Escrow, not custody.
The desk holds the block only between post and settlement. Every transfer out is a refund or a fill.
Trades that don't fit in a pool, filled at one price. Post the block. Makers quote sealed. The best price settles in a single transaction, and the pool never sees it.
Escrow a block of any stock token and name the worst price you accept. Cancel is free until a maker commits.
Post a block ↗Makers commit a hash and a bond in USDG, then reveal. No one, taker included, reads a price during the seal.
Quote as a maker ↗Anyone settles once the window closes. Best deposit and escrow swap atomically. Losers refund themselves.
Read the contract ↗A block is a token, a side, a size and a limit. A SELL block escrows the base amount; a BUY block escrows USDG at the limit plus the fee. Two windows follow: one for sealed quotes, one for reveals.
The desk holds the block only between post and settlement. Every transfer out is a refund or a fill.
Minimum price on a SELL block, maximum on a BUY block. A revealed quote outside it does not compete.
Seal 1 minute to 7 days. Reveal 1 minute to 1 day. Short for a quick print, long for a patient one.
A quote is a hash of the price and a salt until the seal closes. A bond in USDG rides along, comes back on reveal, and goes to the taker if the maker goes quiet. Inside the limit, reveal also locks the counter-asset so settlement can never fail for lack of funds.
The desk draws a 32-byte salt, hashes it with the block id, your address and the price, and sends only the hash.
Returned in the reveal transaction, win or lose. Forfeited to the taker if there is no reveal.
While the seal is open a new hash replaces the old one. The bond is posted once.
The salt exists only in your browser vault and in the JSON you export. The contract cannot recover it. Export after every commit.
Highest bid on a SELL, lowest ask on a BUY, ties to the earlier reveal. Settlement is permissionless: after the reveal window, or the moment every committed maker has revealed, anyone can call it.
No partial fills, no price ladder. The block clears at the single best quote inside the limit.
The winning deposit and the escrow swap in the same transaction. The fee comes off the USDG leg.
Losing makers call refund(). A base token that refuses a transfer falls to a ledger you drain with withdraw(). The other leg still settles.
Every rule below is a line in BlockDesk.sol. The values are read from the contract when the desk is configured.
| Taker escrow | On a SELL block the taker escrows the full base amount. On a BUY block the taker escrows USDG for the amount at the limit price plus the fee on it. Anything unspent comes back at settlement. |
|---|---|
| Limit price | Quoted in USDG per whole token. On a SELL block it is the minimum the taker accepts; on a BUY block it is the maximum. A revealed price outside the limit does not compete and locks no deposit. |
| Seal window | 1 min to 7 days. Makers commit hashed quotes. Nobody, including the taker, can read a price during the seal. |
| Reveal window | 1 min to 1 day. Follows the seal window. Makers open their quotes with the price and salt. |
| Maker bond | 0.50% of the limit notional, at least 25.00 USDG. Posted in USDG once, on the first commit. Re-quoting during the seal window is free and replaces the hash. |
| Reveal | Returns the bond in the same transaction, win or lose. If the price is inside the limit the maker also locks the deposit: USDG for the notional on a SELL block, the base amount on a BUY block. |
| No reveal | A maker who commits and does not reveal forfeits the bond. It goes to the taker. |
| Best price | Highest bid on a SELL block, lowest ask on a BUY block. Ties go to the earlier reveal. |
| Settlement | Permissionless. Anyone can settle after the reveal window closes, or as soon as every committed maker has revealed. The best deposit and the escrow swap in one transaction. |
| No valid quote | The block is cancelled at settlement. Escrow and any forfeited bonds go to the taker. |
| Losing makers | Reclaim the deposit with refund() once the block is final. |
| Fee | 0.10% of the quote leg, taken at settlement and paid by the taker. Goes to the treasury. |
| Base token reverts | If a base token refuses the transfer at settlement, the amount is credited to a ledger the recipient drains with withdraw(). The other leg still settles. |
| Owner | Can change the fee, the bond, the treasury, and pause new posts and commits. Cannot move user funds. Reveals, settlement and refunds run while paused. |
| Cancel | The taker can cancel only while the seal window is open and nobody has committed. |
BlockDesk holds escrow, bonds and deposits only between post and settlement. The owner can change the fee, the bond, the treasury and pause new posts. It cannot move user funds.