Sky’s token design is built around one claim: protocol revenue can be turned into governance security without leaning on perpetual token inflation. That is the right instinct for an onchain credit system. It is also fragile in one specific way. When cashflows compress, Sky’s security budget can compress with them.
Sky is the MakerDAO system, rebranded and upgraded so that DAI and MKR coexist with their upgraded counterparts, USDS and SKY. USDS is designed to be convertible 1:1 with DAI via an onchain converter described in the USDS token docs. Sky is explicit that USDS stays linked to the same issuance source as DAI, with conversion available at any time through the DAI↔USDS route.
On the governance side, SKY is the successor token to MKR for voting and protocol control, with an upgrade path via an onchain converter at a fixed ratio of 1 MKR → 24,000 SKY as described in the SKY token docs. The migration is not just branding. It changes how governance power is custodied, how staking is productized, and how surplus can be routed into either buy-and-burn or staker rewards.
What Sky is, and what the tokens actually do
Sky remains a collateralized stablecoin and credit platform with onchain governance. The economic center of mass is the stablecoin. The governance token exists to set risk parameters, manage upgrades, and absorb tail risk when the system is under stress. Compared with tokenized T-bills products like USYC, Sky’s stablecoin depends on onchain credit risk and governance.
USDS is an ERC-20 token designed with upgradeability (UUPS / ERC-1967 proxy patterns) and supports permit plus EIP-1271 smart contract signatures. Critically for tokenomics, DAI↔USDS conversion is 1:1, bidirectional, and the docs state no fees on that route, with fees not enableable in the future.
sUSDS is the tokenized Sky Savings Rate for USDS, implemented as an ERC-4626 vault with real-time share-to-asset conversion. The docs state no fees on USDS↔sUSDS vault interactions, and again, fees cannot be enabled later. From a security-budget angle, that “no future fees” constraint matters. It limits governance’s ability to fund insurance, audits, or keeper subsidies directly from the savings wrapper if conditions change.
stUSDS is positioned as a higher-risk “Expert token” funded by supplying USDS, explicitly framed as risk capital that “absorbs a greater share of system risk” in exchange for potentially capturing a larger portion of protocol rewards. In plain terms, Sky is experimenting with a risk waterfall that does not rely exclusively on governance token dilution. Whether that works depends on how the losses are actually allocated during bad-debt events. Public docs describe the intent, not the full stress-path accounting.
SKY is the governance token. It is ERC-20 with permit and EIP-1271 signature validation. Its first-order economic utility is governance control. Its second-order utility is access to staking and integrated leverage primitives through the LockStake Engine.
History that changed the economic surface area
The key structural shift is not “Sky vs Maker” branding. It is the governance cutover and the reward-routing plumbing that came with it.
Sky’s upgrade timeline places the governance migration go-live on May 19, 2025 via execution of a governance upgrade spell, and it also states staking rewards activation work (publication of the activation spell) on May 29, 2025. The delayed-upgrade penalty phase is scheduled to begin on September 18, 2025.
Supply, distribution, and the MKR→SKY upgrade penalty
SKY’s distribution is dominated by the MKR conversion path. There is a fixed conversion ratio of 1 MKR → 24,000 SKY. The conversion contract mechanics changed between Converter V1 and V2 in ways that matter for supply discipline.
In the “Token Holders” documentation, Sky describes Converter V2 as a one-way onchain upgrade mechanism using transfers from a pre-funded SKY balance rather than minting new SKY on demand. It also states that Converter V2 burns the MKR being upgraded. The “Codebase Change Analysis” reiterates this: Converter V2 cannot mint new SKY. The full SKY balance required to convert all outstanding MKR is pre-minted and deposited into Converter V2.
The SKY repo README is even more explicit about the initialization: an amount of SKY “equivalent to the total supply of MKR” is minted to the converter upon initialization, and it is “assumed that further minting of MKR will not happen.” That line is not just technical commentary. It is a design signal. It implies Sky wants to reduce reliance on governance token inflation as a routine backstop.
Conversion is also where Sky injects a time-based penalty. Post-upgrade, conversions occur via the mkrToSky function with a governance-controlled fee parameter in the converter, applied as a reduction in SKY received. The upgrade timeline specifies the delayed-upgrade penalty schedule: on September 18, 2025 a 1% penalty applies, and it increases by 1% every 3 months unless governance decides otherwise.
That penalty is not a fee paid in USDS. It is a conversion haircut paid in SKY units, and the docs note accumulated fees are tracked in a take variable and can be extracted by governance via collect(to). Economically, this is a transfer from late MKR upgraders to the governed system, with governance choosing what to do with the captured SKY.
- MKR holders upgrading to SKY (via Converter V2): Conversion at 1 MKR → 24,000 SKY; Converter V2 is one-way MKR→SKY; Converter V2 distributes SKY from a pre-minted balance and burns the MKR received; a governance-set conversion
feecan reduce the effective SKY received post-penalty start.
