Silo

Silo isolated markets and lending risk by pair

Silo isolated markets attach lending exposure to the selected asset pair and its configured borrowing rules. Silo v3’s paired architecture uses two single-asset vaults with separate accounting for the market’s assets. Lending terms belong to that deployment, including collateral limits, pricing rules and liquidation arrangements. A token appearing in several markets does not connect their loan balances. Deposit mode also matters: borrowable assets can earn interest, while protected collateral stays unavailable to borrowers. Understanding the pair means identifying what secures its loans, which direction permits borrowing and how lenders recover value if repayment fails. The same collateral name can therefore describe materially different lending positions.

The short version: A Silo market’s collateral valuation and liquidation configuration determine the exposure behind its lending shares and the assets lenders may recover.

Separate vaults keep unrelated loan losses local

Borrowers secure loans with collateral inside their selected market, so a lender’s claim depends on that market’s collateral. The paired core uses an ERC-4626 vault for each asset, with a shared SiloConfig contract defining their relationship. ERC-4626 standardizes deposits and shares representing a claim on underlying assets. A bad loan elsewhere does not automatically draw on this pair’s balances. The accounting boundary contains losses on loans within that market, although separate deployments can still share technical dependencies.

Which market settings change exposure within the same pair?

Oracle selection, borrowing limits and liquidation modules can distinguish deployments containing the same assets. Their rate models can differ too. A pair label identifies its assets; the deployment’s contracts identify the actual terms. One-sided markets allow the configured collateral asset to secure loans of the other asset. The reverse direction remains unavailable in that deployment.

Fixed configuration does not make every displayed figure constant. Interest accrual, asset valuations and available liquidity change during operation. Some deployments also permit limited changes to oracle or interest-rate modules through authorized controls. The scope of those permissions belongs to the selected deployment.

An interest-bearing market deposit requires the borrowable mode and the intended underlying asset. Protected deposits remain unavailable to borrowers and earn no borrower interest. Before selecting the borrowable position, check its terms:

  • Confirm the vault’s underlying asset and permitted borrowing direction.
  • Identify the collateral backing borrowers’ debt in this deployment.
  • Separate maximum borrowing limits from liquidation thresholds.
  • Read the configured oracle and interest-rate model alongside current liquidity.
  • Check whether debt resolution can reimburse lenders through collateral share tokens.

If these terms fit the intended exposure, depositing in borrowable mode creates shares in the selected vault. The resulting onchain share balance and the vault’s underlying asset identify the position independently of its displayed yield. A settled deposit establishes the holding; it does not establish future withdrawal liquidity.

Separate thresholds limit new borrowing before liquidation

Maximum loan-to-value (LTV) limits additional borrowing against collateral, while the liquidation threshold determines when a position becomes eligible for liquidation. LTV compares debt value with collateral value using compatible valuation units. The standard configuration places maximum LTV below the ordinary liquidation threshold. If both tests use the same valuation, a position can exceed its borrowing limit without yet crossing the liquidation threshold.

Accruing interest raises debt, which can increase LTV even without a collateral price decline. Collateral withdrawals can also reduce the denominator. For lenders, the liquidation threshold describes when a remedy becomes available. It does not promise immediate execution or enough recovery value to cover the loan.

How do oracle choices change the meaning of collateral value?

Oracle choices determine which valuation the market uses for borrowing capacity and solvency checks. The architecture supports separate oracle roles for those calculations. Market pricing reflects exchange values; fundamental pricing can follow an asset’s redemption relationship or underlying value. These approaches can diverge during stress, so the protocol’s collateral valuation may differ from the amount a sale realizes.

A delayed or inflated collateral quote can permit borrowing against value a sale cannot recover. Conversely, a low quote can make a healthy position appear liquidatable. The relevant dependency includes the pricing method and the data feeding it. A redemption-based valuation does not establish how readily the asset can sell for the quoted amount.

Liquidation design determines what lenders recover

A collateral-sale liquidation repays debt in the loan asset and transfers collateral to the liquidator. Selling that collateral can fund repayment, so execution depends on sale liquidity and incentives. Insufficient sale proceeds can leave liquidators unable to recover their repayment cost.

Some Silo v3 markets support collateral-debt swaps as an alternative resolution mechanism. A collateral-debt swap reimburses lenders through claims on collateral share tokens. The mechanism writes off the corresponding debt without selling the collateral for the original loan asset.

