docs mechanism
Settlement after restart
What happens in the first blocks after the chain restarts.
Settlement turns a halt into payouts. It cannot happen while Base is halted, because nothing executes on Base during a halt. It is designed to run in the first blocks after the chain restarts, and to need nothing from cover buyers.
As with the rest of these docs, this page describes the intended design. The contracts are not deployed.
Sequence at restart
- The sequencer resumes. Base starts producing blocks again.
- The feed catches up. The queued status updates are processed. The round that reports the sequencer down and the round that reports it up again are recorded on the Sequencer Uptime Feed.
- Settlement is called. Once the feed reports the sequencer up, any address can call the settlement function.
- The halt is measured. Settlement reads the feed's rounds, computes the halt duration from their status timestamps and determines which trigger tiers it crossed.
- Triggered positions are paid. Every active cover position in each triggered tier receives its full payout size in USDC. Payouts are drawn first from the tier's first-loss capital, then from its vault.
- Positions close. Each paid position closes and cannot pay again.
Permissionless settlement
Settlement is designed to be permissionless. Any address may call the settlement function: a cover buyer, an underwriter, a staker or anyone else. The caller cannot choose who is paid or how much; the result depends only on the feed's rounds and on which cover positions were active.
There is no claim form, no voting and no committee at any stage.
Batching
If many positions are triggered, payouts are processed in batches over the first blocks after the restart. Batching spreads the work across several blocks. It does not change who is paid or how much, and each position is still paid at most once.
What cover buyers need to do
Nothing. Payouts go directly to the cover buyer's address, in USDC on Base (0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913). A cover buyer does not need to file a claim, sign a message or call any function, although nothing prevents them from calling settlement themselves.
Edge cases
Halt near the end of a period
A halt is covered if it begins during the cover period. A halt that begins on the last day of a period and ends after the period has ended is covered. Settlement for it necessarily happens after the restart, which may also be after the period has ended.
Second halt in the same period
A position that has already paid is closed, so a second halt in the same period does not pay it again. Positions that the first halt did not trigger stay active. If a 30 min halt is followed by a 70 min halt in the same period, the 15 min positions that paid after the first halt do not pay again, and the 1 h positions are triggered by the second.
Halt that stops short of a threshold
If the halt duration is below a tier's threshold, nothing is paid in that tier. Its positions stay active until they expire or a later halt in the period triggers them.
Several tiers at once
A halt that crosses the 1 h threshold triggers both the 15 min tier and the 1 h tier. Each tier pays from its own first-loss capital and its own vault. See the capacity rule for why each tier must be able to pay all of its cover at once.
Late or incorrect feed data
Settlement follows the feed. If the feed records the down status late, the measured halt duration is shorter than the halt itself and may fall below a threshold. See oracle failure or late flag.