Kasumi
Kasumi is an encrypted frequent batch auction for onchain markets. An order is signed and encrypted on the trader's machine, stays unreadable to everyone until its batch closes, and then clears at one price that anyone can recompute.
- SealedCiphertext only
- CommittedRoot onchain
- DecryptedKey published
- MatchedOne price
- SettledTokens move
Your order should be verifiable after execution without being visible before execution.
The first markets are Stock Tokens against USDG on Robinhood Chain. Kasumi is not owned, endorsed, sponsored or operated by Robinhood.
What it guarantees#
Pre-trade intent privacy. Before an epoch's decryption time, nobody can read an order's market, side, size, limit price or wallet. That includes the relay that accepted it. Encryption happens in the client, and the key does not exist until the drand network publishes the round the epoch is locked to.
Verifiable execution. The batch is fixed by a Merkle root before it can be decrypted, so no order can be added once any order is readable. The settlement contract checks signature, epoch, nonce, size, limit price, oracle bounds and batch membership itself, and only settles a market whose result equals the hash the matcher published first. The auction is deterministic: the Rust matcher and the TypeScript reference produce the same result hash for the same input.
What it does not guarantee#
- Hidden settlement, hidden balances or anonymous wallets. Fills and token transfers are public.
- Secrecy after execution. Once an epoch decrypts, every order in it is public, filled or not.
- Network privacy. The relay sees IP addresses, timing and ciphertext sizes.
- Censorship resistance. A relay can refuse or drop an order. A signed receipt makes that provable, not impossible.
Kasumi is not a mixer, a privacy coin or an anonymity tool. The full list of limits is in the threat model.
Status#
| Contracts | Deployed on Robinhood Chain mainnet (chain id 4663) on 2026-10-02. Addresses are on the deployment page. |
| Audit | None. One internal adversarial review, recorded in the security review. |
| Proven on mainnet | Wiring and roles read back. One epoch with a single order from an unfunded wallet was committed by the relay key and settled empty by the matcher key. |
| Not yet proven on mainnet | A trade with real tokens. Nothing has filled on mainnet so far. |
| Proven off mainnet | A full epoch with real Stock Tokens, USDG and Chainlink feeds on a local fork of mainnet. End to end runs on a local chain, including a crash and resume and a griefing recovery. |
| Markets | AAPL, NVDA, TSLA and SPY Stock Tokens against USDG. |
| Terminal | Live on mainnet at kasumisystems.com. Orders are gasless signatures; wallets connect through Privy. |
Stock Tokens are issued by Robinhood Assets (Jersey) Limited and are not offered to US persons. Nothing in these pages is investment advice.
Where to go next#
| If you want to | Read |
|---|---|
| Place a sealed order from code | Quickstart |
| Understand the moving parts | Concepts |
| Check exactly what is signed and what is public | Order format and Relay and receipts |
| Recompute a batch yourself | Matching |
| Integrate | SDK, Relay API, Contracts |
| Decide whether to trust it | Threat model and Security review |