Utility and fiscal flows: where rewards come from, and who pays
Sky’s tokenomics is easiest to understand as a set of pipes. USDS is the unit that users want. Everything else is routing incentives around USDS issuance, demand, and risk containment. For contrast with issuer-led stablecoins, compare this plumbing to Global Dollar (USDG), where control and risk are more directly concentrated in the issuer stack.
Start with the core surplus engine. The Jug contract accumulates stability fees by updating collateral-specific debt when drip() is called, and the docs state this also updates the amount of Dai surplus owned by the Vow. The Vow contract is described as the protocol’s balance sheet, receiving system surplus and system debt, and it contains logic to trigger both surplus and deficit auctions.
The important part is what happens after surplus exists. Sky’s Smart Burn / flapper tooling suggests surplus can be routed to both burning and to staking rewards.
The Splitter module in dss-flappers withdraws USDS from the Vow and splits it into two parts. One part is sent to an underlying burn engine (a “flapper” strategy). The other part is distributed as rewards to a “farm” contract. The Splitter’s key parameter is burn, defined as the percentage of the Vow’s surplus lot (vow.bump) routed to the burn engine.
That is a clean security-budget primitive. It turns protocol profits into:
(1) tokenholder return via burning, and (2) governance security via paying stakers.
Sky’s own UI-level documentation confirms that SKY can be supplied into the Staking Engine to access staking rewards, and it states the staking rewards rate is determined by Sky Ecosystem Governance through onchain voting. It also states staking has no minimum and no exit fee in the UI description. On the contract side, the LockStake Engine docs describe the staking engine as a place to deposit SKY and open a vault position that can be used to borrow USDS, stake the SKY deposit for rewards, and delegate voting power.
One more design choice matters. In the LockStake Engine change analysis, Sky states the exit fee is fixed at deployment and will be set to 0. That improves UX and reduces “sticky capital” risk, but it also makes governance participation more reflexive. Capital can flee quickly when rewards compress or perceived risk spikes.
USDS also has non-staking reward paths. Sky’s app documentation states that supplying USDS to a “Sky Token Rewards” module yields rewards over time in the form of SKY governance tokens and “Sky Star tokens.” Sky’s legal terms also describe protocol rewards accessible via different features including “USDS Token Rewards,” with accumulated rewards potentially including non-native DeFi project tokens (examples given include SPK and CLE). For tokenomics modeling, the key point is that reward distribution is multi-asset and feature-specific, and not all reward funding sources are fully specified in developer docs.
Governance control surfaces (and why they matter for security)
SKY governance runs through the classic “Chief / Pause / Spell” pattern. Sky’s governance overview states the governance module contains contracts that facilitate SKY voting, proposal execution, and voting security. It names Chief, Pause, and Spell as the three core components.
The Chief mechanics themselves are standard approval voting primitives: lock governance tokens for weight, vote slates, and lift an authority address when it has sufficient votes. The difference in Sky’s upgrade is not the voting model. It is how the model is hardened against flash-loan and timing manipulation.
Sky’s “Codebase Change Analysis” documents two Chief V3 security changes that are worth treating as tokenomics constraints because they shape the cost of governance attacks. First, flash-loan protection logic changes so that lift and free cannot occur in the same block. Second, there is a lift cooldown period so that after a successful lift, further lifts are blocked until the cooldown expires.
The same analysis notes IOU tokens were removed in Chief V3, meaning deposit and withdrawal flows no longer require IOU approvals. Operationally, that lowers friction and likely increases participation. Security-wise, it also reduces “integration foot-guns” and speeds up capital mobility in and out of voting weight.
Finally, Sky’s docs make clear that governance can actively shape token conversion economics. Converter V2 introduces a governance-controlled fee parameter, and governance can later extract accumulated fees using collect. That is a powerful lever. It is also a trust surface. Governance is not only setting risk parameters for collateral. It is setting parameters that change conversion outcomes for legacy holders.
Security budget maximalist take: Sky’s rewards are “revenue-secured,” until they aren’t
Sky is trying to pay for security the way a real business does. With profits. In DeFi terms, with surplus from stability fees and system operations routed through onchain accounting.
The best documented piece of this is the Splitter model in dss-flappers: USDS surplus is withdrawn from the Vow and split between a burn path and a farm rewards path, with the burn share controlled by a parameter. If you care about security, the burn-vs-reward split is not cosmetic. It is the security budget dial.
Set burn too high and the system becomes “capital efficient” for tokenholders while starving governance participation. The protocol might look deflationary. It will also look cheap to attack when the active voting set thins.
Set burn too low and governance participation gets subsidized harder, but tokenholder return shifts from supply reduction to yield. That can be the right trade when you need resilient governance turnout. It can also create reflexive sell pressure if recipients treat USDS rewards as income and dump SKY exposure rather than hold it.
