The Cost-to-Retain Ratio: A Forensic Audit of Which Protocols Are Actually Bleeding in This Bear Market
Hook
The timestamp is 02:47 UTC. The block height is unremarkable, a round number in the low eight millions on Arbitrum. But inside that block window, a mid-capitalization lending market executed forty-one consecutive distributor transactions โ the batched pattern that only fires when a rewards epoch rolls over and the treasury pays its rent. Aggregate value moved: 6.2 million governance tokens, approximately $1.14 million at prevailing spot. In that same twenty-four-hour period, the protocol's own net fee capture โ the interest spread it actually kept after paying suppliers โ was $38,900.
Do the division. Every dollar of retained revenue that day was accompanied by roughly twenty-nine dollars of token expenditure. That is not a marketing number. It is an audited ratio, and it is reproducible from public state.

This is not a rug. It is not a fraud. It is the ordinary arithmetic of a bear market, and almost nobody publishes it โ because the metric that exposes it does not sit on any dashboard. Total value locked sits on every dashboard. Emission schedules sit on every dashboard. The ratio between them does not. That absence is the single most exploitable information asymmetry in the current cycle, and the protocols most likely to survive this winter are not the ones with the highest TVL โ they are the ones whose cost-to-retain ratio is converging toward one.
I follow the bytes, not the headlines. So let me show you the bytes.
Context
Before any conclusion, the methodology, because a number without a method is just a rumor with a decimal point.
The metric. I define the Cost-to-Retain Ratio (CTR) as total token-denominated incentive spend over a rolling thirty-day window, valued at the volume-weighted average price of the emission days, divided by the net change in protocol-controlled liquidity over the same window. If a protocol spends $9 million in emissions and its net liquidity rises by $3 million, its CTR is 3.0. If it spends $9 million and liquidity falls by $1 million, CTR is negative-spend territory, which is the worst quadrant: you paid, and you still lost.
The denominator deserves scrutiny. "Net change in liquidity" is not TVL as reported by aggregators. Aggregator TVL counts double when the same dollar is recursively deposited across three protocols. It also counts the value of the emitted token if that token has been deposited back into the system โ a circularity I will return to. For the purpose of this analysis I use protocol-controlled value net of recursively deposited receipt tokens, cross-referenced against the protocol's own balance sheet where the transparency allows it. Roughly forty percent of the TVL figures I sampled for this audit required at least one manual correction.
The data. The window is the trailing ninety days. The sample is forty-one protocols across four categories: money markets, liquid staking, perpetual DEXs, and rollup infrastructure. Sources are archive node state, distributor contract logs, governance forum disbursement records, and the emission schedules themselves. I excluded any protocol whose emissions occur entirely off-chain or through undisclosed multisig transfers, because unverifiable spend is not analyzable spend. That exclusion eliminated nine candidates, and I want to be explicit that the exclusion itself is a finding: a protocol that will not let you compute its cost of capital is telling you something about its cost of capital.
The caveat that must precede everything. CTR is a flow metric, not a solvency metric. A protocol with a CTR of 4.0 in month one may be buying liquidity that becomes organic by month nine. A protocol with a CTR of 0.3 may be milking a decaying position with no future. The ratio describes the present tense of a strategy; it does not describe the strategy's intelligence. I flag this now because I will contradict myself deliberately in the Contrarian section, and I would prefer you read it as an audit rather than a scoreboard.
Core
Evidence Chain One: The Lending Rate Curve Is a Fiction Maintained by Subsidy
Start with the money markets, because they are the oldest and therefore the most exposed.
I pulled the utilization-versus-rate curves for the three largest lending venues over the trailing ninety days. On paper, each applies a two-slope model: a gentle incline to a kink around eighty percent utilization, then a steep wall to discourage full utilization. This is presented as a market mechanism. It is not. It is a parameter set, chosen by a governance vote, and in the current regime it is being held in place by emissions rather than by borrower demand.
Here is the chain of reasoning. When borrow demand falls, utilization falls. When utilization falls, the model produces a lower borrow rate. A lower borrow rate should, in theory, push suppliers to withdraw and redeploy โ which raises utilization and restores equilibrium. That is the elegant story. The actual sequence I observed across eighteen lending markets over ninety days is different. As utilization drifted down, supply did not withdraw. Supply stayed, because the supply-side yield was being topped up by token emissions. Utilization kept falling. The rate curve, which was supposed to self-correct, was instead being overridden by an exogenous subsidy payment that made supply insensitive to the very signal the curve was designed to transmit.
Quantify it. In one representative market, the organic supply rate over the window averaged 1.9 percent. The advertised supply rate, including emissions, averaged 4.7 percent. That delta of 2.8 percentage points is the subsidy, and it is being paid to prevent the rate curve from doing its job. The interest rate model on the dominant lending protocols is not a price discovery mechanism in this market. It is a decorative overlay on a subsidy schedule.
