Risks
On this page
- 1. In year one, there is effectively no external inflow
- 2. The price-compute link is dormant early
- 3. The utility floor is untested, and the only evidence points against it
- 4. The drip is the largest unmitigated legal exposure, and there is no geoblocking
- 5. The reserve can shrink in absolute terms while backing per token rises
- 6. The ways backing can actually fall
- 7. Our margin is an execution advantage, not a structural one, and anyone can copy it
- 8. The ticker collides with a tokenized stock on the same chain
- 9. The volume base stands on an expiring subsidy, and the fee rate can never be corrected
- 10. v0 is not trustless, and the trust that remains has moved
- 11. The retail question with the uncomfortable answer
This chapter is written for the reader looking for the flaw. It is not a disclaimer appendix; it is the counter-ledger, and it is held to the same standard of verifiability as everything else here. Nothing below is softened, and several of these points have no mitigation.
1. In year one, there is effectively no external inflow
The only inflow that does not come from trading our own token is the deposit fee on direct credit purchases, and in the worked base scenario it is about 0.5% of total inflows. The other 99.5% is fees on trading the token itself. The move to the higher fee rate made this ratio worse, not better: fee inflows grew 3.6x while the external inflow stayed the same size.
The strongest form of the objection, quoted from our own research rather than paraphrased into something weaker: we are not a company with a treasury; we are a treasury that exists as a reason to trade the token whose trading fills the treasury. The input is speculation, and speculative volume on memecoin launchpads has a half-life measured in weeks.
That is true at its core, and we do not argue it away. Hyperliquid and pump.fun, the working examples of fee-funded value return, earn their fees from third-party activity; ours come from our own token. The design makes this reflexivity non-fatal (backing per token does not fall at zero volume; outflows throttle automatically), but it does not cure it. The only way out is Workbench revenue from paying non-holders. It exists from before launch and it is small. Judge this project by whether the non-holder revenue share grows. If it does not, this risk is the whole story.
2. The price-compute link is dormant early
The sensitivity analysis in The Numbers shows that changing the burn assumption by a factor of ten, from 0.3M to 20M tokens per month, moves six-month backing by less than 1%. Early on, the backing trajectory is almost entirely inflow-driven. The mechanism that is supposed to connect price and compute exists mathematically and is economically invisible until substantial burn volumes exist.
3. The utility floor is untested, and the only evidence points against it
In the one comparable project we verified on-chain, 4 of 1,145 holders ever used the burn-to-redeem function, for $113.77 in total. The mechanism is provably real; its usage is not. A redemption value that nobody exercises disciplines nothing. Our Workbench lowers the redemption barrier compared to raw API keys, but that is a hypothesis, not a finding, until our own redemption numbers exist. The reserve page publishes claims per month, consumed credits, and non-holder revenue share from day one so that this hypothesis is falsifiable in public.
And sharper, before a critic says it: the redemption value is also the ceiling. If volume dies, the market price converges down toward the backing; the backing is then the terminal valuation, not a floor under anything. If demand for machine work itself also dies, the economic value is zero with a full reserve, because nobody wants the only thing the reserve pays out. This is why our copy never says "price floor" and always says "redemption value". The distinction is not stylistic.
4. The drip is the largest unmitigated legal exposure, and there is no geoblocking
A distribution for merely holding structurally resembles a dividend. Under the US Howey analysis it is the strongest single factor ("expectation of profits from the efforts of others"); under MiCA it strains the definition this design would otherwise most resemble. The SEC's Interpretive Release 33-11412 (March 2026) explicitly names backing language, reserve growth, and buyback mechanisms as investment-contract indicators.
The operator has decided: the drip stays as designed, and there is no geoblocking, including for US persons. US exposure is live. Legal review is running in parallel with counsel; it is not concluded. The remaining controls are therefore load-bearing, not cosmetic: language hygiene (MiCA Art. 15 makes those responsible for misleading crypto-asset white paper statements personally liable, and no disclaimer can contract that away; these pages are written under that constraint), the service being live before the token, display in work units rather than dollars, and a documented fallback that replaces the holding drip with a usage rebate within one epoch if counsel requires it. That fallback has a named cost: the holding narrative loses its ongoing inflow. Both the switch and its cost are documented in advance so the decision, if forced, is prepared rather than improvised.
5. The reserve can shrink in absolute terms while backing per token rises
Not a hidden leak: the intended semantics of redemption. Claims are served (capped at roughly 1% of net reserve per day) and the remaining holders end up better backed. Anyone watching only the absolute reserve curve can misread this as an outflow, which is why both figures are published side by side. The converse also holds and matters more: per-token backing can fall only through reserve asset losses or operational failure. Which leads to:
6. The ways backing can actually fall
The mechanism cannot reduce backing per token; these can:
- Reserve asset risk. USDC issuer failure or depeg. Reduced but not removed by the yield-free policy: there is no vault, no collateral chain, no bridge position to fail, which eliminates the category of loss that materialized in the ecosystems we evaluated (Stream Finance, November 2025, $285M to $700M bad debt; Aave, April 2026, $196M to $290M). What remains is the stablecoin itself and the custody below.
