close
Skip to content

Capital without compromise.

Borrow against what you hold, on terms fixed when you sign.

Non-custodial No automatic liquidations No oracles
Scroll
The state of play

Two markets lend against collateral.
Only one of them margin-calls you.

Crypto lending
$19B

liquidated in a single day

10 October 2025

Corporate credit
$59.5T

corporate debt outstanding, none of it margin-called

OECD Global Debt Report 2026

The difference is not scale, and it is not risk appetite. It is that one market lends on agreements and the other lends on positions.

$67.4B
crypto-collateralised lending outstanding
Galaxy Research, Q1 2026
1.19M BTC
held by 174 public companies
Bitwise, Q1 2026
100M+
Bitcoin holders worldwide
Crypto.com 2026
Credit

Credit built around terms, not price.

Rate and term are set at signing, and nothing afterwards reopens them. Default is a matter of payment behaviour, not market movement: no price feed watches the collateral.

Credit

An agreement, not a position

A loan used to be an agreement. Two parties settled what was owed and when, and once signed, the agreement held.

Crypto lending replaced that with a position: continuously priced against a feed, closed out whenever a number crosses a line, whether or not the borrower ever missed a payment. The borrower's own conduct stopped being what determined the outcome.

Pogun goes back to the agreement.

Rate fixed at signing Term is a date Default means non-payment Terms can only soften
Borrow

Every payment known before you sign.

The terms are set before you arrive, so the only decision left is how much. Stablecoins come to you, and what backs them stays where it is.

Borrow

Every payment known before you sign

Rate, duration and payment schedule are all fixed before you arrive. The cost of the loan is a figure you can put in a model rather than a range you have to watch.

Rate
Fixed at signing. It cannot be revised up, and no market condition reopens it.
Term
A date, not a condition. The loan ends when it ends.
Interest basis
30/360, the bond-market day count, so every payment lands on an exact figure rather than a rounded cent.
Default
Non-payment, and nothing else. No price movement can put you in default.
Revision
Terms can only soften. A lender can ease them; neither side can tighten them.
Pre-approved BTC → USDC Instant Funded

Drawn from the Conservative desk 1% fixed 30 days 50% LTV

Choose an amount
You repay
50,041.67USDC
You lock
0.966184BTC
Your payment: 50,041.67 USDC, once
Day 30
Cost of the loan
41.67 USDC
Collateral value
$100,000

Both figures final before you sign. Neither can move after.

One loan drawn from the Conservative deskIllustrative
Desks

Lend on terms you set.

A desk is your standing offer. You publish it, and borrowers come to those terms rather than to a pool.

Desks

Lend on terms you set

Every term is fixed before a borrower arrives: the asset, the rate, the duration, the collateral you accept and how much is available. A borrower picks a desk and an amount, and that is the whole decision — no book to read, nothing to negotiate.

You publish
Asset, rate, duration, accepted collateral, LTV, and the size available.
Two routes in
Instant takes your terms and funds straight through with no approval step. Request applies for an amount and waits for you to approve it, or not.
Your exposure
To that one borrower, on that one contract. Nothing else on the market reaches it, and a failure elsewhere is not yours.
If they struggle
You can ease the terms instead of foreclosing. Every loan carries a visible repayment history, so the decision is informed.
Your position
The loan is a bond token, minted at signing. You can hold it, sell it, or insure it.
Conservative BTC → USDC Instant Open
Interest rate
1%fixed
Term
30days
Per loan
$50K–2M
Available
$8.2M
Repayment: one payment at maturity
Day 30
LTV
50%
Bond token
Minted at signing

No margin call. No price ends this loan early.

The Conservative desk, as its lender published itIllustrative

Ready now, or built for you

Every loan carries a visible repayment history. Your exposure is to that borrower and to nothing else on the market, and if they run into trouble, you can ease the terms instead of foreclosing.

Your deskevery term fixed up front
Instant
Takes the termsfunded and waiting
Straight throughno approval step
Request
Appliesfor an amount
You approveor you don't
The loan is liveone agreement between two parties
The two routes to a deskIllustrative
Collateral

Collateral that stays yours

Borrowing has always come with a handover. The pawnbroker takes the watch, the broker takes the securities, the lending protocol takes your tokens into a pool with everyone else's. Somewhere along the way this stopped being a limitation and started being treated as the nature of credit itself. It never was. It was plumbing.

Pogun replaces the plumbing.

The hard case

Bitcoin, first

Bitcoin has no contract layer, so every path to putting it to work has run through someone else. Pogun begins with Bitcoin because it is the hardest asset to make eligible without that handover.

