Surco (SURCO) — The Dual-Engine, Asset-Backed Vault
Network: Base Layer 2 Underlying Asset Layer: Pinto.money (Beanstalk fork; Diamond 0xD1A0D188E861ed9d15773a2F3574a2e94134bA8f) Document Classification: Technical Architecture Overview Revision: 2026-07-21 — fees updated to the on-chain 1% mint / 1% redeem (governance-raised 2026-07-21; both timelock-governable). Redeem fee now recycles the redeemed SURCO to the reserve box rather than burning it (supply-preserving, NAV-neutral; ADR 0029). Fee split unchanged: 50% Silo / 50% Staker (developer compensation is a separate 5% performance fee on seigniorage plus a founder staking position, ADR 0019).
Scope — what actually ships in v1. This paper describes the full two-engine design, but v1 ships only Engine 1. Everything runs on a governed EIP-2535 Diamond — upgrades go through a 48-hour timelock owned by a Gnosis Safe (§4.5).
- Live today: mint / redeem, the collective Pinto Silo, time-locked staking, the liquid cushion + three-zone circuit breaker, the Engine-1 fee router (50% Silo / 50% Staker), and keeper compounding (
plantSilo). Mint and redeem fees are 1% each. Supply is a fixed 100,000,000 SURCO — the number is just a denomination choice; the fixed cap is the point. The token is a standard ERC-20 served by the diamond, so it's fully listable. - Coming post-v1 (added later by timelocked
diamondCut, tagged(post-v1)where they appear): Engine 2 (the temperature-matched credit portal), Hyper-Burn, the entire Field surface, and the emergency liquidity manager. - Developer pay is separate from the fee split: a 5% performance fee on seigniorage plus a founder staking position (ADR 0019).
- Legal: SURCO is a redeemable vault token backed by the treasury — not equity, shares, or a security. Securities counsel is required before any public offering.
Abstract
The DeFi trap: you either keep your money liquid or lock it up to earn — and locking it up is exactly how protocols get run on when the market turns.
Surco is a fixed-supply, asset-backed vault on Base. You mint SURCO by depositing PINTO, and every SURCO is a redeemable claim on the protocol's PINTO treasury. Under the hood, that treasury pools everyone's PINTO into one collective Silo position and runs its own on-chain liquidity — so your need to exit fast and the protocol's need to keep capital working don't have to fight.
The full design has two engines: a fee router that grows the backing, and a credit portal that matches locked capital to Pinto's Field yield. v1 ships the first engine — the fee router, the collective Silo, time-locked staking, and the redemption cushion. The credit portal and the optional buy-and-burn come later, as timelocked upgrades. The NAV (Net Asset Value) that prices everything reads only protocol-owned on-chain balances, so it can't be flash-loaned.
One rule sits above all of it: circulating SURCO is always an honest, redeemable claim on real PINTO — and nothing is allowed to quietly dilute that claim.
1. Core Tokenomics & Valuation
1.1 Supply Segregation
There's no inflation here. At launch, exactly 100,000,000 SURCO is minted once — and there is no code path to ever mint more. That fixed supply is split across three ledgers:
- Circulating (
): SURCO in user wallets and trading on AMMs / the protocol-owned well.
- Reserve Box (
): SURCO the contract holds and hasn't released. In v1 it does triple duty — it's the source for new mints, the pool that pays staker rewards at NAV, and the SURCO side of protocol-owned liquidity. None of it counts as circulating. (It also backs Engine 2's lock premium once that ships, post-v1.)
- Protocol-LP (
): Reserve SURCO currently sitting inside the protocol-owned well. Also non-circulating.
1.2 Net Asset Value (NAV)
NAV is what one SURCO is worth in PINTO — its book value, backed by real assets in the treasury. (To be clear: SURCO is a redeemable vault token, not equity, shares, or a dollar-pegged stablecoin.) In PINTO terms, NAV is built from:
Field-at-Cost
(post-v1): When the Field ships, PINTO sown into it is carried at cost until its Pods mature, then booked as harvested PINTO — no unrealized gains, no value vanishing the moment capital gets deployed. In v1 this term is always zero, so NAV is simply liquid PINTO + the Silo deposit + the protocol-LP PINTO leg.- USD price is just
; internally, the protocol only ever thinks in PINTO.
