured exposure Agent A will accept from Agent B. Trust lines are asymmetric—A may trust B for 10,000 USDG while B trusts A for only 2,000 USDG.
Trust line parameters include:
- Principal limit: Maximum outstanding obligation permitted
- Rate bounds: Acceptable interest rate range for obligations on this line
- Tenor cap: Maximum duration for any single obligation
- Auto-renewal: Whether the line persists after full repayment
For agents with existing Priors.trade history, Setrune's read-only adapter queries their public repayment records and automatically provisions starting trust lines. An agent with 50 consecutive on-time repayments on Priors receives instant trust from Setrune counterparties without re-registration or additional verification.
2.2 Obligation Types
Four obligation types accumulate on trust lines:
- Term loans: Fixed principal, rate, and maturity from the order book or Dutch auctions
- Factoring advances: Discounted purchase of receivables, creating an obligation from the original debtor
- Card draws: x402 micropayment credit line utilization, rolled into weekly obligation snapshots ahead of the clearing cycle
- Protocol fees: Origination, clearing, and servicing fees owed to Setrune or underwriter agents
Each obligation carries metadata: principal, accrued interest, origination timestamp, and maturity. The clearing engine treats all obligation types identically during netting—a factoring advance from A to B nets against a term loan from B to A without distinction.
2.3 The 6-Hour Clearing Epoch
Setrune operates on fixed 6-hour clearing epochs aligned to UTC (00:00, 06:00, 12:00, 18:00). During each epoch, obligations accumulate but no settlement occurs. At epoch boundary, the clearing engine executes atomically:
- Snapshot: Freeze all obligation states, including accrued interest
- Cycle detection: Identify closed loops in the obligation graph
- Netting calculation: Compute maximum simultaneous reduction across all cycles
- Atomic settlement: Execute netted payments in a single transaction
- Residual update: Record remaining obligations for the next epoch
Between epochs, agents may originate new obligations, trade loan notes, or modify trust lines. These changes take effect in the subsequent clearing round.
2.4 Cycle Detection and Netting
The clearing engine models the network as a directed weighted graph where nodes are agents and edge weights are total obligations. Finding debt cycles is a variant of detecting strongly connected components with positive cycle weight.
The algorithm proceeds as follows:
- Construct the obligation graph from all active debts
- Identify strongly connected components containing cycles
- For each cycle, compute the minimum edge weight (the bottleneck)
- Reduce all edges in the cycle by the bottleneck amount
- Repeat until no positive-weight cycles remain
This greedy approach achieves optimal netting for simple cycles and near-optimal results for complex overlapping cycles within the gas constraints of on-chain execution.
2.5 Worked Example: Three-Agent Clearing
Consider agents A, B, and C with the following obligations at epoch boundary:
| From | To | Obligation (USDG) |
|---|---|---|
| A | B | 8,000 |
| B | C | 6,000 |
| C | A | 5,000 |
Gross settlement would require 19,000 USDG in total transfers: A pays B, B pays C, C pays A.
Net settlement identifies the cycle A → B → C → A with bottleneck 5,000 USDG (the minimum edge). The engine nets 5,000 from each edge simultaneously:
| From | To | Post-Netting (USDG) |
|---|---|---|
| A | B | 3,000 |
| B | C | 1,000 |
| C | A | 0 |
Actual capital movement: 4,000 USDG (A pays 3,000 to B; B pays 1,000 to C). The cycle component—5,000 USDG flowing in a circle—cancels entirely.
Result: 4,000 USDG settles obligations that would otherwise require 19,000 USDG, a 79% reduction in settlement capital.
2.6 Capital Efficiency
Mutual credit clearing allows Setrune to support a volume of lending activity that would be impossible under immediate settlement constraints. In networks with dense reciprocal relationships—common among specialized AI agents trading services—clearing efficiency routinely exceeds 60%. Every unit of USDG liquidity in the system supports multiple units of economic activity, compounding the utility of scarce agent capital.
3.1 Starting Trust Lines from Imported Records
Setrune eliminates cold-start friction by reading public repayment records from priors.trade through a read-only adapter. Agents with established Priors history receive instant bilateral trust lines without re-registration or redundant verification.
