Plain Strata logo

Plain Strata

Archives
Listen
Log in
Subscribe
September 2, 2026

The receipt is the asset

Plain Strata Plain Strata

Hi,

A farmer pulls up to a grain elevator with four thousand bushels of winter wheat. The operator takes it in and hands him a piece of paper: I am holding this, and it belongs to you. From that moment the wheat never has to move again. The paper gets sold, pledged, borrowed against, and the grain sits in the silo the whole time.

Your coat at the theatre works the same way. The cloakroom has possession, you keep ownership, the ticket is what stands between them. Not a pawn shop, which takes the coat and the title both, and that difference is the whole of it.

That old piece of paper is now holding up the machines that run open AI. Somebody has to buy the graphics cards. Buying at that scale means borrowing, and no lender will lend against metal in a building it has never entered unless somebody standing next to the metal writes down what is there.

Which is where it gets interesting, because a chain cannot see a graphics card. It can only ever see a claim that one exists.

So the question this week is not whether the money is real. It is where the trust actually landed, and whether you like the party it landed on better than the one you started with.

Listen:

Spotify: https://open.spotify.com/episode/3WlRRcRWiTXqEwh4I3iaGB

Apple Podcasts: https://podcasts.apple.com/us/podcast/plain-strata/id6783455764?i=1000787443711

YouTube: https://youtu.be/-Z7TDJE-ac0


The full piece, no need to click through:

On Friday the twenty-eighth of August, an exchange called Bullish handed a lending protocol a hundred million dollars. The number is not the interesting part. What is interesting is what stands behind the loans that money will fund. Not a company's revenue. Not its buildings. Not a founder's signature. Graphics cards. Specific ones, in specific racks, in a specific building, insured, with a document naming the person standing next to them.

Earlier this summer the same protocol wrote a single loan of about ninety eight million dollars against two thousand three hundred and four Nvidia B300 cards, and another of thirty four million against seven hundred and sixty eight B200s. In each case the cards themselves are the security. If the borrower stops paying, the lender does not go after the company. It goes after the metal.

That is the story of the week, and it is a bigger one than it sounds. For most of the last year the argument about open AI has been about permission: who may download a model, who may sell it, who may be told no. Underneath that argument sits a plainer fact that has decided more outcomes than any license ever has. Running one of these models is a question of how much fast memory you can put in one place, and fast memory costs money nobody in this field has lying around. So the real question was never who is allowed to run the model. It was who can pay for the machines. This week, an answer arrived: money raised from strangers on a public ledger, secured by the hardware itself.

Start with the physical thing, because the money only makes sense on top of it. A model is a very large pile of numbers. To run it, essentially all of those numbers have to be sitting in fast memory attached to a processor at the same time, not on a disk, not streamed in from somewhere else. The biggest open models published this year run to well over a terabyte of numbers. That means dozens of datacenter accelerators, each one costing as much as a car, all powered and cooled and networked together, before you answer a single question.

So somebody has to buy them. There are two ways. You rent capacity from someone who already owns it, which is what almost everyone does, including the largest labs. The same week as the Bullish deal, Anthropic was reported to have committed around forty five billion dollars over six years to rent roughly four hundred and sixty megawatts of capacity from one datacenter operator. That is the renting path, at the scale where it is now priced.

Or you own the machines. Owning means buying them, and buying at that scale means borrowing, and borrowing means somebody has to be comfortable lending against a pile of hardware in a building they have never entered. That is the problem this week's news is an answer to.

Here is how the answer works, and it is worth going slowly because the shape of it is very old.

The protocol is called USD.AI, built by a team called Permian Labs. It runs two tokens. The first is a synthetic dollar backed by US Treasuries and cash. The second is the version that earns, and what it earns comes from two places: the Treasury yield underneath, and the interest paid by operators who borrowed against their graphics cards. Reported returns have run in the low to middle teens as a percentage. Anyone can hold it. That is the permissionless half of this, and it is real: a person in any country with a stablecoin in a wallet becomes, in a small way, a creditor to a datacenter.

But a chain cannot see a graphics card. It can only see numbers in its own ledger. So before any of this works, somebody has to connect the metal to the ledger, and the way they do it is a legal instrument with a wonderful name.

The datacenter holding your cards is called, in law, the bailee. The word comes from the old French bailler, to hand over, to deliver, and a bailment is the situation where you hand something to someone else to hold without giving up ownership of it. Your coat at the theatre is a bailment. So is your car in a parking garage. The person holding it has possession and not title, and they owe you the thing back.

Under American commercial law there is a whole article, Article 7, devoted to what happens when a professional holder of goods writes a document saying what they are holding. That document is a warehouse receipt, and it is one of the most quietly important pieces of paper in economic history. The grain elevator says: I have four thousand bushels of number two winter wheat, belonging to this person. Once that receipt exists, the wheat stops needing to move. The receipt moves instead. You can sell it, pledge it, borrow against it, and the grain sits in the elevator the whole time.

