Docs / Protocol

The oracle(14)

Prices come from RedStone signed data packages, data service redstone-primary-prod. A package is one price for one feed at one timestamp, signed by one RedStone node. The program verifies every signature itself and trusts no relayer.

Signers

Five signers are authorised and three must agree. The admin can change the set, never with a threshold below three.

  • 0x8BB8F32Df04c8b654987DAaeD53D6B6091e3B774
  • 0x9c5AE89C4Af6aA32cE58588DBaF90d18a855B6de
  • 0xdEB22f54738d54976C4c0fe5ce6d408E40d88499
  • 0x51Ce04Be4b3E32572C4Ec9135221d0691Ba7d202
  • 0xDD682daEC5A90dD295d14DA4b0bec9281017b5bE

The signed message

[ Fig. 1 ] PER PACKAGE
hash   = keccak256( feedId[32] ‖ value[32] ‖ timestampMs[6] ‖ uint32(32)[4] ‖ uint24(1)[3] )
feedId = ASCII id right-padded with zeros to 32 bytes     "BTC" → 0x425443 00 … 00
value  = price × 1e8 as a big-endian uint256, from the exact decimal
signer = last 20 bytes of keccak256(pubkey),  pubkey = secp256k1_recover(hash, v − 27, r ‖ s)

On Solana the program hashes with keccak::hashv and recovers with secp256k1_recover, at about 25,000 compute units per signature. There is no message prefix.

A price proof

  • At least three packages for the same feed and the same timestamp, from distinct authorised signers.
  • The price is the median of their values; for an even count, the mean of the two middle values.
  • Duplicates, unknown signers, mismatched timestamps and zero values are rejected.

The reference band

Each market also reads a Pyth price account on Solana (PriceUpdateV2, owned by the Pyth receiver rec5EKMGg6MxZYaMdyBfgwp4d5rB9T1VQH5pJv5LtFJ). The program requires full verification, the expected feed id and a publish time at most 300 seconds old. Then:

[ Fig. 2 ] BAND
|price − ref| × 1e4 ≤ ref × 250        2.5 %

If the Pyth price is stale, the program fails closed: it accepts no RedStone price for that market until a fresh reference exists. This bounds what a compromised signer set could do. It cannot push a price more than 2.5 % away from an independent source.

PYTH REFERENCE ACCOUNTS
MarketAccountFeed id
SOL / USD7UVimffxr9ow1uXYxsr4LHAcV58mLzhmwaeKvJ1pjLiE0xef0d8b6fda2ceba41da15d4095d1da392a0d2f8ed0c6c7bc0f4cfac8c280b56d
BTC / USD4cSM2e6rvbGQUFiJbqytoVMi5GgghSMr8LwVrT9VPSPo0xe62df6c8b4a85fe1a67db44dc12de5db330f7ac66b72dc658afedf0f4a415b43
ETH / USD42amVS4KgzR9rA28tkVYqVXjq9Qa8dcZQMbH5EYFX6XC0xff61491a931112ddf1bd8147cd1b641375f79f5825126d665480874634fd0ace