Skip to content

How it works

  1. PromiseA team publishes a claim with a deadline that a program can check onchain.
  2. CollateralThe team locks funds behind it. They lose them if the claim fails.
  3. MarketAnyone buys YES or NO. The YES price reads as the crowd’s odds.
  4. VerdictAfter the deadline, the program reads chain state and resolves.
  • SHIPCondition met: collateral returned to the team, YES holders paid.
  • SLASHCondition missed: collateral slashed to NO holders.
The lifecycle of a windle promise. Design, subject to change.
  1. A team makes a promise. The team writes a claim as a condition a program can evaluate from Solana state, plus a deadline. For example: “A program is deployed and executable at a declared address on mainnet before Dec 1.” A tweet saying “mainnet soon” is not a promise; a condition over accounts is. → Promise

  2. They lock collateral behind it. The team deposits collateral into a program-controlled account. Until resolution, neither the team nor windle can withdraw it. The amount is public, so everyone can see how much the team stands to lose. → Collateral

  3. The market prices it. A YES/NO market opens on the promise. Buy YES if you believe the team ships, NO if you don’t. The YES price, between 0 and 1, reads as the market’s probability that the promise is kept. → Market & pricing

  4. At the deadline, the chain decides. After the deadline, anyone can trigger resolution. The program reads the accounts named in the promise and checks the condition. There is no vote and no dispute window in this design: the result is whatever the chain state says. → Resolution

  5. Two endings. Ship: collateral returned to the team, YES paid. Slash: collateral slashed to NO holders. → Ship vs slash payouts

Role Does Can’t do
Team Writes the promise, locks collateral, can trade like anyone else (subject to limits still being designed). Withdraw collateral before resolution, change the condition or the deadline after the market opens.
Trader Buys and sells YES or NO; holds positions until resolution or exits early at the market price. Influence the verdict other than through what the team does onchain.
Program Holds collateral, runs the market, evaluates the condition, pays out. Read anything that isn’t onchain.
windle (the team behind the protocol) Builds the programs and interfaces. Decide outcomes. The design keeps resolution in the program, not with us.

The outcome of a promise depends on one party’s actions: the team’s. That makes the team the only real insider. The design goal is that their best strategy is to deliver, because delivering returns their collateral and missing costs it. Where that goal could break (a team betting NO against itself with more than its collateral is worth), the protocol needs explicit limits. Those limits are not final; see Collateral → open questions.