Himess/ghostloop

Private leverage and borrowing on Vesu, powered by STRK20.

★ 0Forks 0TypeScriptGitHub ↗Compare

README

GhostLoop

Private leverage and borrowing on Vesu.

GhostLoop is building a focused Starknet Mainnet experience for borrowing USDC and opening leveraged ETH positions on Vesu without linking those positions to the user's public wallet.

STRK20 provides private balances and unlinkable execution identities. Vesu provides lending and risk management. Ekubo provides swap liquidity for Multiply and unwind flows.

Status: Option B contracts, Wallet API serialization, encrypted capability keys, the live-data position dashboard, and fail-closed privacy-wallet capability detection are implemented. The UI also requires a locally encrypted key, downloaded backup, and explicit recovery acknowledgement. Contract lifecycles are fork-proven. Live deployment remains gated by Vesu market capacity, independent review, and a connected-wallet prepare dry-run. No deployment, demo URL, contract address, or transaction hash is claimed yet.

Product flows

  • Borrow: private ETH → capability-bound GhostPosition → Vesu ETH/USDC position → borrowed USDC returned to a private STRK20 balance.
  • Multiply: private ETH → capability-bound GhostPosition → Vesu Multiply + Ekubo → persistent leveraged ETH position.
  • Unwind: Vesu Multiply closes debt and collateral → residual ETH returned to a private STRK20 balance.

Privacy model

GhostLoop aims to hide the link between a user's public wallet and the Vesu position. The Shadow Account address, collateral, debt, health, swaps, timing, and other onchain activity remain public. See docs/PRODUCT.md and docs/ARCHITECTURE.md.

Current milestone

The first milestone is evidence, not UI polish:

  1. Feature-detect current Mainnet Shadow Account wallet execution. Native dapp Wallet API support is not currently shipped; see the decision request.
  2. Verify live STRK20 and Vesu ETH/USDC contracts and configuration.
  3. Verify whether a canonical Vesu Multiply deployment exists.
  4. Implement the minimal signed GhostPosition authorization boundary.
  5. Prove borrow, Multiply, and full unwind on a Mainnet fork. Both lifecycle proofs pass against canonical contracts at pinned block 4172487.
  6. Serialize every closed helper operation as exact STRK20 Wallet API actions. The six builders match starknet.js compilation of the generated Cairo ABI, including open-note placeholders and integer limbs.
  7. Build the Borrow/Multiply preview against live Vesu risk data. The dashboard renders current oracle and market state server-side, applies a 10-point LTV buffer, and keeps every execution control disabled while a required safety gate is incomplete.
  8. Add privacy-wallet capability detection and a prepare-only boundary. Discovery requires Wallet API 0.10.3+ on Mainnet before account access; the narrowed connection can simulate but cannot submit a transaction.
  9. Require the encrypted capability-key backup ceremony. A future position key is generated and encrypted locally; creation readiness requires a backup download plus explicit acknowledgement that GhostLoop has no recovery path.

Research is recorded in docs/RESEARCH_LOG.md, and architectural decisions in docs/DECISIONS.md.

Verification tools

Node.js 22 or newer is required.

npm install
npm run dev
npm run check
npm run build
npm run verify:contract-abi
npm run verify:wallet-actions
npm run verify:wallet-capability
npm run verify:key-store
npm run verify:key-backup
npm run verify:risk
npm run verify:addresses
npm run preflight:vesu
npm run verify:tx -- <STARKNET_MAINNET_TX_HASH>
npm run evidence

STARKNET_RPC_URL may point to an authenticated Alchemy Mainnet endpoint. The read-only public sprint RPC is used when it is unset. Never commit API keys.

The ABI and Wallet API serialization verifiers consume Scarb artifacts under contracts/target/dev; run scarb build in contracts/ first after a clean checkout. Serialization verification is offline and does not submit a wallet request or transaction.

verify:risk covers Borrow and 1×–2.5× Multiply previews, the configured LTV buffer, oracle precision, ETH/USDC unit parsing, and slippage bounds.

Wallet discovery first queries supportedWalletApi and the network. It does not request an account from unsupported/non-Mainnet wallets, call shielded balances, or expose a submit method through GhostLoop's connected-wallet boundary. The currently wired boundary can only call strk20PrepareInvoke(actions, true).

preflight:vesu is a deployment gate and exits non-zero when the current Prime ETH/USDC cap cannot support a position above Vesu's debt floor. That is the expected live result while the market remains capped at 1 USDC.

The transaction verifier requires both successful execution and receipt/trace evidence that the canonical STRK20 pool was touched. It does not treat an address appearing only in calldata as proof.

License

MIT

Contributors

Himess

Issues