Protocol

Escrow invariant

Everything the protocol could owe is already in its custody.

Statement

for every token T: balanceOf(BarrierCore, T) ≥ Σ obligations in T across all series

Consequences

  • No payout depends on a later deposit.
  • No position can be liquidated, because none is borrowed.
  • A frozen oracle delays settlement but cannot create a shortfall.

Flow of value

Deposits enter subscription buckets, move to live buckets at strike, and to claimable buckets at settlement. Fees leave only through FeeRouter, and only out of amounts already earned.

Bucket transitions

FromToWhen
SubscriptionRefundableStrike, unmatched part
SubscriptionLiveStrike, matched part
PrefundCoupon claimableEach paid observation
LiveRedeemableSettlement

Rounding

Every division rounds against the claimant and in favour of escrow, so dust stays inside the contract rather than leaving it short.

How it is tested

A stateful fuzz suite checks the inequality after every random action sequence. See Invariants.

Stock Tokens are not offered to US persons. A barrier note can lose value: if the final close sits below the barrier, CARRY holders are paid in stock valued at S0, which can be worth less than what they put in. Nothing on this site is investment advice.

© 2026 Get Berrier · @getberrier