Bottom line
- GPU debt went from ~14% private credit in 2023 to A3 / SOFR+225 in 2026. More than $20B of GPU-backed facilities have been announced.
- The market learned that the real collateral is contracted cash flow. CoreWeave can borrow at +225 against a hyperscaler and +450–550 against weaker customers, using broadly the same hardware.
- The system looks diversified but may not be. Customers prepay, lenders finance the middle, and Nvidia and Google increasingly insure the tail. Yet all of them ultimately depend on continued AI demand.
Note: Special thanks to Brexton Pham (Co-head of Compute at Cantor) for key insights described below.
The founding loan
On August 3, 2023, CoreWeave closed a $2.3 billion delayed-draw term loan co-led by Magnetar, an Evanston fund with two decades of structured-credit expertise, and Blackstone Tactical Opportunities, with Coatue, DigitalBridge, and BlackRock, PIMCO, and Carlyle funds in the syndicate. Back-of-envelope, at the reported ~70¢ advance rate, the collateral pool was $3B+ of H100 servers, on the order of 70–100k GPUs.
Data Gravity is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Hardware-secured lending wasn’t new, strictly speaking. Upper90 had been writing equipment-backed facilities for Crusoe since 2019, and the crypto cycle produced plenty of smaller loans against mining hardware. What was new in August 2023 was the scale and the structure. Nobody had borrowed billions against accelerators, and nobody had paired the chips with assigned customer contracts inside one bankruptcy-remote SPV. That pairing is the invention, and every GPU deal since is a descendant of it.
The borrower hardly looked like institutional-grade credit. Five years earlier CoreWeave was Atlantic Crypto, an Ethereum miner run by three former commodities traders. Magnetar was in first, and early: $50M of convertible notes in November 2021, two years before large credit funds touched the space. Blackstone arrived with the debt, co-leading once there were contracts to lend against. By mid-2023 Nvidia was on the cap table, Microsoft was becoming the dominant customer, and CoreWeave faced a capex problem equity could no longer solve. A single H100 data-center build could cost more than the company had raised in its lifetime. (The conviction paid historically well. That $50M note converted at the IPO, and by late 2025 Magnetar’s stake was worth roughly $12.5B, one of the defining credit-to-equity calls of the AI cycle.)
Priced at a reported 11–14% all-in (SOFR was ~5.3%, so call it 600–870bps of spread) for senior secured paper, the deal looks expensive in hindsight and wasn’t. Magnetar and Blackstone were underwriting a structure with no template, so they wrote one. The SPV design, the contract assignment, the depreciation-paced amortization: every deal since traces to choices made in this document. What made it writable at all was take-or-pay contracted cash flow from an investment-grade counterparty, sized to fully amortize the loan before the chips age out. The H100’s spot scarcity, trading above list with long waiting lists, was the recovery story, not the credit. That design choice, repay before you ever have to sell a used GPU, is the founding insight of the whole asset class, and it has never changed.
The repricing
CoreWeave inadvertendly created a controlled experiment in GPU credit. Hold the borrower and hardware roughly constant; vary the customer and the contract. The spread moves by hundreds of basis points. Across the eight facilities you can watch the collateral concept itself migrate: from the GPU, to the contract, to the counterparty.

Each facility resolved a specific question. DDTL 2.0 in May 2024, $7.5B with the same leads plus Carlyle, CDPQ, and Eldridge, answered whether the structure could scale. The October 2024 bank revolver (JPM, Goldman, Morgan Stanley) answered whether bank credit committees would touch the collateral. The May 2025 unsecured notes at 9.25% ran the control: unsecured CoreWeave priced wider than GPU-secured CoreWeave, the market’s way of saying the SPV structure itself carries several hundred basis points of value.
DDTL 4.0 in March 2026 is the one to study. $8.5B at SOFR+225 (5.9% fixed tranche), rated A3/A(low), structured by MUFG and Morgan Stanley, anchored by Blackstone Credit & Insurance. That anchor puts Blackstone at every stage of the curve. Tactical Opportunities underwrote the trade when it was unproven in 2023, stayed lead as it scaled to the $7.5B DDTL 2.0, among the largest private credit financings ever completed, and the firm’s credit and insurance arm anchored the investment-grade version three years later. Few firms get to create an asset class, scale it, and then become its senior buyer, and it took a platform of Blackstone’s breadth to do all three from one shop. Two things changed under the hood. The collateral narrowed to one SPV and its associated hyperscaler contract, so Moody’s was effectively rating the counterparty, not the chips. And the lenders themselves moved the borrowing base away from hardware value and toward contract execution.
Two facilities later the curve had a full term structure: DDTL 5.0 (two non-IG customers) at SOFR+450, Ba2/BB+; DDTL 5.5 (three-year contracts, re-lease optionality) at SOFR+550. Same borrower, same silicon, 325bps between tiers. The market is overwhelmingly pricing offtaker credit and contract tenor, not GPU residual value.
