← back to index

The launch of Onchain Gacha, and its FWA comparison#

August 18th 2026

Fake World Assets (FWA) launched recently and while an interesting new experiment (of which Ethereum mainnet needs more!), it has a number of shortcomings, namely:

FWA is one of the more interesting things to happen on Ethereum mainnet in a long while. I understand people's excitement for something onchain that they can engage with. Yet, in this excitement I believe people are not engaging critically enough with the protocol and have not taken the time to truly understand the economics and game theory. The initial conditions of the protocol had a player RTP of ~0.77 with most of that completely leaving the protocol. Current depositor yield, in ETH terms, can go negative, and while depositor yield and player RTP are subsidised by $FWA buybacks this buyback is misleading accounting that's being counted as revenue. Most importantly the long term equilibrium of the protocol is undermined by the lack of a mechanism enforcing parity between the deposited asset and the paired ETH. Capital efficient depositors will simply pair the cheapest asset they can with an arbitrary amount of ETH, eroding the player experience.

If I have a sufficient understanding to critique FWA then I should have a sufficient understanding to propose a better alternative - one that fixes all of the above issues. Enter the Onchain Gacha.

Onchain Gacha#

This essay is primarily a comparison between Fake World Assets and the Onchain Gacha. It is therefore highly recommended, if not entirely necessary, to first read the Onchain Gacha litepaper. My hope is that readers will leave with a better understanding of both the Onchain Gacha and FWA and better be able to critically engage with them, understanding what they optimise for and what the long term equilibrium is.

FWA Overview#

First, a brief overview of FWA and the reason the long term equilibrium is suboptimal. Depositors can put an asset paired with an amount of ETH into the protocol. The amount of ETH they pair the asset with is the proxy for its value and it is this value that represents the deposit's chances of being pulled by a player and consequently the depositor's expected yield. Players can purchase tickets to draw an asset at random from the pool with the majority of the ticket proceeds going to depositors. Users face the choice between:

An inverse of the deposit's value is the "hazard", ie: the chance of it being drawn by a player. High value deposits risk more if they're drawn but have a lower hazard such that their deposits are expected to stay in the pool longer, accruing more total rewards than smaller deposits. As such, ignoring the "tithe", deposits of all sizes have the same expected return on their supplied ETH.

When a player's ticket lands on a deposit the player can choose between taking the asset or the backed ETH. We can assume that players are rational actors and will always choose the higher value of these two such that their choice, and the depositor's cost is just max(asset value, paired ETH) which is expected to be counteracted by the accrued ticket rewards.

Depositors do not want to undervalue their asset. If they do, their deposit has a disproportionately high chance of being landed on for how much they're risking as we can assume the player will take the higher value option - the NFT. For example if a user pairs a Cryptopunk with just 0.1 ETH, they would have a high hazard, the same as any other 0.1 ETH backed deposit, and expect to receive back about 0.1 ETH. Yet, if someone landed on their deposit, they'd lose the Cryptopunk, worth approximately 32 ETH. The protocol does not know or care how much the asset is worth, everything rests upon the paired ETH.

Onchain Gacha overview#

It is expected that readers have first read the litepaper but as a refresher here is a summary of the Onchain Gacha.

Depositors can deposit native ETH, or allowlisted ERC20 and ERC721 tokens. Only highly liquid tokens will be allowed. Non native ETH deposits enter a valuation phase which the depositor opens with an ETH-backed initial vouch, subject to a minimum of 0.02 ETH. The resulting appraisal remains valid for 30 days, after which the position must be revouched before it can resume accruing or entering new draws. Every position must remain active and drawable for seven days after activation before it can be marked for withdrawal; anyone taking over a position inherits its remaining appraisal lifetime, but the deposit lock ends on takeover.

This initial vouch can be outbid by anyone else during the valuation phase. Outbidders put up a higher amount of ETH which represents their belief that the asset is worth more. The initial vouch is reserved for the duration of the valuation phase as some or all of it will go towards paying the highest voucher in order to reward their participation. Any other vouches that are outbid are returned immediately.

At any point during the valuation phase anyone is able to "yoink" the current highest vouch, taking the ETH and providing that voucher with a comparable asset. If yoinked the original deposited asset and the initial vouch return to the depositor. It does not pass go and does not enter the gacha protocol. Vouches can thus be considered standing bids / cash-secured puts that the voucher is selling.