- Custody compromise. 2-of-3 multisigs, separate people, hardware keys, a published 48-hour delay above $10,000. A compromise of two keys loses the tranche. Partially mitigated, never zero.
- Operational error. v0 accounting runs with us. The invariant-tested claim registry bounds the worst class of error (double-crediting), not all of them.
7. Our margin is an execution advantage, not a structural one, and anyone can copy it
Batch processing (about 50% off) and prompt caching (about 90% off cache reads) are available to everyone; real volume discounts start far beyond our size; the largest router in the space charges 0% markup on model prices. What remains is architecture: roughly 10% gross margin in the expected v0 mix (ASSUMPTION, to be measured; the mix, not negotiating power, is the variable). Anyone can rebuild this. There is no moat on the demand side by construction: we aggregate no supply and own no network. What is defensible is the brand, trust in the reserve, and product quality, and nothing else. The comparable project had five clones at a $35,000 reserve; we expect fakes on launch day, which is why the address, not the name, is the identifier everywhere.
8. The ticker collides with a tokenized stock on the same chain
RUN on this chain is the tokenized Sunrun Inc. equity (0x756Bc80af765C82da966a788858d65aDF14f3793), alongside several unrelated RUN-ticked tokens. A redeemable, reserve-backed token under an equity symbol on a chain built for tokenized stocks raises the risk of being read as a security, and our own necessary vocabulary ("reserve", "redeemable") amplifies exactly that reading. The risk was named, recommended against, and consciously accepted by the operator; it is managed, not avoided:
- The immutable on-chain
namefield is RUNTIME, the cheapest permanent disclaimer, rendered in every wallet. - Name and ticker always appear together as RUNTIME ($RUN); the contract address is the canonical identifier everywhere.
- Hard rule, without exception: no liquidity pool between this token and the Sunrun token, ever, and no Sunrun references in any promotion. A September 2026 precedent on this chain (a token sharing a Nasdaq ticker, the real stock up 350% intraday on no news) defines the fact pattern that rule exists to keep us out of.
- The immutable name protects only our own disclosure. It prevents nobody from launching an identical name and symbol to imitate us. Verify the address, always.
9. The volume base stands on an expiring subsidy, and the fee rate can never be corrected
The chain's gas subsidy ends 2026-09-29; the trading volumes observed before that date are subsidized, not steady state. Launch happens after expiry and all projections are computed twice, subsidized versus post-subsidy, with only the post-subsidy numbers used for planning.
On top of that sits a permanent pricing decision. The trade fee is 3.35%, the venue's maximum; a round trip costs 6.7%. Fee income is volume times rate, and if the higher rate suppresses volume by more than the rate gained, the total is a net loss against a cheaper setting. The rate is written once at launch and there is no function, for us or for the venue, that can ever change it. If 3.35% turns out to be the wrong price, it is the wrong price forever. (The graduation risk that stood in this section previously is gone with the venue change: the current pool trades from the launch block, there is no graduation step and no threshold to miss.)
10. v0 is not trustless, and the trust that remains has moved
The drip job, metering, valuation, and controller execution run off-chain with the team. The claim registry is on-chain and irrevocable; its valuation and servicing are not. Anyone promising "fully decentralized" in v0 would be lying, so we do not.
What changed with the venue: the fee flow itself is no longer a point of trust. The pool's fee recipient is an immutable splitter contract with a public, permissionless collection function; no keyholder, including us, can redirect the stream or change the 2/3 : 1/3 ratio, ever. The earlier design's single named power ("whoever holds the recipient right controls 100% of funding") no longer exists, and no hardening ladder is needed for it because there is nothing left to harden.
The cost of that guarantee is its own risk, and we name it the same way: there is no migration path. If a receiving treasury permanently loses the ability to accept ETH and cannot be repaired, its booked share waits in the router forever; if the split ratio ever turns out to be wrong for the protocol's survival, it cannot be adjusted; and no future improvement to the fee routing can be adopted for this pool. Permanence removes both the abuse and the remedy, and we chose it knowing both halves.
11. The retail question with the uncomfortable answer
Why hold a volatile token for something providers give away in free tiers? For most people: no reason, and we say so when asked. The realistic buyers are speculators on the narrative (initially the majority), crypto-native users and agents who want to pay for compute from a wallet without an account, card, or KYC, and holders who want the drip as a usage credit. The design is built so the second group can grow while the first comes and goes. Whether it does is measured, not assumed: the KPI list in point 3 exists for exactly this question.