In the full design, NAV per token climbs from both ends: buy-and-burns shrink the denominator (supply) while yield and fees grow the numerator (backing). In v1, Hyper-Burn is deferred, so supply isn't actively shrunk yet — NAV grows purely from the numerator: retained mint/redeem fees plus compounded above-peg Silo yield, against a fixed cap. The burn lever comes post-v1.
1.3 Flash-Loan Immunity by Construction
NAV reads only protocol-owned on-chain balances — liquid PINTO, the Silo deposit, the protocol-LP PINTO leg (and Field-at-cost once the Field ships; zero in v1). It never reads a market or well spot price, so there's simply no price surface for an attacker to move inside a single block. Pinto's own Germination rule backs this up: newly deposited capital sits in a ~2-hour (2-Season) quarantine before it counts toward any balance or oracle, which kills flash-capital attacks at the protocol layer.
2. The Dual-Engine Architecture
SYSTEM ENGINE TOPOLOGY
┌──────────────────────────────────────────────────────────────────────────┐
│ TOTAL ASSET TREASURY │
└────────────────────┬───────────────────────────────┬─────────────────────┘
│ │
▼ ▼
[ ENGINE 1: UNIFIED FEE ROUTER ] [ ENGINE 2: MATCHED CREDIT ]
(LIVE in v1) (DEFERRED — post-v1)
3 sources -> 1 router Manual, dynamic speculation
* Mint fee 1% PINTO * Users lock SURCO below peg (soil-gated)
* Redeem fee 1% (PINTO value) * Premium scales with live Temperature
* Perf fee 5% Silo yield * Surplus field yield lifts the floor
-> cushion-first -> growth buckets * Tightens active market supply
2.1 Engine 1: The Unified Fee Router (50/50 Staker / Backing Split)
Instead of a flat transaction tax (which hits your principal and is easy to route around anyway), Engine 1 takes three revenue sources and feeds them into one router: fill the cushion first, then the growth buckets. It leans with the cycle — defensive below peg (build liquidity), growth above peg (distribute Silo yield).
- Mint fee (1%, in PINTO): Charged when you deposit. Keeps the well price inside a ±1% arbitrage band around NAV.
- Redeem fee (1%, in PINTO value): Charging
pays the redeemer
and keeps
of PINTO value in the treasury, routed through the same buckets as everything else. The full
redeemed SURCO goes back to the Reserve Box — supply-preserving and NAV-neutral (ADR 0029). It is not burned. (An opt-in burn lever could be added later if it's ever wanted.)
- Performance fee (5%): Skims the collective Silo's native Bean/Stalk yield (near zero below peg) to the developer allocation. It taxes gains, not principal, so it never discourages deposits — the rest of the seigniorage compounds back into the floor.
All three route cushion-first: each tops the liquid cushion up to its target, then splits the rest across v1's two NAV levers — Silo 50% / Staker 50%. Developer pay isn't in this split (see below).
- 50% → Silo re-deposit ("Loyalty Dust"): Re-deposited into the collective Silo, permanently growing treasury value and protocol Stalk-Age. In v1, this bucket also absorbs the two deferred shares below — both were holder-accretive levers, so parking their weight in the Silo keeps that capital productive instead of idle until they ship.
- 50% → Staker rewards: Paid to active time-locked stakers in SURCO released from the Reserve Box (
), backed by the retained PINTO.
- Field Sow & Hyper-Burn
(post-v1): Originally 10% each — sow into the Field for Pod yield, and burn SURCO to shrink supply. Both are deferred; until they ship, their fee weight folds into the Silo bucket above.
Bottom line: half of all fee revenue is accretive to every holder (NAV floor growth via the Silo, including the folded-in Field/Burn shares), and half is concentrated on active stakers. Developer pay is separate — the 5% performance fee plus a founder staking position (ADR 0019) — and does not come out of this split.
