Finite supply defended & attacked; the 1000-cap verdict; the threshold endgame · content/qals-tokenomics-paper.md
The Finite Qals — a paper on scarcity, caps, and what happens at the threshold
Author: qalcode (GLM 5.3) · Date: 2026-09-12 · Status: positions of the project, argued honestly — both sides first Companions: token supply · fee policy · exchange feasibility · the backing design
Abstract
QALS has a fixed maximum of 1,000,000 Qals with a 500,000 sales cap — enforced in code: the full sellable supply is pre-endowed in the genesis issuer wallet qals:issuer (2026-09-15) and each purchase transfers out of it, so the cap is the wallet running out (402 "sellable supply exhausted"); the on-chain cap-gate (qal_reserve) is written and tested — the on-chain twin is being redesigned from mint-gated to genesis-preminted + transfer-gated at the cap-raise checklist. This paper defends that design, attacks it, and resolves the founder's three live questions: should per-person purchase caps (1,000 Qals/card) limit supply domination; what actually happens when the 500K threshold is crossed; and whether a second, stable token (qAUD) with a QALS↔qAUD exchange is the right endgame — the IOTA↔Shimmer relationship, done deliberately. We conclude: finite is right but for a subtler reason than "store of value"; per-person flat caps are the wrong tool (graduated caps are right); and the two-token endgame is structurally correct with the Shimmer lesson baked in.
1. The design as it stands
| Property | Value | Enforced by |
|---|---|---|
| Max supply | 1,000,000 Qals | genesis + qal_reserve code (written + tested) |
| Sales cap | 500,000 (50% founder hold) | loopd sales rail — the issuer wallet runs out (proven live); on-chain twin qal_reserve written + tested, being redesigned genesis-preminted + transfer-gated at the cap-raise checklist |
| Divisibility | 1 Qals = 1,000,000 doofs (10⁻⁶) | protocol |
| Credit phase | 1 Qals = AU$1 of prepaid credit | reserve + redemption policy |
| Fees | none at network level | code (spread = the margin) |
The critical, often-missed nuance: during the credit phase, QALS is not an asset — it is a liability. Every sold Qals is a claim on AU$1 of service redemption. "Scarcity" of a liability is meaningless until the cap is crossed and the credit promise is unwound. That is exactly why the 500K threshold question matters so much.
- 1,000,000 — max supply — Qals, ever (genesis + qal_reserve code (written + tested))
- 500,000 — sales cap — 50% founder hold (loopd refuses past-cap sales (proven live))
- 10¹² — total base units — doofs (1 Qals = 1,000,000 doofs)
- 500,000 sold — glowing
- 500,000 founder hold — dim
2. The case FOR finite supply
- The network beneath it is finite. This is a private chain with operator-run validators and a real compute fleet behind it. Token float should reference actual capacity, not speculative infinity. An infinite-credit ledger pretending to be backed is how every fractional-reserve disaster starts.
- The IOTA natural experiment (the hard evidence). IOTA abolished its cap in 2025; supply now inflates ~6%/yr. Result: world-class infrastructure (Starfish consensus, WEF-grade trade deployments) and a token at −99% from ATH, rank ~#180. The lesson cuts BOTH ways: inflation didn't fund success, and finite supply wouldn't have prevented the decline — token economics didn't determine either outcome; usefulness did. Finite supply's honest job here is discipline: it forces the operator to fund the network from revenue (spread, services) rather than from dilution. That discipline is the real argument.
- Gresham dynamics are absent while it's credit. Nobody hoards gift cards when the shop might close; they spend them. A finite credit supply simply bounds outstanding liabilities — good accounting, not monetarism.
- Crossing the threshold creates a genuine asset. At 500K sold, unsold Qals become the scarce settlement/governance asset of a working network (see §5). Scarcity then means something: you cannot issue more network-foundation shares quietly. The fail-closed refusal (loopd rail today; on-chain gate written + tested) is the whole point — it makes the promise verifiable rather than aspirational.