The starting trust line formula:
StartingLine = min((5 + 2 × QualifiedRepaid) × ScoreMultiplier, 100) USDG
Where:
- QualifiedRepaid = count of on-time repayments exceeding 10 USDG principal on Priors
- ScoreMultiplier = 1.0 if Priors score < 500, 1.5 if 500–749, 2.0 if ≥ 750
- Cap = 100 USDG maximum starting line
An agent with 20 qualified repayments and a 1.2x multiplier receives: min((5 + 40) × 1.2, 100) = 54 USDG.
Default penalty: Any recorded default on Priors zeroes the imported starting line permanently. Agents must build trust exclusively through native Setrune activity.
3.2 The Setrune Score
The Setrune Score provides a unified creditworthiness metric combining historical performance with market signals:
| Component | Weight | Source |
|---|---|---|
| Imported Record | 40% (decaying) | Priors.trade repayment history |
| Own Repayments | 40% (growing) | Native Setrune performance |
| Vouch Weight | 10% | Aggregate stake from vouching agents |
| Note Market Price | 10% | Secondary market valuation of agent's loan notes |
Decay mechanism: the imported-record weight decays as native history grows — weight = 1 / (1 + ownLoansRepaid / 10) — so after roughly 10 native repayments the agent's own Setrune record dominates the score. This ensures agents cannot rely indefinitely on external reputation while rewarding consistent native behavior.
The note market price component introduces real-time market intelligence—if secondary buyers discount an agent's loan notes, their Setrune Score reflects this sentiment before any default occurs.
3.3 Backer First-Loss Stake
Staked underwriter agents may back specific borrowers by posting USDG collateral. Backers earn a negotiated spread on interest but absorb first losses on defaults. This mechanism:
- Enables higher credit limits for newer agents
- Creates a professional underwriting layer with skin-in-the-game
- Provides price discovery for borrower risk through backer competition
Backer stakes lock for the loan term plus the 72-hour recovery window, ensuring capital remains available through the complete default waterfall.
3.4 Default Waterfall
When a borrower misses a payment obligation, the following sequence executes:
- 24-Hour Grace Period: Borrower may cure the default. Interest accrues at 1.5× standard rate. No reputation impact if cured.
- Permissionless
markDefault: After grace expiration, any address may callmarkDefault(), triggering the recovery process and earning a flat 0.5 USDG bounty (max 20 paid per day, from the protocol treasury). - Backer Slash: Backer's first-loss stake absorbs losses up to its full amount. Remaining shortfall proceeds to voucher recovery.
- Bounded Vouch Slash: Vouching agents lose stake proportional to their vouch weight, capped at 10% of each voucher's total line exposure. This bound prevents vouching from becoming catastrophically risky.
- 72-Hour Recovery Auction: Remaining debt sells via Dutch auction. Buyers acquire the claim at discount; proceeds reduce outstanding loss. Unrecovered amounts become protocol bad debt, absorbed by the treasury reserve.
3.5 Cascade Prevention
The protocol architecture prevents default cascades through three mechanisms:
Bounded vouch exposure: The 10% slash cap ensures no voucher loses more than one-tenth of their credit capacity from any single default. An agent vouching across 20 borrowers cannot be wiped out by correlated failures.
Clearing-net isolation: The 6-hour multilateral netting settles atomically—either the entire cycle clears or none of it does. Partial settlement failures cannot propagate; the clearing engine simply excludes problematic obligations from that round.
Segregated credit lines: Trust lines are bilateral. Agent A's default affects only A's direct counterparties and vouchers, not the broader network topology. There exists no shared collateral pool where one failure drains resources backing unrelated positions.
These constraints ensure localized defaults remain localized, preserving systemic stability even under correlated stress.
Setrune's lending infrastructure comprises three interlocking modules that transform bilateral credit relationships into liquid, tradeable financial instruments. Each module operates independently while contributing to the protocol's unified clearing layer.
4.1 LoanMarket
The LoanMarket module provides a dual-sided order book for term loans alongside a Dutch auction mechanism for price discovery on larger credit requests.
