Wash App · Structured credit on Solana Devnet · Sheet 1 of 1 · Rev A

Devnet demo. Simulated lending pool, test token from a faucet. Not on mainnet, not audited.

One deposit, two risks. A loss hits junior first.

Wash App slices a deposit into a lending pool into a senior tranche with a capped yield and a junior tranche that takes the rest of the yield and absorbs losses first. A separate market lets anyone buy or sell cover against a loss in that pool, settled on chain.

A · Before
Before the loss: the senior vessel is full to its level, the junior vessel below it holds its level, and the cover pool holds a reservation for the buyer. SENIOR JUNIOR COVER RESERVED FOR THE BUYER SENIOR LEVEL JUNIOR LEVEL
B · After a 15 % loss
After the loss: the senior vessel is at the same level, the junior level is lower with the lost part hatched, and the cover pool pays the buyer. SENIOR JUNIOR LOSS, BURNED FROM THE VAULT COVER PAYS 15 % OF NOTIONAL SENIOR · UNCHANGED JUNIOR · ABSORBS THE LOSS

Schematic, not to scale. When the loss is smaller than junior, senior keeps its value to the micro-unit.

Detail A

What it does

A1

Choose your risk at deposit

Senior earns up to its target rate and is first in line; junior earns everything left and is last. Each tranche is a token — sWUSD, jWUSD — priced at its own NAV.

A2

Losses fall in order

A loss of L hits junior first. Senior loses only L − junior, and only once junior is wiped out. Every loss is an account on chain anyone can read.

A3

Cover against the pool’s loss

Sellers fund a cover pool and earn premiums. Buyers pay a premium up front for a notional and a term. When a loss above the trigger is recorded, anyone can settle: the buyer receives notional × loss.

Detail B

How it works

  1. Deposit

    Base token in, tranche token out, one signature.

  2. Accrue

    Yield accrues on a model clock: on the demo pool one minute on chain is 30 model days (43,200×). Every instruction accrues first.

  3. Record a loss

    The pool operator records a loss in basis points; the program splits it junior → senior and writes a LossEvent account.

  4. Settle

    Anyone calls settle on an active cover contract; the payout is notional × loss_bps / 10,000, once. An unclaimed contract expires and its reservation returns to the sellers.

Pool 0 · Parameters
Pool yield
8 %/yr
Senior target
5 %/yr
Junior floor
20 %
Performance fee
10 %
Cover premium
2 %/yr
Cover trigger
1 %
Model clock
43,200×
Detail C

Measured

97.4 s
Full scenario on devnet from two fresh wallets — deposit, cover sold and bought, a 15 % loss, settle, expiry, redeem, withdraw — 16 transactions. Budget 180 s.
4.2 s
Slowest single step, from signature to the change visible over RPC. Budget 10 s.
+150.00
WUSD paid by one settle on a 1,000 WUSD notional for a 15 % loss, to the micro-unit: the buyer went from 95.04 to 245.04.
3 of 3
Second settles of the same contract refused in the program tests. A contract pays once.
0
Deviations of assets = senior + junior = vault over 100 random sequences of 24 steps with losses, checked after every step.
40,713
Compute units of the heaviest instruction, record_loss, against a 200,000 ceiling enforced in the test suite.
152
Waterfall cases generated from the on-chain program and reproduced exactly by the TypeScript mirror the app uses.

Measured on devnet on 30 September 2026 and in tests run on the program’s real bytecode. The demo token has no value.

Limits

Not in this demo

  • N1

    The lending pool is a simulation. Yield accrues at a configured rate; it is not Kamino, MarginFi or any external protocol.

  • N2

    Losses are recorded by the pool operator, not derived from prices or an oracle.

  • N3

    The cover premium is a fixed rate set for the pool, not a market price. Sellers share one cover pool; there are no individual offers.

  • N4

    No secondary market for tranche tokens or cover contracts.

  • N5

    Devnet only. No mainnet deployment, no audit, no protocol insurance.

  • N6

    The position view with a “what if the pool loses X %” forecast is the next release, not this one.

  • N7

    Time is a model clock, sped up 43,200×. A 90-day contract in the demo lasts three minutes.

Detail D

Questions

Is any of this real money?

No. The base token WUSD is a devnet mint handed out by a faucet on the pool page, 1,000 per request.

Who decides that a loss happened?

In this demo, the pool operator. Deriving a loss from an external pool’s state is out of scope.

What if the loss is larger than junior?

Junior goes to zero and senior loses exactly the excess, L − junior.

Do I have to file a claim?

No. Once a loss at or above the contract’s trigger is on chain, anyone can call settle; the payout goes to the buyer.