Skip to content

Core invariants

  • One token unit has one economic claim: free balance, Spot reserve, passive principal/fees, Perp margin/reserve, protocol fee, or builder claim—not two.
  • Withdrawals consume only free balance.
  • Resting Spot bids reserve quote plus maker fee; asks reserve base.
  • Passive liabilities remain distinct from active Spot reserves.
  • Perp modes are mutually exclusive and risk remains Engine/quote scoped.
  • Reduce-only capacity includes projected exposure from existing closing orders.
  • Normal Perp order actions settle their complete journal atomically through AccountCore and the registered Engine.
  • Upgrades preserve populated storage, immutable relationships, routing, and decoder compatibility.
  • Indexing preserves event identity, transaction ordering, schema boundaries, and reorg rollback.