Verify it yourself
You should not have to take opcode's word for an OPmode fill, a fee, or the contents of a vault. Everything that matters is on Solana and can be checked with a block explorer or a few lines of code.
Check an OPmode fill with an explorer
Open the transaction
In Portfolio, under Activity, follow the link in the order's Transaction column, or choose View transaction in the ticket. It opens the transaction on a block explorer.
Read the token balance changes
There should be exactly three transfers. From your wallet: the protocol's 20% of the fee to the fee vault, and the rest of your payment, including the providers' 80% of the fee, to the pool's vault. To your wallet: the output from the pool's vault. The first two add up to You pay on the review; the third equals You receive.
Check the instructions
The last instruction is the settlement program's
execute_quote. The one before it is the Ed25519 program, and its data contains the maker's public key followed by the signature and the 509-byte quote. Nothing may followexecute_quote.Open the receipt account
Among the accounts the transaction created is the receipt. It holds the quote hash, your wallet, the amount in, the amount out, the fee and the slot. Those should match the review in the terminal digit for digit.
Check the fee
The fee must equal five ten-thousandths of the amount you paid, rounded up to the next smallest unit. For 100 USDC that is 0.050000 USDC. For 0.45094870 raw tokens it is 0.00022548. The program rejects any other value, so a fill that exists has the right fee. Of that fee, 80% rounded down stays in the pool's vault and the rest goes to the fee vault.
Check the maker's signature
The 32-byte key inside the Ed25519 instruction must be the quote authority recorded in the market's account: E9jZWuYZzXwaGrQnX245jG1Ay54kqKRM9FJuuDtx3u6y on all ten markets. The program enforces this, and you can confirm it by reading the market account. The SHA-256 of the 509 quote bytes must equal the hash in the receipt and in the fill event.
Check the reference
An OPmode fill is checked against the market's on-chain reference, and that reference is written only from a Pyth report the chain has verified. Each market's OracleConfig account, listed below, records the hash of that report, its source time, the policy revision and the normalization epoch, and is one of the accounts in every fill. The reference transaction itself contains the Ed25519 check of Pyth's signature and a call to the Pyth verifier program. Its price is the underlying dollar price times the token's multiplier; USDC is assumed to equal one dollar, not checked on chain.
Check the vaults
Each market has two inventory vaults, one in the token and one in USDC, and a fee vault for its token. The protocol's USDC fees from all ten markets go to one shared USDC fee vault. They are ordinary token accounts whose balances anyone can read. The Pools view shows the inventory figures, read from chain. A pool's inventory is whatever its two vaults hold; there is no off-chain balance behind it.
Addresses
| What | Address |
|---|---|
| Settlement program | tDDsGm8ga9hETFRCut3mb7L9kkBiS4xrBEsXmEpgB7c |
| Owner wallet: administrator, treasury and upgrade authority | FyRz7wPjrFqj6RAwk1EcrJfhFaEpnChXAm21MrdGKyw6 |
| Ed25519 program (Solana built-in) | Ed25519SigVerify111111111111111111111111111 |
| Protocol USDC fee vault, shared by all ten markets | 5tXHFPLEYWAMtiaTKnQZ4qPDWzrStsxid8ohJL1zs3Nc |
| Pyth Pro verifier program | pytd2yyk641x7ak7mkaasSJVXh6YYZnC7wTmtgAyxPt |
| Token-2022 program, for stock tokens | TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb |
| SPL Token program, for USDC | TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA |
| USDC mint | EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v |
The ten OPmode markets and their liquidity pools:
Each market's oracle account and the Pyth feed it accepts:
| Market | OracleConfig | Pyth feed |
|---|---|---|
| NVDAx / USDC | 7FyqvSc9i8byqd8XvvdQYdmcP32HsR8NyWs22xc4XSZ6 | Equity.US.NVDA/USD |
| SPYx / USDC | 3rVd6VYrwreWRiG4dmWrQt36xuQ9UtUGLQCK61ra28fE | Equity.US.SPY/USD |
| QQQx / USDC | CPGMXnm8qCnUNCEz1qh4DgJMQLBmwwQqC3TRTeYsYj6r | Equity.US.QQQ/USD |
| GLDx / USDC | EaxSRbNVqg8FizEA8xtBTFEFsRvVnxt12PdgB8wmXFw7 | Equity.US.GLD/USD |
| TSLAx / USDC | 2U82NKtANesFs6U8PujXskvLJdSv4V5DnaQBe65j83Fp | Equity.US.TSLA/USD |
| AAPLx / USDC | BFz7fxNzAixp4f252osy6kiF7fsPmASRitHXgG6y5H5L | Equity.US.AAPL/USD |
| MSFTx / USDC | 2gVrbBaHUbMtyfuKiwpFQEBbEREtoNcvMaoavDESQnZF | Equity.US.MSFT/USD |
| METAx / USDC | 81pU3Xpb4BqCRrXxjcV28HJUEmyGMnNMrK48JYUfZc1u | Equity.US.META/USD |
| COINx / USDC | 7pQDSfzpGKruvYA9Z6MdVWxDKSvQYWrZ1a2wf9qJ3WwH | Equity.US.COIN/USD |
| CRCLx / USDC | 5bHHjgHPAB45bVWSZLU7NVuc7iKTBzngLjkbHtW1RhLm | Equity.US.CRCL/USD |
Stock token mints are on Markets. Per-market accounts are derived, not chosen, so you can compute them rather than trust a list:
| Account | Derived from the seeds |
|---|---|
| Protocol | "protocol", deployment domain |
| Market | "market", protocol, token mint, USDC mint, maker id |
| Risk state | "risk", market |
| Reference | "reference", market |
| OracleConfig | "oracle", market |
| LP pool | "liquidity", market |
| Receipt | "receipt", market, quote id |
Go deeperDecode a quote by hand
The 509 bytes, in order, little-endian for the integers:
0 13 "opcode:rfq:v1"
13 32 deployment_domain 237 32 user_source
45 32 program_id 269 32 user_destination
77 32 protocol 301 32 input_mint
109 32 market 333 32 output_mint
141 32 maker_id 365 32 input_token_program
173 32 quote_id 397 32 output_token_program
205 32 trader
429 8 amount_in 453 8 issued_slot 477 8 config_epoch
437 8 amount_out 461 8 max_valid_slot 485 8 normalization_epoch
445 8 fee 469 8 expires_at (i64) 493 8 risk_epoch
501 8 policy_epochIn the Ed25519 instruction's data the key is at byte 16, the signature at byte 48 and the quote at byte 112, for 621 bytes in all.