Skip to content

Atomic Settlement

Submitting an order is not the same as completing a trade. The matching engine finds matching orders. The Cashu mint then exchanges the authorized funds and shares. The mint completes each settlement group as one operation. It does not complete only one side of that exchange. This is what atomic settlement means.

Review the quantity, quoted trade value, and separate fees. The engine refuses a trade that costs more, or pays less, than the trade value you accepted. It also checks the accepted worst execution price. These limits do not remove wallet preparation or refund fees. Preparation can cost a fee even if no trade completes.

To sell all your shares, keep some ordinary sats available for preparation fees. The wallet can pay those fees with sats instead of reducing the shares you sell. The sale proceeds cannot pay this fee because preparation comes first.

Both the web app and CLI use fill-or-kill (FOK) orders in this release. When the engine accepts the order, the available matching orders must cover its full quantity within the accepted trade-value and price limits. Otherwise, it cancels the whole order. It does not fill only part of your request or leave the rest waiting for a buyer or seller. A matching decision still needs settlement confirmation.

Cancellation because the full quantity cannot match does not itself spend the trade authorization or start a refund. If your wallet already prepared locked funds, they can remain unavailable until the refund conditions are met.

The wallet keeps a completed preparation if the order fails. It does not undo the preparation or refund its paid fees. Unused locked funds follow the normal expiry and refund process. Recovery does not submit a new order automatically.

If the mint’s preparation reply is missing, the wallet keeps the affected funds reserved while it checks the result. An expired authorization or a rejected retry does not prove that the first request failed. Recovery can remain pending if the mint cannot complete or return the exact result.

A lost connection does not prove that a trade failed. The mint may have completed the exchange before your wallet received its reply. Do not create a new order just to retry a trade whose result is still unknown.

Keep the same wallet and its local data. The wallet stores the submitted operation and checks the existing result during recovery. A saved result survives a server restart. Recovery of that same operation must not create another trade.

Do not clear browser storage or delete the wallet’s local records while an operation is unresolved. Your recovery phrase does not reconstruct every pending operation or refund record. See wallet backup and recovery.

If settlement does not complete, the authorized funds can become refundable after the authorization expires. A timeout alone does not make them available to spend. The wallet must check the existing settlement and refund conditions.

Expiry reclaim unlocks the original asset. Regular ecash keeps its currency unit. Conditional tokens keep their condition and outcome collection. The mint’s swap fee still applies. The protocol calls this operation refund. The mint operator’s discretionary compensation policy is separate. See market resolution.

The web app keeps wallet alerts until you dismiss them. Use Next to read more alerts without dismissing an unresolved alert. Use First alerts to return to the start. Dismissing an alert does not stop recovery or delete funds.

The Active trade progress list shows operations that the wallet still needs to finish. It survives a reload while the wallet data remains available. Use Refresh status to check again. An unavailable status is not a failed trade. A confirmed settlement can still need wallet recovery. Refund eligibility does not mean a refund is complete. An operation leaves this active list when the wallet finishes its work. The list is not your completed-trade history.

Wallet preparation is separate from order acceptance. The progress list shows which stage is confirmed. A prepared payment does not prove that the engine accepted an order. A rejected order can still need funds recovery. An accepted order is not a completed trade until settlement is confirmed.

Your wallet sends the ecash records, called proofs, that authorize this order. The engine sees those proofs and their secrets. It does not receive your recovery phrase, the private material needed to unlock the received outputs, your refund key, or your other wallet proofs.

The engine can select only the outputs your wallet authorized. It cannot redirect that value or extend the authorization. It can delay settlement, which can keep the authorized funds unavailable until a refund becomes valid.

See the technical settlement protocol for authorization rules, fill and group identifiers, conversion types, and client retry requirements.