The hard case

Why Bitcoin is the hard case

Bitcoin is the largest holding in crypto and the least employed, and the reason is structural rather than cultural. With no contract layer, every route to putting it to work has run through someone else: you hand the coins over, an institution holds them, and a receipt goes into the market in their place.

That trade has never been worth making for most holders, so the positions sit still. Solve it without the handover and the same asset backs a loan while staying on Bitcoin, under Bitcoin's own consensus.

The life of one deposit
You deposit
It stays on the chain it came from. No custodian holds it. What stands for it on the other side is bound to that one coin, not a claim on someone's reserves.
While it serves
Nothing is done with it. It is not lent on, not rehypothecated, not pooled with anyone else's. Not by the lender, not by the operator, not by us.
If the price moves
No price can reach it. No oracle is consulted, so there is no number that ends the loan early.
At close
Your own deposit is released, not a share of a pool. Run your own operator node and the exact coin comes back, satoshis and inscriptions intact.

Bitcoin that backs a loan and never leaves Bitcoin.

Request early access
Proof

The hard part already runs on Bitcoin.

Everything above rests on one thing, and the idea is not new. On 4 August 2026 we ran ours end to end on Bitcoin mainnet, twice: once where a fraudulent claim was defeated, and once where an honest claim was challenged and went through anyway. Eighteen transactions, eleven blocks, two hours. Every one of them is public.

Open the run in the explorer
The cost of settling a dispute on Bitcoin

Why this was hard until now

Settling a dispute like this on Bitcoin was first done in 2025, and it was expensive: $14,211 across 5.4 MB of non-standard transactions. The on-chain cost has since come down to tens of dollars, and that reduction is not ours — BitVM3 achieved it.

What stayed prohibitive was the setup. Tens of gigabytes per circuit, growing into terabytes once a dishonest setup has to be defended by running many copies, which is why this stayed in papers rather than in production. That is the part we moved.

Pogun
55,490 vB

to settle two contested claims on Bitcoin — about $57 at 1 sat/vB

18 transactions, Bitcoin mainnet, 4 August 2026 · blocks 960,975–960,986

BitVM2
5.4 MB

to settle one challenge, the first time it was done on mainnet — $14,211

Non-standard transactions · 2025 · [BITVM2_SRC]

Bitcoin never ran the verification. It checked a hash. The heavy work happens off the chain and the chain enforces the outcome with one of the cheapest operations it has, which is the whole reason the number moved.

Proof

How to read the run

Two contested settlements, back to back, with a set of three operators. Both are in the explorer, and every broadcast transaction links out to mempool.space.

First pass
Operator 2 claimed, operator 3 challenged, and operator 2's assert was invalid. It ended in NoWithdraw: the fraudulent claim was blocked, by one honest challenger out of three.
Second pass
Operator 1 claimed, operator 2 challenged, and operator 1's assert held. It ended in WronglyChallenged, then Withdraw: an honest claim went through despite being challenged.
18 of 61
The explorer lists 61 transactions but only 18 were broadcast. The other 43 are pre-signed and were never needed — that is what a covenant looks like from the outside. Every branch exists and is signed; the run only spends the ones the dispute reached.
Where the cost is
Four transactions carry it: two Asserts at 8,703 vB and two ChallengeAsserts at 8,914 vB, which is 64% of the total. Everything else is a few hundred bytes.
Why mempool.space shows a zero fee
Every transaction carries a P2A anchor output and is funded by a separate child transaction, so the fee sits on the child rather than the transaction itself. The vB figures are measured sizes; the dollar figure applies a stated 1 sat/vB to them.
Timing
Blocks 960,975 to 960,986 — eleven blocks, about two hours, on 4 August 2026.

Open the explorer

28.1 MB
the verification circuit, against roughly 40 GB per instance for BitVM3
Pogun, [DATE] · still being reduced
~$1
the uncontested path, where no verifier ever touches the chain — well under a dollar
Two transactions · ClaimOptimistic measured at 167 vB, its partner pre-signed and not needed
1 of n
honest operators needed to stop a false claim
Run with a set of 3 on mainnet, 4 August 2026 · designed for around 100
What this is not

The deposit sits under a covenant held by a known operator set, all of them KYC'd legal entities under binding agreements. That is trust-minimized, not trustless, and the difference matters. No operator can move the coins outside the rules, and it takes exactly one honest operator in the set to stop a fraudulent claim. Every other one can be colluding against you and it changes nothing about what you get back. The most a colluding set can do is make you wait for it.

There are two smaller assumptions, and neither one is the operator set.

What this is not

The whole trust model, in five lines

Security reduces to five assumptions. Nothing else on this page is load-bearing, and none of them is hidden behind a word like "secure".

