MMashDiv

Inventory and funding the house

The house's two inventories - ledger balances that balance converts pay from, and coins at its own addresses that Sends pay from - which may be funded with a ledger move and which only on-chain, why coins from your own master wallet or exchange account are not credited, the house deposit addresses, rescan, floors and defunding.

7 min readUpdated 1 October 2026admin, inventory, funding, defund, floor, target, deposit, rescan

Admin → Convert → Inventory (/admin/convert/inventory). Viewing needs view.convert.inventory; funding, defunding, floors and rescans need edit.convert.inventory.

The house is a system account. It cannot sign in, receive email, receive transfers from users or be deleted, and it is never the Super Admin or the pool-backing treasury: revenue and inventory must not mix, and the Super Admin's identity can change. It holds a Spot wallet and an Ecosystem wallet per currency, and every convert is paid out of those.

Two inventories, not one

Ledger inventory On-chain inventory
What it is the house's wallet.balance per currency and wallet type the coins the house's own addresses hold, per currency and chain
What pays from it balance converts (Spot and Ecosystem) Convert & Send payouts
Kept back the asset's floor the Send chain's floor, plus what open Sends and movements have reserved
Shown on the House ledger tab the Send chains tab

They differ, and the difference is structural. When a user converts ECO BTC to the house, the BTC stays on the user's own deposit address, in the pool: the house's ledger inventory of BTC rises, its on-chain inventory does not. Only coins that arrive at a house address are on-chain inventory.

For a Send on chain k, available is:

available = min(key tracker, address map) − open reservations − floor

The two trackers are the ecosystem's two records of what the house's key holds on that chain; the lower one counts, so a tracker that runs ahead of the chain can delay a Send but never overspend one. The payout re-reads the chain itself immediately before signing and refuses a shortfall. A chain with nothing available above its floor stops being offered to users.

How each currency may be funded

  • Coins sent from one of your master wallets are never credited. The deposit scanners skip transfers the platform made itself, on EVM and on TRON. They leave the master and arrive nowhere on the books.
  • Never withdraw funding from the platform's own exchange account. That lowers what the platform holds without changing what it owes, and the pool-backing reconciliation reports it as exchange drift. Moving the house's own coins between the exchange and the chains is a house movement, never funding.
  • Never fund the house with an admin balance adjustment. An adjustment with no coins behind it writes a pool-backing obligation that stays open for ever.

There are two ways to fund the house, and which one a currency may use is decided in code.

Fund (a ledger move) moves a balance from the Super Admin wallet of the same currency and wallet type to the house. Nothing is minted, so the platform's totals do not change. It is allowed for:

  • Spot, any currency. Both balances are backed by the same exchange account.
  • Ecosystem, only for a currency with one enabled chain of a pooled family: UTXO coins, EVM tokens, TRC-20 tokens, TRX. The Super Admin's balance of those is backed by pooled coins, so moving it keeps everything backed.

It is refused, by name, for every other Ecosystem currency. The Super Admin's native balances are fee credits whose coins sit on the payers' addresses, and an SPL or multi-chain token can only be paid from the address that holds it, so a ledger entry would give the house something it could never pay out with.

Fund in the House ledger card's header picks the row to fund (USDT · Spot, BTC · Ecosystem), or Another currency (Spot)… for a Spot currency the house does not hold yet; a row's own menu funds or defunds that row, and a row that may not be funded this way reads Funded on-chain only there.

On-chain funding works for every family and is the only way to fund Send inventory: send coins from outside the platform to the house's own deposit address, and the deposit scanner credits them.

Every Fund and Defund is one database transaction that locks both wallet rows in id order, is audited, and carries a request id from the dialog: a retried click finds the first transfer and answers with it rather than moving twice.

The house deposit addresses

The Funding addresses panel lists the house's Ecosystem deposit address on each chain, per currency, with a copy button and an explorer link. The scanner credits a deposit to the house only if it watches that address, so the house's addresses are registered with it through the ecosystem addon's house deposit watch. It applies the same filters as customers' addresses: the network must match, native coins are credited only to the native coin's wallet, and TRON tokens only for their own contract.

  • The quote-cleanup job re-registers every house address every 30 minutes, well inside the 72 hours after which the scanner forgets an address it has not been told about.
  • Rescan deposits is the "I just sent coins, look now" button. It registers the house's addresses (all, or one currency's) and asks for an immediate scan. The answer says how many addresses it registered and lists every one it skipped, with the reason: for example a chain whose deposit monitor the Rust backend owns, where a registration would be a silent no-op.
  • No funding address yet means the house has no Ecosystem wallet for that currency, or none of its addresses is one the deposit scanner would credit. Rescan deposits does not open a wallet: for a currency with none, it answers under Skipped by the deposit watch that the house has no ECO wallet of that currency yet. The wallet is opened by a Fund of the currency, by the first Ecosystem convert from it, or by an exchange-to-chain house movement. A currency that Fund refuses (see above) cannot be converted from on Ecosystem either, so for it only an exchange-to-chain movement opens the wallet.

Rescan is open while quoting is paused: funding the house is how you get it ready to unpause.

Floors and targets

Edit floor and target in a ledger row's menu sets the asset's floor and target. On the Send chains tab each (currency, chain) line carries its own floor and target in on-chain units, changed with Edit in its menu. A per-chain value, not one number per currency, because on some chains two currencies share one address key and a single number would be a floor in both units at once.

  • The floor closes converts (or Sends on that chain) before the house runs dry. At the floor exactly, nothing can be paid.
  • The target is what hedging and movements aim for. It must be at or above the floor.

Send chains

A Send of a currency on a chain is possible only with a Send chain here whose Sends switch is on. Add one per (currency, chain) you intend to pay on, fund the house address on that chain, then turn Convert & Send on in Settings.

The tab is one Send chains card, one line per (currency, chain): its Sends on or Sends off badge; On chain, what the house's address holds there (the lower of the two trackers, with both shown under it as Trackers differ when they disagree); Reserved, what open Sends and movements hold, with how many open Sends; the Floor and Target; Available above the floor (at zero, with its Sends on, it reads Closed to new Sends); and the House address with copy and explorer buttons.

  • Add Send chain, in the card's header, picks the currency (the Ecosystem currencies Instant Convert knows, or Another currency… to type a code) and one of its enabled chains (a chain already set up is listed greyed out), with the Sends switch, the floor and the target.
  • Edit, in a line's menu, changes the Sends switch, the floor and the target; the currency and chain are fixed.
  • Delete, last in the menu, asks first, and is refused while the chain's Sends are on or an open Send holds a reservation there. The house's coins stay at its address.

Defunding

Defund is the reverse move, from the house to the Super Admin wallet of the same currency and wallet type, with the same family rule as Fund. It never takes the house below its floor plus what open work holds: a Send's hold on what the user paid, a hedge's hold, a movement's hold. Those normally sit in the wallet's in order column, where a debit of the balance cannot reach them; any part the column does not cover is kept back as well. In the dialog, Max fills what the row has available above its floor.

On-chain inventory at house addresses (native coins, SPL, multi-chain tokens) is never defunded by ledger. It leaves the house only on-chain.

The core house page has a defund of its own that keeps working while the addon is disabled or unlicensed. It respects open holds but not the floor, because it is the wind-down path: emptying the house of a retired currency must be possible.