Core invariants
One token unit has one economic claim: free balance, Spot reserve, passive principal/fees, Perp margin/reserve, protocol fee, or builder claim—not two.
Withdrawals consume only free balance.
Resting Spot bids reserve quote plus maker fee; asks reserve base.
Passive liabilities remain distinct from active Spot reserves.
Perp modes are mutually exclusive and risk remains Engine/quote scoped.
Reduce-only capacity includes projected exposure from existing closing orders.
Normal Perp order actions settle their complete journal atomically through AccountCore and the registered Engine.
Upgrades preserve populated storage, immutable relationships, routing, and decoder compatibility.
Indexing preserves event identity, transaction ordering, schema boundaries, and reorg rollback.
Back to top