Concepts

Six ideas carry the whole design. Each has a page of its own under Protocol; this is the short version.

  1. Client

    Signs and encrypts locally

    Sees: Its own order
  2. Relay

    Sequences, signs receipts, commits the root

    Sees: Ciphertexts only
  3. Epoch manager

    Schedule, commitment, state machine

    Sees: A Merkle root
  4. Matcher

    Decrypts after the round, proposes price and fills

    Sees: Orders, once public
  5. Settlement

    Re-checks every signed constraint, moves tokens

    Sees: Orders, once public
The path of an order. The matcher proposes; the settlement contract enforces. No user constraint relies on the relay or the matcher being honest.

Epoch#

Trading is cut into short windows called epochs. Every order belongs to exactly one. On mainnet an epoch is open for 30 seconds. While it is open the relay accepts sealed orders. At the cutoff the batch is fixed. Nothing about submission time inside an epoch affects price or allocation, so there is no race to be first.

Sealing#

An order is signed with EIP-712 and then encrypted in the client with timelock encryption to the drand quicknet network. The decryption key for an epoch is the network's signature over one specific round. It does not exist until a threshold of drand nodes produce it, 15 seconds after the cutoff on mainnet, and it is public afterwards. The relay cannot open an order early because nobody can.

Commitment#

Alongside the ciphertext the client sends a salted hash of the signed order. The relay puts every accepted ciphertext and its commitment into a Merkle tree and anchors the root in the epoch manager contract. The contract only accepts a root between the cutoff and the decryption time. From then on the set of orders is fixed onchain before anyone can read one, so the operator cannot add an order after seeing the others.

Receipt#

For every accepted ciphertext the relay returns a signed statement: this ciphertext, this epoch, this position, received before this cutoff. If the published root does not contain the matching leaf, the receipt proves the relay dropped the order.

Clearing price#

After decryption each market clears at a single price: the one that trades the most volume, and among those the one closest to the oracle reference price. Everyone who trades in that market in that epoch gets the same price. Limits more aggressive than the clearing price fill first; orders at the margin share pro rata.

Enforcement#

The matcher only proposes a price and fill sizes. The settlement contract recomputes every amount from the price, re-checks each order against what its owner signed, and refuses a market whose result differs from the hash the matcher published beforehand.

Vocabulary#

Term Meaning
Envelope What the relay receives: ciphertext, its hash, the commitment, the epoch and scheme ids. Nothing else.
Sealed payload What is encrypted: the order, its signature and a cancel hash.
Cutoff The moment an epoch stops accepting orders (closeTime).
Reveal delay Time between the cutoff and the decryption time. The commitment must land inside it.
Settle window Time after decryption in which settlement must finish, otherwise the epoch cancels.
Market A base token and a quote token, for example the AAPL Stock Token against USDG.
Protocol price Quote raw units per base raw unit, times 1e18. No decimal normalisation is needed.