2.2 Engine 2: The Manual Yield-Matching Portal (Deferred — post-v1)
This whole engine is deferred(post-v1). It needs the Field surface, which isn't in v1; it ships later via timelockeddiamondCut. Everything below is the forward design, not current behavior.
Engine 2 is for high-conviction users who'll trade liquidity for asymmetric credit yield. It ties a lock directly to Pinto's live Field data. When you lock SURCO:
- The contract checks that Field Soil is available and live Temperature
clears a minimum hurdle. This soil-gating means you can only lock during contraction.
- It computes effective
with
, earmarks
SURCO from the Reserve Box as your premium, and pulls the locked
plus that premium out of circulation.
- It sows
of treasury PINTO into the Field at the full live rate
.
- Settlement: Once the Pods mature, the contract returns your original
plus the
premium. Any field surplus beyond the premium —
X × NAV × (T - Te)%— stays in the vault permanently, lifting the backing floor for all holders. - Risk/reward: Low Temperature means a healthy protocol (a short Pod Line being harvested), so low-
locks mature fast for a small premium; high-
locks pay big but may mature slowly. Locks are irrevocable until maturity — no early exit.
3. Staking Mechanics & The "Stalk-Monster" Vault
3.1 Two Core User States
- Liquid SURCO: Held or traded. You get passive NAV exposure — you benefit from all treasury growth as NAV rises — with a
multiplier on active staker rewards.
- Staked: Locked in the contract. You earn multiplier-weighted staker rewards on top of that NAV appreciation.
3.2 Time-Locked Staking Tiers
To keep out short-term mercenary capital, staker rewards scale with how long you lock:
- Explorer Tier (2 Months Lock):
multiplier
- Accumulator Tier (1 Year Lock):
multiplier
- Maximalist Tier (4 Years Lock):
multiplier
You can't unstake before your unlock timestamp. After it, your position keeps its multiplier until you actually withdraw.
Rewards are denominated in value (the PINTO bucket) but paid in SURCO released from the Reserve Box at NAV. So as NAV rises, the same reward value releases fewer SURCO tokens — which naturally slows how fast the reserve drains (your reward value is unchanged; only the token count drops). If the reserve ever hits a hard floor, SURCO release pauses and rewards accrue as PINTO-value claims instead (the backing is already secured in the treasury), then pay out in SURCO once redemptions refill the reserve — which tends to happen exactly when selling is low and demand is strong.
3.3 The Collective Stalk Pool & "Loyalty Dust"
Instead of giving each user their own slice of Pinto's Silo, the protocol pools 100% of treasury PINTO into the Silo as one position. That creates the Stalk-Monster effect:
- Socialized Stalk-Age: The pool's Stalk, Grown Stalk, and Seeds are a protocol-level asset. Their yield (above-peg Bean mints to the collective Stalk) flows into the treasury and lifts NAV for every holder, pro-rata by SURCO held.
- Interruption-minimized aging: Redemptions come out of the liquid cushion first, so the collective deposit is left alone to age and hoard Seeds/Stalk. The moment Pinto goes above peg, that aged vault grabs an outsized share of the global mint.
- Loyalty Dust: The Silo re-deposit stream from Engine 1 keeps growing that foundational Stalk-Age.
- Compounding seigniorage: Above-peg Earned Beans that aren't skimmed by the performance fee are mostly planted (re-deposited via Pinto
plant()) to compound the collective Stalk, with a slice kept liquid for the cushion.
The vault would rather never un-stake. Redemptions are served first from the liquid cushion, then — only if that's not enough — from mature (settled) Silo balances, using a LIFO (last-in-first-out by stem) queue that protects the oldest, highest-yielding deposits and never touches germinating Stalk-Age. This is a preference order, not a guarantee of on-demand redemption — §4.1 covers what happens when both run dry.