If not yoinked, once the valuation phase ends the asset enters the protocol and is valued at the highest final vouch. The highest voucher receives their vouch back as well as some or all of the initial vouch as a finders fee, while the depositor receives whatever remains from the initial vouch and ownership of this new deposit in the protocol.

Players buy tickets priced on the average value of assets in the protocol. Ticket revenue almost entirely flows to depositors, paying them back for their deposited asset + some expected positive yield. A small percentage of this revenue buys and burns $ONG. None is retained by the protocol owner.

Tickets randomly draw an asset in the protocol - more valuable assets are less likely to be drawn. Players can choose to take the asset, to take over the deposit, or accept any collection bids on the asset. Anyone can place collection bids on assets in the protocol.

The key takeaways here are:

Depositor yield and gacha as liquidity provision#

One of the biggest ways people view FWA is through the lens of it "providing liquidity for NFTs". I think it largely misses this aim due to a number of reasons. I'll provide dual definitions for liquidity provision and explore both of them.

  1. Providing liquidity as turning an asset into its FMV in ETH
  2. Providing liquidity as taking a normally unproductive asset and earning yield on it

Let's look at the first definition of "providing liquidity" - the provision of a counterparty such that someone with an asset can sell it for close to FMV. Less than 10% of players choose the NFT when playing FWA: at the time of writing the NFT-kept rate is 8.1%.1 This means that in over 90% of cases, depositors place an NFT into the protocol and then receive it back, ie: failing at satisfying this first definition. We can understand this to mean that in over 90% of cases players see more value in taking the ETH vs taking the asset.

Furthermore, this is even with the large 10% (initially 15%) haircut players receive when choosing the ETH skewing their decision making. If a depositor fairly backs their asset (which they have no requirement or even incentive to do) then the player has a choice between an asset of value A or taking the backing of 0.9A, it is likely they will consider choosing the asset but only because of the haircut.

This haircut is essentially subsidising the depositor's ability to actually sell their asset and not have the player simply choose the ETH, but even then we still see a very low rate of players choosing the asset. If this fee were to ever be lowered in order to improve player RTP we would expect to see this get even worse as players are even less incentivised to choose the asset.

Now let's look at the secondary definition of "providing liquidity" as meaning to earn yield on an otherwise unproductive asset. To understand whether FWA satisfies this definition we must understand the yield that depositors expect. The majority of the depositor yield was juiced by $FWA distributions in the first 15 days. Under the current parameters, the maximum nominal ETH fee profit for an ordinary non-crown deposit is approximately 0.46% of backing before gas and excluding $FWA rewards - dynamic diversion of the surcharge to the purchaser's $FWA-buy allocation can reduce this ETH-only return as low as approximately -1.99%.3 The most common outcome is therefore that the depositor receives their NFT back after earning very little ETH. There is little "liquidity provision" here.

It is worth noting though that now some of the haircut players receive upon choosing the ETH goes back towards depositors (3%), increasing depositor yield by an average of 91.9%*3%, aka 2.76%. On the other hand though this yield only materialises when players choose the ETH, so you have a diametric opposition between depositors selling their assets and getting yield on them - it's one or the other, not both.

If, despite this, a user still wants the yield from FWA, they still are not even incentivised to deposit anything above the cheapest asset possible. Let's take an example. If a user deposits a Cryptopunk (worth 32 ETH) and 32 ETH their eventual cost will be 32 ETH (player choosing both the ETH and the asset will result in -32 ETH) and expect approximately 32 ETH in return, but will be locking up 64 ETH of capital. If a user deposits an asset worth 0.05 ETH and pairs it with 32 ETH, they will expect approximately 32 ETH in return and will have a risk of 32 ETH, yet will have only locked up 32.05 ETH.

Anyone seeking to maximise how much capital they deploy into FWA is incentivised by way of capital efficiency to find a perfunctorily cheap asset and pair it with however much ETH they want to place into the protocol. FWA lacks any punishment for depositors pairing a low value asset with an arbitrarily large amount of ETH and even if they enforced parity there would still be the issue of capital efficiency.

Furthermore, a rational depositor (ie: one that does not want to undervalue their asset) is required to already have the FMV of the asset in ETH, which is already a non-starter for many seeking liquidity on their assets. "Providing liquidity" often means selling an NFT for ETH, but FWA creates a pseudo paradox where if you want to sell an NFT for ETH you already need to have its value in ETH. This makes the protocol a non-starter for asset-rich depositors who lack ETH.

