Skip to main content

Bad data should stop the machine.

The protocol's price input is a time-weighted average price of PAPER against SPY, taken from the market where the pair trades. It is measured in half-hour buckets across a six-hour window (one full run), so a single trade, however large, carries almost no weight in the average. The buckets are fixed to the clock, so nobody chooses where the window starts and ends.

The average only exists if it is kept fed. A reading is taken every half hour; if those readings stop, the price goes stale rather than silently drifting. Submitting a reading is a public function that anyone can call, not only an operator, but nobody is obliged to keep doing it.

There is no second opinion​

At launch the protocol reads one price source. There is no secondary feed to fall back on and no external cross-check. That is a deliberate choice, and the trade-off is explicit: rather than act on a source it cannot verify, the press stops. A stale, missing, or unsafe read halts the run.

Circuit breaker​

A circuit breaker that skips a six-hour run after a move greater than 20% is built in, but it is off at launch: the governance multisig can switch it on once there is price history. Once on, it stays inactive during the bootstrap window and two runs after. It is a guardrail against sudden moves and manipulation, not a promise that the market will be protected.

Unsafe price reads​

SPY tokens may trade in market sessions while PAPER can trade around the clock. During closures, gaps, stale inputs, and fast moves are possible. The press does not detect closures; the average keeps following whatever trades. Only a stale or missing read stops a run, and a stopped run waits rather than acting. Read Security & Risks.