---
title: "CaviarNine and the FLOOP DAO"
url: "https://caper.network/wiki/daos/dexs/caviarnine"
updated: 2026-08-23
last_verified: 2026-08-23
license: CC-BY-4.0
license_url: "https://creativecommons.org/licenses/by/4.0/"
---

# CaviarNine and the FLOOP DAO

|  |  |
| --- | --- |
| **Name** | CaviarNine (the FLOOP DeFi ecosystem) |
| **Type** | Company-operated DEX suite on Radix: an order book, Shape Liquidity (concentrated AMM), the LSU Pool for liquid-staking units, HyperStake and an aggregator. Not a DAO – every live component answers to an operator badge |
| **Governance token** | [FLOOP](https://dashboard.radixscan.io/resource/resource_rdx1t5pyvlaas0ljxy0wytm5gvyamyv896m69njqdmm2stukr3xexc2up9) – 1,000 minted on 19 August 2021, bridged to a fixed-supply, burnable Babylon token; 942.46 in circulation across 2,211 holders, read on ledger 23 August 2026 |
| **Governance model** | Promised, never deployed. The [docs](https://docs.caviarnine.com/tokens/floop) describe a FLOOP DAO with control over reserve keys, fees and the burn rate; on ledger those dials sit behind the C9 Admin Badge |
| **Admin control** | [C9 Admin Badge](https://dashboard.radixscan.io/resource/resource_rdx1nglan7djf0stpdm5pf3hzctlha366l3s5xllu9z04z6puctdg200m4): three badges in three accounts, unchanged since November 2023. Minted and recalled by four of the nine [C9 Super Admin Badges](https://dashboard.radixscan.io/resource/resource_rdx1nt5v96ds9x5h7wl3jdzvlmg06727560ksml5tqxp5dhfv8chs0fvqh), held three per account – so any two of the three accounts |
| **Status** | **Winding down.** Announced **19 August 2026**; the DEX site becomes a withdraw-only sunset page, the contracts stay on ledger, Surge unwinds in stages, JustLock is unaffected. No badge handover recorded as of 23 August 2026 |
| **Founded** | 2021 – validators live on Olympia in July, FLOOP minted 19 August |
| **Website** | [caviarnine.com](https://www.caviarnine.com) · [docs](https://docs.caviarnine.com) |
| **Open source** | [caviarnine-scrypto](https://github.com/caviarnine/caviarnine-scrypto) – MIT, 13 packages, last pushed 25 April 2025 |
| **Primary sources** | [the announcement](https://t.me/radix_dlt/998739), [the 21 August clarification](https://t.me/caviarxrd/70246), [docs.caviarnine.com](https://docs.caviarnine.com), the [ledger](https://dashboard.radixscan.io/component/component_rdx1cppy08xgra5tv5melsjtj79c0ngvrlmzl8hhs7vwtzknp9xxs63mfp) |
| **Related** | [DXdao](/wiki/daos/dexs/dxdao), [Typed vs arbitrary execution](/wiki/dao-governance/concepts/voting/typed-vs-arbitrary-execution), [Rage-quit and exit rights](/wiki/dao-governance/concepts/membership/rage-quit-and-exit-rights) |

**CaviarNine** built and ran the largest trading venue on Radix – an order book, a concentrated-liquidity AMM it called Shape Liquidity, a pool for the network's liquid-staking units, and the aggregator most traders routed through – and on **19 August 2026** announced that it is winding those products down and leaving the network. It belongs in a directory of DAOs for what it was not. A FLOOP DAO was promised in 2023 and described in the documentation until the end; what the ledger shows instead is three accounts holding three admin badges over every live component. The wind-down is a clean test of what an operator's keys can and cannot do to a self-custodial protocol once the operator goes: a front end is a shopfront, the contracts are the building, and the badge is the key to the fuse box.

Everything below was read first-hand on 23 August 2026 from the Telegram posts, CaviarNine's documentation, its open-source repository and the mainnet ledger. Where a number comes from the ledger, the epoch is given with it.

