Private leverage and borrowing on Vesu.
GhostLoop is building a focused Starknet Mainnet experience for borrowing USDC and opening leveraged ETH positions on Vesu without linking those positions to the user's public wallet.
STRK20 provides private balances and unlinkable execution identities. Vesu provides lending and risk management. Ekubo provides swap liquidity for Multiply and unwind flows.
Status: Option B contracts, Wallet API serialization, encrypted capability keys, the live-data position dashboard, and fail-closed privacy-wallet capability detection are implemented. The UI also requires a locally encrypted key, downloaded backup, and explicit recovery acknowledgement. Contract lifecycles are fork-proven. Live deployment remains gated by Vesu market capacity, independent review, and a connected-wallet prepare dry-run. No deployment, demo URL, contract address, or transaction hash is claimed yet.
- Borrow: private ETH → capability-bound GhostPosition → Vesu ETH/USDC position → borrowed USDC returned to a private STRK20 balance.
- Multiply: private ETH → capability-bound GhostPosition → Vesu Multiply + Ekubo → persistent leveraged ETH position.
- Unwind: Vesu Multiply closes debt and collateral → residual ETH returned to a private STRK20 balance.
GhostLoop aims to hide the link between a user's public wallet and the Vesu position. The Shadow Account address, collateral, debt, health, swaps, timing, and other onchain activity remain public. See docs/PRODUCT.md and docs/ARCHITECTURE.md.
The first milestone is evidence, not UI polish:
Feature-detect current Mainnet Shadow Account wallet execution.Native dapp Wallet API support is not currently shipped; see the decision request.Verify live STRK20 and Vesu ETH/USDC contracts and configuration.Verify whether a canonical Vesu Multiply deployment exists.Implement the minimal signed GhostPosition authorization boundary.Prove borrow, Multiply, and full unwind on a Mainnet fork.Both lifecycle proofs pass against canonical contracts at pinned block4172487.Serialize every closed helper operation as exact STRK20 Wallet API actions.The six builders match starknet.js compilation of the generated Cairo ABI, including open-note placeholders and integer limbs.Build the Borrow/Multiply preview against live Vesu risk data.The dashboard renders current oracle and market state server-side, applies a 10-point LTV buffer, and keeps every execution control disabled while a required safety gate is incomplete.Add privacy-wallet capability detection and a prepare-only boundary.Discovery requires Wallet API0.10.3+on Mainnet before account access; the narrowed connection can simulate but cannot submit a transaction.Require the encrypted capability-key backup ceremony.A future position key is generated and encrypted locally; creation readiness requires a backup download plus explicit acknowledgement that GhostLoop has no recovery path.
Research is recorded in docs/RESEARCH_LOG.md, and architectural decisions in docs/DECISIONS.md.
Node.js 22 or newer is required.
npm install
npm run dev
npm run check
npm run build
npm run verify:contract-abi
npm run verify:wallet-actions
npm run verify:wallet-capability
npm run verify:key-store
npm run verify:key-backup
npm run verify:risk
npm run verify:addresses
npm run preflight:vesu
npm run verify:tx -- <STARKNET_MAINNET_TX_HASH>
npm run evidenceSTARKNET_RPC_URL may point to an authenticated Alchemy Mainnet endpoint. The
read-only public sprint RPC is used when it is unset. Never commit API keys.
The ABI and Wallet API serialization verifiers consume Scarb artifacts under
contracts/target/dev; run scarb build in contracts/ first after a clean
checkout. Serialization verification is offline and does not submit a wallet
request or transaction.
verify:risk covers Borrow and 1×–2.5× Multiply previews, the configured LTV
buffer, oracle precision, ETH/USDC unit parsing, and slippage bounds.
Wallet discovery first queries supportedWalletApi and the network. It does
not request an account from unsupported/non-Mainnet wallets, call shielded
balances, or expose a submit method through GhostLoop's connected-wallet
boundary. The currently wired boundary can only call
strk20PrepareInvoke(actions, true).
preflight:vesu is a deployment gate and exits non-zero when the current
Prime ETH/USDC cap cannot support a position above Vesu's debt floor. That is
the expected live result while the market remains capped at 1 USDC.
The transaction verifier requires both successful execution and receipt/trace evidence that the canonical STRK20 pool was touched. It does not treat an address appearing only in calldata as proof.