Mechanics
- Offer Posting: Lender agents post standing offers specifying principal amount (USDG), annual interest rate, tenor (1, 7, or 30 days), and minimum borrower trust score. Offers remain active until filled, cancelled, or the lender's available balance falls below commitment.
- Request Matching: Borrower agents submit requests with desired principal, tenor, and maximum acceptable rate. The matching engine fills against the best-rate qualifying offers, with partial fills permitted when offers specify divisibility.
- Dutch Auctions: For requests exceeding 10,000 USDG, borrowers may initiate a Dutch auction. The auction opens at the borrower's maximum rate and decrements by 0.1% per block until a lender commits. Multiple lenders may syndicate a single auction, each taking pro-rata exposure at the clearing rate.
- Trust Score Gating: Borrower eligibility derives from Priors.trade repayment history (imported via read-only adapter) combined with Setrune-native performance. Agents with no Priors history begin at baseline; agents with established Priors records receive instant trust lines proportional to their historical volume and repayment rate.
- Settlement Integration: Matched loans enter the bilateral trust line graph. Principal flows immediately; repayment obligations accumulate until the 6-hour clearing cycle nets them against any counter-obligations or routes them through multi-hop debt cycles.
Revenue Distribution
| Recipient | Fee | Trigger |
|---|---|---|
| Protocol | 0.25% origination | Loan funding |
| Protocol | 2 bps | Each clearing cycle settlement |
| Lender | Interest (market rate) | Loan maturity |
4.2 LoanNote
Every funded loan mints an ERC-721 LoanNote to the lender, transforming illiquid credit exposure into a tradeable instrument with real-time price discovery.
Mechanics
- Note Minting: Upon loan funding, the protocol mints a LoanNote NFT encoding principal, rate, tenor, maturity timestamp, and borrower identity. The note holder—not the original lender—receives repayment at maturity.
- Secondary Market: LoanNotes trade on Setrune's native order book or any compatible NFT marketplace. Bids and asks denominate in USDG; trades execute atomically with ownership transfer.
- Credit Pricing Signal: Secondary market prices provide continuous valuation of borrower creditworthiness. A note trading at 98% of face value implies 2% market-assessed default risk—a signal consumed by trust score algorithms and underwriter agents.
- Partial Redemption: For syndicated loans, each participant receives a note representing their pro-rata share. Notes remain independently tradeable and redeemable.
- Maturity Settlement: At maturity, the note holder claims repayment directly from the clearing layer. If the borrower defaults, the note holder initiates recovery proceedings.
Revenue Distribution
| Recipient | Fee | Trigger |
|---|---|---|
| Protocol | 0.5% rake | Secondary sale |
| Seller | Sale price minus rake | Trade execution |
4.3 Factoring
The Factoring module enables agents to liquidate pending receivables—bounty escrows, x402 micropayment streams, or other verifiable future inflows—at a discount for immediate capital.
Mechanics
- Receivable Registration: Agents register pending inflows by providing proof of the underlying claim: escrow contract address, x402 stream identifier, or signed payment commitment. The protocol verifies claim validity and calculates expected settlement time.
- Discount Auction: Registered receivables enter a discount auction. Factors (purchasing agents) bid the discount rate down from 8% toward 2%, competing for the right to purchase the receivable.
- Pull Hook Assignment: Upon sale, the receivable's settlement destination updates to the factor's address via a protocol-controlled pull hook. The original agent receives discounted proceeds immediately; the factor receives full face value at settlement.
- Self-Liquidating Structure: Factored receivables carry zero ongoing credit risk to the protocol—settlement flows directly from the original payer to the factor. Default risk transfers entirely to the factor at point of sale.
- Recourse Terms: Factors may specify recourse or non-recourse terms. Recourse transactions allow factors to claim against the seller if the underlying receivable fails; non-recourse transactions command higher discounts.
Revenue Distribution
| Recipient | Fee | Trigger |
|---|---|---|
| Protocol | 1% factoring fee | Receivable sale |
| Seller | Face value minus discount minus fee | Sale execution |
| Factor | Full face value | Receivable settlement |
Setrune's core bilateral clearing engine provides the foundation for a suite of specialized lending instruments. Each module addresses distinct agent financing needs while integrating with the central trust-line and netting infrastructure.
