Trust
Security model
The protections that keep a market’s outcome tied to the coin’s real price.
- Only approved keepers take readings. Nobody can buy a coin, trigger a reading at the inflated price and sell, all in one transaction.
- Reading times are secret. Each keeper derives its schedule from its own key, so the moments a market is read cannot be computed in advance.
- Readings are spread and the median decides. One distorted reading cannot move the result; an attacker would have to distort most of them.
- Readings cannot be bunched. They must be at least 60 seconds apart, and the owner cannot lower that. Each market keeps the time between readings it opened with.
- Only approved resolvers. A creator cannot bring rules that pick their own winner.
- Supply is fixed at creation. The contract reads it when the market opens. Burning tokens mid market cannot move FDV, and a burn just before a market opens cannot stop it opening.
- Windows must sit inside the market’s timeline. A window that opens before trading closes, or ends after the resolve time, is rejected when the market is opened.
- Windows must hold their readings. A window with less than twice the room its readings need is rejected, so no market can be opened that is certain to void.
- A pause cannot decide anything. Readings, settling, selling and every refund keep working while the protocol is paused.
- Questions are rebuilt from terms. Misleading question text is never shown.