Now let's compare with Onchain Gacha. Onchain Gacha both provides better depositor yield and actually accomplishes the primary aim of liquidity provision. Depositors put an asset into the protocol and receive an expected 1.03x back in ETH. In every completed draw the depositor gives up the asset and receives ETH for it, ie: the depositor always expects to receive both the FMV of their deposited asset in ETH, and yield on top. It satisfies both conditions and does so in all cases. FWA only achieves this outcome when the player keeps the NFT, currently 8.1% of settlements. In every other settlement it is at best a low-yield (possibly negative in ETH terms) strategy applied to the backing ETH, not liquidity for the NFT.

In FWA you could place a Cool Cat (0.17 ETH) and pair it with 0.17 ETH and once it's drawn, if the player chooses the ETH, expect to end up with best case the same Cool Cat and 0.170782 ETH (+0.46% = +0.000782 ETH). If the pool has a lot of activity this can decay down to 0.166617 ETH (-1.99% = -0.003383 ETH) due to the protocol purchasing $FWA to give to the player. In effect, you can deposit an NFT and equivalent amount of ETH, seeking liquidity, and expect to end up an indeterminate amount of time in the future with the same NFT and less ETH. This is also not factoring in gas, nor that all of the above "yield" (or lack thereof) is still dependent on the backing ETH, not the asset itself.

FWA counteracts this by having 3% of the haircut players receive when choosing the ETH go towards buying $FWA to reward depositors. This increases depositor yield by an average of 2.76% (0.919*3%) *but* this is completely reliant on players continuing to choose the ETH in most situations. If FWA were to ever fix the issue where assets are way overbacked the depositor yield would fall to the ETH-only yield, which is often negative.

Whereas with Onchain Gacha there are broadly 2 cases (yoinked case notwithstanding):

  1. Depositor places Cool Cat and performs the minimum vouch of 0.02 ETH

    1. The market ends up vouching the Cool Cat at 0.17 ETH; the depositor pays them VF = min(2.5% × (0.17 ETH - 0.02 ETH), 0.02 ETH) = 0.00375 ETH Note: this is close to the worst case % wise depositors will need to pay
    2. Asset enters the protocol
    3. Once it's drawn the depositor expects to have received 0.1751 ETH (+3% = +0.0051 ETH) - payment to voucher = total 0.17135 ETH (+0.79% = +0.00135 ETH)

    Note: if the depositor is unhappy with the market-found valuation of their asset they can just cancel the pending deposit.

  2. Depositor places Cool Cat and initially vouches it's worth 0.17 ETH if they have the liquidity (or they start as branch 1 and subsequently outbid the highest voucher if it's undervalued)

    1. Asset enters the protocol, depositor pays nothing as they were the highest voucher
    2. Once it's drawn the depositor expects to have received 0.1751 ETH (+3% = +0.0051 ETH)

No matter the branch, as long as the asset enters the protocol close to its FMV (and depositors have complete control over ensuring it isn't undervalued by optionally vouching themselves or cancelling) they end up with no asset and an expected positive yield of between 0.56% and 3% on top of the asset's value, before gas and the size and exotic adjustments.7 The better yield is a bonus satisfying the secondary definition of liquidity provision from above, but even in its absence we satisfy the primary definition: the exchange of the asset for its FMV in ETH. Onchain Gacha provides that outcome in every completed draw - FWA currently provides it in only 8.1% of settlements, and even this is subsidised by the protocol's 10% ETH haircut for players. We use the word "expected" here as it is all probabilistic: it's possible, same as FWA, for depositors to have their asset drawn rather quickly and lose money. It is also possible for it to never be drawn and for them to yield well above 3%.

Player RTP#

Not touched on above but also critical to the long term state of the protocol is player behaviour. If RTP is too low and the protocol is too extractive then depositor yield, pool dynamics, tithe rewards, etc are all moot as no tickets will even be purchased.

