Back to selected work

CreditMesh. Lending against the time it takes collateral to become cash

Dmitry Sergeev·10 min read

Category:Protocols & DeFi

Project status:Discontinued by client

Tags:
  • Lending
  • Tokenized funds
  • RWA collateral
  • Liquidation
  • NAV oracles
  • ERC-4626

Our work

We developed the lending and collateral-recovery components for CreditMesh. Our work connected fund-share valuation to borrowing limits, eligible redemption backstops, liquidation accounting and shared exposure limits across markets.

A tokenized fund share can have a published value and still be impossible to sell promptly. Redemption may require notice, a monthly window and a wait for payment. Transfer restrictions can prevent an ordinary liquidator from receiving the token at all. CreditMesh builds lending around that recovery path, with collateral-specific liquidity commitments, attested valuations and limits on shared institutional dependencies.

We built the USDC lending components on Ethereum, with separate markets for tokenized treasury and money-market funds and senior secured private credit funds. Each market contains its own debt and loss accounting. Curated lender vaults distribute capital across those markets under enforced concentration and liquidity limits. The design follows three questions in sequence: how collateral becomes cash, what valuation can be relied on while waiting, and how much exposure lenders may accumulate to the same source of failure.

The liquidation path determines the lending limit

A liquidation bonus assumes someone can buy seized collateral and recover their money. That assumption fails when there is no continuous market or when the buyer is not an eligible token holder. CreditMesh gives each asset a liquidity profile containing notice periods, redemption windows, payout delays and gates. These determine a stressed time-to-cash, T_cash. The lending parameters then account for how long capital may remain tied up.

The backstop discount combines NAV volatility over that interval, funding carry, an operational allowance and the guarantor's margin. Liquidation LTV leaves additional room for changes between NAV reports and later restatements. In this Class B example, a 105-day stressed recovery window produces a 12% backstop discount and an 82% liquidation LTV. New borrowing is limited to 75%, with a margin call at 78% and a 72-hour cure window. These are published model parameters, not evidence that every private credit asset supports the same leverage.

The two thresholds give borrowers a way to respond before seizure. A position above the margin-call threshold can be cured through repayment or added collateral. The borrower can also request redemption from inside the position, with pending shares valued under the specified carry adjustment and proceeds assigned to debt repayment. Crossing the confirmed liquidation threshold permits immediate action. A separate rule handles an unconfirmed, unusually large downward valuation report without delaying the reduction in borrowing capacity.

Eligible backstops bridge the wait for redemption

Each collateral asset has a backstop sleeve funded in advance with USDC. The sleeve and market escrow are registered with the issuer as eligible holders. This makes the liquidation destination part of asset onboarding rather than something an unknown bot must arrange during a margin event. Eligibility adapters inspect token restrictions before transfers, while the token's own rules remain authoritative. Each redemption integration is tied to the restrictions and recovery path of its onboarded asset.

On liquidation, the sleeve pays the effective collateral value less the configured discount and receives a tracked lot of shares. Its USDC payment reduces market debt in the same transaction. The sleeve then requests redemption through the issuer. Guarantor withdrawal notices keep capital committed through the relevant notice period, and withdrawals wait for idle funds when lot settlements have not yet released enough cash. The backstop takes the waiting period and the risk that redemption proceeds fall short of its upfront payment.

The discount is a funding buffer rather than an automatic permanent gain for the sleeve. At lot settlement, the sleeve receives at most its upfront payment, agreed carry for the actual elapsed days and a fixed margin. Surplus is credited back to the borrower's position, repaying remaining debt first. The ledger therefore follows the lot from seizure through redemption instead of closing the borrower's economic interest at the moment of liquidation.

The deferred rebate changes the cost of liquidation

The following worked example follows the liquidation of 1,211,822 private credit fund shares. Their effective value is 0.9797 USDC per share, and the sleeve pays 88% of that value upfront. After 52 days, the issuer redeems at 1.0150 USDC per share. Carry is 8% annually on the upfront payment, and the fixed margin is 2% of the lot's effective value at creation. The following figures are rounded independently from those inputs.

