How it works
Settlement and compensation
Each epoch settles from the onchain aggregates alone. The slash comes from a formula, and slashed USDG goes to the customers of the window.
allowed = floor((1 - availTarget) * probes) excess = max(0, fails - allowed) f = min(maxSlash 30%, min(capAvail 25%, excess * 10 bps) + 50 bps * hours over latency) S_L = f * assets_L junior first, then seniors pro-rata comp_c = min(3 * paid_c, S_USDG * paid_c / sum(paid))
The formula
Settlement waits until the epoch has ended and the later of the settle delay (2 h) and the post deadline (30 min) has passed, then anyone may call settle(bond). Epochs settle once and in order. The canary bond uses one-hour epochs, so its record moves every hour; the others settle daily.
Who pays
The slash is taken from each leg: the operator's junior tranche first, then senior backers through the share price. Slashed USDG goes to the Compensation contract. Slashed $PBI is sent to 0x...dEaD.
Who is paid
The customers of an epoch are the addresses that paid USDG to the service's payTo during it, read from public Transfer logs; x402 payments settle as such transfers. Each is paid at most three times what it paid, and the pot is shared pro-rata to payments. What is left goes to the reserve; with no onchain customers, all of it does.
Claiming
The publisher posts one Merkle root of (customer, amount, paid) and then submits every claim itself: a claim always pays the customer, whoever sends it. You can also claim with the SDK's claimCompensation or POST /api/v1/tx/claim-compensation. The contract refuses a root above the slash and a leaf above three times the payment.