At launch FWA priced tickets such that they cost 10% more than the expected value of the draw. If every NFT was perfectly backed and the player took the asset, nominal RTP was therefore 90.9%. But, if the player took ETH (>90% of cases) they only received 85% of the backing, making RTP before the separate VRF fee:

RTPFWA,launch,ETH=0.851.10=77.27%RTP_{FWA,launch,ETH}=\frac{0.85}{1.10}=77.27\%

Starting with 1 ETH and repeatedly playing the full balance, five plays at 77.27% RTP leave an expected 0.275 ETH. To reiterate, a player starting with 1 ETH, after 5 plays, is expected to be down -72.5%. The option to buy FWA during the gated phase subsidised this, but the core game absolutely rinsed early players who settled into ETH.

This haircut accounts for, given current ticket surcharge and the proportion of users choosing ETH, approximately 12.53% of every ticket purchase with the initial launch parameters leaking from the protocol.8 This initial ETH completely left the protocol and went to TokenWorks until the community pushed back.

The parameters have since improved. The ticket surcharge is now 2.5% and the ETH payout is 90% of backing.4 This gives 97.56% nominal RTP when a perfectly backed NFT is taken which looks great on paper. In actuality, it is not so great. Due to the lack of incentives ensuring assets are accurately backed, if the asset is underbacked by more than 10% the player has essentially no choice but to eat this 10% ETH haircut. The reality of player choices shows this too - as mentioned above, in only 8.1% of cases are players choosing the asset. No matter how good the RTP of the "choose asset" branch is, if the protocol cannot enforce valuations of the assets and they are significantly overbacked, users are forced to eat the additional 10% haircut and the "choose asset" branch's 97.56% is an illusion.

This is why, as previously mentioned, choosing the ETH is the supermajority of cases - 91.9% of players currently choose the ETH or $FWA branch which returns 87.80% before any $FWA buyback.

RTPFWA,current,ETH=0.901.025=87.80%RTP_{FWA,current,ETH}=\frac{0.90}{1.025}=87.80\%

Five repeated plays at this RTP leave an expected 0.522 ETH. Averaging the observed choices we get a blended ETH RTP of 88.6% before the purchaser's $FWA allocation, the VRF fee, marketplace value errors, and price impact.

It's worth noting that the 10% haircut now does not go to TokenWorks and instead is split, with 30% being burned, 30% going to depositor rewards and 40% going to purchasers as FWA. This takes the RTP up to about 92%, but this simply feels like a mechanism to inflate protocol revenue figures. If players are eating a -10% and then being given back 4%, this is functionally equivalent to players simply having a -6%. All the 70% of the haircut being routed back to players and depositors achieves is creating an illusion of "protocol revenue" and inflating $FWA buy volume. Same with depositors. The protocol could simply reduce the haircut to 3%, have this be burned, and then increase player RTP by 4% and depositor yield by 3% by increasing the ticket surcharge.

If players want to buy $FWA they will take their winnings and do so. If they want ETH, they will take their portion of the haircut's $FWA and sell it for ETH. This buyback in reality is an unnecessary intermediate step that is for some reason seen as revenue, and marginally further erodes RTP due to the need for players wanting ETH to twice eat the LP fees and price impact of buying and selling a token. Taking it to the extreme, a protocol could in fact enact a 100% haircut when players choose the ETH, use all of this to buy their token, and then give 92% back to players. You now have 10x'd your revenue compared to taking just a 10% haircut, right? I would argue that Defillama should in fact only consider the buyback and burn as any sort of protocol revenue.

Onchain Gacha does not need this choice-dependent haircut and explicitly avoids accounting tricks. The player receives the drawn asset, takes over its position, or sells it into a collection bid. At its provisional 5% ticket surcharge its nominal RTP is 95.24% regardless of which branch they choose, assuming appraisals are accurate. Of the 5% surcharge, 3% of appraisal goes to depositors and 2% buys and burns $ONG. None goes to the protocol owner.

Hazard comparison#

FWA fixes the exponent at 1 when calculating deposits' hazards, their likelihood of being drawn. A deposit's raw hazard weight is proportional to A1A^{-1}, where AA is the value of its backed ETH. More generally, this can be written as AαA^{-\alpha}. For FWA, α=1\alpha=1.

Looking at the current state of the FWA pools, the highest deposit is a Cryptopunk backed by 300 ETH. Under FWA's exponent of 1, it has only a 1-in-24.8-million chance of being selected on any draw. Applying Onchain Gacha's exponent of 0.9 to the same pool would improve this to approximately 1 in 10.7 million: 2.32x the hazard, while still keeping the Punk exceptionally rare. See Appendix D for the onchain snapshot and calculation.

