The Contract Stack
Never send funds directly to a settlement address. Value moves only through a signed order’s flow; preflight
nextActions say what to sign and where funds travel.Settlement Lifecycle
Every quote carries its own EIP-712escrow-v0 payload. Your signature authorizes it, your router locks the input into escrow on those terms, and only a delivery proof moves the funds onward.
If the expiry passes without a delivery proof, the escrow refunds your input through a path that is permissionless and unpausable. There is never a half-settled state.
Where the Next Layers Plug In
Coming soon. Multilateral Netting and the Shared Collateral Network are in design.
Rolling Out on the Rails
- Bonded firm quotes - a proven no-show refunds you; the bond is slashed only on positive evidence
- A governed compliance plane - a delayed main lane and an instant emergency lane
- Per-corridor settlement oracles
- An add-only module catalogue - a refund is bound to the version that opened the trade
- The same escrow model on Solana and Tron
Funding Locks
Preflight selects the lock for the corridor and token; Token Approvals covers the check-and-approve flow.Signed Payloads
Each quote carries its complete typed payload inquote.order: for escrow-v0, the StandardOrder typed data. Sign exactly what the quote returns; the integrityChecksum binds your submission to the quote shown, so any mutation is rejected. Signing flows: RFQ Order Submission guide, Router API quickstart.