Parties
| Term | Meaning |
|---|---|
| App, integrator | Whoever signs open_wager: a program over CPI, a server or a wallet. Identified by the signing address alone. Its on-chain record is created by its first wager. |
| Operator | An app that holds its users’ funds and stakes from them. It names itself beneficiary and credits its users. |
| User | The person the payout is for. Sees the app, not Fade. |
| Liquidity provider (LP) | Anyone who deposits USDC into the pool and takes the other side of every wager it accepts. |
| Cranker, keeper | Anyone who sends a permissionless transaction that moves the protocol forward (request_randomness, settle_wager, expire_wager, strike_epoch, claim_*) and is paid a prepaid, flat fee for it. A keeper is a cranker that runs continuously. |
| Beneficiary | The USDC account a payout is sent to. Named at open, never changeable. |
| Council, guardian | Governance. The council can upgrade the program and change parameters; the guardian can only tighten (set pause flags). See Security model. |
Wagers and paytables
| Term | Meaning |
|---|---|
| Wager | One payout: a stake, a paytable and the account that holds both, plus the outcome once drawn. |
| Paytable | The list of outcomes as (p, m) pairs, up to 32. An argument of open_wager, copied into the wager before the draw. |
| Bucket | One row of a paytable. p is a u64 probability in billionths; all p sum to exactly 1 000 000 000. m is a u64 multiplier in basis points; 10 000 is 1×. |
| Edge, declared edge | What the house keeps in expectation, in bps: 10 000 − ceil(Σ p·m / 1e9). |
| Pool edge | The part of the edge the pool earns: declared edge − app fee − protocol fee. The per-wager cap is computed on it. |
| Edge floor | The admission rule declared edge ≥ 100 (LP floor) + 20 (protocol fee) + app fee. Refused with EdgeFloor otherwise. |
| M_CEILING | The largest multiplier any bucket may carry: 10 000×. |
Money and risk
| Term | Meaning |
|---|---|
| Stake | What is put in, in USDC base units (6 decimals). |
| Pool credit | What reaches the pool at open: stake − protocol fee − app fee. |
| Payout max | stake × max(m) / 10 000: the largest payout the paytable can produce. |
| Liability | The pool’s worst-case additional outflow: payout_max − pool_credit. Reserved at open, released at settlement or expiry. |
| Assets | total_assets: the pool’s own ledger of what it owns. Never read from a token balance. |
| Free balance | assets − reserved liability − open pool credits. |
| Per-wager cap | min(0.5 × pool_edge × free balance, 150 bps × assets), applied to the liability. Above it, the wager is refused at open. |
| App ceiling | The most one app may have at risk at once: 20 % of assets, the new wager included. |
| Utilisation | (reserved liability + open pool credits) ÷ assets. New wagers are refused above 70 %. |
| κ (kappa) | Hard ceiling on reserved liability: 80 % of assets. |
| Breaker | An automatic stop on new wagers: utilisation above 70 %, or a fall of 15 % or more in the share price over 24 hours. Neither can block a settlement, a strike, a claim or a withdrawal request. |
| Turnover | Volume wagered over a period divided by the pool’s time-weighted assets over that period. |
The pool
| Term | Meaning |
|---|---|
| Share | A standard, transferable SPL token (9 decimals) representing a claim on the pool. Minted and burned only at a strike. |
| NAV, share price | Assets over shares, with a fixed virtual offset that defeats first-depositor manipulation. |
| Epoch | A batch of deposit and withdrawal requests that clears at one price. The first request opens one; it closes at the next multiple of the epoch length (10 minutes by default, 120 seconds on devnet). Unrelated to a Solana epoch. |
| Strike | The permissionless transaction that prices an epoch and processes its requests, once the epoch has closed and every wager opened before the close has resolved. |
| Claim | The permissionless transaction that delivers a struck request: shares to a depositor, USDC to a withdrawer, the request’s rent to its owner. |
| Strike fund | SOL held by the pool’s Queue account that pays the striker. Refilled by requests while below its target. |
Randomness and settlement
| Term | Meaning |
|---|---|
| VRF | Verifiable random function: an oracle output that comes with a proof it was produced, not chosen. |
| ORAO | The VRF provider Fade uses. |
| Request after entropy | Fade’s rule that the randomness is requested only after the open, with a seed built on a block hash that did not exist at open. |
| s*, h* | The first slot present in SlotHashes after the open slot, and its hash. |
| T_SETTLE | 150 slots, about a minute: how long Fade waits for randomness. After it, an unfulfilled wager can be expired. It is never a deadline to settle a fulfilled wager. |
| Forfeiture | What expiry does: the pool keeps the pool credit. |
| Crank fee | 250 000 lamports prepaid at open: 50 000 to whoever requests the randomness, 200 000 to whoever settles or expires. |
| PayoutPending | The state of a wager whose beneficiary could not receive at settlement. The payout waits in an escrow until claim_payout delivers it. |
| Direct path | A wager with its own draw. What the program runs today. |
| Shared beacon | A design for small stakes in which one draw serves a round of wagers. See Shared beacon. |
Solana terms
| Term | Meaning |
|---|---|
| CPI | Cross-program invocation: one program calling another. |
| PDA | Program-derived address: an address derived from a program id and seeds that only that program can sign for. |
| Slot | Solana’s unit of time, a few hundred milliseconds. Fade specifies chain-timing bounds in slots, so they do not drift as block times fall. |
| SlotHashes | A sysvar holding the hashes of recent slots. |
| bps | Basis points. 100 bps = 1 %. |
| Legacy SPL token | The original token program. Fade accepts legacy SPL USDC only; Token-2022 is rejected. |