The FWA Pulse site currently shows roughly 870 tickets purchased per day. At that rate, one draw in 24.8 million means an expected wait of approximately 28,500 days, or 78 years, for the Punk to be drawn. This is being very generous in assuming that the current rate of ticket purchases stays constant for nearly eight decades.

More importantly, FWA's α\alpha is fixed at 1. This results in a rigid approach to pool hazards. There is no flexibility to respond to market behaviour and tune the player experience. The rigidity also compounds the crown incentive: 1% of each acquisition's distributable fee is routed into a pot for the single highest-backed listing, significantly improving its yield. Because α=1\alpha=1 makes an extremely large listing extraordinarily unlikely to be drawn, a whale with enough ETH can hold the crown and farm this pot while facing very little selection risk.

Onchain Gacha turns this hazard into a variable, initially set to 0.9. At the same rate of play, the 300 ETH deposit's 1-in-10.7-million hazard implies an expected wait of approximately 12,300 days, or 34 years. This might still be too long, in which case we could lower α\alpha to 0.75, giving the Punk a 1-in-3.05-million hazard and an expected wait of approximately 3,500 days, or 9.6 years.

Onchain Gacha's depositor-reward weights change with α\alpha to offset the corresponding change in hazard, so tuning the draw distribution does not change a position's expected lifetime return. Its size premium is the crown's closest equivalent, but is distributed smoothly across larger positions and can be tuned independently rather than awarded entirely to one depositor.

Long term equilibrium#

FWA's long term pool composition equilibrium is not incentivised to be healthy. Depositors hoping to sell an NFT through the gacha currently have an 8.1% observed success rate of the player keeping it. If you actually wish to sell your asset you're better off WETHing it into the highest collection bid on OpenSea. Everyone else is left trying to earn yield. That ETH-only yield is at best +0.46% for an ordinary non-crown position and can fall to -1.99% and is only made positive by $FWA rewards from when players choose the ETH, not the asset. When the player takes the backing rather than the NFT, which happens in the overwhelming majority of cases, the asset itself is perfunctory. A depositor seeking yield is better off pairing backing with the cheapest accepted NFT than committing a valuable asset alongside the same amount of ETH.

This is the strategy FWA's game theory incentivises. If you want to maximise your yield a rational depositor will overback cheap assets. This leads rational players to take the discounted ETH, and the protocol increasingly fills with NFTs nobody actually wants, all the while juicing arguable fake revenue numbers. The initial token emissions could temporarily hide that equilibrium by paying both sides to participate, but they do not change it. Once the emissions end, the underlying game is still the underlying game.

Onchain Gacha changes what the productive capital is. The deposited asset is appraised, enters without permanently paired ETH, and earns based on its own appraised value. There is the deposited asset and nothing else. A depositor cannot obtain the same capital efficiency by substituting a dust NFT because the dust NFT itself receives a dust appraisal. This produces materially better depositor yield than FWA, but Onchain Gacha does not depend on yield in order to satisfy the claim it provides liquidity. Every completed draw removes the asset from the depositor and returns ETH for it, whether the player keeps the asset, takes over the position, or accepts a collection bid. FWA only provides that liquidity when the player keeps the NFT, currently 8.1% of settlements. The remaining 91.9% leave the depositor holding the same NFT and merely settle the separate backing position.

The intended long term loop is therefore straightforward:

A token, specifically $ONG, should amplify a protocol whose core economics is already healthy and allow anyone to buy into revenue upside, but it cannot fix underlying mechanism design flaws.

Supported assets#

FWA allows ERC721 tokens to be deposited along with paired ETH. ERC20 exposure requires a wrapping layer that turns a specified token amount into an NFT before it can enter the protocol. The current interface therefore supports this route, but with the added friction of an intermediate wrapping step.6

Onchain Gacha supports native ETH, ERC721s, and ERC20 amounts directly. An ERC20 position is simply a token address and amount with one appraisal. A valid yoink comparable is the same amount of the same token, and a collection bid must cover that full amount. VF_min prevents economically meaningless quantities from entering regardless of token decimals or unit price.

Native ERC20 support lets the protocol support memecoins, governance tokens, stablecoins, etc, without pretending each one is natively an NFT. Native ETH can enter at face value without a valuation period. ERC721s retain collection-based comparables and collection bids.

