DocsSecurity model

Trust

Security model

The protections that keep a market’s outcome tied to the coin’s real price.

  • Only approved keepers take readings. Nobody can buy a coin, trigger a reading at the inflated price and sell, all in one transaction.
  • Reading times are secret. Each keeper derives its schedule from its own key, so the moments a market is read cannot be computed in advance.
  • Readings are spread and the median decides. One distorted reading cannot move the result; an attacker would have to distort most of them.
  • Readings cannot be bunched. They must be at least 60 seconds apart, and the owner cannot lower that. Each market keeps the time between readings it opened with.
  • Only approved resolvers. A creator cannot bring rules that pick their own winner.
  • Supply is fixed at creation. The contract reads it when the market opens. Burning tokens mid market cannot move FDV, and a burn just before a market opens cannot stop it opening.
  • Windows must sit inside the market’s timeline. A window that opens before trading closes, or ends after the resolve time, is rejected when the market is opened.
  • Windows must hold their readings. A window with less than twice the room its readings need is rejected, so no market can be opened that is certain to void.
  • A pause cannot decide anything. Readings, settling, selling and every refund keep working while the protocol is paused.
  • Questions are rebuilt from terms. Misleading question text is never shown.