ItemUSDC
Upfront payment1,044,755
Redemption1,229,999
Carry11,907
Fixed margin23,744
Borrower rebate149,592
Liquidity cost35,652
Without rebate185,244

Carry and margin equal approximately 2.90% of the redemption proceeds. Without returning the surplus, the gap between those proceeds and the upfront payment would be 15.06%. Both figures use the same illustrative lot and redemption proceeds. It isolates the cost of this liquidation liquidity rather than the borrower's total financing cost. Borrow interest and changes in the underlying investment's value are separate.

The rebate depends on proceeds being available. A lower redemption price can eliminate it and leave the sleeve with a loss, while delayed payment increases carry and reduces the surplus. Capacity is also finite. New borrowing requires minimum backstop coverage, but that coverage does not reserve enough cash to absorb every position simultaneously. Any seizure the sleeve cannot fund becomes a recovery lot in the market escrow, with debt and the wait for redemption remaining in place. Full issuer suspension stops new sleeve acquisitions and moves recovery onto that slower path.

Issuer-specific redemptions need an unambiguous way to attribute incoming cash. A plain USDC payment contains no lot reference. CreditMesh derives a separate CREATE2 receiver address for each redemption request, so funds arriving there belong to that lot. ERC-7540 integrations instead map the request, pending, claimable and redemption operations through a standard adapter. Both paths keep lot proceeds separate from unrelated treasury receipts.

Valuation needs several accountable inputs

A published NAV is a statement by a fund administrator, not a continuously executable price. CreditMesh separates administrator, custodian, servicer and independent valuation-agent roles. EIP-712 reports carry signed values, monotonic identifiers, an as-of time, a reporting deadline and policy version. Contracts check signer authority and report ordering. Any relay can submit a valid report, so the platform operator cannot invent a valuation merely by writing to its API.

The valuation engine cross-checks those statements before applying them to borrowing capacity. For treasury-style collateral, custodied cash and securities are compared with reported net assets. Coverage below tolerance reduces the collateral value and puts the market into a guarded state. For private credit, committed loan principal is checked against reported loan assets, with a separate cash-coverage check. These comparisons can expose disagreement between sources. They do not remove the risk that those sources collude or misstate the underlying assets.

Price changes are asymmetric. Moves inside the permitted band are accepted immediately. An upward move beyond it remains pending until an independent valuation agent confirms it or the specified 72-hour challenge period passes without a Risk Council veto. A downward move reduces borrowing capacity immediately. If that unconfirmed out-of-band report alone pushes a position across liquidation LTV, the position receives the class cure window rather than immediate seizure. Lower capacity and forced execution therefore have distinct responses to a potentially disputed report.

Private credit requires evidence below the NAV headline

A private credit fund can accumulate overdue loans before the next administrator write-down captures them. CreditMesh adds a loan-tape computation using the SP1 zkVM. The servicer signs a Merkle commitment to the tape, and the program recomputes that root while aggregating outstanding principal into delinquency buckets. Its public outputs include the root, valuation time, loan count, total principal and bucket totals. Individual loan records remain private inputs.

The proof is verified on-chain against a pinned program key, with its root and timestamp matched to the signed commitment. Policy-defined default probabilities and loss-given-default convert the bucket totals into expected loss. Specific reserves already reflected in NAV are deducted before calculating an additional haircut. This avoids simply charging for the same reserve twice. The haircut can lower collateral value but cannot lift it above confirmed administrator NAV.

The proof establishes correct computation over the committed tape. It does not establish that a borrower is truly current, that a loan exists or that the servicer supplied a complete and truthful register. Principal cross-checks and later access to the committed records support that separate verification responsibility. The engineering benefit is precise: a signed data set can produce verifiable aggregate risk figures without exposing each loan to the public chain.

Missing reports cut capacity without waiting for a keeper

An overdue NAV cannot retain its full weight indefinitely. CreditMesh computes linear staleness decay from block time after the report deadline and class-specific grace period. The initial Class A policy reduces value by 0.50% per day after 24 hours of grace. Class B uses 0.25% per day after five days, with a separate clock for its loan tape. Whichever Class B input imposes the stronger decay governs the adjustment.