## 19 August 2026 – the announcement

Tronn, CaviarNine's co-founder, posted the announcement at 08:23 UTC in the main Radix Telegram channel ([t.me/radix_dlt/998739](https://t.me/radix_dlt/998739)), dating it to the token's fifth birthday: "Five years ago today we minted FLOOP, the first utility token on Radix", two years before the network had smart contracts. The stated reason is economic. "The economics of operating here no longer work, and the network is a long way from what any of us signed up for in those early years." The team would "rather wind down properly, with time and care". The product fates, in the announcement's own order:

- **The DEX** – the website "will soon move to withdraw-only mode". "The smart contracts remain on ledger, but the site will only support removing LP positions."
- **Surge**, the perpetuals venue – "will unwind in stages", with a date to be announced for closing all open positions; unclaimed collateral is to be bridged to Ethereum and held for later claiming.
- **JustLock**, the token locker – "unaffected. It runs entirely on ledger."

No deadline was set and no action was required that day; withdrawals are needed "in the coming months", with notice promised before each step. The first line under the heading about funds was "Everything is self-custodial", and the closing one was "This is goodbye to Radix, not CaviarNine": [caviarnine.com](https://www.caviarnine.com) now presents a team that builds Cantex on Canton and runs CaviarLabs as a software house, with the Radix products listed beside earlier decommissioned ones.

Two days later, at 12:41 UTC on 21 August, Tronn corrected a reading some had taken from the announcement ([t.me/caviarxrd/70246](https://t.me/caviarxrd/70246)): "We are not switching the DEX off. The smart contracts stay live on ledger. What changes is our website: it will be replaced with a simple sunset page, no backend, supporting remove LP only." Anyone "can build and run their own front end to any of the components, today or in a year." Astrolescent's Timan, whose aggregator routes through the pools, took the clarification the same afternoon as the useful fact it is – "components and its liquidity stay usable if we have a new frontend" ([t.me/radix_dlt/999003](https://t.me/radix_dlt/999003)). As of 23 August the site had not changed: [caviarnine.io](https://www.caviarnine.io) still served its full trading interface.

## The DAO that was promised

The governance story predates Babylon. In June 2023 CaviarNine's tokenomics post ([archived copy](https://web.archive.org/web/20250512182832/https://blog.caviarnine.com/floop-tokenomics-part-1-72e2a4c1fc62)) set the plan out: Babylon FLOOP would be burnable, "the actual rate of burning is under the purview of the FLOOP DAO, and could be set to zero"; fixed fees would go to "the FLOOP Treasury smart contract"; and "the DAO will use FLOOP tokens to vote on various activities within the ecosystem, such as the burn rate (if any) on FLOOP Treasury fees and FLOOP Reserve activities." The [token's docs page](https://docs.caviarnine.com/tokens/floop) widened the list: control over the keys to the FLOOP reserves, whitelist and blacklist provisions, fee structures, the burn rate, rewards for long-term LPs, and "any future governance roles that may be introduced". The [LSU Pool page](https://docs.caviarnine.com/products-floop/lsu-pool/lsu-pool-overview) put the tense plainly: "CaviarNine (and in future the FLOOP DAO) has the ability to determine which LSUs are eligible for the Pool."

The token exists as described. [FLOOP on Babylon](https://dashboard.radixscan.io/resource/resource_rdx1t5pyvlaas0ljxy0wytm5gvyamyv896m69njqdmm2stukr3xexc2up9) has a fixed supply of 1,000, no minter, a public burn and locked rules; 942.46 remain across 2,211 holders, the rest burned from fees, which the docs put at "100% of all fees collected" as of December 2024. What does not exist is the DAO. Nothing on ledger acts in its name. The parameters it was to own – the burn rate, the fee dials, the validator whitelist, the reserve keys – are real, live and on-chain, and each is set through a badge.