The protocol should still begin conservatively. Fee-on-transfer, rebasing, callback-heavy, or otherwise non-standard ERC20s complicate custody and settlement and should not be allowlisted until their behaviour is explicitly supported. But treating ordinary ERC20 amounts as first-class assets is not meaningfully harder at the economic layer. The valuation, weighting, draw, accrual, and settlement system all function whether the deposit is an ERC20, native ETH, or ERC721. Additionally tokens will be chosen based on having healthy secondary markets, otherwise player RTP is inadvertantly reduced.

$ONG vs $FWA#

The initial launch of $FWA was mostly well done. My only criticism was that in releasing 30% of the supply as rewards during the first 15 days it artificially incentivised volume, and did so while buys were gated and the 15% haircut on ETH went entirely to TokenWorks.

$ONG avoids this entirely. It similarly will put 50% of tokens in a single sided liquidity pool. There will be no revenue going towards the team from any sort of player haircut though - not at first, not ever. The team will instead use the protocol to perform a pseudo gacha-ICO, and do it at a conservative market cap that incentivises players to buy tickets.

Similarly during this initial phase, rather than forcing players to purchase a token during their ticket resolution window we instead grant all players and depositors a buy allowance whenever a deposit is landed on. This gives everyone control over when and how they wish to purchase the token. Players can sell the asset they landed on and wait for a dip before buying. Similarly depositors now can take their expected positive yield and buy the token if and when they wish.

Long term the protocol will earn yield on the LP position - ETH from the LP will be treated as revenue and $ONG will be burnt, in addition to the buyback and burn occurring on ticket sales. This buyback and burn will also be live from day 0.

Finally, the team will reserve a portion of tokens in order to properly align incentives. These tokens will not be sold on the open market.

Unlocks#

Onchain Gacha unlocks a range of new incentivised behaviours for market participants. I will detail one below, but I am certain that many more will emerge as the protocol grows.

Double productive capital#

In FWA you should have an asset and at least that asset's FMV in ETH. Yet, your liquidity/yield is only based on the ETH deposit. With Onchain Gacha, if you had both the asset and the ETH like all depositors in FWA have now, you could:

You have now

This is just an example of novel market behaviour that the Onchain Gacha unlocks.

Note: my hope is that as the protocol matures the collection bid discount will narrow. Similarly, if a collection bid is discounted too much then the player will simply take the asset and sell it elsewhere if they wish.

Caveats#

Only floor NFTs deposited#

Astute readers will have noticed that given the yoink mechanic any non-floor NFT will need to still be valued at the floor price, as any vouch above the floor can be yoinked by providing a floor NFT. FWA does not have this issue but with our design this is a necessary short term concession, but is solvable.

In parallel and once the core Onchain Gacha protocol is live I'll build out a "boxing protocol". In brief:

This will allow for interesting collections like trading cards, casino-within-a-casino where you can box different amounts of a fungible token and then put them into the gacha, etc.

Conclusion#

The contracts for $ONG are partway through completion. Solo-launching ETH products was not my primary focus but upon seeing FWA launch, if I were to critique it then I had to propose an alternative. I am open to collaboration but with or without collaboration will continue work on the contracts as Ethereum deserves a better gacha. Depositors and players alike deserve a more capital efficient, less extractive, and long-term healthier gacha.

It is entirely possible that players long term don't actually want a gacha protocol. That's ok - the only way to know that is to build the best one possible and put it in front of them. Having spent a lot of time thinking about FWA and how so few players choose the NFT in the end, I do wonder if players actually want an NFT gacha. That's ok, the solution there too is to build the best one possible, have it support ETH and ERC20s, and then both increase the desire for NFTs in the short term and have the infrastructure ready for when the pendulum swings back towards those assets. In the meantime the Onchain Gacha is poised to take advantage of any ERC20 related bull run.

Regardless, Onchain Gacha delivers improvements in all key areas:

Thank you for reading. I will post updates about the development of the contracts and am looking forward to robust discussion on everything outlined above. I hope readers leave this essay with a better understanding of FWA and its economics, as well as how the Onchain Gacha aims to fix the areas where FWA falls short.