The more delicate issue is the backstop model. The Vow documentation still describes deficit auctions (flop) and explicitly references MKR lot sizing and MKR minting dynamics in its failure-mode section. Meanwhile, the SKY converter repo states it is “assumed that further minting of MKR will not happen.” Those two statements do not reconcile cleanly in the public docs.
That mismatch creates a modeling problem. In Maker’s historic design, the governance token’s ability to be diluted during crises is part of the safety case for the stablecoin. Remove or constrain that, and you must replace it with something else that is credible under stress. stUSDS is described as a risk capital token meant to absorb greater system risk. But the documentation does not fully spell out the exact accounting path of losses, triggers, and priority between USDS holders, stUSDS, and governance tokenholders in a severe deficit scenario. That is structural uncertainty, not a minor missing detail.
If you are building or advising on similar systems, this is where token economy design stops being narrative and becomes engineering. A small amount of tokenomics consulting focused on stress-path recapitalization and governance security budgeting-starting from concrete design components-can prevent years of accidental fragility later.
Risk analysis (ranked), with dominant risk called out
Sky has serious protocol engineering heritage. It also has serious tokenomics surface area. The risks below are framed mechanistically, not as vibes. Some recurring patterns show up in our research notes.
Top 3 risks
-
Dominant risk: security budget compression in a downturn. Trigger: a sustained drop in stability-fee income and system surplus, or a rapid increase in bad debt after liquidations. Mechanism: staking rewards are positioned as governance-set and productized through the Staking Engine, and surplus routing in the flapper tooling explicitly splits USDS from the Vow between burn and farm rewards. When surplus shrinks, the protocol has less to route. That means lower rewards, weaker staking participation, and thinner governance “active security.” Who bears it: USDS users first (peg and risk parameter response speed), then SKY holders (governance token price and dilution risk if recapitalization reappears), and stUSDS participants if risk is actually pushed there. Measurable indicators: onchain Vow surplus/debt state (variables like
Sin,Ash,bump,humpdefine the auction and buffer regime), plus sustained declines in reward routing cadence (Splitter.hop) or reward share (burnshifted upward to defend burn optics).The deeper reason this dominates is that it stacks two effects. First, the security budget is partly variable with profit. Second, public docs contain tension around crisis recapitalization. The Vow docs discuss deficit auctions and MKR minting dynamics as a failure mode. The SKY converter repo assumes further MKR minting will not happen. If the protocol is steering away from governance token inflation as a backstop, it must have an alternative that is both (a) explicitly specified and (b) large enough in stressed conditions. stUSDS gestures toward that role, but the docs are not yet a full, auditable “loss waterfall spec.”
In a benign regime, this is fine. Surplus exists, rewards flow, governance is active, and risk tooling can be tuned. In a hostile regime, the weakest point is not “token price volatility.” It is the possibility that the system’s backstop capacity is less explicit than it needs to be, right when you need it to be most explicit.
-
Governance capture or execution-risk events. Trigger: concentrated ownership, low participation, or tactical use of governance mechanics during a period of thin voting weight. Mechanism: Chief-based governance can elevate authority through
liftonce sufficient votes are assembled, with execution mediated by Pause/Spell style components. While the Chief upgrade adds flash-loan related restrictions and a lift cooldown, governance remains an economic-security game where the cost of attack is tied to the cost of acquiring and mobilizing voting weight. Who bears it: every protocol participant. Stablecoin users bear immediate harm via parameter sabotage or malicious upgrades. SKY holders bear value destruction. Indicators: declining locked governance weight in Chief, increasing vote concentration, and governance events clustered at low-liquidity times, alongside any emergency governance interventions. -
Legacy MKR liquidity and borrower pathologies during one-way migration. Trigger: delayed conversion into the penalty phase beginning September 18, 2025, plus continued use of MKR in third-party venues after liquidity thins. Mechanism: Sky’s integrator guide warns that as MKR holders convert to SKY, the diminishing MKR supply creates liquidity risk and price volatility risk, making it hard for borrowers to source MKR for repayment and potentially triggering unexpected liquidations. Who bears it: MKR borrowers and any market participants relying on “MKR is fungible with SKY” mental models. Indicators: widening MKR/SKY market dislocation, collapsing MKR lending liquidity, and rising liquidation volumes on venues that still treat MKR as active collateral or debt.
Sky is doing something many protocols avoid: tying governance participation to a real surplus engine rather than pretending that emissions are free. The design still needs one thing to be maximally legible: a fully specified, credible recapitalization path that remains strong when revenue is weak. If you want help pressure-testing those assumptions, our tokenomics services focus on stress-path design and governance security budgeting.
This article is part of our Tokenomics Deep Dive series.








