bWalletX is in beta: test with small amounts.
bWalletX DownloadWeb →

Development blog · 011 · 4–5 Oct 2026

From a dollar bond to PNEEs on mainnet

A BSV-backed dollar token went from a design note to a small, capped mainnet pilot in two days. This is what is enforced, what is not, and what went wrong.

Contracts and bonds

On 4 October we wrote a design for a "$1 bond": lock BSV in a vault and mint dollar tokens against it. On 5 October the wallet got Exchange › Contracts and Bonds, where contract descriptions are published as public NFTs.

The prototype

The vault and token contracts are written in sCrypt in a separate repository. A vault holds BSV, mints against it up to a set ratio, lets the owner close it by handing the tokens back, and lets anyone liquidate it below 150% using a price signed by 3 of 5 signers (the median of the 3). There are 22 local tests, run through the Bitcoin Script interpreter.

We could not run it on testnet. On 5 October no faucet we tried could give us test coins: one returned an error, and the others were unreachable or needed a captcha.

Bonds became Penny Notes, then PNEEs

The same day we changed the design. These are not bonds; they are cash. One unit is one cent. Vaults start at 10x collateral, so $1 of BSV mints 10 cents, and a vault survives an 85% fall in BSV. The notes became an ordinary BSV-21 token, $PNEE, with 2 decimals, so any 1Sat-compatible wallet can hold them. The name settled as PNEEs (Penny Stablecoins).

The mainnet pilot

Mainnet runs only in a pilot mode with hard caps in code: about $5 of collateral per vault, $10 across all vaults, $2 of notes per vault, and a fee cap per transaction. Every broadcast prints a summary and needs "broadcast" typed to confirm. Plain mainnet mode is refused. The first vault locked 12,500,000 sats; the first mint was 25 PNEEs against a 3-of-5 price of $20.32. The transaction IDs are on the PNEEs page.

What went wrong

The trust gaps

The vault script can't check other inputs, so it can't prove that real notes were burned when a vault closes. For now bCorp, as issuer, co-signs releases and burns, in public on chain. That means the issuer could refuse to co-sign a liquidation. All five price signers are run by us during the pilot, so they are not independent. A liquidator can also choose an old transaction lock time, which weakens the price freshness check. The prototype's README lists these in full.

Note transfers themselves need no co-signer. Releases and burns do.

What's not done

← 010 Agent accounts, strategies, CLI and MCP012 The extension, the web app and pairing →