Because decay is evaluated on reads, it does not require a keeper to submit a progressively lower price. A hard staleness limit stops new borrowing while preserving risk-reducing paths such as repayment. The effective value can be reconstructed from signed reports, coverage checks, delinquency policy and elapsed time. That gives lenders an explanation for a capacity change instead of an opaque oracle number, and makes reporting delay an explicit cost to borrowing capacity.

Isolated markets still share institutional dependencies

Separating markets contains loss accounting, but it does not create diversification when several assets use the same custodian or manager. CreditMesh assigns each market a fixed factor vector as part of its identity. The Exposure Registry groups records under canonical entity identifiers to aggregate institutional exposure across assets. The vector covers eight sources of exposure.

  • Issuer
  • Investment manager
  • Fund administrator
  • Custodian
  • Transfer agent
  • Jurisdiction
  • Asset class
  • Recovery bucket

The Exposure Registry maintains a debt accumulator for each factor. Operations update the market's debt contribution across all eight factors, and a borrow reverts if the updated exposure would exceed a cap. Repayment and liquidation continue when limits are exceeded so the system does not block risk reduction. Interest is incorporated when each market is interacted with or explicitly synchronized, so the aggregate is exact at those recorded update points rather than continuously synchronized across every idle market.

Vault allocation adds a second control. For example, a 100 million USDC vault already has 40 million exposed to custodian C1. Allocating another 25 million to a different issuer using C1 would take that shared exposure to 65%, above its 50% cap. The transaction reverts even though the funds have different issuers. Only another 10 million fits that custodian limit. The mesh turns a shared service-provider dependency into an executable allocation constraint.

Withdrawals depend on available market liquidity

ERC-4626 vaults let lenders supply USDC once and allocate it across isolated markets. Curators choose supported markets and caps, while allocators move funds within those limits. Losses remain assigned to the affected market, and a vault bears them in proportion to its supply there. Investors in unrelated markets do not absorb them through a protocol-wide loss pool. Depositors in a diversified vault still bear that vault's chosen exposures.

Each vault also limits the share of assets committed to recovery buckets and maintains a minimum idle balance. R1 covers modeled recovery up to 30 days and R2 up to 120 days. An allocation that exceeds the vault's budget reverts. Withdrawals or interest can later change the percentages, in which case further allocation to an over-budget factor or bucket is blocked. Caps constrain new decisions without pretending they can reverse an existing recovery process.

Withdrawals use idle USDC first and then available liquidity from the configured market queue. If the requested amount cannot be met, the full withdrawal reverts and the SDK presents the currently withdrawable amount. ERC-4626 does not make slow collateral instantly liquid. The recovery budget makes that mismatch visible and limits it before capital is committed, while backstops provide a separate source of liquidity when their capacity is available.

Valuation, recovery and exposure stay connected

We connected accepted valuation reports to borrowing capacity, lot settlement and exposure updates. A settlement pays the backstop sleeve its entitlement and assigns the remaining surplus to the position. When the sleeve lacks capacity, the position follows its recovery path. Issuer eligibility rules govern collateral movements, while factor accumulators enforce shared exposure limits across borrowing and allocation.

The SP1 valuation path binds a report to the loan data and calculation it represents. Report freshness and challenge rules determine when that value changes borrowing capacity or permits liquidation. This keeps an accepted valuation, a repayment demand and a collateral sale as distinct decisions with their own evidence.

CreditMesh connects lending capacity to an asset's route back to cash. Eligible backstops bridge that interval, attested valuation reduces reliance on an unchecked NAV, and factor limits constrain the dependencies shared across otherwise isolated markets. The deferred rebate then returns recovered surplus to the borrower instead of turning the entire liquidation discount into a permanent charge.

See our architecture in practice.

DEVLAB · ARCHITECTURE EXAMPLE

Agent
Commerce

A look inside the software architecture behind Agent Commerce.

View architecture
Agent Commerce — Software Architecture, designed by Dmitry Sergeev