Lenders claim the distributed shares through the Incentive Controller. Their recovery then depends on the collateral’s value and redemption conditions. Those shares represent collateral; obtaining the original loan asset can require redemption followed by a sale.

In deployments combining both engines, the swap route uses a higher liquidation threshold than ordinary collateral-sale liquidation. Writing off debt changes the ledger; it does not replenish liquidity in the original loan asset.

Why can a solvent market delay withdrawals?

A solvent market can delay withdrawals when borrowers have used the loan asset’s available liquidity. Solvency concerns collateral coverage; a withdrawal requires transferable underlying assets. A lender’s shares can retain a claim on assets without representing tokens available immediately. Increasing utilization can leave less unborrowed supply for withdrawals.

The configured interest-rate model sets borrowing costs as market conditions change. Dynamic models react to utilization, while supported fixed-rate configurations follow their selected rate. A high supply rate cannot establish available exit liquidity. Protected deposits avoid lending utilization, although collateral securing debt still faces withdrawal limits from solvency checks.

Shared dependencies limit the protection isolation provides

Several markets can rely on the same contract implementation, price infrastructure or collateral issuer. A defect in shared code or a pricing failure can therefore affect multiple deployments at once. Isolation prevents unrelated loans from sharing this market’s accounting; it does not make common dependencies independent. A collateral token’s own administrative powers also remain relevant to its value and transferability.

Illustration: Silo isolated markets: Shared dependencies limit the protection isolation provides
Diagram: Shared dependencies limit the protection isolation provides.

View full-size image

Managed vaults can distribute deposits across selected isolated markets, giving their depositors exposure to several underlying pairs. Allocation choices determine that combined exposure without changing each pair’s borrowing or liquidation rules. A direct market deposit stays tied to its chosen deployment. Its exit remains constrained by available liquidity and any borrowing obligations the position’s collateral secures.

Before you start with Silo isolated markets

Can the same account owe both assets in a single isolated market?

Silo v3’s paired core prevents one account from carrying debt in both asset vaults at the same time. A deployment may also restrict the permitted borrowing direction. Holding deposits on both sides does not override the debt restriction; deposit balances and outstanding borrowing describe different parts of the position.

Does a missing oracle mean the market has no valuation rule?

An unset oracle address does not remove collateral checks. When no applicable oracle is configured, the core can use the asset amount directly as its value. The other asset’s oracle may express its valuation in those same units. This convention establishes no fixed currency peg or matching sale price.

What fees reduce interest earned in an isolated market?

Configured DAO (decentralized autonomous organization) fees and deployer fees can take a share of borrower interest before it accrues to lenders. Their settings belong to the market configuration. These deductions differ from liquidation fees, so the borrow rate alone does not describe the lender’s net interest income.

Will a lending receipt redeem assets from another isolated market?

A receipt represents shares in its issuing vault, with redemption tied to that vault’s underlying asset. Another market holding the same token does not share the receipt’s claim. ERC-4626 compatibility standardizes the interface; it does not merge redemption liquidity or make different deployments’ shares interchangeable.

Is conversion into protected collateral always available?

Conversion from borrowable deposits into protected collateral requires enough available market liquidity. The core moves the amount between accounting categories without transferring it outside the market. It applies relevant solvency checks, so changing the deposit type cannot bypass an outstanding borrowing obligation.

Do isolated markets hide collateral balances from other users?

Positions remain visible through public blockchain records. Contract state exposes collateral and debt balances associated with an address. Separate market accounts control lending exposure; they provide no confidentiality layer for the underlying public records.

Who can trigger a collateral-debt swap liquidation?

A collateral-debt swap can allow permissionless execution or restrict execution to approved actors, depending on its configuration. The v3 collateral-sale module is permissionless when no executor allowlist is configured; otherwise, only approved actors may execute it. A market enabling both mechanisms can therefore give them different access conditions; the swap’s configuration controls who may execute it.

Why might a partial liquidation require full debt repayment?

A liquidation intended to be partial can require full debt repayment when the remainder would leave an uneconomical dust balance. A call capped below the required full repayment amount reverts. This behavior belongs to the liquidation module. A partial-liquidation design therefore does not promise a surviving loan after every liquidation.

· updated