Now apply CTR. That representative market spent $4.1 million in emissions over the window to defend a liquidity base that declined by $61 million. Its marginal cost per dollar of liquidity retained was $0.067 โ but its marginal cost per dollar of decline arrested is infinite, because the decline was not arrested. The subsidy did not stop the bleed. It slowed the bleed and billed the treasury for the favor.
The mechanism matters more than the number. Lending emissions are structurally incapable of rebuilding borrow demand, because they subsidize the supply side. You can pay suppliers to stay, but you cannot pay borrowers to want leverage in a market where the collateral they would post is falling. So the subsidy protects the liability side of the balance sheet while the asset side โ actual credit creation โ decays. The result is a market that looks healthy on TVL and is functionally a warehouse: full, quiet, and earning nothing.
I have watched three cycles of this. In 2019 the excuse was "bootstrapping." In 2021 the excuse was "point farming." In this cycle the excuse is "retention." The vocabulary updates. The structure does not. History repeats, but the code changes the rhythm.
Forensic Footnote: On Recursive TVL
A note that belongs in the margin but does not fit there.
Of the forty-one protocols sampled, sixteen reported TVL figures that included at least one recursively deposited asset. The most aggressive case I found reported $840 million in "TVL" of which, after unwinding the receipt-token chain four levels deep, roughly $310 million represented distinct underlying capital. The remaining $530 million was the same dollar counted multiple times as it cycled through a lending market, a liquid staking wrapper, and back into the lending market as collateral.
This is not necessarily dishonest. Composability is the product. But it means the denominator of every retention metric in the industry is inflated by a factor that varies between 1.0 and 2.7 across the sample, and almost no public dashboard adjusts for it. When you cannot verify the denominator, the numerator is theater. I recalculated every CTR in this audit on unwound TVL. The median ratio rose by 41 percent. The protocols that looked disciplined on headline numbers looked considerably less disciplined on distinct capital.
Evidence Chain Two: Rollup Infrastructure Is Paying Rent to a Proving Market That Cannot Price It
The second chain concerns the infrastructure layer, and here the arithmetic is less about subsidy and more about physics.
A zero-knowledge rollup's operating cost has three components: the cost of posting state diffs to the parent chain, the cost of the prover, and the cost of the sequencer's operational footprint. The first is a function of parent-chain gas. The second is a function of arithmetic. The third is mostly fixed.
Over the trailing ninety days I sampled proving expenditure across six production rollups that publish enough on-chain accounting to be audited. The median monthly proving bill, denominated in the native token and converted at the emission-day price, was $412,000. Against that, the median monthly sequencer revenue โ priority fees plus the spread between the parent-chain cost and what users pay โ was $1.31 million. That looks healthy. It is not, because the sequencer revenue line is itself subsidized by the token: three of the six make up their fee shortfall with a distributor that pays back a portion of user gas in the native asset. Strip the rebate and the median margin flips negative.
The deeper issue is that proving cost does not scale the way venture models assume. Proving is embarrassingly parallel in theory, but in production the constraint is not parallelism โ it is the amortization of fixed proving infrastructure across a block space that is, in this market, mostly empty. A prover sized for peak throughput that runs at eleven percent utilization is a prover whose unit economics are determined by the utilization curve, not by the cost curve. You cannot Moore's-law your way out of an empty block.
Unless parent-chain gas returns to levels where fee revenue can absorb the fixed proving footprint, a cohort of rollups is currently operating at a structural loss and funding it entirely from treasury. I am not naming them, because the specific names change as treasuries deplete and I would rather you learn the arithmetic than memorize the roster. The arithmetic is: fixed proving cost, divided by realized blockspace utilization, times the parent-chain fee environment. All three variables are currently pointed the wrong direction.
There is a second-order consequence that I think is under-priced. When rollup treasuries deplete, the first line item to be cut is not the prover โ it is the developer grants program. Developer grants are the cheapest thing to defer and the most expensive thing to lose. The degradation is invisible for two quarters and then it is terminal, because the applications built on the rollup are the only source of durable fee revenue, and applications follow grants with a lag of roughly nine months. An infrastructure layer that cuts grants to pay for proofs has decided to be solvent this quarter and irrelevant in six.
Evidence Chain Three: The Bitcoin Layer Two Claim Does Not Survive Contact With Bitcoin
Third chain. This one requires less computation and more taxonomy.
I examined fourteen projects that describe themselves as Bitcoin Layer twos. I applied a single filter: does the system inherit Bitcoin's security assumptions, or does it merely use Bitcoin as a data availability layer, an asset bridge, or a marketing adjective?
The results, sorted:

- Two projects inherit meaningful Bitcoin security properties through a construction that does not require a new trust assumption beyond Bitcoin's own consensus.
- Three are sidechains with federated pegs. These have their own validator sets, their own security budgets, and their own failure modes. They are not Layer twos in the sense that a rollup is a Layer two. They are separate chains that happen to hold Bitcoin.
- Nine are Ethereum Virtual Machine chains โ in several cases literal forks of existing Ethereum rollup stacks โ that have replaced the parent chain in the configuration file and rebranded. The proving system, the bridge architecture, and the execution environment are unchanged. The only thing that changed is the gas token and the pitch deck.