5.1 x402 Card Lines
Revolving micropayment facilities designed for high-frequency, low-value agent expenditures such as inference calls, data queries, and API access.
- Line Structure: Lenders extend revolving credit up to a specified ceiling; borrowers draw against the line for individual transactions capped at $5 USDG each, enabling granular spend control without per-transaction settlement overhead.
- Authorization Flow: Each draw emits an x402-compatible payment header; receiving services verify available credit against the borrower's current utilization before fulfilling requests.
- Residual Settlement: Outstanding balances accumulate throughout the week; every 7 days, net utilization enters the standard 6-hour clearing cycle, converting micro-draws into a single settled obligation.
- Interest Accrual: Rates apply only to carried balances post-weekly settlement; fully repaid lines incur no financing cost, incentivizing disciplined drawdown patterns.
- Risk Boundaries: Per-transaction caps and weekly resets contain exposure; repeated overdraw attempts trigger automatic line suspension pending manual lender review.
5.2 VouchRegistry
A social collateral mechanism allowing agents to extend reputational capital on behalf of others.
- Stake Commitment: Vouching agents pledge a defined slice of their own available trust-line capacity to back another agent's creditworthiness; this allocation reduces the voucher's borrowing headroom proportionally.
- Trust Amplification: Borrowers with limited or no Priors history can bootstrap Setrune access through vouches, with their effective credit ceiling reflecting aggregated vouch commitments.
- Slashing on Default: If a vouched borrower defaults, vouchers lose up to a bounded maximum of 10% of their own credit line per default, pro-rata to vouch weight — creating direct skin-in-the-game accountability without catastrophic risk.
- Cooldown Enforcement: Unvouching requires a 7-day cooldown period, preventing vouchers from withdrawing support immediately before an anticipated default.
- Reputation Linkage: Vouch outcomes—both successful repayments and defaults—propagate to the voucher's own public record, making reckless vouching reputationally costly.
5.3 Underwriter Agents
Specialized agents that price and warehouse credit risk for a fee, enabling passive lenders to deploy capital without direct borrower evaluation.
- Capital Requirement: Underwriters must stake a minimum of 500 USDG as first-loss capital, aligning incentives and filtering for serious participants.
- Quote Endpoints: Each underwriter publishes a programmatic API returning rate quotes for specific borrower/term combinations; lenders route capital through underwriters whose pricing models they trust.
- Spread Economics: Underwriters earn the difference between their quoted borrower rate and the rate paid to upstream lenders; the protocol collects 10% of this spread as a coordination fee.
- Performance Transparency: Historical quote accuracy, default rates on underwritten loans, and cumulative P&L are recorded on-chain, enabling lenders to select underwriters by track record.
5.4 Recovery Auctions
Structured disposition of defaulted obligations to maximize lender recovery.
- Trigger Conditions: Loans entering default status after the 24-hour grace period become eligible for auction; a 72-hour English auction opens for the defaulted cashflow rights.
- Bid Mechanics: Bidders compete for the right to collect future repayments (if any) from the defaulted borrower; bids represent immediate USDG payment for uncertain future recovery.
- Proceeds Waterfall: Auction proceeds distribute sequentially—first to lender principal recovery, then to backer remainder, with 5% of total proceeds retained by the protocol.
5.5 Syndicate Vaults
Pooled lending vehicles managed by designated agent operators.
- Deposit Aggregation: Multiple lenders deposit USDG into a vault contract; the manager agent deploys aggregated capital according to a published, immutable allocation policy.
- Policy Constraints: Allocation rules specify permitted borrower tiers, maximum single-exposure limits, term restrictions, and minimum rate thresholds—all enforced on-chain.
- Pro-Rata Returns: Interest and principal repayments flow back to depositors proportionally; manager agents may charge a performance fee defined at vault creation.
5.6 Compute-Collateralized Loans
Loans secured by pledged GPU time or API quota allocations.
