CoinYQ Dossier

Anvil separated a credit claim from the vote that governs the protocol

Anvil lets someone set aside crypto collateral so a named beneficiary can claim an agreed asset through a letter of credit (LOC). That payment claim is separate from the ANVL token used to govern the protocol. The 2025 token migration changed who could vote with which token; the version deployed in 2026 exposes a gap between the promised payout and what the code pays when collateral falls short.

The vault requires approval from the protocol and the depositor

CollateralVault is the accounting gate for available and reserved ERC-20 balances. Governance chooses supported tokens and approves contracts that may use the vault. An account must also set an allowance before one of those contracts can reserve its collateral. The contract therefore does not turn every deposit into a general line of credit.

LetterOfCredit adds named parties to that base. A creator reserves collateral for a beneficiary and specifies a credited amount. Redemption requires the beneficiary or a third party holding its signed authorization. Cancellation follows that rule before expiry, while current v3 allows any caller to cancel after expiry. The code creates a bounded on-chain claim rather than a transferable ownership interest in everything held by the vault.

A dynamic LOC must turn one asset into another

A static LOC uses the same token as collateral and credited value. A dynamic LOC separates them. The latter must begin overcollateralized because exchange rates can move before redemption. Governance configures creation and liquidation factors, limits and Pyth price feeds for each supported pair.

If the position weakens, a liquidator can convert collateral into the credited token. The beneficiary receives that asset and never owns the underlying collateral. Documentation says the full credited value is invariably received; current verified v3 code also handles insolvency by paying liquidator and protocol fees first and giving the beneficiary as much as possible. The absolute guarantee therefore conflicts with the deployed implementation.

Pool units and ANVL votes solve different problems

TimeBasedCollateralPool gathers supported ERC-20 assets from multiple accounts for a specified claimant. Contributors receive units tied to their share, while configured epochs delay unstaking so collateral remains predictable across the current and following period. A new pool proxy also needs governance approval before CollateralVault accepts it. Each pool instance assigns separate administrator, claimant, routing and reset roles; ownership of the shared beacon does not mean core governance holds every instance role.

These pool units are not ANVL. ANVL is an ERC20Votes token whose voting weight must be delegated to oneself or another address. Current rules require 1 billion delegated votes to propose, 10 billion votes for quorum, five days of voting and a seven-day timelock before an approved call can execute.

The timelock sits behind both parameters and upgrade paths

The repository maps the Governor proxy, AnvilTimelock, CollateralVault, LetterOfCredit proxy, Pyth adapter and pool beacon. At Ethereum block 25,908,119 on 5 September 2026, read-only calls returned the timelock as owner or admin across those reviewed core paths. The LOC proxy had already moved to verified v3 implementation 0x6c22beA8930980C6C5B4f9c449DA0964eDCAa33B on 27 August, while the README still named an older singleton.

A delay makes a change visible before execution, but does not make the machinery immutable. Delegated-vote concentration can decide which calls pass, and proxy upgrades can alter logic while keeping familiar addresses. The documentation’s public queue and execute route goes through the Governor. In the reviewed pinned source, AnvilGovernorDelegate inherits that route and forwards internal operations to the timelock. The September 5, 2026 role probes did not grant direct Timelock roles to the zero address; that result does not test a user’s access through the Governor and does not establish a conflict with the documentation. Current deployed roles and an end-to-end call through the live Governor were not verified in this source comparison.

The v2 migration fixed one block before it changed the Governor

ANVL v1 deployed on 3 June 2024 with a Claim contract that handled initial issuance and vesting. A September 2025 proposal chose Ethereum block 23,461,500 as the v2 snapshot. It specified 1:1 v2 amounts for snapshot-recorded community balances, full vesting for Claim and Reward allocations, and at least a twelve-month lock for contributor and team allocations. V2 itself has no Claim-contract vesting integration, which does not mean every allocation was immediately unlocked.

The v2 contract deployed on 2 October and its initial recipient began distribution transactions on 3 October. Two executed proposals then upgraded governance and made v2 the Governor’s token on 15 October, restoring the seven-day timelock. The reviewed thread does not establish a continuing bridge for v1 bought after the snapshot, and its published schedule was not treated as a fully reconciled transfer ledger. Public materials identify Acronym Foundation as publisher, but do not establish its registration jurisdiction or additional contractual rights for ANVL holders.

How the project changed

  1. 2024-06-03
    ANVL v1 is deployed

    The first token uses a separate Claim contract for initial issuance and vesting.

  2. 2024-09-26 to 2024-11-30
    LOC configuration and launch upgrades

    Governance configures credited assets and factors, then replaces LOC v0 with the current proxy pattern and upgrades the pool beacon.

  3. 2025-09-28 12:29:23 UTC
    Migration snapshot

    Ethereum block 23,461,500 fixes the community-balance reference used by the v2 proposal.

  4. 2025-10-02 to 2025-10-03
    V2 deployment and distribution begin

    The fixed-supply v2 token is deployed, then its initial recipient begins outbound distribution transactions.

  5. 2025-10-15 17:02:47 UTC
    Governor adopts ANVL v2

    The second executed proposal points governance to v2 and restores the seven-day timelock.

  6. 2026-08-27 18:49:47 UTC
    LetterOfCredit proxy moves to v3

    An executed governance transaction upgrades the live proxy to a verified implementation newer than the repository map.

Evidence and primary sources

Last evidence review: 2026-09-05

What is Anvil?

Anvil is a set of Ethereum contracts for reserving collateral and creating what the project calls letters of credit (LOCs). A creator reserves assets in CollateralVault for a named beneficiary, who can redeem the LOC’s credited value. A separate TimeBasedCollateralPool lets multiple accounts contribute supported ERC-20 assets for a specified claimant.

