Resources
Security model
What the program enforces, what you trust, and what Chord doesn’t do.
Chord splits its work between an on-chain program and an off-chain collector. The program enforces everything that touches your tokens. The collector decides what happens when: which orders go in a batch, which quote wins, and when transactions are sent. This page draws that line exactly.
#Enforced by the program
These hold no matter what the collector or a solver does.
- Your minimum. You never receive less than your signed minimum for what was sold:
received ≥ ceil(sold × minBuy / sell). - One price. Every fill in a batch uses the price committed in its batch account, and nothing can change it.
- Escrow first. The winning solver deposits every gross output before the first fill, and can’t withdraw it while the batch is active.
- Atomic fills. Your input moves only in the instruction that pays your output. If either transfer fails, neither happens.
- Your signature, your accounts. A fill needs your Ed25519 signature over that exact order, verified on chain, and moves tokens only between your own source and destination accounts.
- No replay. A signature is bound to one program, config, chain and batch. Every nonce gets a permanent receipt.
- Your exit. You can cancel a nonce, raise your nonce floor, or revoke the allowance at any time, without the collector.
- Bounded fills. Cumulative fills can’t exceed your sell amount or the batch’s budget, and a retried fill can’t apply twice.
#What you trust the collector with
| It can | It can’t |
|---|---|
| See every order before its window closes | Change your price, amount or minimum |
| Choose which quote wins | Move your tokens anywhere but your destination |
| Leave an order out of a batch, or not submit a fill | Fill you below your limit |
| Delay a batch until it expires | Use your signature in another batch |
If the collector stops, batches can still be finished: finalize, timeout, expiry and refund claims are permissionless instructions anyone can send.
#What you trust about tokens
- Classic SPL only. Token-2022 accounts and extensions are rejected.
- Freeze authority. Tokens with a freeze authority, such as USDC, are allowed. An issuer that freezes your account can block your fill, and a frozen vault can delay a solver’s refund until it thaws.
- Single delegate. An SPL token account has one delegate. Approving another program from the same account replaces Chord’s allowance.
#Solvers
Solvers commit unconditionally: once a quote commits, the solver must fill it or lose its bond, even if a trader cancels or revokes first. That protects traders’ freedom to leave, and puts the risk of disappearing orders on the solver, who prices it in.
#The program itself
- The program is upgradeable. Its upgrade authority can change the code, which is the same trust assumption as any upgradeable Solana program.
- The config is immutable once created by the upgrade authority: its auctioneer, treasury, chain domain and bond size can’t be changed.
- The program has no instruction that lets anyone withdraw an active batch’s escrow, call another program on a solver’s behalf, or route your tokens through an external swap.
#What Chord doesn’t claim
- Chord’s clearing price isn’t an oracle and doesn’t track any market. It is the best quote solvers offered for that batch.
- The reference solver follows a documented, bounded policy. It doesn’t prove that no better price existed.
- A batch takes time. If you need an instant fill, an AMM is the right tool.