MOVE Contracts
Architecture
Orders are matched off chain. Collateral, positions and settlement live on chain, and the chain only accepts fills that the trader signed.
Traders
Web app
Order entry, positions, charts
API
REST and WebSocket
Off chain · venue services
Sequencer
Order book, matching, risk checks, liquidation monitor
Epoch keeper
Settles each epoch with an oracle update
Price service
Candles and live prices for the app
Market makers
Quote both sides of the book
On chain
Settlement
Verifies signatures, applies fills in batches
Markets
Positions, epochs, liquidations
Hub
Collateral vault
Insurance fund
Covers losses beyond margin
Oracle
Pyth prices
Orders and matching
A trader signs an order intent that fixes the maximum size, the price limit, the leverage, the collateral, a deadline and a nonce. The sequencer matches orders on its book and submits the fills to the chain in batches. The settlement contract checks every fill against the signed intent and rejects any that exceeds it, so the sequencer cannot trade on a trader's behalf beyond what was signed. Positions in the sequencer update only after the chain confirms the batch.
Custody
Collateral is held by the Hub contract, not by the sequencer. Withdrawals are co-signed by the sequencer. If the sequencer stops responding for longer than a grace period (one day on testnet), traders can withdraw their available balance directly from the contract.
Oracle
Epoch settlement uses Pyth. The price is updated and read in the settlement transaction itself, which is only accepted after the epoch has ended and with a price no older than 60 seconds. A circuit breaker rejects a price that jumps more than 10% from the last accepted one until the guardian resets it.
Liquidations use the order-book mid price, as described in Trading and risk.
Controls
- A guardian role can pause the vault and the oracle, and can only tighten risk limits.
- Administrative changes go through a two-day timelock.
- Open interest and position size are capped per market.
