Working paper · v0.1

Underwriting for tokenised value.

Metastability underwrites tokenised assets: it prices the risk that a token does not do what it says it will. This paper sets out the demand case, the network model behind it, three sized scenarios and the token mechanics that fund them.

Everything numeric on this page is a model. Inputs are stated where they are used and carry the marker assumption; change an input and the conclusion moves. Nothing here is a forecast, a projection of value, an offer, or investment advice. The purpose is to make the reasoning inspectable — including by people who expect to disagree with it.

An early preview. In line with the Metastability roadmap, the specification will be released after the genesis launch — including the final technology and further details, some of which cannot be disclosed yet. The token mechanics in section 04 are therefore illustrative and will be superseded by that specification.

01 · The demand case

Settlement is being tokenised faster than the assurance around it.

Two things are happening at once. Payment stablecoins are being brought inside licensing regimes — the GENIUS Act treats them as payment instruments rather than securities, with licensing from January 2027, and the EU, UK, Singapore, Hong Kong, the UAE and Japan have moved comparably. Separately, central banks are issuing or piloting CBDCs. Both shift settlement onto token rails.

Tokenised settlement does not remove risk. It relocates it. Redemption risk, reserve composition, operational failure, bridge and custody risk, and the correctness of the logic that moves the value all remain — and they now sit in instruments that move instantly and clear without an intermediary who would otherwise have absorbed them.

Conventional insurance prices risks with long loss histories. These do not have one. The gap between tokenised value outstanding and tokenised value with assurance behind it is the demand Metastability addresses.

Figure 1 — The assurance gap. Indexed model, not measured data. The upper band is tokenised value outstanding; the lower band the share carrying any form of assurance. The distance between them is the addressable gap. Index 100 = 2024 outstanding. inputs below
Figure 1 is drawn from three inputs: a growth rate for tokenised value outstanding (38 % CAGR assumption), an assurance coverage ratio starting at 6 % assumption, and the rate at which coverage improves (+1.6 pp per year assumption). None of the three is observed, and none is yet sourced: read the figure as the shape of the argument, not as data.

02 · The network model

Two sides, one book.

Metastability sits between issuers who want their tokens underwritten and subscribers who supply the capacity. Underwritten volume is the product of both sides — which is why the model is multiplicative rather than additive, and why early periods look flat and later ones do not.

Vt  =  It  ×  v̄  ×  min( 1 , Ct / ( It × v̄ ) )
Ct  =  St  ×  c̄  ×  λ
Rt  =  Vt  ×  f

Vt
underwritten volume in period t
It
token issuers onboarded
v̄
average volume submitted per issuer $4.0 m
Ct
available capacity
St
subscribers supplying capacity
c̄
average capacity per subscriber $120 k
λ
capacity leverage — capacity written against pool 2.4×
f
underwriting fee on written volume 165 bps

The min() term is the part that matters. Demand above available capacity is not revenue — it is a queue. A model without that term overstates early years badly, which is the most common flattery in this category of document.

Figure 2 — Demand, capacity and what actually gets written. Where demand exceeds capacity the written line follows capacity, not demand. The shaded wedge is unserved demand. In the medium case the subscriber side is the binding constraint in years one and two; from year three capacity runs ahead and demand binds instead. Which side binds is the model's most consequential structural claim, and it is the first thing to test against reality. medium case

03 · Three sized cases

Base, medium, optimum.

The three cases differ in two inputs only — the rate at which issuers onboard and the rate at which subscribers join. Everything else is held constant, so the spread below is attributable, not assembled.

Base case · year 5 0m USD written

142 issuers, 2,100 subscribers. Adoption at the pace of a specialist B2B infrastructure provider with no regulatory tailwind.

Medium case · year 5 0m USD written

510 issuers, 10,000 subscribers. Assumes licensing regimes make assurance a procurement requirement rather than a discretionary purchase.

Optimum case · year 5 0m USD written

1,240 issuers, 24,000 subscribers. Requires at least one CBDC corridor to adopt third-party assurance. An upper bound, not a target.