3. The case AGAINST (steel-manned)
- Deflationary currency is a bad medium of exchange. If QALS appreciates, rational users hoard rather than spend — but our users must spend to get compute. The system resolves this by pricing services in AUD-pegged credit and letting the asset float separately — which concedes the critic's point: a spending unit should not be the scarce asset. That is the two-token argument arriving early (§5).
- A cap creates a death-spiral scenario. Near the threshold, compute demand in credit terms could exceed remaining sale supply: prices of Qals spike, compute becomes "expensive" in Qals even though the AUD price is unchanged — a pure unit-supply artifact that damages users. Mitigation: threshold day IS the migration day (convert pricing to qAUD simultaneously); don't operate near-cap in the old unit.
- 1M units may be socially awkward even though divisibility (10¹² doofs) makes it economically sufficient — "only a million" reads small to crypto natives habituated to billions. Counter: BTC is 21M units; the number is marketing, the divisibility is the substance; a 1:1000 redenomination later is trivial if ever wanted (rename, don't inflate).
- Fixed supply removes a governance tool. Validator decentralisation (Phase 3+) needs a funding source; an inflating token funds it invisibly (and corruptly — see IOTA). Honest answer: fund validators from service margins and the Reserve yield, stated in the fee policy's caveat. If that ever proves insufficient, that is a Phase-3+ redesign conversation with holders — not a quiet emission.
4. The 1,000 Qals/person cap — the founder's instinct, examined
Goal: prevent few actors buying dominating supply. Founder's own objection: in practice it caps a heavy user at AU$1,000 of compute — a day of GPU for some.
Analysis. A flat, forever cap fails both ways: too tight for real users, too loose for domination (1,000 people × 1,000 = the whole cap; a sybil with 500 cards owns half). The domination problem is about concentration, not individual size; the compute problem is about usage, not holding. These need different tools:
| Tool | Fixes | Mechanism |
|---|---|---|
| Graduated purchase tiers (recommended) | domination | Tier 1: 1,000/card without verification. Tier 2: +10,000 with qalid-verified identity. Tier 3: +50,000 with KYC tier 2. Rising with account age + settled history — you earn limits by using the network, not by arriving with capital. |
| Time-release windows | hoarding at launch | e.g. first 90 days: per-identity daily purchase max; removes launch sniping. |
| Usage-linked, not wealth-linked | the compute objection | caps apply to purchase of new Qals only — never to earning (compute providers), transfers in, or spending. A provider earning 50K Qals/yr for GPU work is unaffected; only buyers of the fixed sale are tiered. |
| Governance circuit-breaker | stealth accumulation | if any identity cluster exceeds 5% of sold supply, a public review flag (anchored; no seizure — transparency, not confiscation). |
Recommendation: graduated tiers + launch windows; drop the flat 1,000 idea. It solves domination with sybil-cost (verified identity tiers) while leaving genuine usage unlimited through the earn side.
5. Crossing the 500K threshold — the two-token endgame
What the founder sketched is correct, and here is the precise mechanics:
- Day 0 (threshold): sales close (cap-refused already, in code). Announce migration: service pricing moves to qAUD, a new AUD-pegged stable token (mint-on-AUD-deposit, burn-on-redeem — the
qal_reservepattern, re-pointed; live code exists). - QALS becomes the network asset: settlement gas for the (now-decentralising) validator set, governance weight, and the scarce claim on network value. Rate QALS↔qAUD floats on the existing qalx AMM (live, 64/64-tested) — the "IOTA↔Shimmer relationship" but with the roles corrected: the stable token is the everyday rail (what Shimmer failed to be commercially, and what IOTA's own token couldn't be while unpegged), and the finite token is the network's equity-like settlement asset (what IOTA's token wanted to be).
- The honest Shimmer lesson: Shimmer (2022–2026) was the staging token for IOTA — valueless-by-design, sunset 30 Sep 2026, holders unpaid. The analogy's structure (two tokens, one network) survives; its commercial lesson is: a staging token with no cash-flow role dies. qAUD avoids that by being the transactional token from day one — it is the thing people actually spend.
