1. the token

the token contract is plain. there is no transfer hook, no fee on transfer, no blocklist, no pause, and no mint path reachable after construction. supply is fixed and nothing adds to it. none of this is declared in a field, because erc-20 has no field that declares the absence of a hook, so the claim is verifiable only in the way any claim about a contract is verifiable: by reading the bytecode. there is no proxy, no admin storage slot and no delegatecall anywhere in it. whether the coin moves is not programmable by anyone here, and it is why the rest of this document concerns a precompile rather than a balance. what was left to design was not the distribution. it was the condition on which it fires.

2. the horizon

the evm remembers two hundred and fifty six block hashes and drops the rest. at a two hundred and fifty millisecond block target that is about one minute of history, and it is the entire extent of what any contract on this chain can prove about blocks it did not witness. [NAME]'s horizon is two hundred and fifty six blocks because the chain's horizon is two hundred and fifty six blocks. the size was not chosen and cannot be changed by anyone here.

there are no holes inside the window. one sequencer orders this chain and every block number has a hash, so the horizon is not a thing to count. it is a continuity test and nothing else. if the previously observed block is older than two hundred and fifty six blocks, blockhash returns zero, the contract cannot prove the interval it just crossed, and the difference is added to unseen. the program counts these rather than concealing them. the unseen figure is chain the contract could not vouch for, and it only rises.

fig. 1, coverage. every interval since the first observation. an open cell is an interval the contract could prove. a filled cell is one that fell out of reach before anyone observed it.

3. the contract

the state is six fields: the level, the vault, the rain count, the observation count, the last observed block, and the unseen total. it is hand-written solidity that inherits from no library. the abi is a convenience for callers and is not shipped as the specification, and the bytecode is the only thing that binds. verify it against this document, and where the two disagree, the code on chain is what you own.

four functions exist. observe is described below. stake and unstake move coin in and out of the pool with no lockup and no exit penalty. claim pays accrued wei pro rata. there is no setter, no reset, no pause, no migration, no withdrawal, no proxy and no admin. a rule you can amend is a preference. this one has no amending function in the binary, and the binary that handles the first observation is the binary that handles the last.

4. inside observe

observe takes no arguments. it reads the gas-info precompile and takes one scalar: what the chain has collected from users for posting their data against what it has actually paid ethereum to post it. where the second exceeds the first, the difference is the shortfall over the last pricing interval.

if the previous observation's block sits further back than the blockhash horizon, the difference is added to unseen and is named in the emitted event. the contract does not estimate what happened in that interval and does not interpolate across it. an unproven interval is recorded as unproven and nothing further is claimed about it.

if the shortfall does not exceed the level, the call updates the last observed block and the observation counter and ends. the caller has paid gas and receives nothing, which is why the next paragraph exists.

if the shortfall exceeds the level, four things happen in one transaction. two percent of the vault pays the caller. the remainder sweeps to the staking pool and the reward index advances in fixed point, so a claim is constant time for a holder regardless of how many dry observations they sat through. the level is set to the shortfall. the rain counter increments and an event is emitted carrying the figure, the payout, the interval and the coverage.

because observe is permissionless and reverts nothing, the contract needs no operator and grants none any discretion. if nobody calls it, the vault fills, the horizon rolls forward, and the loss goes unrecorded.

5. the rate

call each observed interval a draw. rain occurs at a draw exceeding every draw before it, which is the definition of a record.

proposition one. the expected number of rains after n observations is the harmonic number. the kth draw is a record when it is the largest of the first k, which for exchangeable draws has probability one over k. rain count is the sum of these indicators, so its expectation is the sum of one over k from one to n, which is h of n, approximately the natural log of n plus zero point five seven seven two.

proposition two. the expected wait for the next rain multiplies by e. immediate from proposition one.

a day of continuous observation produces about six and a half rains. a month produces about ten. a year produces about twelve and a half. a decade produces about fifteen. the vault fills continuously and empties only at a record, so the payments are exponentially rarer and correspondingly larger, and this is a property of maxima rather than a schedule anyone wrote.

exchangeability is an idealisation. settlement losses are not stationary, they rise when ethereum's gas market moves faster than the chain's estimate and fall when it is calm, and a period of genuine turbulence will produce records faster than the clean model predicts. the measured value also moves continuously rather than once per window, so denser sampling finds higher maxima and callers influence the record count more than a fixed window would. that does not break the result. it means the contract is most generous exactly when the chain is losing worst, which is the behaviour it was designed around.

132064001937
fig. 2, the level. every interval ever observed against the worst one before it.

6. what cannot happen

proposition three. the level is non-decreasing. the only write is a maximum against the existing value, there is no function that reduces it, and there is no authority to add one.

proposition four. the vault cannot be removed except by rain. the only debit is the rain branch of observe, reachable only above the level, and there is no withdrawal, migration, pause or sweep anywhere in the binary.

proposition five, and it is weaker than the others. no participant holding this coin can cause rain. every transaction on this chain pays into the account being measured, so transacting reduces the shortfall and moves the figure away from a record rather than toward one. no outsider can buy one cheaply either. forcing a record means moving ethereum's gas market and holding it there, at ethereum's prices, paying ethereum's validators in order to pay this program's holders. what cannot be claimed is that nobody at all can cause it. the sequencer is a single party, it sets the estimate that produces the shortfall, and it is not bound the way a solana leader would be, who has to forfeit their own block rewards to manufacture the defect. that asymmetry is real and this document does not argue it away.

there is no state of the world in which this contract gives back a level it has already reached. not in a drawdown, not in a panic, not if nobody observes it for a year, and not if everyone involved in deploying it would prefer otherwise. idleness is the worst case, and the worst case is that the vault keeps filling while the loss goes unrecorded.

notes

the two hundred and fifty millisecond block target is nominal. real block times vary, so the one minute horizon is approximate and the observation counts on this page are the authority rather than any wall clock figure derived from them.

the figures are instruments, not illustrations. in the live record they draw from contract emissions and chain reads and nothing else.