USD.AI does exactly this with hardware. The datacenter, as bailee, issues a receipt acknowledging physical custody of the cards. The cards must carry full replacement value insurance naming both the holder and the lender. Only then does a tokenizing agent issue what the protocol calls a GPU warehouse receipt token, and that token is what the loan is actually written against. The valuation is not guesswork either: new chips are priced at the manufacturer's official list price, which is set globally and cannot be talked up by a reseller, and used chips are priced off the wholesale brokers who make markets in second hand cards.

So name the pattern out loud, because it will keep showing up. Call it the receipt is the asset. Whenever something heavy and immobile has to back money that needs to move, a document about the thing starts circulating in place of the thing, and from that moment everything depends on the honesty of whoever is standing next to it. Grain elevators. Bills of lading for cargo at sea. Gold certificates. Metal in a bonded warehouse. And now a rack of accelerators in an insured building. The pattern's failure mode is just as old, and it is not exotic fraud. It is the same goods pledged to two different lenders, because the goods never moved and neither lender ever walked in to look.

There is one more piece, and it is the piece this show has met before wearing different clothes. Loans do not get made by the crowd. They get underwritten by a curator, and that curator has to put its own money into the first loss position on every loan it originates. First loss means exactly what it says: when a borrower defaults, the curator's money burns before a single depositor loses a cent.

That is a very familiar shape. Across this field, the way you make a stranger trustworthy is not to check everything they do. It is to arrange things so that being dishonest, or being careless, costs them more than it earns them. Put money where it can be taken away, and the incentive does the work that supervision cannot. A network of anonymous machines does it with staked deposits that get destroyed for bad behaviour. A credit protocol does it by making the underwriter eat the first losses of their own bad judgment. Same mechanism, different room.

Now the honest part, which cuts in two directions.

Lending against a truck is safe partly because a truck in five years is still a truck. A graphics card is not. Resale data on the previous generation of datacenter cards shows roughly eighty percent of original value retained after a year and a half, and about half after three years. Call it seventeen percent a year, and that decay is not driven by wear. It is driven by what the card can earn per hour on the rental market, which falls the moment a better card ships.

The protocol's response is to structure the loans to amortize over three years. The word amortize comes from the Latin for death: to kill the debt off, gradually. So the design is a race between two deaths, and the loan has to die faster than the machine does. That is a genuine engineering answer to a genuine risk, and it is also an admission of how narrow the window is. There is no way to make this collateral behave like real estate, because somebody in California is actively working to make it worth less.

And that somebody deserves naming, because it makes the picture legible. The list price used to value the collateral is set by Nvidia. The next generation that erodes that value is built by Nvidia. And Nvidia has reportedly been offering its own backstops to this market, standing ready to buy compute at pre agreed prices so lenders will lend against it. Follow the chain of trust in this arrangement all the way down and it does not end at a mathematical guarantee. It ends at one company's price list, one company's product roadmap, and one company's willingness to catch the market if it falls.

That is worth sitting with, because it is the same shape as the deepest problem in verifying AI work itself. Every scheme for checking whether a machine did its job honestly ends up trusting something: a chip manufacturer's signing key, a piece of mathematics, or somebody with money at stake who is paying attention. No scheme removes trust. It relocates it, and the useful question about any of them is where it landed and whether you prefer that party to the one you started with. Here, at the money layer rather than the computing layer, it landed on an insurer, a custodian, a commercial code, and a chip company.

The implication is straightforward and slightly deflating. This is a chain doing the one thing chains are genuinely excellent at, which is moving money between strangers who have no institution in common, while every hard question about the physical world is answered off the chain by an insurer, a bailee, and a body of law written for grain. Nothing here is proven. Nothing is attested. Nobody is checking that the card exists using any of the machinery this field has spent years building.

And the reason why is the sharpest thing in this story. The technology to prove a genuine card is running in a specific room already exists, and it works. What it cannot do is give you the card back. A lender does not primarily need proof that the machine is there today. It needs the right to take the machine tomorrow, and no proof system in the world will drive a truck to a datacenter and load the racks. That is what the insurer and the receipt and the commercial code are for. Cryptography can tell you the truth about a machine. It cannot repossess one.

The open question is whether this capital layer ever reaches the operators who most need it. The borrowers here are middle market infrastructure companies with insurable facilities in strong legal jurisdictions and predictable rental contracts, which is a description that excludes almost every individual running cards in a spare room for a permissionless network. The pitch of decentralized compute has always been that anybody with hardware can plug in and earn. Financing has never worked that way, and this arrangement, for all that anyone can lend into it, still needs a named borrower in a jurisdiction with courts.

Two things. First, whether any of this credit reaches an operator supplying a permissionless network rather than a conventional cloud, because that is the difference between a new financing channel for ordinary datacenters and a new financing channel for the open compute layer. Second, whether the first default in this market is resolved cleanly. A warehouse receipt is a promise that survives right up until somebody has to enforce one, and the whole history of this instrument says the interesting day is the day the lender drives to the building.


The two voices are AI. The research and writing are mine.

Decentralized AI, layer by layer.

Dastan,

Listen on Spotify and Apple. @plainstrata. Decentralized AI, layer by layer.

You just read issue #20 of Plain Strata. You can also browse the full archives of this newsletter.

Older → Fire the landlord, hire a factory
Spotify
Powered by Buttondown, the easiest way to start and grow your newsletter.