From a dollar bond to PNEEs on mainnet
A BSV-backed dollar token went from a design note to a small, capped mainnet pilot in two days. This is what is enforced, what is not, and what went wrong.
Contracts and bonds
On 4 October we wrote a design for a "$1 bond": lock BSV in a vault and mint dollar tokens against it. On 5 October the wallet got Exchange › Contracts and Bonds, where contract descriptions are published as public NFTs.
The prototype
The vault and token contracts are written in sCrypt in a separate repository. A vault holds BSV, mints against it up to a set ratio, lets the owner close it by handing the tokens back, and lets anyone liquidate it below 150% using a price signed by 3 of 5 signers (the median of the 3). There are 22 local tests, run through the Bitcoin Script interpreter.
We could not run it on testnet. On 5 October no faucet we tried could give us test coins: one returned an error, and the others were unreachable or needed a captcha.
Bonds became Penny Notes, then PNEEs
The same day we changed the design. These are not bonds; they are cash. One unit is one cent. Vaults start at 10x collateral, so $1 of BSV mints 10 cents, and a vault survives an 85% fall in BSV. The notes became an ordinary BSV-21 token, $PNEE, with 2 decimals, so any 1Sat-compatible wallet can hold them. The name settled as PNEEs (Penny Stablecoins).
The mainnet pilot
Mainnet runs only in a pilot mode with hard caps in code: about $5 of collateral per vault, $10 across all vaults, $2 of notes per vault, and a fee cap per transaction. Every broadcast prints a summary and needs "broadcast" typed to confirm. Plain mainnet mode is refused. The first vault locked 12,500,000 sats; the first mint was 25 PNEEs against a 3-of-5 price of $20.32. The transaction IDs are on the PNEEs page.
What went wrong
- Reused coins. We were picking coins from WhatsOnChain's unspent list, which can lag behind. That let the tool try to spend a coin that had already been spent, and WhatsOnChain's broadcast did not report the double spend clearly. We now broadcast through ARC first, which reports double spends as errors, and keep a local list of spent coins.
- Missing notes. WhatsOnChain's address index skips inscription outputs, so notes didn't show up. We added a local ledger of notes.
- Indexing. The 1Sat overlay did not index PNEEs straight away, even after we paid its funding template. The wallet now shows PNEEs from GorillaPool, labelled "Indexing", until the overlay catches up.
The trust gaps
The vault script can't check other inputs, so it can't prove that real notes were burned when a vault closes. For now bCorp, as issuer, co-signs releases and burns, in public on chain. That means the issuer could refuse to co-sign a liquidation. All five price signers are run by us during the pilot, so they are not independent. A liquidator can also choose an old transaction lock time, which weakens the price freshness check. The prototype's README lists these in full.
Note transfers themselves need no co-signer. Releases and burns do.
What's not done
- Independent price signers.
- An on-chain check that burned notes are real, replacing the issuer co-signer. Shieldpool is one route we are watching; it is testnet only.
- The stability pool (backers earn from liquidations) is design only.
- A testnet run, and a review of the scripts, before any meaningful amount.
- Wallet screens for opening and closing vaults. The PNEEs card is there; vault management is not.
- Legal review before the stability pool opens to the public. Store editions stay browse-only.