## Who holds the keys, read on the ledger

Read at epoch **337,505** on 23 August 2026. The [LSU Pool](https://dashboard.radixscan.io/component/component_rdx1cppy08xgra5tv5melsjtj79c0ngvrlmzl8hhs7vwtzknp9xxs63mfp), the [fee vaults](https://dashboard.radixscan.io/component/component_rdx1cpa08p8gkvg966cvqglmtcfknp45ex5rtj69j3dd422sqcvtg6cpcn) that collect and burn protocol fees, the [HyperStake pool](https://dashboard.radixscan.io/component/component_rdx1cpz0zcyyl2fvtc5wdvfjjl3w0mjcydm4fefymudladklf6rn5gdwtf) and the Shape Liquidity pools all carry the same owner rule: a proof of the [C9 Admin Badge](https://dashboard.radixscan.io/resource/resource_rdx1nglan7djf0stpdm5pf3hzctlha366l3s5xllu9z04z6puctdg200m4), a non-fungible resource with the symbol C9AB, the description "With great power comes great responsibility", and a total supply of three. The fee vaults' `treasury_manager` and `reserve_manager` roles, the two that can withdraw, require the same badge. The three badges sit one each in three accounts, where the ledger shows them since November 2023.

Above the admin badge is a second one. The [C9 Super Admin Badge](https://dashboard.radixscan.io/resource/resource_rdx1nt5v96ds9x5h7wl3jdzvlmg06727560ksml5tqxp5dhfv8chs0fvqh) – "Nine badges to rule them all" – has a fixed supply of nine, locked rules and one job: a proof of four of the nine can mint a new admin badge or recall an existing one. The nine are held three per account by the same three accounts, so no account can do it alone and any two can. That is the whole governance of the largest venue on Radix, legible from three resource reads: three keys, any two of three holders can re-issue them, and no token holder anywhere in the chain.

The fee vaults' own parameters confirm the docs: `burn_percentage` 1 and `treasury_percentage` 0, so every protocol fee is swapped for FLOOP and burned and none reaches a treasury. The LSU Pool's protocol, liquidity and reserve fees sit at 0.0001, 0.0005 and 0.0001 of each swap, and its own cached valuation of the units it holds was 315,192,930 XRD. Each of those numbers is one badge-gated call from being different.

## What the badge can and cannot do

The source is public, so the badge's reach can be read rather than guessed. On the LSU Pool ([lsu_pool.rs](https://github.com/caviarnine/caviarnine-scrypto/blob/main/lsu_pool/src/lsu_pool.rs)), `OWNER` gates six methods: `set_token_validator`, which decides which validators' LSUs the pool accepts; `set_protocol_fee`, `set_liquidity_fee` and `set_reserve_fee`; `set_validator_max_before_fee`; and `take_from_reserve_vaults`, the one that moves tokens out. `OWNER` also sets the rule on the `user` role, which gates `add_liquidity` and `swap`. On the order book and the Shape Liquidity pools, the owner can update the owner and user rules and the metadata, and nothing else ([order book README](https://github.com/caviarnine/caviarnine-scrypto/blob/main/order_book/README.md), [QuantaSwap README](https://github.com/caviarnine/caviarnine-scrypto/blob/main/quantaswap/README.md)).

What the badge cannot do is the more important list, and the READMEs state it in the same words twice: "claiming orders can not be restricted" and "removing liquidity can not be restricted". On the LSU Pool, `remove_liquidity` is public. The pool unit itself, [LSULP](https://dashboard.radixscan.io/resource/resource_rdx1thksg5ng70g9mmy9ne7wz0sc7auzrrwy7fmgcxzel2gvp8pj0xxfmf), has its freezer and recaller set to `deny_all` with the rules locked, and mint and burn gated to the pool component. So the holder of an admin badge can shut the entrance – deny the user role and no new liquidity or swaps go in – can empty the reserve vaults, and can move the fee dials. It cannot lock the fire exits. Whoever holds the keys, the operator or an heir, has no lever over the balances users hold and every lever over the terms on which new ones arrive.

The "self-custodial" line in the announcement is therefore checkable, and it checks. It is also narrower than it sounds. Custody was never the badge's business; configuration is.

## The unwind, in one number

The pool unit tells the story faster than the front end does. LSULP's total supply was **267,774,125.70** at epoch 336,318 on the morning of the announcement ([radix.wiki's read](https://radix.wiki/ecosystem/caviarnine), CC BY 4.0) and **257,765,167.93** at epoch 337,504 on 23 August, 13:57 UTC: 10,008,957.77 units redeemed, about 3.7% of the pool, in four days – while [caviarnine.io](https://www.caviarnine.io) still served the full trading interface. The exit began before the operator touched anything. Withdrawing needs no permission, no front end and no badge, which is the one part of the design the wind-down could not have changed.