Appendix A: FWA ordinary depositor ETH yield#

This derives the nominal lifetime ETH fee return for an ordinary FWA deposit that does not hold the crown. It excludes $FWA emissions and rewards, gas, NFT price changes, and the economics of the player's eventual settlement choice.

Let:

FWA uses inverse-backing selection weights, so:

Pi=1/BiSP_i=\frac{1/B_i}{S}

and its expected-value acquisition base is the harmonic mean:

M=NSM=\frac{N}{S}

After the purchaser-allocation slice, protocol cut, and crown tithe, the amount shared equally among ordinary active positions per acquisition is:

Rticket=M[1+s(1f)](1o)(1t)NR_{ticket}=\frac{M[1+s(1-f)](1-o)(1-t)}{N}

Position ii remains active for an expected 1/Pi=BiS1/P_i=B_iS acquisitions. Because FWA includes the selected position in the fee distribution for its final acquisition, its expected lifetime ETH fee accrual is:

Ri=RticketBiS=Bi[1+s(1f)](1o)(1t)R_i=R_{ticket}\cdot B_iS =B_i[1+s(1-f)](1-o)(1-t)

Its nominal ETH fee profit relative to backing is therefore:

y(f)=[1+s(1f)](1o)(1t)1y(f)=[1+s(1-f)](1-o)(1-t)-1

At the most favourable setting for ETH depositors, where none of the surcharge is diverted to the purchaser (f=0):

y(0)=(1.025)(0.99)(0.99)1=0.00460250.46%y(0)=(1.025)(0.99)(0.99)-1 =0.0046025 \approx 0.46\%

If the entire surcharge is diverted (f=1), the ETH-only return becomes:

y(1)=(1)(0.99)(0.99)1=1.99%y(1)=(1)(0.99)(0.99)-1=-1.99\%

The current dynamic split moves between these endpoints according to time since the previous acquisition. Crown holders receive the tithe pot and therefore have different economics. This is why approximately 0.46%, rather than 2.5%, is the appropriate best-case nominal ETH fee profit for an ordinary non-crown deposit under the current parameters. See FWA's pricing, fee, top-deposit reward, and $FWA documentation.

Appendix B: Onchain Gacha depositor yield bounds#

This derives the expected baseline depositor yield after paying the winning-voucher fee. It assumes the asset enters at appraisal AA, baseline depositor profit is p=3%p=3\%, and the vouch discovery rate is k=2.5%k=2.5\%. It excludes gas and the size and exotic adjustments.

The depositor expects to accrue A(1+p)A(1+p) before the asset is drawn. If their opening vouch is ViaV_{ia}, the winning-voucher fee is:

VF=min(k(AVia),Via)VF=\min(k(A-V_{ia}),V_{ia})

Expected profit after this fee is pAVFpA-VF, so expected yield relative to appraisal is:

y=pVFAy=p-\frac{VF}{A}

The maximum is reached when no vouch fee is paid:

ymax=p=3%y_{max}=p=3\%

To find the minimum, let x=A/Viax=A/V_{ia}. The fee as a share of appraisal is:

VFA=min(kx1x,1x)\frac{VF}{A}=\min\left(k\frac{x-1}{x},\frac{1}{x}\right)

The first term rises with xx and the second falls. Their minimum is therefore largest where they intersect:

k(x1)=1k(x-1)=1 x=1+1k=41x=1+\frac{1}{k}=41

At this point, the maximum vouch fee as a share of appraisal is:

VFA=141=k1+k2.439%\frac{VF}{A}=\frac{1}{41}=\frac{k}{1+k}\approx2.439\%

The minimum expected baseline yield is therefore:

ymin=3%2.439%0.561%y_{min}=3\%-2.439\%\approx0.561\%

This is why expected baseline depositor yield after valuation fees is bounded between approximately 0.56% and 3%, before gas and the size and exotic adjustments. The 0.17 ETH Cool Cat example produces 0.79% because its appraisal-to-opening-vouch ratio is 8.5 rather than the worst-case ratio of 41.

Appendix C: FWA ETH-haircut value leak#

This derives the expected value withheld from players by FWA's current 10% ETH haircut. It assumes the observed ETH or $FWA choice rate is 91.9%, the ticket surcharge is 2.5%, positions are perfectly backed, and the separate VRF fee is excluded.

