Deterministic option pricing on Arbitrum Stylus. Black-Scholes, five Greeks, CRR lattices and implied volatility in integer fixed point, with no floating point in the deployed artifact.




Arboretum implements option pricing as a computation rather than a value delivered to a contract. Black-Scholes with continuous carry, five Greeks, Cox-Ross-Rubinstein lattices (European and American, to 4096 steps), implied-volatility inversion, and a no-arbitrage band are written in Rust and compiled to an Arbitrum Stylus contract.
Stylus does not support floating point, so the engine is signed fixed point at 1e9 in i128 with round-half-up fixed as the single rounding mode, and every elementary function is implemented in the crate rather than taken from a dependency. The contract compiles to 14,668 bytes compressed against a 96 KB limit.
Reproducibility is checked against the chain rather than asserted: ten entry points on the deployed contract are compared with a local build of the same source and agree as integers, and a script disassembles the deployed artifact to confirm it contains no floating-point instruction. 3336 reference cases from CPython hold each function inside a budget derived from the published error of the normal CDF approximation.
Where this belongs. Today's on-chain options protocols take their mark price from an off-chain model, so the number driving a liquidation comes from a computation the consuming contract cannot inspect. Executing the formula on-chain turns it into something a third party can re-derive from public inputs with the same program. That costs one to two orders of magnitude more gas than reading a feed, so the applicable cases are settlement and expiry prices, fallback marks when a feed is stale, reproducible audit, and structured-product construction. Streaming quotes should stay off-chain, and this is not competing with a market maker.
Numbers. 36 Rust tests and 5 Solidity tests, 0 failures, clippy clean. 3336 reference cases, 0 over budget. Contract 14,668 bytes compressed. 10 of 10 entry points bit-identical to a local build. 0 float instructions in the compiled artifact. 0 third-party dependencies in the pricing kernel. exp error 2.2e-9 relative, normal CDF error 7.55e-8 absolute against a published bound of 7.5e-8, lattice error 1.4e-6 relative.
Known limits. Volatility is an input, and there is no live implied-volatility surface for tokenised equities to read, so the commitment scheme for it is designed but not implemented. The normal CDF is Abramowitz & Stegun 26.2.17: accurate, not correctly rounded, and monotonicity in volatility holds only within its error band. Premiums below 1e-9 flush to zero by construction. There are no jump-diffusion, stochastic-volatility or barrier models. The contract is deployed on Arbitrum Sepolia, not on a mainnet, and has not been audited.
Prior art, so no claim of priority is made. Lyra's first version ran Black-Scholes inside the contract. Offchain Labs demoed Black-Scholes in Stylus in October 2024 (Stylus Pro Series, Day 3), listed in their own awesome-stylus. chrisco512/black_scholes (October 2024) is the closest public repository: European only, built on rust_decimal rather than integer fixed point, never deployed, no demonstration page. Within this buildathon there is also afterhours, a Stylus contract pricing a put on top of an ERC-4626 vault. What none of them covers is the combination here: closed form, five Greeks, lattices with early exercise, implied-volatility inversion and a derived uncertainty band together, in pure integer arithmetic, with the absence of floating point verified against the compiled artifact and the deployed contract checked entry point by entry point against a local build.
Week 1 built and verified the engine rather than the wrapper.
arbnum: signed fixed point at 1e9 in i128, hand-written exp, ln, sqrt, pow, erf, norm_cdf and norm_pdf, no third-party crates, every operation checked so overflow reverts instead of wrapping.
arbpricing: Black-Scholes with continuous carry, five Greeks, CRR lattices to 4096 steps with early exercise, implied volatility by plain bisection on a fixed bracket, and a public no-arbitrage band.
arbreport: 3336 reference cases generated from CPython, with per-case budgets derived from the CDF's published error rather than chosen for convenience. The accuracy report is regenerated by the same binary the tests assert against, so the published numbers cannot drift from the code.
arbcontract: the Stylus contract, 14,668 bytes compressed as deployed.
Five defects were found and fixed during that work, each now pinned by a test:
1. Rounding ln 2 to the fixed-point scale made it the dominant error term once multiplied by the argument-reduction factor. Fixed with nine guard digits carried through the reduction.
2. Catastrophic cancellation in the closed form produced a negative price for deep out-of-the-money quotes. Fixed by deriving a noise band from the CDF error and flooring inside it rather than returning noise.
3. A European put is not bounded below by intrinsic value. The bound is the discounted forward difference, and the wrong invariant was corrected in the public bounds function.
4. The lattice carried each node's underlying forward across levels, so a terminal entry that underflowed the representation stayed pinned at zero. That made the American early-exercise test compare K minus zero against the continuation value, pricing a deep in-the-money put about 5 percent too high while the European path, which never reads the lattice, agreed with the reference to 1e-8. Fixed by rebuilding each level's row from the diagonal.
5. The implied-volatility solver's answer depended on its starting guess, because it stopped as soon as the price residual fell inside the quote's noise band. Two callers with different guesses got answers eight quanta apart, both legitimate and neither reproducible. The solver is now plain bisection on a fixed bracket, so volatility is a function of the quote and the parameters and of nothing else.
Week 2 deployed to Arbitrum Sepolia and proved the property end to end. scripts/verify_onchain.sh calls all ten entry points on the live contract and compares them against a local build of the same source; every one agrees bit for bit. scripts/verify_no_floats.sh disassembles the compiled module and counts float-typed values in it: zero.
Deploying took one portability patch to the official CLI, because its published source does not build on Windows at all. The patch is in the repository at scripts/patches/cargo-stylus-windows.patch and the six configuration gates it imposed are written up in docs/DEPLOY.md.
A demo page lets a reviewer check the claim without trusting any part of this stack. It contains no pricing code of its own: the host-side comparison ships as data generated by the same Rust crate, because a JavaScript reimplementation would be a second, floating-point answer to a question whose only interesting property is that it has exactly one answer. The page prints the exact calldata of the call it made, so the same value can be fetched with eth_call from any node.
Not raising. This is a hackathon entry, not a product offering.