Back to selected work

RentChain. Making fractional property income practical to distribute

Dmitry Sergeev·10 min read

Category:Tokenization

Project status:Discontinued by client

Tags:
  • Real estate
  • Tokenization
  • Income distribution
  • ERC-3643
  • Order book
  • USDC

Our work

We developed the ownership, rental-income distribution and settlement components for RentChain. Our work covered cumulative income accounting, transfer corrections, reconciled funding, secondary-market settlement and the closing process for property disposals.

A commercial property can support thousands of small investors without generating enough rent to justify thousands of separate monthly payments. Dividing ownership is easy compared with servicing it. RentChain addresses that mismatch through a property-level income index, transfer-aware entitlement accounting and withdrawals that happen separately from allocation. The architecture connects those mechanisms to an internal exchange and the financial records behind each distribution.

The product covers offices, retail premises, warehouses and logistics facilities. Each property has a dedicated ownership vehicle, one fungible share class and an isolated USDC distribution vault. The token represents the economic rights defined for that vehicle. Rental income, the proceeds of an investor's secondary sale and the proceeds of selling the building remain separate cash flows. This distinction determines the accounting model before any exchange or wallet interaction is added.

Small holdings changed the distribution model

For example, with 100,000 tokens outstanding and a funded distribution of 10,000 USDC, each whole token receives 0.1 USDC. A wallet holding 0.0001 token receives only 0.00001 USDC. Across 300 such wallets, the combined income is 0.003 USDC. At an illustrative cost of 0.01 USDC per payout, sending that income separately would cost 3 USDC.

Batching the transfers would share some transaction overhead, but each recipient would still require execution and storage work. RentChain instead separates allocation from withdrawal. Funding a property updates one cumulative index without iterating through its holders. Each investor's entitlement follows from that index, their token balance and a correction value that preserves previously credited income. The operation remains constant in holder count because funding changes the property index rather than each holder's record.

Arbitrum One and native USDC provide a common network and settlement asset for shares, trades and claims. Lower transaction costs help withdrawal economics, but the index is what removes the holder loop. A sponsored claim is optional and subject to both payout economics and a budget. Small positions continue accumulating entitlement even when sponsorship would be uneconomical. We kept credited income separate from USDC already delivered to the wallet.

The index preserves value below a transferable USDC unit

Each property maintains two fixed accounting streams, RENT and EXIT. Both use a precision multiplier of 2^128, a cumulative index and a carried remainder. Funding divides the newly received USDC amount, magnified by that multiplier, across the fixed token supply. Any division remainder carries into later funding. Wallet-level calculations retain fractional precision until a claim can transfer whole USDC base units.

The contract credits only the measured increase in the vault's USDC balance. Funding and index advancement occur in the same transaction, and a repeated distribution identifier reverts. An unexpected direct transfer remains unallocated until reconciliation. This prevents a treasury acknowledgement or duplicated workflow message from creating an entitlement without corresponding funds. Supply is finalized before distributions begin, so routine minting cannot change the denominator halfway through the income stream.

The cost claim has a precise boundary. Allocation is O(1) in holder count, and an ordinary token transfer updates two wallets across two fixed streams. Withdrawals still cost work per claim, and a multi-property batch still calls each relevant vault. Lifetime funding and supply bounds constrain integer arithmetic, while carried property-level rounding remains below one USDC base unit under the specified supply cap. Fractional ownership does not eliminate transaction costs or make an unrepresentable payout transferable.

Transfer corrections preserve already credited income

An index multiplied only by the current token balance would assign historical income to whoever holds the shares now. After a sale, that would reduce the seller's accrued entitlement and give the buyer income from an earlier distribution. RentChain adds signed corrections to every balance change. When Alice transfers quantity x, her correction increases by I × x and the recipient's decreases by the same amount. Combined with their changed balances, both investors' existing entitlements remain unchanged.

