MethodologyReference Baskets

USDC Core DeFi Vaults

A reference basket of pure-USDC DeFi lending vaults at Philidor's Core risk tier (5 ≤ risk_score < 8). v2.1.1 keeps the v2.0 diversification rules with capped constituents, protocol diversity, a forty percent curator cap, the vault TVL floor, and the 6-month protocol-age floor. It also keeps v2.1 asymmetric requalification and adds an ERC-4626-compatibility filter that excludes SparkLend money-market positions (`SparkLendEthereum`) for the same reason as the Prime basket. SparkLend aTokens are not natively ERC-4626 and no Philidor-endorsed 4626 wrapper path is currently maintained. Constituents are auto-demoted on incident-clamp, hard-fail-flag, or sustained downward drift before a tier-crossing event materializes.

Summary

A reference basket of pure-USDC DeFi lending vaults at Philidor's Core risk tier (5 ≤ risk_score < 8). v2.1.1 keeps the v2.0 diversification rules with capped constituents, protocol diversity, a forty percent curator cap, the vault TVL floor, and the 6-month protocol-age floor. It also keeps v2.1 asymmetric requalification and adds an ERC-4626-compatibility filter that excludes SparkLend money-market positions (SparkLendEthereum) for the same reason as the Prime basket. SparkLend aTokens are not natively ERC-4626 and no Philidor-endorsed 4626 wrapper path is currently maintained. Constituents are auto-demoted on incident-clamp, hard-fail-flag, or sustained downward drift before a tier-crossing event materializes.

Constituent Type

Vault (each constituent is a DeFi vault holding a qualifying terminal-underlying asset)

Minimum constituents are 5.

Eligibility Rule

A vault is eligible when its Philidor risk tier is Core, its asset_components array is exactly ["USDC"], is_stablecoin = TRUE, vaults.tvl_usd is above the basket TVL floor, the vault has been live at least 60 days, the underlying protocol has been live at least 180 days, and the vault's adapter external_id is not in the exclusion list. v2.1.1 excludes SparkLendEthereum because SparkLend aTokens are not natively ERC-4626 and no 4626 wrapper is currently endorsed. Spark Savings (4626) remains eligible. Core vaults that drop to Edge tier or fall under any floor are removed at the next rebalance. Core vaults upgraded to Prime move into the USDC Prime basket.

Structured form

The rebalancer reads this exact shape.

{
  "asset_category": [],
  "review_status": ["reviewed"],
  "terminal_underlying_category": [],
  "terminal_underlying_min_backing_offchain_pct": null,
  "tier": ["Core"]
}

Weighting Rule

Each Core constituent receives a raw weight proportional to its risk score above 5.0 (the Core tier floor). Raw weights are then normalised so the basket sums to the full allocation. The Core universe is broader than Prime, so caps lean tighter than the Prime basket to enforce diversification.

Formula

w_i ∝ max(0, risk_score_i − 5.0); normalize so Σ w_i = 1.0

Worked Example

ConstituentRisk ScoreRaw Weight (score - pivot)Normalised Weight
Constituent A7.002.0038.10%
Constituent B6.501.5028.57%
Constituent C6.001.0019.05%
Constituent D5.500.509.52%
Constituent E5.250.254.76%
Sum-5.25100.00%

This table shows the raw normalisation step before cap redistribution. If a constituent exceeds the single-name cap or falls below the floor, the rebalancer iteratively trims or removes it and redistributes the excess across the remaining names in proportion to their current weights, repeating until all caps and the floor are simultaneously satisfied within 50 iterations.

Caps

CapValueMeaning
Single-name20%No constituent may exceed this share of the basket.
Issuer40%Cross-chain deduplicated; aggregate exposure to one issuer is bounded.
Floor2%Any constituent below the floor is dropped before final normalisation.

Refresh Schedule

Rebalances run on the last business day of March, June, September, and December at 16:00 UTC. They also fire when any constituent crosses a tier boundary, when a hard-fail flag triggers, when an active-incident clamp applies, when a constituent's score moves up by at least 1.0, or when a constituent's score moves down by at least 0.3. The asymmetric thresholds reflect the institutional client posture because routine upward APY drift should not churn the basket, but any meaningful downward move on a current member must trigger requalification so deteriorating exposures are removed promptly. Rating-triggered rebalances are throttled to at most one every 30 days. Calendar rebalances always fire and are not throttled.

Structured form

The rebalancer reads this exact shape.

{
  "calendar_day": "last_business_day",
  "calendar_months": [3, 6, 9, 12],
  "calendar_time_utc": "16:00",
  "rating_move_throttle_days": 30,
  "rating_move_triggers": [
    "tier_change",
    "score_delta_ge_1_0",
    "score_delta_down_ge_0_3",
    "hard_fail_flag",
    "active_incident_clamp",
    "new_eligible_entrant",
    "methodology_version_change"
  ]
}

Halt Conditions

The rebalancer enforces the following halt-closed invariants. When any of these fails the rebalance aborts and the prior published version is preserved. Alerts page the on-call.

IDDescription
I1Every constituent must have a non-null issuer_id and risk_score and review_status = "reviewed". Otherwise the constituent is rejected.
I2The eligible set must contain at least min_constituents names. If it falls below, the rebalance aborts and the prior published version is preserved.
I3Eligible-set turnover versus the prior version must not exceed 50%. A higher turnover triggers a "universe shock" abort with the prior version preserved.
I4The indexer must have a successful run within the last 6 hours. Stale ratings abort the rebalance and the prior version is preserved.
I5Cap-redistribution must converge within 50 iterations. Otherwise the rebalance aborts; equal-weight fallback only runs with an explicit operator flag.
I6The published weights must sum to 1.0 within 1e-6. The database CHECK constraint refuses to commit a version row that violates this.
I7Calendar and rating-move rebalances are mutually exclusive per basket via a Postgres advisory lock; a second concurrent rebalance exits cleanly.
I8Every published version is content-hash signed; the current_version_id pointer is moved atomically only after constituents and signature are written.
I9Every version is reproducible from frozen inputs stored in basket_version_inputs; CI replays the latest version and asserts byte-equality of canonical JSON.
I10The methodology doc_url must resolve with HTTP 200 before publish. A missing or 404 doc aborts the rebalance.

Version

Current methodology version 2.1.3

Methodology document URL docs page

Change Log

  • 2.1.3 Voice-compliant human prose reconciliation.

On this page

Raw