chordDocs

Resources

Security model

What the program enforces, what you trust, and what Chord doesn’t do.

Chord splits its work between an on-chain program and an off-chain collector. The program enforces everything that touches your tokens. The collector decides what happens when: which orders go in a batch, which quote wins, and when transactions are sent. This page draws that line exactly.

#Enforced by the program

These hold no matter what the collector or a solver does.

  • Your minimum. You never receive less than your signed minimum for what was sold: received ≥ ceil(sold × minBuy / sell).
  • One price. Every fill in a batch uses the price committed in its batch account, and nothing can change it.
  • Escrow first. The winning solver deposits every gross output before the first fill, and can’t withdraw it while the batch is active.
  • Atomic fills. Your input moves only in the instruction that pays your output. If either transfer fails, neither happens.
  • Your signature, your accounts. A fill needs your Ed25519 signature over that exact order, verified on chain, and moves tokens only between your own source and destination accounts.
  • No replay. A signature is bound to one program, config, chain and batch. Every nonce gets a permanent receipt.
  • Your exit. You can cancel a nonce, raise your nonce floor, or revoke the allowance at any time, without the collector.
  • Bounded fills. Cumulative fills can’t exceed your sell amount or the batch’s budget, and a retried fill can’t apply twice.

#What you trust the collector with

It canIt can’t
See every order before its window closesChange your price, amount or minimum
Choose which quote winsMove your tokens anywhere but your destination
Leave an order out of a batch, or not submit a fillFill you below your limit
Delay a batch until it expiresUse your signature in another batch

If the collector stops, batches can still be finished: finalize, timeout, expiry and refund claims are permissionless instructions anyone can send.

#What you trust about tokens

  • Classic SPL only. Token-2022 accounts and extensions are rejected.
  • Freeze authority. Tokens with a freeze authority, such as USDC, are allowed. An issuer that freezes your account can block your fill, and a frozen vault can delay a solver’s refund until it thaws.
  • Single delegate. An SPL token account has one delegate. Approving another program from the same account replaces Chord’s allowance.

#Solvers

Solvers commit unconditionally: once a quote commits, the solver must fill it or lose its bond, even if a trader cancels or revokes first. That protects traders’ freedom to leave, and puts the risk of disappearing orders on the solver, who prices it in.

#The program itself

  • The program is upgradeable. Its upgrade authority can change the code, which is the same trust assumption as any upgradeable Solana program.
  • The config is immutable once created by the upgrade authority: its auctioneer, treasury, chain domain and bond size can’t be changed.
  • The program has no instruction that lets anyone withdraw an active batch’s escrow, call another program on a solver’s behalf, or route your tokens through an external swap.

#What Chord doesn’t claim

  • Chord’s clearing price isn’t an oracle and doesn’t track any market. It is the best quote solvers offered for that batch.
  • The reference solver follows a documented, bounded policy. It doesn’t prove that no better price existed.
  • A batch takes time. If you need an instant fill, an AMM is the right tool.