Collateral shutdown
A branch can be shut down. The whole system can be shut down by shutting down every branch. Shutdown is a terminal state for a branch, there is no path back to normal operation. This page covers the triggers, the effects, and what stays alive afterward.
Triggers
A branch becomes shutdownable when any of these conditions hold:
- Branch TCR has fallen below its SCR (per-branch shutdown collateral ratio, set to MCR − 0.5% — e.g. 109.5% on WETH). The branch is dangerously undercollateralized and continuing to issue debt would be irresponsible. Anyone can call
BorrowerOperations.shutdown()to formalize. - Branch oracle is failing.
priceFeed.previewWillShutdown(false) == truemeans the feed is in a fallback state with no path to recovery. Anyone can callBorrowerOperations.shutdownFromOracleFailure().
The Aggregator also exposes:
Aggregator.tryAllShutdown() // attempts shutdown on every branch that reports shutdownable
Aggregator.getShutdownableBranches() returns (address[])
so a keeper can sweep all branches in one tx.
The protocol does not include an admin-only shutdown trigger. Shutdown is permissionless and condition-driven.
What changes on shutdown
When a branch is marked isShutdown[troveManager] = true:
| Subsystem | Behavior |
|---|---|
BorrowerOperations | New openTrove, withdrawRD, addColl etc. revert. closeTrove, repayRD, claimCollateral still work. |
InterestEngine | Interest stops accruing on the branch (effective rate set to 0; existing accrued interest is preserved). |
StabilityPool | SpIssuance stops emitting FEE for this branch. Existing depositor balances and gains remain claimable. |
Aggregator | Branch removed from the redemption basket weights (no normal-mode redemption). Branch removed from the cross-branch drip sweep. Branch's debt EMA stops being refreshed. |
Redemptions | Switches to shutdown pricing mode. Both base and Redemption Shield sorted lists are reachable. |
Liquidations | Still callable. Existing path (offset + redistribute) still works. |
In short: no new borrowing, no new SP incentives, but redemption and liquidation continue so the branch can wind down to zero.
Shutdown redemption pricing
In shutdown mode, redemption no longer uses the live oracle price minus a redemption fee. Instead, it applies a discount multiplier to the oracle price (or to a fallback if the oracle failed).
The multiplier depends on why the branch was shut down and how much time has passed:
Trigger Start Max discount Ramp window
-------------- -------------------------- ---------------------------------- -----------------------------------
TCR < SCR 1% premium (BASE_DISCOUNT) MAX_DISCOUNT_TCR_BELOW_SCR = 5% MAX_DISCOUNT_TIME_SCR = 1 day
Oracle failure same first-day ramp MAX_DISCOUNT_ORACLE_FAILURE ≈ 100% MAX_DISCOUNT_TIME_FAILURE = 14 days
The multiplier starts at 1 + BASE_DISCOUNT (1.01 — a 1% premium). The premium start is an
anti-griefing measure: shutdown redemptions bypass the redemption quota, so an instantly profitable
discount would make forcing a shutdown a prize that scales with branch size. The first hour is a
fast linear ramp from the 1% premium to a 1% discount (crossing break-even about 30 minutes in);
from that kink it ramps gently over the remaining 23 hours to the 5% cap. Both causes share the
identical first-day ramp; when
causes overlap, the contract takes the min of the two multipliers on their own clocks
(Redemptions._calcPriceMultiplier), so the schedule is continuous and monotonic — a cause flip can
never jump the price.
A redeemer hands the protocol RD; the collateral they receive is valued at
oracle price × multiplier. Below parity, redeemers receive more collateral per RD. At the
oracle-failure cap the multiplier approaches zero — the branch pays out whatever collateral remains
to whoever clears its debt. That's intentional: it lets the branch fully clear even when its price
feed is broken.
For TCR-below-SCR shutdowns, the discount is capped at 5% — much gentler, because the protocol still trusts the oracle and is just adding urgency to the wind-down.
Why troves with Redemption Shield enabled lose their shield
Inside shutdown mode, redemption can walk both books on the same discount schedule. The redemption shield's purpose was to delay redemption while the base book existed, but the branch is being wound down anyway, so that delay would just leave RD holders unable to exit.
The fairness argument: troves with Redemption Shield enabled paid a premium when the branch was operating. The premium they paid is captured in the branch's fee history. In shutdown, they get the same discount treatment as troves without it, but the protocol is also no longer accruing the premium against them. The deal balances at the moment of shutdown.
Effects across branches
A single-branch shutdown has cross-system consequences via the Aggregator:
- Basket weights:
_basketWeights()checksisShutdown[troveManagers[i]]and sets the shutdown branch's weight to 0. SubsequentAggregator.redeemCollateralcalls route 100% of the requested RD across the remaining active branches. - Drip sweep:
Aggregator.drip()skips shutdown branches. - Issuance quotas: the shutdown branch's quota is frozen.
- Debt EMA: the shutdown branch's base debt EMA stops contributing to total system debt.
Healthy branches keep operating normally. The only externally visible change for a borrower on a healthy branch is that they no longer share fees with the shutdown branch's depositors (because SP issuance there has stopped).
System-wide shutdown
The protocol doesn't have a "global shutdown" switch. System-wide shutdown is what happens when every branch has been shut down individually. There's no global state for it; each branch just transitions on its own conditions.
In a system-wide shutdown:
- All RD holders can redeem against whichever branch they choose, at that branch's discount schedule.
- No new borrowing anywhere.
- Liquidations on each branch continue until troves are cleared or oracle pricing is no longer trustworthy.
- The Aggregator effectively becomes a redemption-only contract.
What survives shutdown
| State | Survives |
|---|---|
| RD token | Yes, it's a standalone ERC-20 |
| Trove debt and collateral | Yes, claimable via redemption / liquidation / closeTrove |
| SP depositor balances and gains | Yes, claimable via withdrawFromSP |
| FEE staking lockups | Yes, earnings stop for that branch's fees, but principal and other-branch fees continue |
| FEE token | Yes |
| Pending redistribution rewards | Yes, applied on the next state-touching call |
| Front-end tags | Yes, preserved |
No admin can confiscate, freeze, or migrate user assets. Shutdown is a controlled wind-down, not a rug.
When not to use a shutdown branch
If a branch is in shutdown:
- Don't open a new trove on it. You can't.
- Don't deposit fresh RD into its Stability Pool. Deposits are still accepted, but FEE emissions for the pool have stopped, and you're just signing up for the wind-down's liquidation exposure with no upside.
- Do redeem RD against it. The discount schedule rewards early redeemers, and the branch's collateral has to clear.
- Do close your existing trove if you can. Repaying full debt and claiming collateral is unaffected by shutdown.
Deep dive
- Redemption mechanism: how shutdown branches are excluded from normal-mode routing.
- Shutdown redemption (user view): same content, less detail.