Skip to content
Logo

Trust model

WickPlay uses an onchain USDG escrow with ordered offchain settlement. This removes one blockchain transaction from each normal trade, but it adds a trusted settlement service and signer.

What runs onchain

The LaunchLabStateCommitment contract:

  • holds deposited USDG;
  • queues deposits and forced-exit actions;
  • stores finalized account-state and action-data roots;
  • verifies the settlement signer's transition signature;
  • transfers USDG for a committed withdrawal;
  • reserves, challenges, and finalizes forced exits; and
  • enforces replay, sequence, inbox-order, and exact-transfer checks.

The contract does not store each trade or recalculate each payout.

What runs offchain

WickPlay services:

  • authenticate the root wallet and one-click play authority;
  • read external market prices and calculate quotes;
  • validate the signed account, market, direction, stake, payout guard, round, and nonce;
  • order deposits, trades, results, fees, and withdrawals in one settlement Durable Object;
  • calculate account balances, positions, payouts, fees, and risk limits;
  • return signed action receipts;
  • keep the action data used for the committed data root; and
  • periodically submit a signed state transition to the contract.

Points and referrals use a separate D1 projection built from ordered settlement events. They are not part of the financial state root.

Main trust assumptions

  • The settlement service and settlement signer can delay actions. The contract accepts their valid transition signature and does not run a validity proof for every offchain calculation.
  • The availability of account proofs and signed receipts depends on WickPlay's settlement data.
  • The pricing and result services control the external market data used for quotes and results.
  • Governance can upgrade the escrow contract and rotate the settlement signer.
  • A service failure can delay a normal withdrawal until recovery or the forced-exit path completes.

User protections

  • The root wallet authorizes a restricted one-click key. That key cannot authorize withdrawals.
  • A trade signature binds the account, market, direction, exact stake, payout guard, round, and sequential nonce.
  • A separate short-lived pricing authorization binds the current strike and probability.
  • A valid trade returns a settlement-signed receipt for the resulting account leaf.
  • Deposits enter an onchain forced inbox and cannot be silently omitted from all future commitments.
  • A forced exit can use the latest finalized Merkle proof or a newer signed receipt. A newer action receipt can challenge a stale exit during the release profile's challenge period.

These controls reduce replay and omission risk. They do not replace an independent validity proof or independent data-availability system.

See Custody and control, Withdrawals, and Contracts and status.