Go deeperVerify it yourself
Go deeper

Verify it yourself

You should not have to take opcode's word for an OPmode fill, a fee, or the contents of a vault. Everything that matters is on Solana and can be checked with a block explorer or a few lines of code.

Check an OPmode fill with an explorer

  1. Open the transaction

    In Portfolio, under Activity, follow the link in the order's Transaction column, or choose View transaction in the ticket. It opens the transaction on a block explorer.

  2. Read the token balance changes

    There should be exactly three transfers. From your wallet: the protocol's 20% of the fee to the fee vault, and the rest of your payment, including the providers' 80% of the fee, to the pool's vault. To your wallet: the output from the pool's vault. The first two add up to You pay on the review; the third equals You receive.

  3. Check the instructions

    The last instruction is the settlement program's execute_quote. The one before it is the Ed25519 program, and its data contains the maker's public key followed by the signature and the 509-byte quote. Nothing may follow execute_quote.

  4. Open the receipt account

    Among the accounts the transaction created is the receipt. It holds the quote hash, your wallet, the amount in, the amount out, the fee and the slot. Those should match the review in the terminal digit for digit.

Check the fee

The fee must equal five ten-thousandths of the amount you paid, rounded up to the next smallest unit. For 100 USDC that is 0.050000 USDC. For 0.45094870 raw tokens it is 0.00022548. The program rejects any other value, so a fill that exists has the right fee. Of that fee, 80% rounded down stays in the pool's vault and the rest goes to the fee vault.

Check the maker's signature

The 32-byte key inside the Ed25519 instruction must be the quote authority recorded in the market's account: E9jZWuYZzXwaGrQnX245jG1Ay54kqKRM9FJuuDtx3u6y on all ten markets. The program enforces this, and you can confirm it by reading the market account. The SHA-256 of the 509 quote bytes must equal the hash in the receipt and in the fill event.

Check the reference

An OPmode fill is checked against the market's on-chain reference, and that reference is written only from a Pyth report the chain has verified. Each market's OracleConfig account, listed below, records the hash of that report, its source time, the policy revision and the normalization epoch, and is one of the accounts in every fill. The reference transaction itself contains the Ed25519 check of Pyth's signature and a call to the Pyth verifier program. Its price is the underlying dollar price times the token's multiplier; USDC is assumed to equal one dollar, not checked on chain.

Check the vaults

Each market has two inventory vaults, one in the token and one in USDC, and a fee vault for its token. The protocol's USDC fees from all ten markets go to one shared USDC fee vault. They are ordinary token accounts whose balances anyone can read. The Pools view shows the inventory figures, read from chain. A pool's inventory is whatever its two vaults hold; there is no off-chain balance behind it.

Addresses

WhatAddress
Settlement programtDDsGm8ga9hETFRCut3mb7L9kkBiS4xrBEsXmEpgB7c
Owner wallet: administrator, treasury and upgrade authorityFyRz7wPjrFqj6RAwk1EcrJfhFaEpnChXAm21MrdGKyw6
Ed25519 program (Solana built-in)Ed25519SigVerify111111111111111111111111111
Protocol USDC fee vault, shared by all ten markets5tXHFPLEYWAMtiaTKnQZ4qPDWzrStsxid8ohJL1zs3Nc
Pyth Pro verifier programpytd2yyk641x7ak7mkaasSJVXh6YYZnC7wTmtgAyxPt
Token-2022 program, for stock tokensTokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb
SPL Token program, for USDCTokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA
USDC mintEPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v

The ten OPmode markets and their liquidity pools:

Each market's oracle account and the Pyth feed it accepts:

MarketOracleConfigPyth feed
NVDAx / USDC7FyqvSc9i8byqd8XvvdQYdmcP32HsR8NyWs22xc4XSZ6Equity.US.NVDA/USD
SPYx / USDC3rVd6VYrwreWRiG4dmWrQt36xuQ9UtUGLQCK61ra28fEEquity.US.SPY/USD
QQQx / USDCCPGMXnm8qCnUNCEz1qh4DgJMQLBmwwQqC3TRTeYsYj6rEquity.US.QQQ/USD
GLDx / USDCEaxSRbNVqg8FizEA8xtBTFEFsRvVnxt12PdgB8wmXFw7Equity.US.GLD/USD
TSLAx / USDC2U82NKtANesFs6U8PujXskvLJdSv4V5DnaQBe65j83FpEquity.US.TSLA/USD
AAPLx / USDCBFz7fxNzAixp4f252osy6kiF7fsPmASRitHXgG6y5H5LEquity.US.AAPL/USD
MSFTx / USDC2gVrbBaHUbMtyfuKiwpFQEBbEREtoNcvMaoavDESQnZFEquity.US.MSFT/USD
METAx / USDC81pU3Xpb4BqCRrXxjcV28HJUEmyGMnNMrK48JYUfZc1uEquity.US.META/USD
COINx / USDC7pQDSfzpGKruvYA9Z6MdVWxDKSvQYWrZ1a2wf9qJ3WwHEquity.US.COIN/USD
CRCLx / USDC5bHHjgHPAB45bVWSZLU7NVuc7iKTBzngLjkbHtW1RhLmEquity.US.CRCL/USD

Stock token mints are on Markets. Per-market accounts are derived, not chosen, so you can compute them rather than trust a list:

AccountDerived from the seeds
Protocol"protocol", deployment domain
Market"market", protocol, token mint, USDC mint, maker id
Risk state"risk", market
Reference"reference", market
OracleConfig"oracle", market
LP pool"liquidity", market
Receipt"receipt", market, quote id
Go deeperDecode a quote by hand

The 509 bytes, in order, little-endian for the integers:

  0  13  "opcode:rfq:v1"
 13  32  deployment_domain        237  32  user_source
 45  32  program_id               269  32  user_destination
 77  32  protocol                 301  32  input_mint
109  32  market                   333  32  output_mint
141  32  maker_id                 365  32  input_token_program
173  32  quote_id                 397  32  output_token_program
205  32  trader
429   8  amount_in      453   8  issued_slot       477  8  config_epoch
437   8  amount_out     461   8  max_valid_slot    485  8  normalization_epoch
445   8  fee            469   8  expires_at (i64)  493  8  risk_epoch
                                                   501  8  policy_epoch

In the Ed25519 instruction's data the key is at byte 16, the signature at byte 48 and the quote at byte 112, for 621 bytes in all.