fheMX
fheMX is a privacy layer for GMX V2 built on Fhenix CoFHE fully homomorphic encryption (FHE).
Video
Công nghệ sử dụng
Sự miêu tả
Overview
Motivation
Conditional orders on on-chain perpetual exchanges are fully transparent. Once an order is placed, its trigger price, size and direction are visible to every market participant. This exposes traders to:
Stop hunting: adversarial price movement aimed at clusters of visible stop-losses.
Front-running: trading ahead of known limit entries.
Position profiling: copy trading, or trading against, large and predictable participants.
Solution
fheMX is a privacy layer for GMX V2 built on Fhenix CoFHE fully homomorphic encryption (FHE). Order parameters are encrypted on the client before submission. The smart contract evaluates the trigger condition directly on ciphertext, and nothing is decrypted while the condition is unmet. When an order triggers, only the values needed for execution are revealed, and the order is placed on GMX V2 as a standard market order.
Parameter | Standard GMX order | fheMX sealed order |
|---|---|---|
Trigger price | Public | Encrypted, never revealed |
Position size | Public | Encrypted until execution |
Direction (long / short) | Public | Encrypted until execution |
Slippage tolerance | Public | Encrypted until execution |
Information per price check | Full order details | Not yet triggered |
Trailing-stop distance | Public | Encrypted, never decrypted |
Execution venue | GMX V2 | GMX V2 |
Key Features
Privacy
Encrypted trigger evaluation: the trigger condition is computed on ciphertext using FHE operations (
FHE.lte,FHE.gte,FHE.select). The trigger price is never decrypted.Non-revealing checks: each evaluation publishes
select(fired, value, 0), so an order that has not triggered decrypts to zeros.Encrypted intake validation: size, slippage and trigger limits are enforced homomorphically. The result is an encrypted flag readable only by the order owner, which prevents parameter probing.
Owner-only visibility: owners can decrypt their own order parameters at any time using a signed permit.
Custody and Security
Isolated user accounts: each user operates through a dedicated
UserAccountcontract (EIP-1167 clone). It serves as the GMXaccount,receiverandcallbackContract, so collateral, proceeds and refunds always return to the user.Restricted adapter permissions: the adapter can only lock funds for an order and submit it to GMX. Withdrawals are owner-only.
Immutable configuration: markets, limits, fees and oracles are fixed at deployment, with no admin, pause or upgrade path.
Verified decryption: revealed values require valid CoFHE signatures (
FHE.publishDecryptResult) and are re-validated against public size, slippage and leverage limits before funds move.Replay protection: encrypted inputs are bound to the submitting address and the adapter contract.
Fired-check expiry: a triggered evaluation is executable only within
maxReportAge, preventing execution at stale prices.Deterministic reconciliation: one adapter order per GMX position may be in flight at a time, so every outcome is resolvable from position state.
Balance accounting: free and locked balances are tracked per order, with reentrancy protection on all fund movements.
Execution on GMX V2
Native GMX orders: triggered orders execute as standard GMX V2 market orders against GMX liquidity.
Impact-aware pricing: the acceptable price is derived from GMX's execution-price estimate (
Reader.getExecutionPrice), bounded by the sealed slippage tolerance.Automatic retry: orders cancelled by GMX are re-armed once using the owner's fallback slippage.
Callback recovery:
reconcileresolves order outcomes from GMX state if a callback is not delivered.
Decentralised Operation
Permissionless keepers: any participant can operate the checker that evaluates, executes and settles orders.
Self-funding evaluation: each check is paid from the order's own check budget, compensating keepers for gas.
Oracle safeguards: Chainlink Data Feeds with per-feed staleness limits and L2 sequencer-uptime validation.