The corrections run inside the atomic token balance mutation for both rental and exit proceeds. A failed eligibility check or failed transfer rolls them back with the ownership change. This is why distribution accounting belongs in the token integration rather than in a separate exchange settlement script. A transfer outside the exchange still has to preserve income rights. The selected property-share model is ERC-3643, with ERC-20-compatible fractional balances and investor eligibility controls integrated with this custom accounting.

The worked example follows Alice selling 40 of her 100 tokens after 2 USDC per token has already been credited. A later distribution adds another 1 USDC per token.

StageAlice sharesAlice income (USDC)Bob sharesBob income (USDC)
Before sale10020000
After sale60200400
Next credit602604040

The table shows cumulative entitlement before withdrawals. If Alice has already withdrawn 50 USDC, she has 210 USDC left to claim after the next credit. Selling her remaining shares does not erase that amount. The buyer's payment for the tokens is accounted for separately from rent. This gives partial exits a defined financial meaning without requiring the exchange to calculate and pay historical income during every fill.

Settlement includes the distribution cutoff

RentChain allocates each funded distribution to settled balances at a published on-chain record point. It does not calculate daily ownership-weighted rent. Someone selling before that point does not automatically retain a share of the month's uncredited rental cash. Once a distribution has been credited, transfer corrections preserve it. The financial statement describes the rent period, while the record point determines which investors receive that distribution.

The procedure publishes the cutoff and prepared financial package, briefly freezes ordinary transfers for the property, advances its order version and credits the funded index against the frozen balances. Trading then reopens with newly signed orders. Preparing funds before the freeze limits the interruption. If funding fails, no distribution is credited and the controller follows an explicit retry or cancellation path.

Order versioning closes the race between a matched trade and the record point. If settlement executes before the cutoff, the buyer holds the shares for the distribution. If the cutoff executes first, the old-version settlement fails. Canonical transaction order decides the outcome, rather than matcher time or a frontend timestamp. This prevents a stale order from executing after the income entitlement attached to the position has changed.

Rent reaches the vault via a reconciled cash waterfall

A commercial lease invoice is not cash available to investors. RentChain begins with settled receipts, applies approved expenses, management fees, debt service, taxes and reserve movements, then records conversion costs where the property receives another currency. Tenant deposits remain liabilities unless the documented treatment permits recognition. Unpaid rent and projected income cannot fund an investor distribution. The approved amount becomes a USDC obligation only when the vault receives funding and credits the distribution.

Bank imports use provider idempotency keys, receipts are matched to tenants and lease periods, and ambiguous items go to review. Finance and property-controller approvals are separate roles. The resulting statement package includes receipt reconciliation, vacancy, concessions, expenses, debt and reserve movements, plus conversion records. Its content hash is committed on-chain with the distribution, while authorised investors access the evidence through an encrypted data room.

This produces a traceable path from reported rent to funded entitlement. It also preserves the actual trust boundary. A document hash establishes that the approved package has not changed, not that every underlying invoice or bank record is true. Property management and external financial records still require oversight. Commercial-specific fields such as rent-free periods, escalation schedules, lease breaks and tenant concentration explain changes in distributions instead of reducing each property to one annual yield figure.

Order acknowledgement and settlement happen separately

RentChain uses an off-chain order book with atomic on-chain delivery against payment. Investors sign limit orders containing the property, quantity, price, expiry, nonce, fee cap and property order version. A single writer per property sequences commands using price-time priority. The PostgreSQL journal commits order commands, reservation changes and result identifiers before acceptance is acknowledged. The in-memory order book can then be rebuilt from durable history.

A match creates a pending fill, not a completed ownership transfer. The settlement contract rechecks signatures, eligibility, balances, allowances, cumulative filled quantity, price limits and fees. Shares and USDC move together or the operation reverts. Backend reservations reduce conflicting attempts across markets, but cannot prevent an investor from revoking an allowance or moving assets elsewhere before settlement. Contract checks remain authoritative.

