T-Bill Anchored DeFi
A reference basket of DeFi vaults whose terminal-underlying exposure is a tokenized T-bill or T-bill-backed stable, with at least eighty percent off-chain backing. Every constituent is a vault (not a raw asset) so depositors get on-chain composability. The underlying-backing rule keeps the basket anchored to short-duration cash-equivalent collateral rather than open DeFi credit risk. The universe is currently small because regulated RWA-direct DeFi markets are an emerging segment. v1.2.1 adds a max_per_protocol_pct=45 selector clamp to provide a five-point structural buffer before the hard issuer cap because Ethena Labs currently sits near the cap through aEthUSDtb and steakUSDTBethena.
Summary
A reference basket of DeFi vaults whose terminal-underlying exposure is a tokenized T-bill or T-bill-backed stable, with at least eighty percent off-chain backing. Every constituent is a vault (not a raw asset) so depositors get on-chain composability. The underlying-backing rule keeps the basket anchored to short-duration cash-equivalent collateral rather than open DeFi credit risk. The universe is currently small because regulated RWA-direct DeFi markets are an emerging segment. v1.2.1 adds a max_per_protocol_pct=45 selector clamp to provide a five-point structural buffer before the hard issuer cap because Ethena Labs currently sits near the cap through aEthUSDtb and steakUSDTBethena.
Constituent Type
Vault (each constituent is a DeFi vault holding a qualifying terminal-underlying asset)
Minimum constituents are 2.
Eligibility Rule
A vault is eligible when its Philidor risk tier is Prime or Core, its review_status is "reviewed", its terminal_underlying.category is tokenized_treasury or t_bill_backed_stable, and the terminal_underlying.backing_offchain_pct is at least eighty percent. Vaults whose terminal exposure is open DeFi credit, LSTs, LRTs, or synthetic stables are excluded.
Structured form
The rebalancer reads this exact shape.
{
"asset_category": [],
"review_status": ["reviewed"],
"terminal_underlying_category": ["tokenized_treasury", "t_bill_backed_stable"],
"terminal_underlying_min_backing_offchain_pct": 80,
"tier": ["Prime", "Core"]
}Weighting Rule
Each constituent receives a raw weight proportional to its risk score above 6.0. Raw weights are then normalised so the basket sums to the full allocation. The pivot is set lower than Basket A's (7.0) because the on-chain T-bill-anchored DeFi universe is currently concentrated in newer institutional markets (e.g. Aave Horizon) which haven't yet built the multi-year track record that justifies a 7.0 floor.
Formula
w_i ∝ (risk_score_i − 6.0); normalize so Σ w_i = 1.0Worked Example
| Constituent | Risk Score | Raw Weight (score - pivot) | Normalised Weight |
|---|---|---|---|
| Constituent A | 8.00 | 2.00 | 38.10% |
| Constituent B | 7.50 | 1.50 | 28.57% |
| Constituent C | 7.00 | 1.00 | 19.05% |
| Constituent D | 6.50 | 0.50 | 9.52% |
| Constituent E | 6.25 | 0.25 | 4.76% |
| Sum | - | 5.25 | 100.00% |
This table shows the raw normalisation step before cap redistribution. If a constituent exceeds the single-name cap or falls below the floor, the rebalancer iteratively trims or removes it and redistributes the excess across the remaining names in proportion to their current weights, repeating until all caps and the floor are simultaneously satisfied within 50 iterations.
Caps
| Cap | Value | Meaning |
|---|---|---|
| Single-name | 50% | No constituent may exceed this share of the basket. |
| Issuer | 50% | Cross-chain deduplicated; aggregate exposure to one issuer is bounded. |
| Floor | 2% | Any constituent below the floor is dropped before final normalisation. |
Refresh Schedule
Rebalances run on the last business day of March, June, September, and December at 16:00 UTC. They also fire when any constituent crosses a tier boundary, moves by at least 0.5 in risk score, when a new eligible name enters the universe, or when the methodology version changes. Rating-triggered rebalances are throttled to at most one every 14 days. Calendar rebalances always fire and are not throttled.
Structured form
The rebalancer reads this exact shape.
{
"calendar_day": "last_business_day",
"calendar_months": [3, 6, 9, 12],
"calendar_time_utc": "16:00",
"rating_move_throttle_days": 14,
"rating_move_triggers": [
"tier_change",
"score_delta_ge_0_5",
"new_eligible_entrant",
"methodology_version_change"
]
}Halt Conditions
The rebalancer enforces the following halt-closed invariants. When any of these fails the rebalance aborts and the prior published version is preserved. Alerts page the on-call.
| ID | Description |
|---|---|
| I1 | Every constituent must have a non-null issuer_id and risk_score and review_status = "reviewed". Otherwise the constituent is rejected. |
| I2 | The eligible set must contain at least min_constituents names. If it falls below, the rebalance aborts and the prior published version is preserved. |
| I3 | Eligible-set turnover versus the prior version must not exceed 50%. A higher turnover triggers a "universe shock" abort with the prior version preserved. |
| I4 | The indexer must have a successful run within the last 6 hours. Stale ratings abort the rebalance and the prior version is preserved. |
| I5 | Cap-redistribution must converge within 50 iterations. Otherwise the rebalance aborts; equal-weight fallback only runs with an explicit operator flag. |
| I6 | The published weights must sum to 1.0 within 1e-6. The database CHECK constraint refuses to commit a version row that violates this. |
| I7 | Calendar and rating-move rebalances are mutually exclusive per basket via a Postgres advisory lock; a second concurrent rebalance exits cleanly. |
| I8 | Every published version is content-hash signed; the current_version_id pointer is moved atomically only after constituents and signature are written. |
| I9 | Every version is reproducible from frozen inputs stored in basket_version_inputs; CI replays the latest version and asserts byte-equality of canonical JSON. |
| I10 | The methodology doc_url must resolve with HTTP 200 before publish. A missing or 404 doc aborts the rebalance. |
Version
Current methodology version 1.2.2
Methodology document URL docs page
Change Log
- 1.2.2 Voice-compliant human prose reconciliation.
RWA T-Bill Conservative
A reference basket of pure real-world-asset and tokenized T-bill assets that have cleared Philidor's Prime/Core review with explicit issuer and reserve provenance. The basket targets a conservative liquidity-and-credit profile where every name is an asset (not a vault) whose primary failure mode is bounded by the issuer's regulated reserves, and weights tilt toward the highest Philidor risk scores subject to single-name and issuer caps.
USDC Core DeFi Vaults
A reference basket of pure-USDC DeFi lending vaults at Philidor's Core risk tier (5 ≤ risk_score < 8). v2.1.1 keeps the v2.0 diversification rules with capped constituents, protocol diversity, a forty percent curator cap, the vault TVL floor, and the 6-month protocol-age floor. It also keeps v2.1 asymmetric requalification and adds an ERC-4626-compatibility filter that excludes SparkLend money-market positions (`SparkLendEthereum`) for the same reason as the Prime basket. SparkLend aTokens are not natively ERC-4626 and no Philidor-endorsed 4626 wrapper path is currently maintained. Constituents are auto-demoted on incident-clamp, hard-fail-flag, or sustained downward drift before a tier-crossing event materializes.