One deposit, two risks. A loss hits junior first.
Wash App slices a deposit into a lending pool into a senior tranche with a capped yield and a junior tranche that takes the rest of the yield and absorbs losses first. A separate market lets anyone buy or sell cover against a loss in that pool, settled on chain.
Schematic, not to scale. When the loss is smaller than junior, senior keeps its value to the micro-unit.
What it does
Choose your risk at deposit
Senior earns up to its target rate and is first in line; junior earns everything left and is last. Each tranche is a token — sWUSD, jWUSD — priced at its own NAV.
Losses fall in order
A loss of L hits junior first. Senior loses only L − junior, and only once junior is wiped out. Every loss is an account on chain anyone can read.
Cover against the pool’s loss
Sellers fund a cover pool and earn premiums. Buyers pay a premium up front for a notional and a term. When a loss above the trigger is recorded, anyone can settle: the buyer receives notional × loss.
How it works
-
Deposit
Base token in, tranche token out, one signature.
-
Accrue
Yield accrues on a model clock: on the demo pool one minute on chain is 30 model days (43,200×). Every instruction accrues first.
-
Record a loss
The pool operator records a loss in basis points; the program splits it junior → senior and writes a
LossEventaccount. -
Settle
Anyone calls settle on an active cover contract; the payout is
notional × loss_bps / 10,000, once. An unclaimed contract expires and its reservation returns to the sellers.
- Pool yield
- 8 %/yr
- Senior target
- 5 %/yr
- Junior floor
- 20 %
- Performance fee
- 10 %
- Cover premium
- 2 %/yr
- Cover trigger
- 1 %
- Model clock
- 43,200×
Measured
- 97.4 s
- Full scenario on devnet from two fresh wallets — deposit, cover sold and bought, a 15 % loss, settle, expiry, redeem, withdraw — 16 transactions. Budget 180 s.
- 4.2 s
- Slowest single step, from signature to the change visible over RPC. Budget 10 s.
- +150.00
- WUSD paid by one settle on a 1,000 WUSD notional for a 15 % loss, to the micro-unit: the buyer went from 95.04 to 245.04.
- 3 of 3
- Second settles of the same contract refused in the program tests. A contract pays once.
- 0
- Deviations of assets = senior + junior = vault over 100 random sequences of 24 steps with losses, checked after every step.
- 40,713
- Compute units of the heaviest instruction,
record_loss, against a 200,000 ceiling enforced in the test suite. - 152
- Waterfall cases generated from the on-chain program and reproduced exactly by the TypeScript mirror the app uses.
Measured on devnet on 30 September 2026 and in tests run on the program’s real bytecode. The demo token has no value.
Not in this demo
- N1
The lending pool is a simulation. Yield accrues at a configured rate; it is not Kamino, MarginFi or any external protocol.
- N2
Losses are recorded by the pool operator, not derived from prices or an oracle.
- N3
The cover premium is a fixed rate set for the pool, not a market price. Sellers share one cover pool; there are no individual offers.
- N4
No secondary market for tranche tokens or cover contracts.
- N5
Devnet only. No mainnet deployment, no audit, no protocol insurance.
- N6
The position view with a “what if the pool loses X %” forecast is the next release, not this one.
- N7
Time is a model clock, sped up 43,200×. A 90-day contract in the demo lasts three minutes.
Questions
Is any of this real money?
No. The base token WUSD is a devnet mint handed out by a faucet on the pool page, 1,000 per request.
Who decides that a loss happened?
In this demo, the pool operator. Deriving a loss from an external pool’s state is out of scope.
What if the loss is larger than junior?
Junior goes to zero and senior loses exactly the excess, L − junior.
Do I have to file a claim?
No. Once a loss at or above the contract’s trigger is on chain, anyone can call settle; the payout goes to the buyer.