Waxseal
Preprod testnet
Built on MidnightZero-knowledge proofs Live on Preprod

Sealed bids. Proven winners.

Run tenders and auctions where no bid ever appears on chain. Bidders post a commitment and a zero-knowledge proof that their bid is valid. The winner is proven against every commitment, not declared by anyone.

Tenders on Preprod
Sealed bids
Proven winners
Stays on your deviceYour bid · your salt · your secrets
Used to build the proof in your wallet
↓ zero-knowledge proof ↓
Goes on chaincommitment = hash(bid, salt, bidder)
+ proof: in range · deposit locked · eligible
↓ after the close ↓
Published at the endWinner and winning price only
Losing bids are never revealed

How it works

Four steps, one rule: bids stay sealed

  1. Create the tender

    The organiser publishes the bid range, deadline, required deposit, and whether the lowest or highest bid wins. An eligibility list can be added. The public metadata is hashed into the contract.

  2. Commit a sealed bid

    Your wallet hashes your bid with a secret salt and proves it is in range. Only the commitment and the proof go on chain.

  3. Prove the winner

    Clock mode: the price clock moves and the first bidder whose sealed bid it reaches proves it. Committee mode: the committee proves the winner against all bids.

  4. Settle privately

    The winner and price go public. Losers receive a private “you did not win” proof and their deposits back. The winner’s deposit becomes a performance bond.

Two modes, one core

Choose who, if anyone, sees the bids

Clock mode

Nobody sees bids

For open auctions and price-only tenders. A public price clock moves round by round. When it reaches your sealed bid, you prove it and win. No trusted party.

Sees bids
Nobody
Trust
None
Best for
Auctions, commodity procurement

Committee mode

Committee sees bids

For evaluated procurement. Bids are also encrypted to a named committee, with a proof that the ciphertext matches the commitment. The committee can read bids but cannot fake the result or leave one out. Optional auditor access is recorded on chain.

Sees bids
The named committee (key can be split t-of-n)
Trust
Committee confidentiality only
Best for
Business procurement with evaluation

Security model

Six invariants, each with its own tests

These rules are enforced by the contracts and checked by adversarial tests. No release may weaken any of them. The full protocol and its security argument are in the whitepaper (PDF).

I1 Bids cannot be changed

Each bid is fixed by a commitment written on chain. Every later proof must open that exact commitment.

I2 The winner is proven

A published winner must beat every commitment on chain, and the proof shows it. Nobody simply announces a result.

I3 No bid can be dropped

In committee mode the result circuit consumes exactly the number of bids on chain, so none can be left out.

I4 Deposits are shielded

Deposits use shielded tokens, so taking part should not show up in your public wallet activity.

I5 Losing bids stay sealed

Losing bids never reach the chain, the indexer, our API, logs or this site. Losers get a private proof that they did not win.

I6 Your bid stays on your device

Your bid and its secret salt are hashed and proven in your browser or wallet. They never reach Waxseal.

Developers

Open contracts, a typed SDK, a committee CLI

Everything that touches a bid lives in one clearly marked module. Integrate Waxseal into your own procurement flow or run the committee app on your own machine.

  • Compact contracts for clock and committee mode, compiled with the pinned toolchain
  • TypeScript SDK for Node and the browser (Midnight DApp Connector: 1AM, Lace)
  • Committee CLI: key generation with t-of-n shares, reveal, auditor export
  • Public API with signed webhooks for tender events
// create a tender (metadata is hashed into the contract)
const address = await createTender(providers, {
  minBid: 100n, maxBid: 1_000n,
  closeTime: new Date(Date.now() + 86_400_000),
  winnerRule: 'lowest', depositAmount: 0n, whitelist: false,
  clockStep: 50n, clockRoundSeconds: 600n, metadata,
});

// commit a sealed bid: (bid, salt) never leave the device
await commitBid(providers, address, 420n);

// which round can I claim in? computed locally
qualifyingRound(420n, tender); // -> 7n

Questions

Frequently asked

Who can see my bid?

In clock mode, nobody: only a commitment (a hash) goes on chain. In committee mode, the named committee can decrypt bids; everyone else sees only the commitment and the final winner.

What do I need to take part?

A Midnight wallet set to Preprod (1AM proves in the browser and needs nothing else; Lace also works but proves its own inputs with a local proof server), a little tNIGHT from the faucet for fees, and a passphrase for your local bid vault. Waxseal generates its proofs in your browser.

What if I lose my vault passphrase?

Your sealed bid (its value and salt) lives only in your browser, encrypted with that passphrase. Without it you cannot claim a win or a refund, so keep it safe.

How is the winner decided in clock mode?

After bidding closes, a public price clock moves one step per round. A bid can be claimed only in the first round the clock reaches it, so nobody can wait for a better price. The first valid claim wins.

Is Waxseal audited?

Not yet. It runs on the Preprod testnet only and mainnet is locked in code until an independent audit is complete.

Run your first sealed-bid tender on Preprod

Free to try on the Midnight test network. Connect 1AM or Lace, unlock your bid vault, and publish a tender in minutes. Testnet only — not audited.

  • Done Phases 0–3 — sealed commitments, clock mode, committee mode with proof of correct encryption, committee app, auditor grants
  • Next Phase 4 — independent audit, mainnet, pilots