Bitcoin consensus
Locked funds at rest, and the final settlement of any dispute. Broken only if Bitcoin's proof-of-work or signature security fails — the same exposure as holding Bitcoin natively.
Operator honesty and liveness
One honest operator in the set, out of any number. Broken only if every operator is dishonest, or all of them abandon the instance. Neither one is theft: the worst case is bounded delay, and abandonment leaves the coins locked under the covenant rather than lost.
Covenant setup
Bitcoin has no native covenants, so one is emulated: a committee pre-signs every transaction the protocol will ever need, then deletes its keys. Once one member has deleted, no new signature can be produced. The ceremony is verifiable before any Bitcoin commits to it.
Destination chain
The softest of the five, and it governs the ordinary redemption path only. If that chain forges its state or halts, funds stay recoverable on Bitcoin alone.
Cryptographic primitives
Groth16, witness encryption, garbled circuits, verifiable secret sharing and the underlying signature schemes. Standard published assumptions.
The lineage

Pogun works in the BitVM lineage without running BitVM. Verification is done with BABE, and the multi-party protocol built on it is ours.

The lineage

What is ours and what is not

Three separate results sit behind the numbers above, and only the third is Pogun's. Saying otherwise would be claiming someone else's work.

BitVM, BitVM2, BitVM3
Published, 2023 to 2025. Established that Bitcoin can settle a dispute optimistically at all, and brought the on-chain cost of a contested round down to tens of dollars. Not ours.
BABE
Peer-reviewed, ePrint 2026/065, to appear at ACM CCS 2026. A two-party verification primitive that holds that on-chain cost while collapsing the off-chain side: the circuit drops from tens of gigabytes to tens of megabytes, and setup from minutes to milliseconds. Not ours either, though we contributed corrections back to it during implementation.
Pogun
The multi-party operator protocol built on BABE, the two-tier optimistic settlement that keeps the uncontested path cheap, and the optimizations past the paper. The cross-chain proving stack, the Bitcoin light client and the covenant instantiation are also ours.

Bitcoin never runs the verification. The heavy work happens off the chain, and the chain enforces the outcome by checking a hash.

About

The rules of bond markets.
The guarantees of Bitcoin.

Credit has always run on agreements between two parties: fixed terms, known counterparties, predictable outcomes. Pogun carries that discipline onto Bitcoin. Every loan is a discrete agreement at the terms its two sides set, and the Bitcoin backing it never leaves Bitcoin.

About

What that means in practice

No pool holds the funds, no oracle prices the collateral, and no keeper watches for a wick. Default is a payment event with a deterministic outcome, contained to that one loan, so a failure elsewhere in the market is not your failure.

Infrastructure like this fails on the details nobody sees. The protocol was built by an engineer who spent a decade in safety-critical control systems before six years designing trust-minimized Bitcoin infrastructure, alongside a product team that has shipped to enterprises and to hundreds of thousands of users. The credit contracts have been through an independent audit.

Nothing here rests on a claim you take on faith: the rules are on-chain, the collateral is verifiable, and the security model is written down.

Fixed terms Known counterparty No automatic liquidations
Request early access
Anatomy of one loan
Originationa desk; every term published up front
Servicingfixed schedule; terms can only soften
Custodystays on Bitcoin; released to you, not from a pool
Containmentone contract per loan; no contagion
Exitthe loan is a bond; sell it or insure it
Memoryrepayment compounds into credit history
Counterpartyhuman, institution, or agent

Remove any row and you have a product. Together, they are a market.

Independently audited · Rules on-chain · Nothing taken on faith

Humans get a better bond market. Agents get their first one.

Founders

The team behind Pogun

Omer Husain
Co-Founder & CEO

Product across financial infrastructure and civic technology since 2016, latterly leading Product and then Bitcoin DeFi at Input Output.

Torben Poguntke
Co-Founder & CTO

A decade in functional safety and industrial control, then six years of trust-minimized Bitcoin infrastructure. He owns Pogun's security model.

Hans Lahe
Co-Founder & CPO

A software engineer and repeat founder who led Bitcoin DeFi product at IOG. He owns the path from protocol to adoption, and stays hands-on.

Together with Alessandro, Briana, Antonio, Nick, Krisztian, Oleksii, James, Carlos, Nikolaos, Stanly, and Andrew, specialists across Bitcoin, BitVM, cryptography, engineering, and product. Contact by e-mail →

Pogun · Early access

Join the waitlist

Fixed-term credit against Bitcoin. You keep custody, and nothing is liquidated automatically. Leave your email and we'll open access in order.

One email when your access opens. Nothing else, ever.

What you are joining
Non-custodial No automatic liquidations No oracles