Skip to content

Commitments

Proof of concept

How the order hash is formed, why the reveal check works, and the tamper demonstration.

Proof of concept Runs on synthetic data.

How the hash is formed#

The commitment is the keccak256 hash of the order fields packed together with a random 32-byte salt:

ts
keccak256(
  encodePacked(
    ["string", "uint8", "uint256", "uint256", "bytes32"],
    [market, side === "buy" ? 0 : 1, size * 1e6, limit * 1e6, salt],
  ),
);

Why the reveal check works#

  • The hash reveals nothing about side, size or price, because the salt is random.
  • At reveal, anyone can recompute the hash from the published order and salt and check it matches.
  • Changing any field, even by one unit, produces a completely different hash. You cannot change your order after committing.

Tamper demonstration#

The Learn section lets you edit a committed order before revealing it. The recomputed hash no longer matches the commitment and the reveal is rejected.

Last updated 2026-09-28