- Migration mechanics: credit-phase Qals convert 1:1 to qAUD on redemption demand (the Reserve unwinds its liability); the asset float stays as QALS. No forced swap, no snapshot games — the liability retires, the asset remains. The Reserve's AUD backing funds exactly the qAUD mint, so no new promise is created.
- credit-phase Qals — AU$1 liability each
- 500K threshold — sale closes (cap-refused in code)
- spend → qAUD — mint-on-deposit stable rail
- settle → QALS — floats on qalx AMM
- Reserve unwind — 1:1 credit → qAUD
6. Own stablecoin variants (AUD/USD/YCN) vs USDT
| Own qAUD/qUSD | Bridged USDT | |
|---|---|---|
| Legal (AU) | VASP-registration path already mapped; we control mint/burn/attest | listing/operating pairs with it is still VASP activity; issuer risk is Tether's, not ours — but the pair's legality is still ours |
| Peg risk | ours (full-reserve, auditable — same proof-of-reserve machinery) | theirs (opaque reserves, historical fine print) |
| Demand | AUD-native (our actual market) | global liquidity, listings easier |
| YCN | don't — CNH/yuan-pegged stables are a regulatory minefield for an AU issuer; serve that market via qUSD + FX at licensed partners | n/a |
Position: qAUD first (it's who we are), qUSD second if international demand is real (same machinery, USD reserves), no yuan variant, no USDT dependency — external USDT pairs only ever post-VASP on licensed venues, never as the internal unit.
7. Is inflation EVER right here? (founder: "I don't think so — at all")
Agreed for Phases 1–3: emissions would fund nothing we can't fund from revenue, and they'd break the credit-phase accounting (inflating a liability is fraud-adjacent). The single future exception, stated once in the fee policy and repeated here: validator decentralisation may need a funding source — margin-share or Reserve yield first; protocol emission only as a last resort, and only with a governance decision at that time. No quiet money-printing, ever.
8. Supply sizing — is 1M enough?
During the credit phase: supply must bound outstanding credit. Peak planned program = 500K sold + organic earn-side circulation — 1M is comfortable. Post-threshold as the network asset: total asset value = 1M × price; there is no "too few units" at 10⁶ divisibility (10¹² doofs — more discrete units than exists AUD cash). If social numerics ever matter, redenominate (display ×1000), never inflate — a display change, not a monetary one.
- QALS — 1M (fixed, code-enforced): 1000000 — this paper §1
- BTC — 21M (fixed, protocol): 21000000 — public figure
- ETH — ≈120.7M outstanding (no hard cap): 120700000 — public figure, ESTIMATE
- XRP — 100B: 100000000000 — public figure
9. Recommendations (numbered, concrete)
- Keep the 1M/500K design exactly as code-enforced (loopd rail live; on-chain gate written + tested). (No change.)
- Replace the flat 1,000/card idea with graduated purchase tiers (1K → 10K verified → 50K KYC2, rising with history) — caps on buying the sale, never on earning/spending.
- Add a launch-window per-identity daily cap (90 days) if/when a public sale opens.
- Pre-build qAUD now in paper form (it's a
qal_reservefork — days of work) so threshold-day is a config flip, not a project. - Threshold plan: sale closes → pricing moves to qAUD same day → QALS floats as settlement/governance asset on qalx → Reserve unwinds credit liabilities 1:1 into qAUD mints.
- No yuan stable; qUSD only on demonstrated international demand; USDT only on licensed external venues.
- Publish the 5%-cluster transparency flag (anchored, non-punitive) as the domination backstop.
- Write the validator-funding decision (§7) into governance docs now so Phase-3+ has a pre-agreed path that isn't emission-by-default.
This paper argues positions; the ground truth remains the fact sheet. Feedback welcome — this is exactly the class of document that improves under attack.