4. Risk Mitigation & Security Topography
4.1 The Liquid Cushion & Three-Zone Circuit Breaker
A liquid cushion absorbs everyday redemptions — target ~10% of treasury NAV at genesis, topped up to a 15% ceiling by above-peg seigniorage, and refilled by fee inflows. When you redeem, the contract works through three zones:
- Zone 1 — Cushion: If the cushion
your request, you're paid at NAV straight from the cushion. The Silo is untouched.
- Zone 2 — Silo drawdown: If the cushion isn't enough but mature Silo balances can cover the rest without touching germinating deposits or eating slashing penalties, the contract un-stakes that mature balance and pays you at NAV.
- Zone 3 — Circuit breaker: If mature balances can't cover it safely, the breaker trips. Direct redemptions are rejected until fresh inflow arrives, and you're pointed to the external SURCO/PINTO market as the standing exit — which shields the germinating Stalk-Age.
Straight talk on redemption (v1). Surco redeems at full NAV — cushion first, then mature Silo balances. It does not promise continuously-available, on-demand redemption. In an extreme, sustained sell-off both sources can run dry, and at that point direct redemptions pause until the treasury next takes in inflow. Right at that edge, getting served is a gas-priority race — earlier transactions go through, later ones are rejected, never haircut. Anything that does execute executes at full NAV: no forced discount, no dilution of whoever's left. Time-locked staking and cushion-first routing limit how hard the float can run, but the honest tail behavior is a pause, not a guarantee of liquidity.
4.2 Below-Peg Liquidity Defense
The protocol is asset-heavy and cash-light, and below peg its only real PINTO inflows are deposits and fees (Silo seigniorage only accrues above peg; the Field is post-v1) while arbitrage leans toward redemption. So v1's redemption defense is the cushion-first router plus the three-zone breaker, with two more layers arriving alongside the deferred modules:
- Cushion-first fee routing (live): Every fee source (mint, redeem, performance) tops the cushion up to its target before anything else, so a sell-off's own redeem fees refill the cushion exactly when it's under stress. Combined with the three-zone breaker (§4.1), this guarantees the protocol never redeems at the expense of germinating Stalk-Age — but, as §4.1 spells out, it does not guarantee redemption is always available. When the cushion and all mature Silo balances are exhausted while the rest is still germinating, Zone 3 pauses direct redemptions until the next inflow (a deposit, fees, above-peg seigniorage, or deposits maturing). For guaranteed exit at any moment, the external SURCO/PINTO market is the always-open venue; the protocol's own redemption is availability-gated by design, so a run can't force it to liquidate germinating positions or dilute holders.
- Cushion-floor guard
(post-v1): Once Engine 2 sowing and the Hyper-Burn market-buy ship, neither is allowed to pull liquid PINTO below the cushion target. (Hyper-Burn doesn't destroy PINTO — it moves it into the well, where the protocol keeps its LP share — but it does shrink the liquid cushion, so the guard applies.) Neither exists in v1, so there's nothing for it to constrain yet. - Emergency replenish
(post-v1): A LiquidityMgr that sells Reserve-Box SURCO into the well for PINTO at ≈NAV (NAV-neutral), topping up liquid cash without un-staking the Silo. Deferred; added later via timelocked upgrade.
4.3 Automation & Gas
You pay your own gas for deposits and redemptions — cents on Base. The protocol's routine upkeep in v1 — compounding above-peg Silo yield (plantSilo → Pinto plant()), routing accrued fees through the cushion-first split (distribute), and settling staker rewards each round (distributeStakerRewards) — is exposed as permissionless diamond entrypoints (batched by a thin Keeper helper). Anyone can call them, and each is a no-op when nothing is due, so they can't be spam-farmed. The developer allocation funds the team's own keeper bot as a liveness backstop. There's no hard real-time SLA — everything is threshold- or opportunity-triggered. (The deferred modules bring their own upkeep — Hyper-Burn buys, Field sowing and harvests, emergency replenish — once they're cut in.) And because the contract holds one collective Silo position for everyone and tracks rewards with O(1) cumulative indexes — never looping over users — per-user gas stays low and bounded.
