Skip to content

Developers

Architecture

The pieces, the trust boundaries and how they fit together.

AppNext.js 16 · Privy wallets · reads chain state directly
Keeperprice feed, yield cranks, relays, expiries
Solana · devnet · base layer
  • tesoro_core Accounts, Positions, Gemas, Debt, Matches, Fees, Backing
  • block_puzzle holdem trading_duel settle by CPI
  • sim_lst simulated staking token Simulated.
  • tesoro_bridge LayerZero V2 OApp
MagicBlock Private Ephemeral RollupIntel TDX TEE · hidden state: Boards, Seed, Deck, hole cards, Books
Ethereum Hoodi · HyperEVMPositionVaultOApp + SimLST on each chain
There are no game servers in the settlement path. The keeper is a fee payer for liveness only: every job is permissionless.

One ledger on Solana, Games as on-chain programs that run their hidden state inside MagicBlock Private Ephemeral Rollups, Positions on their home chains, and LayerZero V2 carrying four messages between them. There are no game servers in the settlement path.

Components

PieceRoleWhere
tesoro_coreThe money rules. A pure, property-tested accounting core wrapped by thin Anchor instructions: Accounts, Positions, Sources, Holdings, Matches and Pots, Fees, Backing, the Game registry and the devnet price feed.programs/tesoro_core
block_puzzle, holdem, trading_duelGame programs. Each keeps its Match state in a rollup, computes the result itself, and settles by CPI into tesoro_core signed by its own authority PDA.programs/*
sim_lstSimulated liquid staking token (simSOL). Simulatedprograms/sim_lst
tesoro_bridgeSolana side of the LayerZero V2 OApp. Records inbound facts, applies them to tesoro_core as the registered source authority, and sends Unlock and PayYield out.bridge/
PositionVaultOAppEVM vault that locks the staking token and speaks LayerZero. Releases Principal only on Unlock and pays at most the accrued yield.contracts/src
KeeperOff-chain liveness: price feed, yield cranks, bridge relays, expiries, stalled-Match settlement. A fee payer only; every job is permissionless.keeper/
AppNext.js 16, desktop first. Reads chain state directly and signs with Privy embedded or linked wallets. A few server routes fund test fees and relay Ethereum steps.app/

Design rules the code enforces

  • Principal is never played and never pays Debt. No ledger function reads Principal after an Advance is sized. The only paths that lower Debt are the Position's own yield and the owner returning their own Gemas. Property-tested.
  • A Gema is a claim on its Source. The dollar price is used once, at issuance. Debt is kept in Gemas and converted to the Source asset on demand. See ADR 0001.
  • Games are programs, not services. A Studio integrates by shipping a program and registering it, not by running a server (ADR 0003).
  • One transport. LayerZero V2 carries every cross-chain message; every payload carries a sequence number and a Position id and every handler is idempotent (ADR 0002).
  • PvP only. Gemas are spent only on zero-sum contests between Players, never on purchases (ADR 0004).

Trust boundaries

BoundaryTrusted forWhere it is checked
Registered Game authorityDeclaring a Match result.tesoro_core `settle_match` accepts only the signer registered for that Game. The authority is a PDA of the Game program.
Oracle keyIssuance price (Solana: the on-chain `PriceFeed`, at most 24 h old; Ethereum: signed with the Advance) and oracle-reported Positions.Single key today. Pyth is planned as a replacement for the source, not for the instruction.
MagicBlock TEE validatorKeeping hidden state private; running the Game programs' rollup logic.Delegation is pinned to one approved validator per Game program (audit F-01).
LayerZero DVNsTruthful delivery of the four messages.Default pathway config. Handlers are idempotent per sequence; the vault caps a payout at its accrued yield.
Admin keyRegistering Games, fees, source authorities, program upgrades.One key. No multisig or timelock.

Read next

Test mode · simulated yield · 1 month = 10 min · nothing here has value