Figure 3 — Written volume by case, years 1–5. The curves are generated by the equations above and by the inputs in Table 1; they are not drawn to a desired shape. Because capacity overtakes demand early in the upper cases, the distance between medium and optimum is almost entirely the issuer path — how many issuers onboard, not how much capital shows up. That makes issuer onboarding the figure to interrogate first.
Table 1 — Scenario detail. Volumes in USD millions written per year.
YearIssuersSubscribers BaseMediumOptimum
Issuer and subscriber counts shown are the medium case. Base and optimum run the same equations with their own issuer and subscriber paths — by year five, 0.28× and 2.43× the medium issuer count, 0.21× and 2.40× the medium subscriber count assumption. Nothing else changes between the three cases. Table and Figure 3 are generated by the same code, so if one is wrong both are.

04 · Tokenomics

What the token does, and what it does not.

The token is the instrument through which capacity is committed and underwriting obligations are tracked. It is a utility token. It is not equity, not a claim on any company's assets or earnings, not a deposit, and not a payment instrument. A regulated payment stablecoin carries a redemption right; this does not, and nothing in the direction of travel gives it one.

Figure 4 — Supply allocation. Proportions only; absolute supply is set at issuance. illustrative split

Where supply goes

  • Underwriting pool — committed capacity, locked for the term of the obligations it backs.
  • Legacy conversion — reserved against the exchange offered to holders of the 2017 instrument. Size is set by the published ratio, not by this model.
  • Consortium — allocated to the blockchain partners who provide settlement and custody rails.
  • Treasury — operations, audit, actuarial work, regulatory capital where required.
  • Early supply — issued before the network carries volume. In the model this is a parameter, not a benefit: it determines how much capacity exists in year one and therefore how hard the capacity constraint binds.

Flows, not promises

  • Fees on written volume accrue to the pool that carried the risk, net of treasury.
  • Capacity is locked while obligations are live; it cannot be withdrawn against a claim that has not yet run off.
  • Losses are borne by the pool, in proportion to committed capacity. This is the part that makes it underwriting rather than yield.
  • No mechanism in the design pays a return for holding alone.
Figure 5 — Where the fee goes. Medium case, year 5. Fee income against premium ceded to reinsurance, expected loss net of that cession, and operating expense. The residual — 18.9 % of fee income — is what funds the pool. In a model whose loss distribution has no history behind it, that residual is the single number most likely to be wrong: it reaches zero at a loss ratio of 78.2 % and is negative above it. loss ratio 54 % cession 22 %

05 · Research

What we studied, and how.

Method

The demand side is built bottom-up from issuer counts and average submitted volume rather than top-down from a market size. Top-down sizing in this category tends to produce a number first and a justification second.

The capacity side is modelled as a constraint, not an assumption of abundance. Every scenario is run through the same equations; the three cases differ only in the two onboarding rates.

Open questions

  • Loss distribution for smart-contract and redemption failure has no credible history. The 54 % loss ratio is borrowed from specialty lines, which may not transfer.
  • Whether assurance becomes a procurement requirement under licensing regimes, or stays discretionary. The medium case assumes the former.
  • Reinsurance appetite for this class is untested at scale.
  • RAG and model-assurance demand — assurance for retrieval-grounded AI systems — is adjacent and may be larger than the token case. It is deliberately excluded here rather than used to inflate the total.

06 · Impact and reach

What changes if this works.

The useful measure is not volume written. It is whether assurance makes tokenised instruments usable by counterparties who are currently excluded from them — treasuries, regulated funds, corporates with audit obligations. That population does not grow because a token exists; it grows because someone will stand behind it.

Figure 6 — Addressable counterparties by class. Medium case, year 5. The bars show how much of each class is reachable with assurance in place against without. The constraint for regulated counterparties is rarely appetite; it is the absence of anyone to point at when it fails. illustrative

07 · Limitations

What would make this wrong.

  • If assurance stays discretionary rather than required, the medium case does not happen and the base case is the realistic ceiling.
  • The residual in Figure 5 is a fixed share of fee income, so it does not improve with scale. It reaches zero at a loss ratio of 78.2 % and is negative above it — in every year and every case. The 54 % used here is borrowed from specialty lines; the margin of safety is 24 points, which is not much for a class with no loss history.
  • If capacity arrives faster than demand, the constraint inverts and fees compress.
  • If a large incumbent insurer enters the class, pricing power disappears first and volume second.
  • Every input on this page is a stated assumption. None is a measured figure, and the market inputs behind Figure 1 are not yet sourced.
  • The model has no stochastic element. A single large correlated loss is not represented and would dominate any of the three cases.
  • Regulatory timing is treated as given. It is not.