Intent Auction
Four of the protocol’s mechanisms, each one yours to drive by hand: seal a bid and open it, order a graph that arrived out of order, fill a block that has to keep room for direct transactions, and try to spend the same coin twice.
Python · ZK proofs
An intent is a request carrying a ceiling on what it will pay. Three solvers bid the fee they want for executing it: sealed now, opened later, and the seed that breaks ties is drawn only once sealing has closed. Open something other than what you sealed and you lose your bond.
Sealed-bid auctionofferthe fee a solver bids for the right to execute the intentutilitythat offer, capped at the intent's maximum fee. Highest winscommitmentbinds the offer, the solution and the identity together, before any seed existstie-breaka hash of the seed, the intent and the solver. Lowest wins, and nobody can aim it
Commit phase. Each solver seals an offer. The commitment binds the offer, the solution and the identity together, and the seed does not exist yet.
- #11solver-alphastake 5,000 · bond 1,000
utility 4
commitment
unsealedrevealpending - #24solver-betastake 5,000 · bond 1,000
utility 4
commitment
unsealedrevealpending - #37solver-gammastake 3,000 · bond 1,000
utility 3
commitment
unsealedrevealpending
Deterministic sequencerarrival orderthe sequence a node happened to receive them in, which differs everywherelinearizedthe order the rules produce from the graph, which is the same everywhere
Arrival order
- V1
ead7f2 - V2
d52963 - V3
85dcbc - V4
419fe3 - V5
455a15 - V6
97561d
Linearized
- V5
455a15 - V1
ead7f2 - V3
85dcbc - V2
d52963 - V4
419fe3 - V6
97561d
Deliver them in another order, and watch the linearized column.
Block assemblyrawa transaction its owner submitted directly, with no solver in betweenintenta request a solver won at auction and is executing on someone else’s behalfquotathe share of a block that must be raw before the block counts as valid
Waiting: 6 raw · 12 intents, for 10 slots. One of the intents is #7, the one the winning solver took at auction — marked in both blocks below.
Fee order alonewhat pays most, goes in
- intent #7
fee 18 - intent
fee 18 - intent
fee 12 - intent
fee 12 - intent
fee 12 - intent
fee 12 - intent
fee 6 - intent
fee 6 - intent
fee 6 - intent
fee 6
refused0 raw of 10 · 0%
With the escape hatch10% reserved first
- raw
fee 4 - intent #7
fee 18 - intent
fee 18 - intent
fee 12 - intent
fee 12 - intent
fee 12 - intent
fee 12 - intent
fee 6 - intent
fee 6 - intent
fee 6
valid1 raw of 10 · 10%
At ×6 fee order leaves 0 raw transactions in the block, under the 10% the protocol requires, so that block is refused however much it earns. Reserving first keeps 1 of 10, whatever the intents are willing to pay.
Unspent outputscommitmentthe leaf stored in the tree: the value, the owner and a salt, hashed togethernullifierpublished when a coin is spent. The same every time for that coin, and it names neither the coin nor the secret
- #a3f140 unitsunspent
commitment
bd47016dnullifiera479562b - #7c2025 unitsunspent
commitment
fb1a500anullifier6246fd09 - #e91840 unitsunspent
commitment
c4c6ee9enullifier0254ffbe
Published nullifiers
Nothing spent yet.
Coins #a3f1 and #e918 hold the same value and the same owner, and their salts differ. So their commitments differ, their nullifiers differ, and spending one says nothing about the other. Both hold exactly the 40 UNIT that intent #7 moves, so nothing published here says which of them the winning solver spent to settle it.
Want to go further?