Concepts
Six ideas carry the whole design. Each has a page of its own under Protocol; this is the short version.
- Client
Signs and encrypts locally
Sees: Its own order - Relay
Sequences, signs receipts, commits the root
Sees: Ciphertexts only - Epoch manager
Schedule, commitment, state machine
Sees: A Merkle root - Matcher
Decrypts after the round, proposes price and fills
Sees: Orders, once public - Settlement
Re-checks every signed constraint, moves tokens
Sees: Orders, once public
Epoch#
Trading is cut into short windows called epochs. Every order belongs to exactly one. On mainnet an epoch is open for 30 seconds. While it is open the relay accepts sealed orders. At the cutoff the batch is fixed. Nothing about submission time inside an epoch affects price or allocation, so there is no race to be first.
Sealing#
An order is signed with EIP-712 and then encrypted in the client with timelock encryption to the drand quicknet network. The decryption key for an epoch is the network's signature over one specific round. It does not exist until a threshold of drand nodes produce it, 15 seconds after the cutoff on mainnet, and it is public afterwards. The relay cannot open an order early because nobody can.
Commitment#
Alongside the ciphertext the client sends a salted hash of the signed order. The relay puts every accepted ciphertext and its commitment into a Merkle tree and anchors the root in the epoch manager contract. The contract only accepts a root between the cutoff and the decryption time. From then on the set of orders is fixed onchain before anyone can read one, so the operator cannot add an order after seeing the others.
Receipt#
For every accepted ciphertext the relay returns a signed statement: this ciphertext, this epoch, this position, received before this cutoff. If the published root does not contain the matching leaf, the receipt proves the relay dropped the order.
Clearing price#
After decryption each market clears at a single price: the one that trades the most volume, and among those the one closest to the oracle reference price. Everyone who trades in that market in that epoch gets the same price. Limits more aggressive than the clearing price fill first; orders at the margin share pro rata.
Enforcement#
The matcher only proposes a price and fill sizes. The settlement contract recomputes every amount from the price, re-checks each order against what its owner signed, and refuses a market whose result differs from the hash the matcher published beforehand.
Vocabulary#
| Term | Meaning |
|---|---|
| Envelope | What the relay receives: ciphertext, its hash, the commitment, the epoch and scheme ids. Nothing else. |
| Sealed payload | What is encrypted: the order, its signature and a cancel hash. |
| Cutoff | The moment an epoch stops accepting orders (closeTime). |
| Reveal delay | Time between the cutoff and the decryption time. The commitment must land inside it. |
| Settle window | Time after decryption in which settlement must finish, otherwise the epoch cancels. |
| Market | A base token and a quote token, for example the AAPL Stock Token against USDG. |
| Protocol price | Quote raw units per base raw unit, times 1e18. No decimal normalisation is needed. |