Let:

The expected value withheld by the haircut per ticket is:

L=qhM=(0.919)(0.10)M=0.0919ML=qhM=(0.919)(0.10)M=0.0919M

The ticket price before the separate VRF fee is:

T=M(1+s)=1.025MT=M(1+s)=1.025M

The haircut as a share of the ticket price is therefore:

LT=qh1+s=(0.919)(0.10)1.0258.97%\frac{L}{T}=\frac{qh}{1+s} =\frac{(0.919)(0.10)}{1.025} \approx8.97\%

The same result can be expressed as lost RTP. Without the haircut, nominal RTP would be:

RTPno haircut=11.02597.56%RTP_{\text{no haircut}}=\frac{1}{1.025}\approx97.56\%

With the observed branch choice rate, expected player value before the purchaser's $FWA allocation is (1qh)M=0.9081M(1-qh)M=0.9081M, giving:

RTPblended,pre-redistribution=1qh1+s=0.90811.02588.59%RTP_{blended,\,pre\text{-}redistribution}=\frac{1-qh}{1+s} =\frac{0.9081}{1.025} \approx88.59\%

The difference is approximately 8.97 percentage points. Relative to expected backing drawn, the haircut withholds 9.19%. Relative to the amount paid for the ticket, it withholds 8.97%.

Appendix D: FWA pool snapshot and hazard comparison#

This appendix records the onchain snapshot used in the hazard comparison. At Ethereum block 25,777,826, FWA's core contract contained 6,391 active listings backed by a total of approximately 1,284.64 ETH. Active backing ranged from 0.05 ETH to 300 ETH; the 300 ETH listing was a Cryptopunk.

The snapshot was constructed by enumerating the contract's active listing slots, reading each listing's backed-ETH value, and summing those values. It measures active ETH backing, not the market value of the deposited NFTs or a broader TVL figure.

For appraisal or backing AiA_i, hazard weight at exponent α\alpha is:

wi=Aiαw_i=A_i^{-\alpha}

and the probability of listing ii being selected on any draw is:

Pi=AiαjAjαP_i=\frac{A_i^{-\alpha}}{\sum_j A_j^{-\alpha}}

Using FWA's α=1\alpha=1, the 300 ETH Cryptopunk's probability per draw was approximately:

P300,α=14.033×108P_{300,\,\alpha=1}\approx4.033\times10^{-8}

This is 0.00000403%, or approximately 1 in 24.8 million draws. Holding the same pool composition constant but applying Onchain Gacha's α=0.9\alpha=0.9 gives:

P300,α=0.99.339×108P_{300,\,\alpha=0.9}\approx9.339\times10^{-8}

This is 0.00000934%, or approximately 1 in 10.7 million draws. The lower exponent therefore makes the Punk approximately 2.32x as likely to be drawn without making it common. These figures are a point-in-time estimate: deposits and withdrawals after the snapshot block change both denominators.

At α=0.75\alpha=0.75, again holding the same pool composition constant, the probability becomes:

P300,α=0.753.276×107P_{300,\,\alpha=0.75}\approx3.276\times10^{-7}

This is 0.00003276%, or approximately 1 in 3.05 million draws: 8.12x the Punk's FWA hazard and 3.51x its hazard at α=0.9\alpha=0.9. At approximately 870 tickets per day, the expected waits at α=1\alpha=1, α=0.9\alpha=0.9, and α=0.75\alpha=0.75 are respectively 78 years, 34 years, and 9.6 years. These are expected waiting times, not deadlines or guarantees.

References#

  1. FWA Pulse is an independent live dashboard of onchain FWA activity. Its NFT-kept rate changes as new settlements occur.
  2. FWA's current parameter documentation specifies a 90% depositor-bid payout, leaving a 10% haircut. The launch contract configuration used an 85% payout, leaving a 15% haircut.
  3. See Appendix A for the complete yield derivation and assumptions.
  4. FWA's current pricing and parameter documentation specify a 2.5% acquisition surcharge and a 90% standing-bid payout.
  5. FWA's official $FWA documentation specifies the 50% market, 30% emissions, and 20% v1 snapshot allocation.
  6. FWA's deposit interface exposes an ERC20 deposit route, while its published core source represents pool positions as ERC721 listings.
  7. See Appendix B for the derivation of the baseline Onchain Gacha depositor-yield bounds.
  8. See Appendix C for the derivation of the expected value withheld by FWA's ETH haircut.