Commit first, reveal later, cross against one reference.
A production batch begins with hashed commitments. Traders disclose the order fields during a later reveal window. After reveals close, settlement matches eligible buys and sells at an external reference price.
A buy specifies USDG to spend; a sell specifies WETH to offer. The limit price protects the order from settlement beyond its selected bound.
Eligible buyers and sellers receive proportional fills when the two sides are unequal. Unmatched amounts remain attributable to their owners. The proposed fee is 0.05% of received assets.
Matched WETH = min(eligible buy USDG / settlement price, eligible sell WETH)
The preview creates a cryptographically random salt and a SHA-256 integrity hash of a local order payload. These receipts are clearly marked as local previews and are not Solidity-compatible on-chain commitments.
Inspecting a reveal shows the saved fields. Exporting downloads those fields and the salt. Removing a receipt downloads a backup first. No commit, reveal, deposit, withdrawal or settlement transaction is sent.
A commit transaction would expose its sender and timing. Revealed order details become public. This model protects pre-reveal intent; it does not provide anonymous trading.
A production design needs explicit reveal deadlines, unfilled-balance accounting, expired-batch refunds and a verified commitment encoding. The UI alone cannot provide these guarantees.