Penumbra

Trade institutional size without leaking intent

A dark pool for Stellar: match privately off-chain, lock collateral in Soroban escrow, settle only netted fills on the public ledger.

The problem

Transparent ledgers punish deep capital

On Stellar, order size, price, and direction are public the moment they hit the book. Institutional market makers will not deploy real size when every participant can see the wall coming.

01

Front-running

Bots see a sell wall and jump ahead, pushing price against you before you fill.

02

Strategy copy

Competitors read your size and levels, then trade against the same thesis.

03

Liquidity withdrawal

Counterparties pull bids and wait for the dump — your own visibility creates the slip.

Concrete example

Selling 10,000,000 XLM at $0.10

Same trade. Same market maker. Two different public footprints.

Without Penumbra

Public Stellar DEX

  1. Submit. A 10M XLM sell at $0.10 lands on the open book.
  2. Instant visibility. Every HFT bot and desk sees a massive sell wall.
  3. Exploitation. Bots sell ahead at $0.0999; buyers pull bids and wait for the dump.
  4. Outcome. Severe slippage — fill nearer $0.095 instead of $0.10. Tens of thousands lost to pre-trade leakage.

With Penumbra

Hybrid dark pool

  1. Commit. Same order — side, size, and limit stay off the public book. Collateral locks in Soroban escrow behind a SHA-256 commitment.
  2. Match privately. Encrypted buyers totaling 8M XLM at $0.10 cross off-chain. The engine works the book without broadcasting intent. (TFHE ciphertext matching — future implementation)
  3. Reveal the net only. A threshold committee decrypts the batch result: 8M XLM matched at $0.10. The remaining 2M stays dark. (Threshold decrypt — future)
  4. Outcome. settle_batch settles atomically on Soroban. Eighty percent fills at the target price — without a public sell wall moving the market.

Without privacy, the market prices your size before you trade. With Penumbra, the ledger sees the settlement — not the strategy.

How it works

Three fixes for institutional privacy

Leakage, instruction limits, and public footprint — solved by a hybrid dark pool on Stellar.

01

Pre-trade privacy

Hide order intent

Commitments lock collateral on-chain while size, side, and limit stay off the public book. (Full TFHE ciphertext matching — future implementation)

02

Hybrid architecture

Match off-chain, settle on-chain

Heavy cryptography cannot fit Soroban’s instruction budget. Matching runs off-chain; the SEP-41 escrow only locks funds and settles authorized batches atomically.

03

Minimal public footprint

Publish netted outcomes only

Batches settle as netted fills. The ledger sees the atomic result — not every resting order or strategy. (Threshold decrypt of matched fields only — future)

Status

Built now — coming next

The escrow rail and matcher board are live on Stellar testnet. Encrypted matching and threshold decrypt ship in later phases — not as a mock of today's console.

Live today

  • Soroban escrow with SHA-256 order commitments and SEP-41 collateral lock
  • Off-chain matcher board with crossing detection and settle_batch
  • Testnet trading console: deposit, register, cancel, settle

Coming next

  • TFHE matching so the engine never sees plaintext price or size
  • Threshold committee that decrypts only netted matched trades
  • Attested settlement path for institutional audit trails

Roadmap

Phased delivery

0

Feasibility

Complete

Mapped Soroban instruction limits, FHE cost, and the hybrid escrow + off-chain matcher design.

1

Escrow rail

Live

SEP-41 collateral lock, SHA-256 order commitments, and matcher-authorized settle_batch on testnet.

2

Matcher board

Live

Shared off-chain order book with crossing detection and batch settlement today.

3

TFHE matching

Research

Homomorphic price comparisons so the matcher never sees plaintext size or limit.

4

Threshold decrypt

Planned

t-of-n committee reveals only netted fills — unmatched size and intent stay dark.