FDC-verified XRP collateral

Native XRP Collateral.Credit on Flare.

Lock native XRP in an Ember-managed XRPL vault and access programmable credit on Flare  verified by FDC, valued by FTSOv2, and released only after repayment.

EmberCredit positionXRPXRPLFDCFTSOv2Flare

Native XRP, programmable credit

XRP remains native to XRPL inside an Ember-managed vault while its verified collateral state secures credit on Flare.

FDC FTSO FCC FASSETS

PROOF PRICE POLICY SETTLE

XRPL FLARE XRPL FLARE

0 1 0 0 1 1 0 1 0 0 1 0

1 1 0 1 0 1 1 0 1 1 0 1

Proof-gated by Flare

FDC verifies XRPL facts, FTSOv2 prices risk, FCC constrains external execution, and FAssets anchors the liquidation design.

Built on verifiable state

External collateral. Onchain credit. No hand-waving.

EmberCredit turns native XRP into programmable collateral through explicit proofs, fresh pricing, and tightly bounded execution.

FDC-verified collateral

XRPL collateral changes Ember state only after an official Flare Data Connector proof is verified and consumed once.

Official proof · replay protected

FTSOv2 risk pricing

Borrow capacity and liquidation health use normalized XRP pricing that must be both fresh and secure.

Fresh price · fails closed

Policy-bound execution

The managed vault signs only exact, protocol-authorized XRP release or liquidation actions  never arbitrary transfers.

Bounded commands · replay protected

The credit flow

Every external action remains pending until authoritative evidence makes it final.

01

Lock native XRP

Fund a position-bound Ember-managed vault on XRPL.

02

Verify on Flare

FDC proves the deposit; FTSOv2 values the collateral.

03

Borrow and repay

Draw test USDT0, repay debt, then prove the XRP return.

Evidence, not promises

One lifecycle. Every critical transition inspectable.

EmberCredit separates what has run live from what is locally verified or simulated  because trust labels are part of the product.

LIVE_VERIFIED

Deposit to credit

An exact XRPL Testnet payment changed Ember collateral only after official FDC verification. Borrow capacity then used a fresh secure FTSOv2 price.

Gate 2 · Coston2 + XRPL Testnet

LIVE_VERIFIED

Repay to release

Debt-zero authorization returned exactly 1 XRP from the managed vault before an official FDC proof closed the position on Flare.

Gate 3 v2 · complete lifecycle

LIVE_VERIFIED

Encrypted transport integrity

Authenticated ciphertext reached the exact live policy rejection on Coston2, while a one-bit tag change failed authentication and persisted nothing.

Gate 5 transport · SIMULATED_TEE boundary

Safety before scale

The protocol fails closed when trust disappears.

EmberCredit is designed around explicit authority, conservative limits, and accounting that refuses to hide bad outcomes.

Collateral integrity

Proof before credit

No verified external deposit means no collateral and no debt issuance.

  • Official proof-verifier path
  • Exact destination and amount binding
  • Single-use transaction protection
  • Pending is never presented as final
See the protocol flow
Core invariant

Asset authority

Bounded execution

Every managed XRP movement must match a narrow onchain authorization.

  • Debt-zero release only
  • Health-triggered liquidation only
  • Exact destination and amount policy
  • No UI, backend, or admin sweep path
Inspect the evidence

Lender protection

Losses stay visible

Shortfall is recognized immediately instead of remaining a fictional asset.

  • Permanent first-loss reserves
  • Explicit lender-loss accounting
  • Automatic new-risk pause
  • Immutable position and global caps
See the protocol flow
Built to be inspected

See the system, not just the pitch.

EmberCredit exposes the transaction, proof, price, execution identity, and final state behind every consequential action.

Current evidence boundary

Coston2 + XRP Testnet

COSTON2
Cross-chain credit lifecycle
LIVE_VERIFIED
Encrypted bid transport
LIVE_VERIFIED
FAssets liquidation rail
LOCAL_VERIFIED
Execution boundary
SIMULATED_TEE