For scale, [DefiLlama](https://defillama.com/protocol/caviarnine) put CaviarNine's total value locked at $461,374 on 19 August 2026 and $400,157 on 23 August, against a peak of $42,087,970 on 9 April 2024. The venue announcing its exit was still the largest one on the network.

## Who inherits the badges – the open question

At 12:21 UTC on 21 August a community member asked CaviarNine ([t.me/radix_dlt/998982](https://t.me/radix_dlt/998982)) whether it would "hand over the admin badges of the current live components to for example the Radix Accountability Council": "the components are live, the liquidity is there, the track record as well", and the badges "have limited capability but should at least be in trustworthy hands (fees, earnings, etc...)". Tronn's reply called it "a fair question and a separate one from front ends, since badges touch fees and configuration", and promised "a considered answer rather than a quick one". Timan raised a second possible home the same afternoon: "Maybe we can arrange something with Radix DAO having control."

As of 23 August no answer has been posted and nothing has moved: the three admin badges are in the same three accounts. Mechanically a handover is small. The badge is a transferable non-fungible – withdrawer and depositor are `allow_all` – so each holder can send theirs in one transaction, or four super-admin proofs can recall all three and mint fresh ones for a new custodian. What a custodian would receive is the list above: the entrance, the dials and the reserve vaults, over pools whose liquidity was leaving at the rate the previous section measured. What it would not receive is a protocol. The front end, the backend, the aggregator's index and the team are what is being withdrawn, and none of those is a badge.

The question is the one this directory's page on [typed versus arbitrary execution](/wiki/dao-governance/concepts/voting/typed-vs-arbitrary-execution) asks of every DAO, arriving from the other side. A badge is arbitrary authority: whoever holds it can call anything it gates, for any reason, with no ballot to read. A council [multisig](/wiki/dao-governance/tooling/treasury/safe) can hold that authority more accountably than three accounts can; it cannot make the authority legible. Only a contract that enumerates what a passed vote may do can do that, and CaviarNine never deployed one.

## The open-source code, and what a fork is not

CaviarNine published its contracts at [caviarnine-scrypto](https://github.com/caviarnine/caviarnine-scrypto) under the MIT licence: the order book and its factory, QuantaSwap (Shape Liquidity) and its factory, the LSU Pool and its token validator, HyperStake, the weighted pool behind the index pools, a token creator, validator and bridge, and the fee controller and fee vaults. The repository has 14 commits between February 2024 and 25 April 2025, READMEs for the order book, QuantaSwap and the fee vaults, and test suites. Two things belong next to the word "open source" before anyone calls it a takeover kit. The packages pin Scrypto at its v1.0.0 tag, three minor versions behind the current toolchain, and the order book and QuantaSwap blueprints hard-code the addresses of the fee controller and fee vaults as constants, so a redeployment needs its own fee components and a patched build. Nothing in the repository claims the published source matches the packages on ledger, and the one audit the docs point to – [sec3's review of the order book](https://github.com/sec3-service/reports/blob/master/reports/sec3_caviar_orderbook_20231025.pdf), dated 25 October 2023 – covered what was deployed, not a fork.

That sets the two paths apart. Inheriting the badges keeps the live components, their liquidity and their track record, and gives the custodian configuration over them. Forking the code produces new components with a new badge, empty, and asks the liquidity to move. The community request was for the first; the licence only provides the second.

## How Caper approaches this

Caper runs the same test on itself, and the answer is that it also has an operator badge. The protocol admin badge on the registry can replace the platform's logic component – at once through `set_current_main`, or after the upgrade delay through propose and activate – and it sets that delay; the logic's own admin can change fees inside limits the contract enforces. Because the logic tier is what calls a caper's treasury, a logic swap is the lever that could reach member funds, which is why the design puts it behind a delay and a second path: a passed $CAPER upgrade vote can install logic with no operator key, and governance can trigger the timelock but never shorten it.

