Trust model
WickPlay uses an onchain USDG escrow with ordered offchain settlement. This removes one blockchain transaction from each normal trade, but it adds a trusted settlement service and signer.
What runs onchain
The LaunchLabStateCommitment contract:
- holds deposited USDG;
- queues deposits and forced-exit actions;
- stores finalized account-state and action-data roots;
- verifies the settlement signer's transition signature;
- transfers USDG for a committed withdrawal;
- reserves, challenges, and finalizes forced exits; and
- enforces replay, sequence, inbox-order, and exact-transfer checks.
The contract does not store each trade or recalculate each payout.
What runs offchain
WickPlay services:
- authenticate the root wallet and one-click play authority;
- read external market prices and calculate quotes;
- validate the signed account, market, direction, stake, payout guard, round, and nonce;
- order deposits, trades, results, fees, and withdrawals in one settlement Durable Object;
- calculate account balances, positions, payouts, fees, and risk limits;
- return signed action receipts;
- keep the action data used for the committed data root; and
- periodically submit a signed state transition to the contract.
Points and referrals use a separate D1 projection built from ordered settlement events. They are not part of the financial state root.
Main trust assumptions
- The settlement service and settlement signer can delay actions. The contract accepts their valid transition signature and does not run a validity proof for every offchain calculation.
- The availability of account proofs and signed receipts depends on WickPlay's settlement data.
- The pricing and result services control the external market data used for quotes and results.
- Governance can upgrade the escrow contract and rotate the settlement signer.
- A service failure can delay a normal withdrawal until recovery or the forced-exit path completes.
User protections
- The root wallet authorizes a restricted one-click key. That key cannot authorize withdrawals.
- A trade signature binds the account, market, direction, exact stake, payout guard, round, and sequential nonce.
- A separate short-lived pricing authorization binds the current strike and probability.
- A valid trade returns a settlement-signed receipt for the resulting account leaf.
- Deposits enter an onchain forced inbox and cannot be silently omitted from all future commitments.
- A forced exit can use the latest finalized Merkle proof or a newer signed receipt. A newer action receipt can challenge a stale exit during the release profile's challenge period.
These controls reduce replay and omission risk. They do not replace an independent validity proof or independent data-availability system.
See Custody and control, Withdrawals, and Contracts and status.