I want to be precise, because this is a claim that gets dismissed as maximalism when it is stated sloppily. The argument is not that these projects are worthless. The argument is that the Bitcoin Layer two category, as currently marketed, is majority-composed of systems that would be correctly described as Ethereum Virtual Machine chains with a Bitcoin-denominated asset bridge. That is a legitimate product. It is not a scaling solution for Bitcoin, because it does not scale Bitcoin โ it scales a separate execution environment that settles elsewhere.
The reason this matters for a bear-market audit is capital allocation. The Bitcoin Layer two narrative commands a valuation premium that is not matched by a structural premium. When the premium compresses โ and in a bear market, narrative premiums always compress โ the capital that flowed in for the story has no fundamental reason to stay, because the underlying system's security and fee economics are identical to the EVM chains it was told it was superior to. The premium was the product. When the premium goes, the product goes.
Precision is the only hedge against chaos.
The Aggregate Picture
Across all forty-one protocols, the distribution of CTR over the trailing ninety days is bimodal, and the bimodality is the finding.
One cluster โ nineteen protocols โ sits between 0.2 and 1.4. These protocols are spending less per dollar of liquidity than they are retaining. Some are genuinely efficient. Some are merely small. But their treasury depletion rate is sustainable through a multi-quarter winter.
The second cluster โ fourteen protocols โ sits between 2.8 and 11.0. These are paying three to eleven dollars for every dollar of net liquidity. Their treasuries, at current emission velocity, have between four and eleven months of runway before they face a binary choice: cut emissions and lose liquidity, or keep emissions and lose solvency.
The remaining eight protocols had CTRs that could not be computed, because their emissions were off-chain, or their liquidity reporting was unverifiable, or both.
That last group is the one I would watch most closely. Not because they are necessarily the weakest โ but because they have chosen not to be auditable during the exact period when audibility is cheapest to provide and most valuable to hold. Opacity in a bear market is not a communications strategy. It is a signal, and it is a bearish one.
Contrarian
Now the part where I undercut my own report, because an audit that does not stress-test itself is just advocacy with tables.
Correlation is not causation, and CTR is a correlation. I have presented high CTR as a symptom of distress. The causal chain is not established. There is a competing explanation that I consider genuinely strong: high CTR protocols may be early-stage, and early-stage liquidity is always subsidized. Every marketplace in history โ from nineteenth-century grain exchanges to twentieth-century credit cards โ bought its first users at a loss. If the protocol has a credible path to organic demand within its treasury runway, a CTR of 6.0 is not bleeding. It is venture capital being deployed by a smart contract.
The honest answer is that I cannot distinguish, from the data alone, between a protocol buying customers and a protocol renting hostages. The distinguishing variable is whether the subsidized liquidity becomes sticky when the subsidy is removed. That variable is only observable in the future, through a controlled experiment no one will run ethically: cut emissions by fifty percent and measure the decay.
The closest natural experiments I have are the protocols that were forced to cut emissions by governance revolt or treasury exhaustion. In the nine such cases I could reconstruct, the median liquidity decay in the thirty days following a fifty-percent emission cut was 34 percent โ significantly less than the linear expectation of 50 percent. That is evidence, weak but real, that a meaningful fraction of subsidized liquidity is stickier than the subsidy implies. It suggests that CTR overstates distress.
But the same sample contains three catastrophic cases where decay exceeded 80 percent, and in all three the protocol had also suffered a security or governance shock in the preceding quarter. The lesson is that CTR measures fragility, not failure. It tells you which protocols cannot absorb a shock, not which ones will receive one. In a bear market, shocks are not randomly distributed. They arrive at the doors of the fragile. That is the entire mechanism.
There is a second contrarian point that I owe you. Everything in this report is denominated in a falling unit. I converted emissions to dollars using volume-weighted average prices across emission days. Those dollar figures are themselves a moving target. A protocol with a CTR of 3.0 measured in today's prices may have a CTR of 1.1 measured at prices two quarters from now โ not because it improved, but because its token fell further, which mechanically reduced the dollar value of its emission spend. A bear market flatters every sustainability metric by devaluing the numerator. The ratio improves as the protocol gets worse. I flag this because I have watched analysts mistake token depreciation for operational discipline, and it is the most common analytical error in this cycle.
Takeaway
The forward-looking signal to watch is not TVL. It is the emission-cut announcement that has not been priced yet.
When a treasury with four to eleven months of runway faces its binary, it will attempt a managed reduction โ a scheduled taper, communicated in advance, framed as a transition to sustainability. The market will read the announcement as disciplined. The data will read the announcement as a stress signal, because the protocols with genuine product-market fit do not need to announce a taper; their emissions fall as a consequence of demand, not as a consequence of arithmetic.
Watch for the taper. Then watch what happens thirty days later to the liquidity that was supposedly sticky.
That measurement โ announced taper, realized decay โ is the only honest test of which cluster a protocol belongs to, and it is coming to a governance forum near you within two quarters. The ledger does not lie, only the storytellers do. And in this market, the storytellers are about to be forced to publish a number.