What the badge cannot touch is structural rather than promised. A caper's token has no mint or burn role, so supply cannot grow. The curve's reserve has no withdrawal except a sale back along the curve. The state package is published with no owner, so the contract that holds every caper's vaults cannot be changed by anyone. And every candidate logic must keep [exit](/wiki/foundations/leaving-a-caper) as a public method that reaches that immutable store – the upgrade-review suite treats it as a release gate, and [Execution](/wiki/governance/execution) walks the rest. Two caveats belong in the same paragraph: the contracts run on Stokenet today, and the upgrade delay on that deployment is set to zero. This is a design contrast, not a claim of superiority; the mechanics are on the linked pages and were verified against the contract source on 23 August 2026.

## References

- [CaviarNine is leaving Radix](https://t.me/radix_dlt/998739) – Tronn, main Radix Telegram, 19 August 2026, 08:23 UTC (primary).
- ["We are not switching the DEX off"](https://t.me/caviarxrd/70246) – Tronn, CaviarNine Telegram, 21 August 2026, 12:41 UTC (primary).
- [The admin-badge request](https://t.me/radix_dlt/998982) and [Astrolescent's reply](https://t.me/radix_dlt/999003) – main Radix Telegram, 21 August 2026 (primary).
- [FLOOP Tokenomics part 1](https://web.archive.org/web/20250512182832/https://blog.caviarnine.com/floop-tokenomics-part-1-72e2a4c1fc62) – CaviarNine, 13 June 2023, Internet Archive capture of 12 May 2025 (primary).
- [FLOOP](https://docs.caviarnine.com/tokens/floop) and [LSU Pool Overview](https://docs.caviarnine.com/products-floop/lsu-pool/lsu-pool-overview) – docs.caviarnine.com (primary).
- [caviarnine/caviarnine-scrypto](https://github.com/caviarnine/caviarnine-scrypto) – the MIT source, including [lsu_pool.rs](https://github.com/caviarnine/caviarnine-scrypto/blob/main/lsu_pool/src/lsu_pool.rs) and the [order book](https://github.com/caviarnine/caviarnine-scrypto/blob/main/order_book/README.md) and [QuantaSwap](https://github.com/caviarnine/caviarnine-scrypto/blob/main/quantaswap/README.md) READMEs (primary).
- [sec3, CaviarNine order book audit](https://github.com/sec3-service/reports/blob/master/reports/sec3_caviar_orderbook_20231025.pdf) – 25 October 2023.
- Ledger reads, mainnet epoch 337,504–337,505, 23 August 2026: [C9 Admin Badge](https://dashboard.radixscan.io/resource/resource_rdx1nglan7djf0stpdm5pf3hzctlha366l3s5xllu9z04z6puctdg200m4), [C9 Super Admin Badge](https://dashboard.radixscan.io/resource/resource_rdx1nt5v96ds9x5h7wl3jdzvlmg06727560ksml5tqxp5dhfv8chs0fvqh), [FLOOP](https://dashboard.radixscan.io/resource/resource_rdx1t5pyvlaas0ljxy0wytm5gvyamyv896m69njqdmm2stukr3xexc2up9), [LSULP](https://dashboard.radixscan.io/resource/resource_rdx1thksg5ng70g9mmy9ne7wz0sc7auzrrwy7fmgcxzel2gvp8pj0xxfmf), [LSU Pool](https://dashboard.radixscan.io/component/component_rdx1cppy08xgra5tv5melsjtj79c0ngvrlmzl8hhs7vwtzknp9xxs63mfp), [fee vaults](https://dashboard.radixscan.io/component/component_rdx1cpa08p8gkvg966cvqglmtcfknp45ex5rtj69j3dd422sqcvtg6cpcn), [HyperStake](https://dashboard.radixscan.io/component/component_rdx1cpz0zcyyl2fvtc5wdvfjjl3w0mjcydm4fefymudladklf6rn5gdwtf) (primary).
- [CaviarNine on radix.wiki](https://radix.wiki/ecosystem/caviarnine) – the 19 August epoch 336,318 LSULP read, CC BY 4.0.
- [CaviarNine on DefiLlama](https://defillama.com/protocol/caviarnine) – TVL series; the figures above were read from its API on 23 August 2026.