ANVL is the protocol’s ERC20Votes governance token. The current v2 contract is 0xAEEAa594e7dc112D67b8547fe9767a02c15B5597 and minted a fixed 100,000,000,000 tokens. ANVL voting power matters only after delegation; holding it does not itself create an LOC, unlock vault collateral or confer pool units.

The current LOC proxy now points to a verified v3 implementation deployed after the repository’s latest mapped singleton. For present behavior, the deployed source takes priority over the older README map.

What problem does Anvil solve?

A collateral promise can be ambiguous unless the code identifies who supplied the assets, who may claim value and who may change the rules. Anvil separates those roles. The depositor controls an account allowance, the protocol approves which contracts may reserve collateral, and the LOC names the beneficiary.

That separation also exposes a governance question. ANVL voters can approve parameters and upgrades through a Governor and timelock, so a fully collateralized position still depends on oracle settings, asset limits, contract implementations and the concentration of delegated votes.

How does Anvil work?

CollateralVault accepts governance-approved ERC-20 assets. Before another Anvil contract may reserve an account’s collateral, both the protocol and that account must approve its use. An LOC then records a creator, beneficiary, collateral amount and credited amount. Before expiry, redemption and cancellation require the beneficiary or its signed authorization; after expiry, current v3 lets any caller cancel the LOC.

When the collateral and credited assets match, redemption can use the reserved asset directly. When they differ, the dynamic LOC must be overcollateralized. Pyth prices and governance-set factors determine when collateral is converted or liquidated to obtain the credited asset. The beneficiary receives that credited asset, not ownership of the underlying collateral. Current documentation says the full credited value is invariably received, but the verified v3 code also handles insolvency by paying liquidator and protocol fees first and giving the beneficiary as much as remains. CoinYQ therefore treats the absolute guarantee as conflicting with deployed code.

TimeBasedCollateralPool is another contract path: contributors receive pool units and withdrawals follow configured epochs while a specified claimant may use the pool’s collateral. ANVL does not represent those units. Delegated ANVL votes instead govern proposals; current on-chain values and published rules use a 1 billion-vote proposal threshold, 10% quorum—10 billion votes against the fixed supply—and seven-day timelock. Per-pool claimant and administrator roles remain separate from core governance.

Key facts

  • ANVL v2 is an 18-decimal Ethereum ERC-20 at 0xAEEAa594e7dc112D67b8547fe9767a02c15B5597.
  • Its constructor minted a fixed 100,000,000,000 ANVL and exposes no later mint function.
  • CollateralVault is 0x5d2725fdE4d7Aa3388DA4519ac0449Cc031d675f.
  • The current LetterOfCredit proxy is 0x14db9a91933aD9433E1A0dB04D08e5D9EF7c4808.
  • An LOC separates its creator, beneficiary, collateral asset and credited asset.
  • Redemption requires the beneficiary or its signed authorization. Cancellation follows that rule before expiry, but current v3 allows any caller to cancel an expired LOC.
  • A beneficiary receives the credited asset and never takes ownership of the underlying collateral.
  • Dynamic LOCs use different collateral and credited assets, so they require overcollateralization, pricing and liquidation rules.
  • Time-based collateral pools issue pool units for contributed ERC-20 collateral and delay exits by epoch.
  • Each time-based pool has its own claimant and administrative roles; core governance owns the shared beacon but does not automatically operate every pool role.
  • ANVL voting power must be delegated; current rules publish a 1 billion-vote proposal threshold, 10 billion-vote quorum and seven-day timelock.
  • On 2026-09-05, read-only calls returned the AnvilTimelock address as owner or admin across the reviewed core and proxy control paths.
  • The live LOC proxy used verified v3 implementation 0x6c22beA8930980C6C5B4f9c449DA0964eDCAa33B after the 2026-08-27 upgrade; the repository README still mapped an older singleton.
  • The migration snapshot was block 23,461,500 on 2025-09-28 12:29:23 UTC; governance switched to ANVL v2 on 2025-10-15.

Official links

Categories

Related coins

Frequently asked questions

What is ANVL?

ANVL is Anvil’s Ethereum governance token. The current v2 contract has a fixed 100 billion supply and uses delegated ERC20Votes voting power.

What does an LOC beneficiary receive?

The beneficiary redeems the credited asset and never acquires the underlying collateral. Documentation says the full credited value is guaranteed, but current v3 code includes an insolvency branch that can leave the beneficiary with less than face value after fees.

Is ANVL the collateral behind an LOC?

No. Supported ERC-20 assets deposited in CollateralVault or a collateral pool secure positions. ANVL is a separate governance token unless a specific product separately approves it as collateral.

Who can change Anvil’s contracts and risk settings?

ANVL governance queues approved actions through the AnvilTimelock. At the review snapshot, that timelock owned core contracts and controlled the reviewed proxy-admin paths. Each pool also has separate claimant and administrative roles that core ANVL governance does not automatically hold.

What happened when ANVL moved to v2?

The official proposal used balances at block 23,461,500 for community 1:1 distribution amounts. V2 deployed on 2 October 2025 and governance adopted it on 15 October. Reviewed sources do not establish a continuing swap or bridge for v1 acquired after the snapshot.

Does ANVL grant company or collateral ownership?

The reviewed sources document delegated protocol voting. They do not establish company equity, revenue, treasury or Foundation-asset ownership, a fixed-price redemption right, or an automatic claim on another user’s collateral.

External trackers

Choose a tracking site for Anvil: