Back to selected work

ZeroGrid. Keeping the next funding decision in investors' hands

Dmitry Sergeev·9 min read

Category:Protocols

Project status:Discontinued by client

Tags:
  • Crowdfunding
  • Milestone escrow
  • Governance
  • Investor exits
  • Ethereum
  • Solidity

Our work

We developed the campaign escrow and milestone-funding contracts for ZeroGrid, together with the supporting application flows. The work covered evidence commitments, voting, investor exits, founder bonds and the accounting that reserves refunds before further funding is released.

A roadmap does not restrict a founder's access to raised capital. Once the full budget leaves escrow, a later vote can express disappointment without changing what happens to the money. ZeroGrid connects delivery review to custody. Campaign funds remain in a dedicated Ethereum contract, and each new allocation depends on the previous milestone's approval and a completed investor exit window.

The design also addresses a different problem inside community funding. A majority may support another stage while smaller investors no longer accept the risk. ZeroGrid gives each investor a separate right to leave before the next payment, using their share of remaining escrow. We separated exit reserves, later funding allocations and failure compensation so each draws from its own recorded obligation.

The campaign commits to terms before accepting money

Each campaign defines milestones, acceptance criteria, evidence requirements, deadlines and gross allocations before fundraising opens. Financial and timing fields needed for enforcement live directly in the contract. Larger descriptions use a versioned canonical manifest committed by hash, with IPFS and independent HTTPS copies for retrieval. A mutable webpage cannot silently become a new delivery promise.

The manifest makes review concrete. A software milestone can identify required source commits, deployed contracts, reproducible tests and the security findings that must be resolved. During delivery, the founder submits an evidence package against those frozen criteria. Its hash is fixed for the ballot, so the package cannot change while investors vote. Automated checks can verify signatures, artifact identity and specified tests, but investors remain responsible for judging whether the evidence satisfies the commitment.

Budgets, thresholds, deadlines and the payout address cannot change after contributions begin. A material change requires settlement of the existing campaign and voluntary participation in a new one. We kept escrow, state transitions and position accounting together so their financial effects are atomic. Versioned ERC-1167 instances can share deployment code while fixing each campaign to its selected implementation. The factory cannot use a later release to rewrite a live campaign's rules.

The first payment is capped, later ones require delivery

Fundraising is fixed-target and all-or-nothing, with a hard cap equal to the target. Contributions create non-transferable accounting units in settlement-asset base units. Before funding closes, contributors can cancel and burn those units. Reaching the target early does not open founder withdrawals. After the deadline, permissionless finalization either opens contribution refunds or moves the funded campaign into its initial exit window.

The first allocation cannot depend on an earlier deliverable, so it is a disclosed bootstrap payment capped at 10% of the target. The campaign's normal holdback applies to it. Investors can still leave before that payment occurs. Each later allocation requires approval of completed work, followed by another exit window. Only one review and one executable release can be active, preventing overlapping ballots from authorising the same budget twice.

An approval is therefore a transition with a limited consequence. It permits the next stage to proceed under the published rules. It does not release the entire remaining raise, replace the next milestone's acceptance criteria or guarantee commercial success. Money already paid to the founder remains outside the protocol's recovery powers.

A vote coordinates funding, not individual choice

Voting weight comes from active contribution units at review creation. Contributions have closed and exits are disabled during the ballot, keeping the denominator fixed. YES, NO and ABSTAIN have distinct treatment. Abstention contributes to quorum but not the approval ratio, and a minimum YES threshold prevents a small supportive group from passing a proposal simply because most participants abstain.

The campaign configuration described here combines 40% participation, at least two-thirds of directional votes in favour and YES votes representing at least 30% of active units. These are configurable campaign parameters frozen before fundraising, not universally optimal governance settings. A quorum-reaching rejection terminates the campaign. Insufficient participation permits one retry using the same evidence and denominator; a second quorum failure terminates it. Neither the founder nor the platform can keep calling votes until a favourable result appears.

Non-transferable positions prevent secondary-market acquisition of voting power immediately before review. Contribution weighting also makes splitting one contribution among wallets neutral in the vote calculation. Neither control eliminates bribery, concentrated ownership or undisclosed founder affiliates. The mandatory exit right addresses a different boundary: a favourable majority decision still cannot commit a dissenting investor's remaining escrow to the next stage without first allowing departure.

An exit reserves money before the founder can receive it

At the start of each exit window, the contract snapshots unreserved investor escrow E and active units S. An investor with u units receives floor(E × u / S). Founder collateral and previously reserved claims are excluded from E. Every investor uses the same snapshots, so being first to claim does not change the rate available to the next participant.

Registering an exit burns the investor's full active position and reserves the payout. A separate claim transfers the funds, allowing a wallet to collect later without holding up continuation. Founder payments remain forbidden throughout the window. An exited position can no longer vote, exit again or receive future bond compensation. We implemented full-position exits at specified boundaries, separate from the delivery period.

After the window closes, the next gross allocation scales by remaining units divided by the original funded units. If 80% of participation remains, the next stage receives 80% of its original gross budget, before the holdback. A minimum continuation threshold decides whether the project may proceed at all. The founder accepts the risk of delivering unchanged commitments with this smaller budget when choosing that threshold. The contract cannot restore departed investors' capital merely because the original plan would be easier to execute.

Founder collateral and the holdback cover different risks

Before fundraising opens, the founder deposits a performance bond in the campaign's settlement asset. A project token cannot stand in for that collateral. Rejected milestones, missed evidence deadlines, repeated quorum failure and other defined termination conditions can assign the bond toward remaining investors' unrecovered principal. A missed funding target returns it to the founder. Quorum failure does not prove misconduct; bond treatment is the execution-risk allocation agreed before launch.

The completion holdback retains a fixed portion of every approved gross allocation. It is part of the project budget, not another investor charge. Final acceptance opens one last exit window before the remaining unreserved budget and holdback become payable. If the campaign terminates earlier, retained amounts remain in investor escrow. This preserves a financial reason to finish after the last development allocation has been authorised.

Bond compensation is capped at actual unrecovered contribution principal for the remaining cohort. Excess bond returns to the founder, and earlier exit claims are untouched. This prevents termination from becoming an automatic windfall funded by collateral. It also makes the limit clear: the bond can reduce losses, but it need not be large enough to replace everything already paid out.

The refund example shows why claim types stay separate

The architecture's worked campaign raises 1,000,000 USDC and adds a 100,000 USDC founder bond. Its gross stages are 100,000, 250,000, 300,000 and 350,000 USDC, each subject to a 10% holdback. The first release pays the founder 90,000 USDC, leaving 910,000 in investor escrow. After approval, investors holding 20% of units exit and reserve 182,000 USDC, equal to 91% of their original contributions.

The next 250,000 USDC gross allocation scales to 200,000 because 80% of participation remains. The founder receives 180,000 after holdback. When the following milestone fails, unreserved investor escrow is 548,000 USDC against 800,000 units of remaining principal. The 100,000 bond raises that cohort's terminal refund pool to 648,000, or 81% of its original contributions.

DestinationUSDCTreatment
Founder payments270,000Already released
Earlier exits182,000Reserved claims
Terminal refunds648,000Escrow plus bond
Total1,100,000All deposited funds

In this example, the recovery amounts follow the remaining escrow and available bond. Earlier exits retain their reserved 91% without sharing in later compensation. Remaining investors recover 81% after the bond absorbs part of their loss. The totals reconcile to investor contributions plus founder collateral, with no assumption that previously released money can be clawed back.

Termination fixes liabilities rather than pushing refunds

At termination, the contract snapshots remaining active units, unreserved escrow and the bond portion assigned to compensation. Each investor claims a proportional amount from that fixed pool. Accounting updates happen before the external token transfer, and a reverted transfer leaves the claim intact. There is no loop paying every investor during finalization, so claim and ballot-finalization work remain constant in participant count.

Reserved investor claims have no routine expiry or administrative sweep. Integer rounding leaves dust locked instead of creating an operator withdrawal opportunity. An unsolicited token transfer is surplus and does not create contribution units or voting weight. The zero-active-investor case has a separate settlement branch so the contract can preserve prior claims and return unused collateral without dividing by zero.

Optional rewards use another accounting path. Campaigns offering project tokens escrow the investor reward allocation before fundraising. Accepted milestones earn the declared rewards for active participants, while exits preserve earned amounts and cancel future earning rights. Settlement-asset refunds use their own accounting path, separate from reward-token delivery. A token reward is not counted as recovered USDC principal.

The website cannot become the withdrawal authority

Solidity contracts enforce custody, votes, deadlines and claims. The React interface and Node.js services prepare wallet-signed calls, index events and distribute evidence and notifications. PostgreSQL stores canonical event identities and rebuildable projections, with a transactional outbox for retryable delivery. API authentication can permit an evidence upload, but cannot authorise a founder payment or investor withdrawal.

Deadline finalization is permissionless. Public state, published contract addresses and a downloadable interaction kit let investors vote or claim without the launchpad API. Evidence mirrors address a separate dependency because a content hash verifies identity without guaranteeing the document can still be retrieved. The interface also distinguishes pending, included and finalized transactions, and its projections rewind after chain reorganizations.

Removing operator control creates a material trade-off. There is no global live-campaign pause key and no forced migration, so an administrator cannot trap exits or extend a campaign indefinitely. The same restriction means a deployed custody defect cannot be patched or paused in place. Independent review, bounded launch exposure and new versions for new campaigns are therefore essential. Settlement-token freezes remain an external limitation that an immutable escrow cannot override.

Exit accounting stays ahead of the next funding release

We connected each ballot to its frozen evidence and each exit window to an accounting snapshot. An accepted exit reserves the investor's claim before the next founder allocation becomes available. Claims, bond compensation and later funding therefore draw from distinct recorded obligations.

The contract enforces the agreed rules, while campaign economics still depend on the chosen thresholds, bond and remaining participation. Majority collusion or repeated exits can leave a project commercially unworkable even when each transition follows the contract. The continuation threshold and termination path make that outcome explicit.

ZeroGrid connects milestone approval to funding while preserving an individual exit decision. Evidence commitments fix what investors review, exit windows reserve claims before payment, and bond and holdback accounting govern the funds still controlled by the protocol.

See our architecture in practice.

DEVLAB · ARCHITECTURE EXAMPLE

Agent
Commerce

A look inside the software architecture behind Agent Commerce.

View architecture
Agent Commerce — Software Architecture, designed by Dmitry Sergeev