Skip to main content

Collateral shutdown

A branch can be shut down. The whole system can be shut down by shutting down every branch. Shutdown is a terminal state for a branch, there is no path back to normal operation. This page covers the triggers, the effects, and what stays alive afterward.

Triggers​

A branch becomes shutdownable when any of these conditions hold:

  1. Branch TCR has fallen below its SCR (per-branch shutdown collateral ratio, set to MCR − 0.5% — e.g. 109.5% on WETH). The branch is dangerously undercollateralized and continuing to issue debt would be irresponsible. Anyone can call BorrowerOperations.shutdown() to formalize.
  2. Branch oracle is failing. priceFeed.previewWillShutdown(false) == true means the feed is in a fallback state with no path to recovery. Anyone can call BorrowerOperations.shutdownFromOracleFailure().

The Aggregator also exposes:

Aggregator.tryAllShutdown()  // attempts shutdown on every branch that reports shutdownable
Aggregator.getShutdownableBranches() returns (address[])

so a keeper can sweep all branches in one tx.

The protocol does not include an admin-only shutdown trigger. Shutdown is permissionless and condition-driven.

What changes on shutdown​

When a branch is marked isShutdown[troveManager] = true:

SubsystemBehavior
BorrowerOperationsNew openTrove, withdrawRD, addColl etc. revert. closeTrove, repayRD, claimCollateral still work.
InterestEngineInterest stops accruing on the branch (effective rate set to 0; existing accrued interest is preserved).
StabilityPoolSpIssuance stops emitting FEE for this branch. Existing depositor balances and gains remain claimable.
AggregatorBranch removed from the redemption basket weights (no normal-mode redemption). Branch removed from the cross-branch drip sweep. Branch's debt EMA stops being refreshed.
RedemptionsSwitches to shutdown pricing mode. Both base and Redemption Shield sorted lists are reachable.
LiquidationsStill callable. Existing path (offset + redistribute) still works.

In short: no new borrowing, no new SP incentives, but redemption and liquidation continue so the branch can wind down to zero.

Shutdown redemption pricing​

In shutdown mode, redemption no longer uses the live oracle price minus a redemption fee. Instead, it applies a discount multiplier to the oracle price (or to a fallback if the oracle failed).

The multiplier depends on why the branch was shut down and how much time has passed:

Trigger          Start                        Max discount                         Ramp window
-------------- -------------------------- ---------------------------------- -----------------------------------
TCR < SCR 1% premium (BASE_DISCOUNT) MAX_DISCOUNT_TCR_BELOW_SCR = 5% MAX_DISCOUNT_TIME_SCR = 1 day
Oracle failure same first-day ramp MAX_DISCOUNT_ORACLE_FAILURE ≈ 100% MAX_DISCOUNT_TIME_FAILURE = 14 days

The multiplier starts at 1 + BASE_DISCOUNT (1.01 — a 1% premium). The premium start is an anti-griefing measure: shutdown redemptions bypass the redemption quota, so an instantly profitable discount would make forcing a shutdown a prize that scales with branch size. The first hour is a fast linear ramp from the 1% premium to a 1% discount (crossing break-even about 30 minutes in); from that kink it ramps gently over the remaining 23 hours to the 5% cap. Both causes share the identical first-day ramp; when causes overlap, the contract takes the min of the two multipliers on their own clocks (Redemptions._calcPriceMultiplier), so the schedule is continuous and monotonic — a cause flip can never jump the price.

A redeemer hands the protocol RD; the collateral they receive is valued at oracle price × multiplier. Below parity, redeemers receive more collateral per RD. At the oracle-failure cap the multiplier approaches zero — the branch pays out whatever collateral remains to whoever clears its debt. That's intentional: it lets the branch fully clear even when its price feed is broken.

For TCR-below-SCR shutdowns, the discount is capped at 5% — much gentler, because the protocol still trusts the oracle and is just adding urgency to the wind-down.

Why troves with Redemption Shield enabled lose their shield​

Inside shutdown mode, redemption can walk both books on the same discount schedule. The redemption shield's purpose was to delay redemption while the base book existed, but the branch is being wound down anyway, so that delay would just leave RD holders unable to exit.

The fairness argument: troves with Redemption Shield enabled paid a premium when the branch was operating. The premium they paid is captured in the branch's fee history. In shutdown, they get the same discount treatment as troves without it, but the protocol is also no longer accruing the premium against them. The deal balances at the moment of shutdown.

Effects across branches​

A single-branch shutdown has cross-system consequences via the Aggregator:

  • Basket weights: _basketWeights() checks isShutdown[troveManagers[i]] and sets the shutdown branch's weight to 0. Subsequent Aggregator.redeemCollateral calls route 100% of the requested RD across the remaining active branches.
  • Drip sweep: Aggregator.drip() skips shutdown branches.
  • Issuance quotas: the shutdown branch's quota is frozen.
  • Debt EMA: the shutdown branch's base debt EMA stops contributing to total system debt.

Healthy branches keep operating normally. The only externally visible change for a borrower on a healthy branch is that they no longer share fees with the shutdown branch's depositors (because SP issuance there has stopped).

System-wide shutdown​

The protocol doesn't have a "global shutdown" switch. System-wide shutdown is what happens when every branch has been shut down individually. There's no global state for it; each branch just transitions on its own conditions.

In a system-wide shutdown:

  • All RD holders can redeem against whichever branch they choose, at that branch's discount schedule.
  • No new borrowing anywhere.
  • Liquidations on each branch continue until troves are cleared or oracle pricing is no longer trustworthy.
  • The Aggregator effectively becomes a redemption-only contract.

What survives shutdown​

StateSurvives
RD tokenYes, it's a standalone ERC-20
Trove debt and collateralYes, claimable via redemption / liquidation / closeTrove
SP depositor balances and gainsYes, claimable via withdrawFromSP
FEE staking lockupsYes, earnings stop for that branch's fees, but principal and other-branch fees continue
FEE tokenYes
Pending redistribution rewardsYes, applied on the next state-touching call
Front-end tagsYes, preserved

No admin can confiscate, freeze, or migrate user assets. Shutdown is a controlled wind-down, not a rug.

When not to use a shutdown branch​

If a branch is in shutdown:

  • Don't open a new trove on it. You can't.
  • Don't deposit fresh RD into its Stability Pool. Deposits are still accepted, but FEE emissions for the pool have stopped, and you're just signing up for the wind-down's liquidation exposure with no upside.
  • Do redeem RD against it. The discount schedule rewards early redeemers, and the branch's collateral has to clear.
  • Do close your existing trove if you can. Repaying full debt and claiming collateral is unaffected by shutdown.

Deep dive​