The curve is already being replicated across borrowers. CoreWeave’s A3 paper at +225 pays roughly double what generic single-A corporate credit has traded this cycle, a premium for structure novelty and renewal risk, and the reason insurance accounts showed up. In July, Nebius raised $775M of secured debt at SOFR+250 from a ten-bank MUFG-led group on its first secured deal. In August, Lambda closed a $926M term loan B at SOFR+300, rated Baa2, fully amortizing to 2030. The operative phrase in Lambda’s own announcement is “an investment-grade offtaker.” Three borrowers, one rate card. The compression is worth real money too: on DDTL 4.0’s $8.5B, the difference between 2023’s ~870bps and today’s 225 is roughly $550M a year of interest expense.
The rate card has a floor, though, and it’s worth being concrete about who lives under it. Price a modest cluster: 1,024 GPUs at $3.25/GPU-hour on a four-year committed contract is about $117M of total contract value. At the 25–30% downpayments unrated borrowers face, that means roughly $30M of cash out the door before the first token is served. The compressed spreads above go to whoever brings an investment-grade contract; a small neocloud without one still sees quotes reported in the SOFR+800–900 range. A startup that can fill nodes but can’t sign a hyperscaler pays roughly what CoreWeave paid before the asset class existed.

FIG. 2 — Spread over SOFR by facility. Bubble area is facility size; dashed rings are spreads estimated from reported all-in cost.
The template travels
The CoreWeave template got copied, then it mutated. Four variants, each changing something specific in the financial architecture.
Direct replication proved the template travels across borrowers: Lambda’s $500M Macquarie facility (April 2024), Crusoe’s ~$425M via Upper90, Fluidstack’s Macquarie facilities of up to $10B in capacity, Nebius against its Microsoft offtake. Macquarie franchised the model to the second tier while Blackstone and Magnetar stayed concentrated in the leader.
The asset-owner SPV separates the GPU-owning vehicle from the compute customer entirely. xAI’s Colossus 2 financing has a standalone SPV raising ~$20B to buy the GPUs and lease them to xAI, with Nvidia putting up to $2B of equity into the vehicle buying its own product. The compute never touches xAI’s balance sheet. It’s aircraft leasing with a five-year asset instead of a twenty-five-year one, minus the half-century of residual-value data that makes aircraft leasing work.
Powered-land financing brings in the Bitcoin miners, who contribute the scarce inputs of power and grid interconnects rather than GPUs. TeraWulf signed 10-year hosting agreements with Fluidstack worth $3.7B, with Google backstopping $1.8B of the lease obligations for warrants on ~8% of the company; Cipher ran the same trade a month later ($3B, $1.4B backstop, ~5.4% stake). Cantor Fitzgerald’s lane is here rather than in the term-loan syndicates: as the conversion trade’s house bank, it runs the collateralized-lending playbook it built for Bitcoin one asset class over.
Vendor credit support may be the most consequential mutation. Nvidia guaranteed $6.3B of CoreWeave’s unsold capacity through 2032, then in August signed MOUs with Apollo, BlackRock, Blackstone, Brookfield, Goldman, and KKR for financing platforms targeting $500B, keeping an option to backstop $125B of it. Add Google’s miner backstops and the pattern is clear: the companies with the best information about GPU demand have started selling credit support instead of deploying capital, supporting demand without funding the capex themselves. A backstop costs nothing today, sits off balance sheet, earns warrants or ecosystem lock-in, and becomes real only in the states of the world where the guarantor’s own product has failed. It is brilliant right up until it is correlated.

FIG. 3 — Announced GPU-backed facilities by borrower (capacity, not drawn balances).
The risk stack
Put the pieces together and the risk sits in four layers.

FIG. 4 — The risk stack and the loop underneath it. Distributed across five balance sheets; correlated to one variable.
Customers take the first loss without calling it that: per the S-1, CoreWeave offtakers prepay 15–25% of contract value at signing on take-or-pay commitments covering 96% of revenue, functionally the equity tranche of their supplier’s capex. Private credit and banks hold the senior middle, protected by contract cash flow and amortization. Insurance holds the duration: the A3 rating exists because general accounts (Apollo’s Athene, KKR’s Global Atlantic, Brookfield’s Wealth Solutions, Blackstone Credit & Insurance anchoring DDTL 4.0) mostly can’t buy sub-IG paper, and Meta’s Hyperion SPV ($27B of A+ debt, PIMCO holding ~$18B) proved the trade at scale. And the vendors sell protection on the tail.
The architecture distributes risk beautifully across legal entities. It does not necessarily diversify the economic driver. Follow the money in a circle: an AI customer raises capital, and prepays for compute. The neocloud borrows against that customer’s contract. The lender funds the GPU purchase. Nvidia books the revenue. Nvidia then backstops future capacity, because it wants the next round of purchases funded. Five balance sheets, four layers of protection, one loop. Every layer is underwriting the same assumption: that AI demand keeps compounding.
The diversification is nominal. The correlation is one.
