Kasumi

Kasumi is an encrypted frequent batch auction for onchain markets. An order is signed and encrypted on the trader's machine, stays unreadable to everyone until its batch closes, and then clears at one price that anyone can recompute.

  1. SealedCiphertext only
  2. CommittedRoot onchain
  3. DecryptedKey published
  4. MatchedOne price
  5. SettledTokens move
One batch. Until the drand round is published the rows are ciphertext to everyone, the relay included. Then every order becomes readable at once and clears at one price.

Your order should be verifiable after execution without being visible before execution.

The first markets are Stock Tokens against USDG on Robinhood Chain. Kasumi is not owned, endorsed, sponsored or operated by Robinhood.

What it guarantees#

Pre-trade intent privacy. Before an epoch's decryption time, nobody can read an order's market, side, size, limit price or wallet. That includes the relay that accepted it. Encryption happens in the client, and the key does not exist until the drand network publishes the round the epoch is locked to.

Verifiable execution. The batch is fixed by a Merkle root before it can be decrypted, so no order can be added once any order is readable. The settlement contract checks signature, epoch, nonce, size, limit price, oracle bounds and batch membership itself, and only settles a market whose result equals the hash the matcher published first. The auction is deterministic: the Rust matcher and the TypeScript reference produce the same result hash for the same input.

What it does not guarantee#

  • Hidden settlement, hidden balances or anonymous wallets. Fills and token transfers are public.
  • Secrecy after execution. Once an epoch decrypts, every order in it is public, filled or not.
  • Network privacy. The relay sees IP addresses, timing and ciphertext sizes.
  • Censorship resistance. A relay can refuse or drop an order. A signed receipt makes that provable, not impossible.

Kasumi is not a mixer, a privacy coin or an anonymity tool. The full list of limits is in the threat model.

Status#

Contracts Deployed on Robinhood Chain mainnet (chain id 4663) on 2026-10-02. Addresses are on the deployment page.
Audit None. One internal adversarial review, recorded in the security review.
Proven on mainnet Wiring and roles read back. One epoch with a single order from an unfunded wallet was committed by the relay key and settled empty by the matcher key.
Not yet proven on mainnet A trade with real tokens. Nothing has filled on mainnet so far.
Proven off mainnet A full epoch with real Stock Tokens, USDG and Chainlink feeds on a local fork of mainnet. End to end runs on a local chain, including a crash and resume and a griefing recovery.
Markets AAPL, NVDA, TSLA and SPY Stock Tokens against USDG.
Terminal Live on mainnet at kasumisystems.com. Orders are gasless signatures; wallets connect through Privy.

Stock Tokens are issued by Robinhood Assets (Jersey) Limited and are not offered to US persons. Nothing in these pages is investment advice.

Where to go next#

If you want to Read
Place a sealed order from code Quickstart
Understand the moving parts Concepts
Check exactly what is signed and what is public Order format and Relay and receipts
Recompute a batch yourself Matching
Integrate SDK, Relay API, Contracts
Decide whether to trust it Threat model and Security review