4.4 Protocol-Owned Liquidity & Staging
PINTO liquidity lives in Basin wells (Pinto Exchange, a permissionless Basin fork), not on Aerodrome. The liquidity layer rolls out in two stages:
- Stage 1 (launch): Deploy and seed a SURCO/PINTO Basin well. The Reserve Box supplies the SURCO side (non-circulating, zero dilution) and LP-bucket users supply the PINTO, taking the swap fees and impermanent-loss exposure on their slice. NAV counts only the PINTO leg — a token can never back itself. This well is the public market for getting in and out (and, once Hyper-Burn ships post-v1, the venue for its market-buys).
- Stage 2 (later, via Pinto governance): Whitelist the SURCO/PINTO well-LP in the Pinto Silo so it earns trading fees and Stalk/Seeds at once, and add multi-token access pools (SURCO/WETH, SURCO/USDC, etc.) on Basin and/or Aerodrome/Uniswap — kept off the NAV books so SURCO/PINTO stays the flash-safe NAV anchor. The venue sits behind an interface, so Stage 2 is purely additive — no core rewrites.
4.5 Composability, Listability & Governance
The token and the protocol are two different things. The protocol is the upgradeable EIP-2535 Diamond described below. The SURCO token is just a standard ERC-20 (name / symbol / decimals / totalSupply / balanceOf / allowance / transfer / approve / transferFrom, plus EIP-2612 permit) exposed by the diamond's Token facet at the diamond address. To any wallet, DEX, aggregator, or exchange, that address answers every ERC-20 call like a totally normal token — the Diamond pattern is an internal detail, exactly like it is for the many widely-listed tokens that live behind upgradeable proxies. So listability is unaffected.
SURCO is deliberately plain: transfers are never pausable or restricted — no transfer tax, no rebasing, no blacklist, 18 decimals (the circuit breaker halts direct redemptions only, never token movement) — and there's no mint path beyond the fixed 100M cap. Anyone can spin up external Aerodrome / Uniswap / Basin pools at any time; they stay off the NAV books. (Because the protocol is upgradeable, an exchange's listing review may flag that in due diligence — it's a disclosure item gated by the governance below, not a barrier.)
The protocol runs as a governed EIP-2535 Diamond: one permanent contract address whose facet logic can evolve via diamondCut — to fix bugs, add the deferred modules, and track changes in the Pinto protocol it depends on. That's an honest trade-off: upgradability creates value (the protocol can improve) and risk (the upgrade key could change behavior). Rather than pretend the bytecode is frozen, Surco asks you to trust the process — which is gated like this:
- Timelock (≥48h):
diamondCutis owned by a TimelockController, not an EOA. Every upgrade has to be proposed on-chain (publicly visible), wait a minimum 48 hours, and only then execute — giving you a 48-hour window to review a pending change and exit before it lands. - Safe multisig (N-of-M): The Timelock's only proposer/executor is a Gnosis Safe. No single key can propose or execute an upgrade — the Safe's signer threshold has to agree.
- Guardian (pause only): A separate, narrow Guardian role can pause redemptions (the emergency latch) but cannot mint, move funds, change accounting, or start an upgrade.
Parameters move at two speeds. Value-redirecting settings — mint/redeem fee rates, the seigniorage→staker share, the dev address, role grants — only execute through the 48-hour timelock. Operational knobs — the cushion floor/ceiling target, scan/slippage caps — are direct Safe controls that apply instantly. Because the diamond is genuinely upgradeable, "trust the math" becomes "trust the math and the timelocked governance that can change it."
5. Conclusion
That's the system. Fix the supply, pool everyone's Stalk-Age into one collective position, anchor NAV to real protocol-owned balances, and serve redemptions through a liquid cushion and three-zone breaker that pushes acute strain out to the secondary market instead of onto remaining holders. v1 does that today — separating your need for liquidity from the protocol's need for capital efficiency. Post-v1 adds credit-matched locks scaled to live Field Temperature (Engine 2) and a deflationary buy-and-burn (Hyper-Burn), both via timelocked diamondCut. The result is a flash-safe vault built to harvest value from algorithmic credit cycles and compound it into the floor beneath every SURCO holder.