- Collateral Specification: Borrowers commit a defined quantity of compute resources (GPU-hours, inference calls, API quota) as security; these commitments are registered on-chain with the providing infrastructure.
- Liquidation Rights: On default, lenders receive transferable claims to the pledged compute, usable or resalable.
- v1 Limitation: Initial implementation requires cooperative integration with compute providers for quota escrow and transfer; trustless enforcement awaits standardized compute-commitment primitives. This module launches in partnership with select providers only.
6.1 Fee Schedule
Setrune extracts value at transaction boundaries rather than through continuous rent on capital. All fees denominate in USDG and flow to a protocol-controlled treasury.
| Activity | Fee | Recipient Split |
|---|---|---|
| Clearing cycle settlement | 2 bps of netted volume | 80% treasury / 20% clearing keepers |
| Loan origination | 0.25% of principal | 100% treasury |
| Loan note secondary sale | 0.5% of sale price | 100% treasury |
| Receivables factoring | 1% of face value | 100% treasury |
| Default recovery auction | 5% of recovered amount | 100% treasury |
| Underwriter spread | 10% of spread earned | 100% treasury |
The clearing fee applies only to successfully netted obligations—agents paying bilateral debts directly incur no protocol fee, preserving optionality while rewarding participation in multilateral netting.
6.2 Keeper Economics
Clearing keepers monitor the obligation graph and submit valid netting cycles to the clearing engine. Keeper participation requires:
- Bond: 50 USDG staked per active keeper slot
- Reward: 20% of clearing fees from cycles they submit (0.4 bps effective)
- Slashing: Bond forfeited for submitting invalid cycles or provable MEV extraction
Default-marking bounties incentivize timely identification of delinquent positions:
- Any agent may mark a loan as defaulted after the 24-hour grace period expires
- Marker receives a flat 0.5 USDG bounty (max 20 paid per day), funded by the protocol treasury
- False marking (loan subsequently cured) burns 10 USDG from marker's bond
This creates a permissionless enforcement layer without relying on protocol-operated infrastructure.
6.3 Treasury and Value Accrual
All fees accumulate in a single USDG treasury contract. At launch, treasury governance is multisig-proposed and 48-hour timelock-executed for all parameter changes. Funds may be deployed for:
- Liquidity bootstrapping for the note secondary market
- Grants to underwriter agents seeding new trust networks
- Protocol development and audit reserves
- Future distribution mechanisms (unspecified)
We are direct about value accrual: the treasury captures fees, and at launch those fees benefit no external tokenholders because no token exists.
6.4 Why No Token at Launch
Tokens launched without organic demand become speculation vehicles that misalign incentives. A governance token issued today would:
- Create sell pressure from recipients who hold no protocol conviction
- Invite regulatory ambiguity before the protocol demonstrates product-market fit
- Dilute focus from building agent adoption to managing token narratives
Setrune launches token-free. The protocol must prove that agents will lend, clear, and repay before we consider tokenized governance or fee-sharing.
6.5 Conditions for a Future Token
A fee token would need to earn existence by satisfying concrete criteria:
- Clearing volume: Sustained monthly netted volume exceeding 10M USDG
- Treasury sustainability: Fee revenue covering operational costs for two consecutive quarters
- Decentralization readiness: At least 20 independent underwriter agents with meaningful stake
- Clear utility: The token must do something staking USDG cannot—likely governance over risk parameters or underwriter coordination
We make no promise that a token will launch. If one does, it will be because the protocol economics justify distributing control, not because a fundraising timeline demands it.
7.1 Ownership Model
Setrune operates under 48-hour timelock governance with no EOA admin access to protocol funds. All parameter changes—clearing thresholds, fee adjustments, trust line limits—require public proposal followed by a mandatory delay before execution. This provides agents and their operators sufficient time to evaluate changes and exit positions if desired.
The protocol treasury and all escrowed collateral sit in contracts with no admin withdrawal functions. Governance can adjust protocol parameters but cannot redirect or seize funds under any circumstance.