What a used GPU is actually worth
The entire structure is built to avoid answering this question, and you can prove it from the documents. I ran a term search of CoreWeave’s DDTL 5.5 credit agreement, the newest one on file. “GPU” appears dozens of times, in defined terms like “GPU Clusters” and “GPU Depreciated Amount.” The words a lender would use to value hardware against an outside reference appear zero times: no appraisal, no residual value, no orderly liquidation, no advance rate, no loan-to-value, no borrowing base, no remarketing. An $8.5B-scale lending program, secured by chips, with no mechanism anywhere for asking what the chips would fetch.
The sharpest tell comes from Nvidia itself. In August it filed a Residual Value Guaranty covering up to $105B on the ~4.25GW of data centers SB Energy is building for OpenAI, which sounds like the vendor finally putting a floor under its product. Read the exhibit. The guaranteed minimum value is defined as data-center, power, and transmission-related costs, and Nvidia’s own equipment is carved out as “Guarantor Property” under a separate repossession clause. The company with the most information about GPU value on earth will guarantee the building and the substation. It will not put a number on the chips.
Meanwhile, what we actually know is thin. Rental rates round-tripped violently, from ~$8/hour in early 2024 to $1.70 by October 2025 and back to ~$2.35 by March 2026. Depreciation schedules disagree by 50% on identical hardware (CoreWeave six years, Nebius four). The broadest public record of executed used-GPU sales, CCIR’s three-year dataset covering the datacenter models it tracks, comes to 3,009 listings, 10,911 units, $26.3M; bilateral trades outside that universe go unrecorded, which is itself part of the problem. Manheim, the used-car benchmark lenders actually underwrite against, processes over 5 million transactions a year. Three years of the whole used-GPU market is about 0.3% of one CoreWeave facility.
And “the GPU” undersells what is actually on the balance sheet. What lenders finance is machines: eight-GPU servers with CPUs, memory, NICs, and switching wrapped around the accelerators, deployed in a specific network topology in a specific building. A machine carries at least three different residual values. There is the face value its depreciation schedule implies; the going-concern value if a buyer takes over the cluster running, which secondary-market estimates put around 50–70% of new for 2–3-year-old hardware; and the orderly-liquidation value if it has to be de-installed, re-certified, and parted out, plausibly 30–50% in a distressed sale, before the cost of redeploying racks engineered for someone else’s data center. Hardware wear is real at fleet scale (Meta logged 419 unplanned disruptions across 16,384 H100s in 54 days of Llama 3 training), so condition varies machine by machine. Today’s structures mostly don’t distinguish among the three values. The one that matters in a default is the last, and it is the one with the least data behind it.
A market is now being built, but ends-first. Silicon Data publishes a daily H100 rental index with a 36-month forward curve, and in August launched a GPU residual value product, a DCF off its own rental curve. That is a value, not a price: it tells you what a GPU earns for whoever keeps running it, not what a lender recovers when they have to sell one. Compute Exchange opened a used-GPU marketplace that publishes reference quotes but takes no custody and clears no trades. CME lists cash-settled H100 and B200 rental futures on October 5, pending review, while the CFTC’s open request for comment questions whether compute yet has the fungibility, standardization, and liquidity to underlie derivatives at all. Even once the futures trade, they hedge the hour, not the box: generation, condition, location, and redeployment cost all sit in the basis between a rental rate and a rack, and the rack is what the lender owns after a default.
The bears (Chanos, Burry) argue two to three years of true economic life. A collateral class with indexes but no prints can’t prove them wrong.
When the contracts expire
The irony is that GPUs became credible collateral only after lenders learned how not to rely on their collateral value. Customer prepays provide a first-loss cushion. Take-or-pay contracts turn uncertain utilization into scheduled cash flow. Loans amortize before the hardware is expected to become obsolete. Investment-grade offtakers collapse spreads. Nvidia and Google increasingly insure the tail. Each innovation pushes the moment when someone has to answer the uncomfortable question of what a three-year-old GPU is actually worth further into the future.
That is why the 2026–27 renewal cycle matters more than any depreciation schedule. The 2023–24 contract vintage starts rolling off next year. If the first generation of contracts renews, lenders may never need a robust answer, and GPU finance will look less like equipment lending and more like project finance wrapped around compute contracts. If they do not renew, the entire structure falls back onto a secondary market where the publicly documented transactions total just $26.3M.
And that exposes the larger contradiction. The risk has been distributed across customers, neoclouds, banks, insurers, and vendors, but every layer ultimately rests on the same underlying assumption: AI demand remains strong enough to keep the machines earning.
The GPU became collateral because finance learned how to avoid testing the collateral. The first real test begins when the contracts expire.
Sources & notesCompany releases and SEC filings via CoreWeave IR (including the DDTL 5.5 credit agreement), Nvidia’s Residual Value Guaranty exhibit, Lambda, Nebius, and TeraWulf; CCIR on used-GPU transactions; CME Group / Silicon Data; Data Center Dynamics; PR Newswire; Bloomberg; Nvidia Newsroom; Fortune; Friedman (2026); Steffen (2026); CipherTalk on residual values. DDTL 1.0/2.0 spreads are estimates from reported all-in cost versus prevailing SOFR. Sector total reflects announced facility capacity, not drawn balances. · datagravity.dev



