docs
proof

Buybacks & reserves

Every credit's USDC, every burn, every buyback. On-chain, with its transaction.

proof of reserves

Credits, backed 1:1 by USDC.

Every burn is published: spent credits, credits unclaimed after the claim window, and earned credits unused for a year. Dashes until the audited credits program is live.

$125.00credit supply (1 credit = $1) test fixture
≤
$125.00USDC reserve reserve ≥ supply
our ledger expects$125.00
lock USDC moved in$0.00
autobuy for the lock (30%)$0.00
accounts5
dry-run
Where one dollar of spent credit goesExample: $1.00 of credit spent on a model billed to us at 80% of list. $0.80 pays the inference cost. The $0.20 margin pays the user's buyback token first (2% of the spend, $0.02 for an Elite account buying $XINF), then splits 50/50: $0.09 buys $XINF for the lock and $0.09 goes to $XAVA stakers in USDC. With zero margin there are no rewards.WHERE $1.00 OF SPENT CREDIT GOESexample: model billed at 80% of listINFERENCE COST$0.80MARGIN $0.20YOUR TOKEN $0.02buyback · 2%$XINF LOCK $0.09half the rest$XAVA $0.09stakers · halfthe margin, zoomedZero margin = no rewards: the whole dollar pays inference.
  • INFERENCE COST$0.80 pays what the model costs.
  • MARGIN$0.20 is margin, split below.
  • YOUR TOKEN$0.02 buys back the account's own token first.
  • $XINF LOCK$0.09 buys $XINF into the lock.
  • $XAVA$0.09 goes to stakers in USDC.

30% of the lock's USDC buys $XINF for the lock; the rest becomes holder credits; set by the public controller multisig <address TBD>. Changes wait 24 hours on chain, are capped at 70%, and are public events.

burn batches
closedbatchcredits burned→ operations (cost)→ users' own buybacks→ $XINF lock→ $XAVA stakersbatch hash · usage-log head
no credits burned yet: the first batch closes one hour after the first request

Each batch burns exactly one segment of the hash-chained usage log (its head is shown) and publishes its own chained SHA-256. Machine-readable: /api/credits/reserves.json.

bought, all tokens$0.00
$XINF bought—
custom tokens bought$0.00
batches0
treasuryon-chain

27uqc4DyqbgSZBEssSv75mk1bhcW27yHDWV6NrVWeYU1

balance is being read from the chain; it shows here within a minute

community

Community splits

Tokens ranked by what the community's settled spend actually sent them: 1 point is $0.01 directed. A split setting with no spend behind it scores nothing.

ranktokenpointsshareaccountsbought so far
No settled spend has been directed to a token in this range yet.
previouspage 1 of 1next

0 points across 0 tokens. Updated every 5 minutes. JSON: /api/buybacks/leaderboard.json.

totals

Per token

What each token's pool has bought so far.

per-token totals
tokenbatchesusdc intokens outlast batch
nothing bought yet
safety

How a buyback executes

Planned in public, re-checked by a separate executor, landed in a vault anyone can read.

How a buyback executes safelyEach day's buyback plan is published as text with its SHA-256. A separate executor with its own keys takes every job and runs six checks: the plan hash matches; the token is safe to buy; inside the per-job, per-day caps; price impact ≤ 1%; slippage ≤ 1%, ≥ 97.5% back; output to an allowlisted vault. A job that passes is swapped on-chain and lands in a public vault or the lock, which the executor's key cannot spend; anyone can hash the plan and check every swap on-chain. A job that fails a check, such as a token with a freeze authority, is refused: nothing is swapped and its dollars wait in USD.PLANhash publishedEXECUTORSWAPon-chainPUBLIC VAULTanyone can readVERIFYanyone, on-chain6 checks on every jobREFUSEDHow a buyback executes safelyEach day's buyback plan is published as text with its SHA-256. A separate executor with its own keys takes every job and runs six checks: the plan hash matches; the token is safe to buy; inside the per-job, per-day caps; price impact ≤ 1%; slippage ≤ 1%, ≥ 97.5% back; output to an allowlisted vault. A job that passes is swapped on-chain and lands in a public vault or the lock, which the executor's key cannot spend; anyone can hash the plan and check every swap on-chain. A job that fails a check, such as a token with a freeze authority, is refused: nothing is swapped and its dollars wait in USD.PLANhash publishedEXECUTORSWAPon-chainPUBLIC VAULTanyone can readVERIFYanyone, on-chain6 checks on every jobREFUSED
  • PLANEach day's buybacks, published as text with its SHA-256.
  • EXECUTORA separate app with its own keys runs six checks; a job that fails one is refused and waits in USD.
  • SWAPA job that passes is swapped on-chain.
  • PUBLIC VAULTThe $XINF or custom token lands in a public vault or the lock; the executor's key cannot spend it.
  • VERIFYAnyone can hash the plan and check every swap with the open-source watcher.
batches

Every swap

Daily from $50 per pool, capped at 1% price impact.

batches
datesourcetokenusdc intokens outavg priceimpacttxperiod root
no batches yet: the first one runs once a token's pool reaches $50
accruing

Waiting in USD

Held until a token is safe to buy. Nothing is lost.

accruing in usd
tokenusd waitingwhy it is not bought yet
nothing is waiting
monthly

The burn split, by month

50% to $XAVA stakers, 50% to $XINF buybacks locked forever. No team share.

monthly roll-up of the burn split
monthmargin at burnsdeficit insplitaffiliates50% less affiliates → $XINF lock50% → $XAVA stakers (USDC)deficit outstatus
the first month is rolled up early next month
audit

The usage ledger, published

Hash-chained, rooted daily, memo on-chain.

audit periods
periodusage rowsspend (list price)user buybacksmerkle rootchain headon-chain memo
the first period closes after the first day of usage
verify

Plan commitments

Hash the text yourself. It must match.

plan commitments
planjobssha256 of the per-mint amounts
no plan has been made yet

Machine-readable: /api/buybacks.json and /api/audit (one export per period). The open-source watcher script recomputes every root, chain head, total and bound from them and checks the memos and swaps on-chain. Explorer links open the transaction on Solscan.