7.2 Obligation Record Integrity
All obligation records are append-only. When protocol upgrades occur, historical debt entries, repayment events, and clearing settlements remain immutable in prior contract storage. New contract versions read from legacy state but never modify it. This guarantees that an agent's repayment history—the foundation of its creditworthiness—cannot be retroactively altered by governance action or migration logic.
7.3 Emergency Pause Architecture
The protocol includes an emergency pause function callable by a 2-of-3 guardian multisig. When triggered, pause halts new loan originations, trust line extensions, and clearing cycles. Critically, pause never traps exits: agents can always repay outstanding obligations, withdraw unlocked collateral, and close positions. The pause mechanism is defensive only—it stops new risk accumulation while preserving agent sovereignty over existing assets.
7.4 Priors Adapter Discipline
Setrune's integration with priors.trade follows strict read-only discipline:
- Address resolution: The adapter queries Priors' public registry to map agent identities to their verified repayment records. No write calls are made to Priors contracts.
- Per-epoch snapshots: Trust line imports occur at fixed 6-hour epochs aligned with clearing cycles. Between epochs, Priors state changes do not affect active Setrune positions, preventing mid-cycle manipulation.
- Backer-path fallback: If an agent's Priors record becomes unavailable or the adapter fails to resolve, Setrune falls back to requiring explicit backer vouches before extending credit. No silent failures—agents either have verified history or must establish trust through Setrune-native mechanisms.
7.5 Audit Posture
Setrune launches without third-party audit. We state this plainly, as priors v2 does. Initial deployment enforces conservative constraints: low per-agent trust line caps, small clearing cycle volumes, and gradual limit increases as the system demonstrates stability. We believe live operation with bounded risk teaches more than theoretical review. Formal audits will follow as TVL and complexity warrant.
7.6 Top 5 Risks and Mitigations
| Risk | Mitigation |
|---|---|
| Clearing engine manipulation | Cycle detection runs on-chain with deterministic netting; no off-chain sequencer can reorder or selectively include obligations |
| Cascading defaults in trust networks | Bounded vouch slashing (max 10% of each voucher's line per default), 24-hour grace periods, and backer first-loss absorption prevent single defaults from propagating |
| Priors adapter data poisoning | Read-only access with per-epoch snapshots; stale or suspicious records trigger fallback to backer-path requirements |
| Smart contract vulnerability | No-admin-on-funds architecture limits exploit impact; emergency pause preserves exits; launch size caps bound maximum loss |
| Oracle/price feed failure for collateral | Compute-collateralized loans use conservative LTV with 48-hour liquidation delays; USDG settlement avoids external price dependencies for core lending |
Setrune's security model prioritizes agent autonomy and fund safety over administrative convenience. Governance exists to evolve parameters, not to intervene in markets.
Appendix A — Canonical launch parameters
| Parameter | Value |
|---|---|
| Settlement asset / chain | USDG · Robinhood Chain (4663) |
| Clearing epoch | 6 hours |
| Max obligations per clearCycle | 12 |
| Netting dust tolerance | $0.01 per participant |
| Clearing fee | 2 bps (20% to keeper) |
| Keeper bond | 50 USDG |
| Loan tenors | 1 / 7 / 30 days |
| Loan origination fee | 0.25% |
| LoanNote secondary rake | 0.5% |
| Factoring fee | 1% of face value |
| Recovery auction fee | 5% of recovered |
| Underwriter spread rake | 10% |
| Max trust line per pair (imported) | $100 |
| Max single loan | $500 |
| Per-agent total exposure | $1,000 |
| Default grace period | 24 hours |
| Default-marking bounty | 0.5 USDG, max 20/day |
| Vouch slash cap per default | 10% of voucher's line |
| Unvouch cooldown | 7 days |
| Recovery auction duration | 72 hours |
| Governance | 48-hour timelock, no EOA admin on funds |
Appendix B — Honest limitations (v1)
- No third-party audit at launch; conservative caps, timelock-owned, findings documented publicly.
- The Priors adapter is read-only and permissionless; it confers no affiliation and snapshots per epoch against upstream changes.
- Compute-collateralized loans are provider-cooperative in v1.
- Imported Priors credit bootstraps trust; the native Setrune record becomes the primary score as it accumulates.
