Introducing ArcLite. $LITE
A private execution venue for tokenized equities on Robinhood Chain.
Your order is encrypted in your browser, sealed into a batch, then crossed at a reference committed after the book closes.
The settlement is proved onchain.
> The market can verify the result without seeing every order before it happens.
Your vault keys stay in your browser. Your balance is calculated locally.
We are building privacy as infrastructure,
we show the limits too: deposits are public, the matcher sees its sealed window, and early anonymity sets are small.
Read the build:
https://t.co/vcLu3F92Th
Try the dashboard:
https://t.co/NwjMbYMC1j
Most protocols onboard you with a tour. ArcLite now just does it.
Connect → open your vault → deposit a dollar → buy a quarter of it. Four steps, one button each, every amount computed for you.
The amounts are the whole point. A note is spent whole, the quote asset has 6 decimals and the equities 18, and one share of NVDA is $220, so the obvious first order is unfundable and the pre-flight is right to refuse it. Now the order size is derived from the deposit instead of picked beside it.
Your first attempt works. Real tokenized equity, on mainnet, and nobody saw the order.
Between one deploy and the next, a reminder what ArcLite is here for.
The market should not see an order before it sees a price.
Back to building.
$LITE
Private execution is not undocumented execution.
ArcLite hashes an encrypted payload before it enters the book, then checks that exact hash at reveal. If it changed or cannot be read, it is rejected with a reason.
It cannot quietly disappear.
https://t.co/lorZdWmd1e
Most software makes noise to feel alive.
ArcLite's settle tone fires only when your order actually crossed, never when a window merely closes. Nothing crossed means silence.
A sound that plays whether or not anything happened is a lie told in audio.
A large order is identifiable by its size alone.
ArcLite now splits one order across windows. Each slice is signed and sealed fresh against that window's key, and hides in a different window's crowd.
It runs while your vault is open, and stops when your vault locks.
That limit is the feature. Your spend authorisation is bound to one window, and a window's id doesn't exist until it opens, so there's nothing to pre-sign, and no key on our side that could sign for you.
A standing order would require us to hold something able to seal on your behalf. We don't hold it.
Every trade has a remainder.
On ArcLite, the buyer’s USDG cost rounds up and the seller’s payout rounds down. That difference stays as dust instead of becoming a hidden deficit.
The pool never has to pay more quote than it received.
https://t.co/lorZdWmd1e
The unused part of a proof is still part of the attack surface.
A window might price four assets inside a 32-row circuit.
The remaining 28 rows must be forced to zero, not assumed irrelevant.
ArcLite does that at circuit level. An order cannot reach a price that never made it into the onchain commitment.
https://t.co/hLD29wqMET
Got feedback on the Arclite? Drop it in the Telegram.
The team is much more active there. Bugs, rough UX, questions, feature ideas, all of it gets read and adequately attended to.
https://t.co/JEwwY1nTOl
Reminders are live.
Set one for when an asset starts trading again, or for the final minute before a window seals.
The obvious build is a server-side watch list. That tells a server which asset someone is watching and roughly when. That is the exact intent sealed orders are built to hide.
So ArcLite keeps it browser-side. The watch lives in local storage, and nothing is sent anywhere.
The tradeoff is simple: it only fires while the tab is open. No push, no account, no email.
https://t.co/NwjMbYM4bL
A sealed window must never settle as “0 orders” because the key to open it is missing.
ArcLite flags the mismatch and voids the window rather than calling it empty. No settlement, no nullifiers, no notes silently spent.
A backend failure should stop the venue before it mutates state.
https://t.co/Jf62zydqjT
Private notes still need a public “spent” signal.
When an ArcLite note is used, the chain gets a nullifier: enough for the pool to kill a replay, without exposing the note balance or the RWA order it funded.
The chain can tell a note is done. It does not get the trade.
One note. One signed order.
ArcLite locks the signature to the exact trade: window, asset, side, size and nullifier.
Try to replay it in another window, change the size, or flip the side, and it dies in the circuit.
Notes aren’t blank cheques.
https://t.co/lorZdWmd1e
Orders should not reach a sealed batch only to discover the funding note cannot cover them.
ArcLite now runs the same affordability check while an order is typed and again at submission.
The panel picks the funding note, flags a USDG shortfall, and shows the largest size that clears.
ArcLite now tells you when your notes are in a retired pool, and what moving them costs.
The pool contract is immutable, so fixes ship as new addresses. Old pools honour withdrawals forever, your funds are safe there, but a note in one can't trade.
Moving it means a public withdrawal then a public deposit: same address, same amount, minutes apart. Timing and amount linkage together.
We show you that cost, then point at the two controls. The gap between them is yours to choose.
Withdrawing from ArcLite takes a few seconds because your browser is generating a ZK proof. It used to say "Proving…".
Now: Finding your note → Building the witness → Generating the proof → Broadcasting. Each stage says where the work happens, the witness holds your note's secrets, so it's built in your browser and sent nowhere.
We left out a "verifying locally" stage. The worker doesn't verify, so nothing claims it does. A progress bar that invents a step is a spinner that lies.
Proof boundary:
The price table only commits the rows it actually uses.
The current circuit forces every unused selector to zero. No trailing padding row can feed a price the contract never committed.
That is table membership. Not a live mid. Not best execution.
Founder/dev note:
The issuer multiplier is not a UI label.
After the book seals, it is committed beside the Chainlink reference in the price row the proof has to use.
If a new multiplier is about to take effect, that asset waits.
Input → committed row → proof.
We've open sourced the client half of ArcLite's shielded pool, so you can build one without writing it twice.
Same logic has to exist in Noir and in the browser. Disagree by one field and the browser computes a commitment the circuit won't accept.
MIT, 90 tests, fully offline. Notes regenerate from a key and a counter, so nothing you run is load-bearing for recovery. Disclosure scope is the key itself, not a flag. Spends are signed, not merely revealed.
Our format, not a standard, take the design.
https://t.co/OosDko4Puz