Integer lots and price ticks make fill amounts explicit. Fees are calculated from cumulative filled value and charged as the difference from fees already paid, so splitting an order into many fills does not change the total fee through repeated rounding. Holdings below the exchange's minimum trade size retain their income rights. Off-chain cancellation stops normal matching, while on-chain cancellation or nonce advancement can invalidate a remaining signature against a faulty operator. Neither reverses a trade already executed.

Withdrawal sponsorship needs an economic limit

A holder can claim directly when there is a positive transferable amount, even if paying gas is an unattractive choice. Sponsored claims apply an additional cost policy. The scheduler checks the investor's minimum payout, a maximum cost ratio and remaining identity and platform budgets. For example, a 0.05 USDC estimated cost and a 1% ceiling imply a 5 USDC payout threshold. The estimate is checked again before submission.

Budgets apply per verified investor as well as per wallet, so dividing a holding across 300 addresses does not create 300 independent sponsorship allowances. Consolidating claims requires authority from each source wallet, not simply a shared identity record. Relayed signatures bind destination, permitted properties, maximum fee, nonce and deadline. Sponsorship expenditure comes from its disclosed budget or an authorised fee, leaving other investors' reserved claims untouched.

A building sale needs its own closing process

Selling tokens on the exchange changes who owns a position. Selling the underlying property changes the assets available for distribution. RentChain handles disposal through a separate record point, frozen balances and the EXIT index. The SPV's received proceeds are reconciled after debt repayment, closing costs, taxes and retained reserves. Only the net distributable amount funds exit entitlements.

The ownership base stays frozen while holdbacks, reserve releases or late rent may still arrive. Claiming an initial exit distribution does not burn away the holder's right to later amounts. Tokens can be retired only after finance closes both streams, with corrections preserving unpaid claims even for zero-balance wallets. Further funding into a permanently closed stream is rejected. This prevents an early payout from prematurely destroying the record needed to distribute the final proceeds.

Recovery has to preserve the same financial result

Temporal coordinates retryable bank, approval and reporting workflows, but retries do not themselves guarantee financial idempotency. Distribution IDs, database constraints, order hashes and contract state identify previously processed operations during recovery. After matcher failure, a new leadership epoch fences the old writer before snapshot loading, deterministic replay and chain reconciliation. Reservations are rebuilt before order admission reopens.

The indexer records canonical block and log identities and distinguishes provisional sequencer confirmation from the required parent-chain data finality. Reorganizations rewind derived projections and replay canonical events. An uncertain funding transaction is reconciled before another submission, and a failed USDC claim preserves the entitlement through transaction reversion. Portfolio balances carry their as-of block and confirmation status so a fast screen update is not mistaken for completed finality.

We kept the same accounting rules across distribution, ownership changes and recovery.

  • Funding records retain the distribution ID for duplicate checks.
  • Transfer corrections preserve credited income when holdings split or merge.
  • Partial sales preserve both parties' previously credited entitlements.
  • Settlement checks the order's property version against the distribution cutoff.
  • Reverted USDC claims retain their entitlement; settlement records identify consumed orders.
  • Disposal holdbacks remain payable after earlier exit proceeds are claimed.

The cumulative index keeps distribution funding independent of holder count. Adding investors does not add a recipient loop to the funding transaction. Transfers preserve already credited income through corrections, and each withdrawal settles a recorded claim. The contract separates those operations so growth in ownership records does not turn every rent distribution into a batch of individual payments.

RentChain makes small property positions serviceable by separating income allocation, ownership transfer and cash withdrawal. The cumulative index controls allocation cost, transfer corrections preserve credited income, and the funded record point ties each distribution to an explicit ownership state and reconciled cash.

See our architecture in practice.

DEVLAB · ARCHITECTURE EXAMPLE

Agent
Commerce

A look inside the software architecture behind Agent Commerce.

View architecture
Agent Commerce — Software Architecture, designed by Dmitry Sergeev