Litepaper

opcode is a proprietary AMM for tokenized equities and ETFs on Solana: liquidity that is priced by an engine, not left on a curve.

1 / A /

Two clocks

Prop AMMs now carry a large share of Solana spot trading. They replace passive curves with quotes a market maker updates from live data. That works for crypto pairs that trade everywhere, all the time.

Tokenized stocks are a harder case. The token trades around the clock, but the share behind it trades six and a half hours a day, five days a week, on a venue the chain cannot see. opcode is a prop AMM built around that mismatch.

1 / B /

Why not a curve

It reprices by being robbed. A constant-product pool learns a new price only when an arbitrageur trades against the old one. Every correction is a loss to the pool, and between corrections takers get a stale price.

It spreads capital where nobody trades. Equity prices move a percent or two a day. Liquidity parked far from the price earns nothing and protects no one.

It cannot see the closing bell. At 16:00 in New York the share stops trading. A curve quotes Saturday night exactly as it quotes Tuesday noon, then pays for it at Monday's open.

1 / C /

Against a curve

A constant-product pool does not know the price moved until someone trades against it. A prop AMM reprices from a price feed.

Below, both designs are put on the same price path, with the assumptions yours to move.

The simulation is a model, not a measurement of any named venue, and it is deterministic: everyone sees the same path. The curve is x·y=k with the fee you set, arbitraged to the edge of its fee band one slot late. Concentrated liquidity is deeper near the price but reprices the same way. The curve's default 2M USDC is an illustrative depth. It is not a statement of current pool liquidity. The ten existing OPmode markets are currently paused; their configured order limits are 100 USDC on NVDAx and 20 on the others.

The opcode side uses the live pool parameters and fee: a 5 bps base half-spread, 4 bps per 1,000 USDC of size, no session premium, and the 5 bps fee taken from the input. Order sizes above 100 USDC are larger than any live pool accepts and show how costs scale. At the default depth and volatility, a curve fee below about 9 bps makes the curve cheaper at live sizes, though its price still lags the reference. On-chain transaction costs are not modelled. The model also leaves out the live confidence cost and requotes every slot; a live reference refreshes about every two seconds while its market has quote requests.

Same price path, two venues

A simulated reference moves every 400 ms for ten minutes. The constant-product pool reprices only when an arbitrageur, one slot behind, finds the gap wider than the pool fee. In the model the engine requotes every slot from a reference one slot old. Reading a curve's quote is instant too; what differs is how fresh that quote is.

Referenceopcode midConstant-product midLast two minutes shown
Over the ten-minute pathConstant-product AMMopcode engine
Cost to buy $100Average over the path, against the reference at that instant, fees included.29.1 bps10.4 bps
Mid-price tracking errorAverage distance between the venue's mid and the reference.8.01 bps0.71 bps
Time more than 5 bps offShare of the ten minutes the quoted mid was stale by over 5 bps.59.5%0.0%
Repricings in ten minutesA curve moves only when someone trades against it. In the model the engine requotes each 400 ms slot.01,500
2 / A /

The parts

The system has eight parts, and each has one glyph. The same glyphs mark the same parts everywhere: on this site, in the whitepaper, and in the terminal, where they show how far a quote has come.

They do not run in sequence. Ticks, the clock and orders each keep their own time, and every fill feeds back into the price of the next quote.

  • Taker

    Asks for a price on an exact input amount.

  • Reference

    The price path the pools are quoted around, tick by tick.

  • Session

    New York's clock. The lit arc is when the share trades.

  • Pool

    One market's inventory, steering toward its target.

  • Engine

    Adds base, size, confidence and session, then skews by inventory.

  • Signer

    Closes Ed25519 brackets around the exact amounts.

  • Ledger

    The chain. Input, output and fee settle in one transaction.

  • Hedge

    The offsetting trade. Dashed: none is sent; the pool keeps its inventory.

