Skip to Content
UnwindLiquidationsLiquidation auctions

Liquidation auctions

Unwinding escrows that turn unhealthy during asynchronous settlement are liquidated through a competitive auction. The interim collateral backing the escrow cannot be flash-sold, so the auction does not hand the bidder any collateral: the winner funds part of the debt repayment in the base asset, the protocol seizes and burns the matching interim collateral, the request’s already-submitted redemption keeps settling through the asset’s own process, and the winner holds a deferred claim in the base asset on those proceeds.

Rounds are opened by a Keyring-held role, which also sets each round’s repay amount, bonus ceiling, and bidding and execution windows. Submitting a bid requires a valid Keyring credential for the market’s auction policy, where the market sets one; execution, bond withdrawal, and the payout claim are not checked again. Participation is otherwise permissionless.

A liquidation auction end to end, recorded in the app on a fork devnet.

How it differs from a classic liquidation

Mechanism
A reverse-bonus auction over a bidding window: bidders quote the bonus they will accept for performing the liquidation, and the lowest bonus at close wins. Each round is opened with a maximum bonus, and a bid above that ceiling is rejected. Each new bid must also undercut the current best by a configured minimum decrement, except where that decrement rounds down to zero, in which case an equal bonus is accepted and the later bidder takes the lead.
When the winner is paid
After the request settles and is finalised, which is asynchronous. The liquidation itself happens while the request is still redeeming, so capital is locked from execution until claim.

The lifecycle

  1. Bid. submitBid(roundId, bonus) while the round is open.
  2. Liquidate. After the auction ends and before the execution deadline, the best bidder funds the repay and calls executeWinningRound. If the executable repay comes in below the requested amount, the difference is refunded on the spot.
  3. Settle. The request’s redemption, submitted when the unwind was requested, keeps settling through the provider; liquidation seized and burned interim collateral and did not start a new redemption. A Keyring operator records the proceeds, all at once, only when the whole request is claimable. The Receipt NFT holder or the operator then finalises the request, which is possible only once no round is active and the manager is unpaused. Asynchronous, outside the bidder’s control.
  4. Claim. Once the request is finalised, the winner claims actualRepay + bonus with claimWinningRoundPayout(roundId), pro rata if the pool is short.
submitBid: lowestbonus leadswindow ends;best bid standsbest bidder funds repay;executeWinningRoundredemption settles;request finalisedclaimWinningRoundPayout:actualRepay + bonusRound openBidding closedExecutedFinalisedClaimedExpireddeadline passes with no execution, best bond slashedClosedno longer liquidatable for this repay:anyone closes the round, all bonds returned
The bonus prices the lockup and the seniority risk between execution and claim. Liquidation seizes interim collateral; it does not start a new redemption. A round that can no longer be executed has to be closed before anyone expires it, or the best bond is slashed.

Who executes on-chain

The winner never touches the lending market directly. When the best bidder executes, the auction contract calls the unwind manager, which grants its internal liquidator contract vault access transiently, executes the liquidation and debt repayment in a single batch, and revokes the access in the same transaction. No external address ever holds vault permissions, before, during, or after.

The bid bond

A bidder’s first bid in a round locks that bidder’s bond, a configured share of the round’s repay amount, denominated in the base asset. The bond is refundable when outbid (the current best bidder’s bond stays locked), is applied toward the repay at execution, and is slashed only when the round expires with the best bidder not having executed. A round closed because the escrow is no longer liquidatable for that round’s repay amount returns all bonds unslashed. Expiring a lapsed round (which slashes the best bidder’s bond) and closing an unliquidatable one are both permissionless; neither needs a privileged caller. Expiry does not check liquidatability, and closing does not check the deadline, so past the deadline the two are a race: a best bidder who can no longer execute must get the round closed before anyone expires it, or lose the bond.

Payout seniority

Settled proceeds are applied in strict priority: escrow debt closure first, the Keyring fee second, the winner’s entitlement third, the Receipt NFT holder’s residual last. The winner is senior to the holder but junior to debt closure and to the fee, so a settlement shortfall first eats the holder’s residual, then the winner’s entitlement. If several rounds executed against one request, the winners share the pool pro rata. The claim pays whatever the pool covers and closes the round; nothing can top it up afterwards, so any unpaid portion is a realised loss at claim time. If proceeds do not even cover the debt, the request cannot be finalised and no payout is possible. This seniority risk, not collateral slippage, is what the bonus must compensate.

4080120 unitshealthy, 1258053010tight, 11580530residual 0winner shortfall, 11080525-5fee shortfall, 8380winner 0debt shortfall, 7070-10 debt, cannot finalise
debt closed (senior) Keyring fee winner payout NFT holder residual shortfall
Illustrative rounds with debt 80 and a winner entitlement of 30 (repay 25 + bonus 5), in base asset units. The Keyring fee is a percentage of the settled proceeds; it is held at 5 units across the rows so they differ only in what the shortfall consumes. A shortfall eats the Receipt NFT holder's residual first, then the winner's entitlement, then the fee; proceeds that cannot close the debt block finalisation altogether.

Pricing a bid

Treat the bid as a reservation bonus: the lowest bonus at which the trade still clears the hurdle, bidding just above it.

  • Cost of capital over the lockup, from execution to settlement.
  • Shortfall premium: probability and severity of settled proceeds falling short, conditioned on being junior to debt closure. Usually the dominant term; it depends on the tokenised asset’s NAV stability, the provider’s reliability, and the headroom above the debt.
  • Bond carry, gas, and oracle fees (execution forwards value for oracle updates).
reservationbonuscost of capitalshortfall premiumbond carry + gas + oracle fees
Illustrative shares; the mix is trade-specific. The shortfall premium prices being junior to debt closure, so it moves with the tokenised asset's NAV stability, the provider's reliability, and the headroom above the debt.

The on-chain oracle determines liquidatability, not realised redemption value, so the tokenised asset’s redemption value, the settlement window, and the proceeds-over-debt headroom must be assessed independently before bidding. Liquidatability and the executable repay are re-checked at execution, and the repay is capped at what the lending market allows. If the escrow is no longer liquidatable at all, execution reverts; the round then has to be closed explicitly, returning all bonds with no profit, so a bonus that cannot actually be captured should never be priced in. Partial recovery is not symmetric: execution still succeeds at the clamped repay, while anyone can close the round in that same state.

The bond share, minimum bid decrement, and bidder policy are fixed per market when it is deployed. The repay amount, bonus ceiling, and bidding and execution windows are chosen per round by the account that opens it. Interfaces and events are listed under smart contracts.

Last verified on