2 / B /

The quote

Each OPmode market is a pool with its own inventory. The engine prices a quote from the market's reference, the underlying share's Pyth price, and the pool's inventory. A half-spread is the sum of four terms, and skew moves its center:

half = base + size + confidence + session
ask  = ref × (1 − skew + half)
bid  = ref × (1 − skew − half)

base is 5 bps (0.05%) on each of the ten live pools. size grows with the order, 4 bps (400 ppm) per 1,000 USDC. confidence is twice Pyth's confidence interval as a share of the price, so the spread widens when the feed is less certain. session is a premium for sessions outside regular hours; the engine supports it, and the live pools set it to zero. skew moves both prices together, by up to 15 bps (0.15%), toward a pool that holds half its value in each asset: down when the pool holds excess stock, up when it holds too little. The builder uses these live values with an illustrative confidence cost. Sizes above 100 USDC are larger than any live pool accepts and show how the size term grows.

The arithmetic is integer-only Rust. Asks round up and bids round down, and at the live pool sizes and order limits a buy followed by a sale always returns less than it cost.

Bid183.229−10.4 bps from reference
Ask183.501+4.4 bps from reference

center = −3.0 bps; half-spread = 5.0 base + 0.4 size + 2.0 confidence + 0.0 session = 7.4 bps

3 / A /

An OPmode quote

The engine prices an exact input from its reference and pool inventory. The quote fixes input, output and fee until the displayed expiry, up to 10 seconds. The trader reviews those amounts and signs the transaction with their wallet.

At the fill, the program checks that the reference's Pyth source is no more than 20 seconds old and that the net price sits within 100 bps of it. OPmode quotes only while a US market session is open, pre-market, regular, post-market or overnight, as confirmed by both Pyth's market-hours calendar and the signed report. At weekends, on exchange holidays and in sessions it cannot confirm, it gives no quote.

A quote can settle once. Input, output and fee transfer atomically, and a receipt records the exact amounts. The fee is 5 bps of the input, included in it: 80% stays in the pool for liquidity providers and 20% goes to the protocol, whose fee revenue funds $OP buybacks as it accrues. Current market limits and transfer conditions still apply.

4 / A /

Available routes

One terminal offers two routes on the ticket. Quick routes through available external liquidity for xStocks and Backpack Securities tokens and shows expected output, minimum received, a 0.50% slippage tolerance and fees before the wallet signs. OPmode is a firm quote from opcode's own pool with exact input, output and fee, valid for up to 10 seconds. The pricing engine, signed quote format, inventory controls and atomic settlement run on mainnet. OPmode's reference is the underlying stock or ETF price from Pyth Pro. Each update is a Pyth-signed report that the program verifies on chain, multiplies by the token's multiplier and records with its source time; no operator key can set it. A market with quote requests in the last minute refreshes about every two seconds, and a quote needs a source price no more than five seconds old. The price assumes 1 USDC equals 1 USD, and new quotes stop if USDC leaves $0.99–$1.01. Quick and the charts use a separate public token price with its own freshness and consistency checks; a market whose checks fail shows no price until they pass. Charts use recorded observations. Orders use raw token units of verified mints, and each order records the share multiplier it was priced under. A Pyth market-hours calendar supplies holidays, early closes and session transitions; OPmode quotes only when that calendar and the signed report both confirm an open US session. Missing coverage is shown explicitly. Trading uses real wallet balances. opcode runs no hedge: after a swap the pool keeps the position, and no issuer redemption takes place.

OPmode has ten existing mainnet markets: NVDAx, SPYx, QQQx, GLDx, TSLAx, AAPLx, MSFTx, METAx, COINx and CRCLx. They are currently paused; the terminal reports their current availability. NVDAx is configured for up to 100 USDC per order and 500 USDC per fixed 60-second window; the other nine take 20 and 100. Additional xStocks or Backpack Securities pools require explicit setup, funding and verified reference support. Quick remains subject to route availability. The whitepaper covers the account model, invariants and admission tests.

4 / B /

Risks

A Solana swap cannot be atomic with a broker hedge or an issuer redemption, and opcode runs no hedge. The pool carries inventory, basis and timing risk, shared by its liquidity providers. Nothing rebalances it automatically; skew moves inventory back toward target, and orders that would push the pool's stock value outside 25–75% are refused.

A verified price for the share does not make the token trade at that price elsewhere. The USDC price is assumed, not measured: the depeg guard only stops new quotes, and USDC risk stays with the user.

Owning a token is not owning the share. Issuer terms, transfer restrictions and corporate actions differ by asset.

The settlement program is upgradeable, and its upgrade authority is the owner wallet. There is no multisig or timelock. The program has had an internal review, not an independent third-party audit. The owner, or a separate emergency key, can pause a market.