Chainlink candidate live · exact-match source · four successful evidence paths    Uniswap v4 Hook

Verified flow. Netted before the AMM.

Institutional access and execution for Uniswap v4.

PROVE ELIGIBILITY ONCE · REUSE SCOPED ACCESS · NET VERIFIED FLOW BEFORE THE MARKET

ILAL NETTING STATUS npm next
canonical batch100 / 70
internal match140 gross
AMM residual30 token0
Solidity tests282
current Chainlink candidate live · source exact-matched

Live Chainlink-guarded netting evidence

Offset first.
Route only what remains.

The current Base Sepolia candidate checks Chainlink USDC/USD and USDT/USD reference feeds before opening every batch, then nets verified orders and sends only the residual to Uniswap v4. The paired hUSDT is an ILAL test representation, so its USDT reference feed demonstrates fail-closed oracle plumbing rather than hUSDT market-price validation. All first-party contracts have Sourcify exact creation/runtime matches. Active v0.3.3 remains a separate unaudited testnet demo.

Current candidate acceptance Chainlink reference feeds → atomic netting → only the 0.03 residual reached the AMM.

Machine-generated institutional validation

Pressure tested.
Economically bounded.

RESULT PENDING

Run make study-report to generate this evidence from repository results.

Strict-gate net benefit—Base fee + solver reserve
Economic matrix—measured + explicit unsupported rows
Stateful pressure—handler calls
RWA issuer scale—PII-free synthetic wallets
Chainlink guard delta—gas over constant snapshot; full batch used for verdict

SUPPORTED—

NOT SUPPORTED—

ILAL profitability heatmap across notional and matching ratio
Profitability · local signal; strict Base fee gate shown above
ILAL capacity frontier by liquidity multiplier
Capacity · safe notional changes with depth, tick and physical balances
Full method, JSON, CSV and bilingual reports ↗

Customers

Built for the desks
that cannot trade naked.

ILAL removes redundancy at both institutional boundaries: Session reuses a short-lived eligibility grant while each scoped action token remains one-time, and SOEE nets offsetting verified flow before the market. Institutions sign locally, permissionless solvers submit canonical batches, and issuers retain their compliance perimeter.

Institutional trader

Trade without routing gross flow through the AMM.

Prove eligibility, then sign exact-input EIP-712 orders locally. Offset flow settles directly between users while only the imbalance touches public liquidity.

Outcome: less AMM exposure + atomic settlement
Market maker

Compete on discovery, not settlement discretion.

Find offsetting orders and submit them in strict canonical order. For a fixed signed set, allocation is deterministic and permutation-independent; execution is permissionless.

Outcome: open solving + canonical fixed-set fills
RWA issuer

Control eligibility without taking custody.

Manage eligible wallets through CNF, EAS or ZK policy paths. The hook and router finish every batch with zero token inventory.

Outcome: issuer-owned compliance perimeter

Product suite

Protocol, tools,
and proof surface.

Protocol

InstitutionalNettingHook

Uniswap v4 hook for eligible stablecoin flow. It verifies exact-input orders, matches opposite directions at raw-unit 1:1, and permits only the net residual to reach the pool.

  • 2–16 orders · strict ascending order hash
  • canonical sequential allocation for a fixed signed set
  • batch-opening ±100 tick guard
Credential

CNFIssuer

Soulbound ERC-721 compliance credential with EAS or ZK issuance, timelocked root/verifier updates, revocation, expiry, and on-chain issuer metadata.

Execution

BatchRouter

Permissionless batch execution with direct user settlement. It transfers matched flow peer-to-peer, routes one residual leg through v4, and leaves both router and hook with zero inventory.

Developer

CLI + npm

@ilalv3/cli@next now includes the netting order, preview, execute and nonce-cancel workflow alongside V1 and V2 tooling. @ilalv3/sdk@next adds V2 session helpers.

npm i -g @ilalv3/cli@next
Audit

Security package

282 Solidity, 56 CLI and 18 SDK tests, plus 100,000 stateful invariant handler calls and 10,000 fixed-seed fuzz cases per critical property. Coverage includes Chainlink failure modes and post-preflight state races, conservation, canonical ordering, solver independence, cancellation, zero inventory and notional break-even stress tests.

The problem

Gross flow. Public impact.
Unnecessary.

Gross AMM routing

Opposing institutional orders independently hit the pool, creating avoidable price impact and fee exposure.

Solver discretion

Opaque ordering and allocation make execution outcomes depend on who wins the batch.

Compliance gap

Generic intent systems do not enforce issuer eligibility at the final execution boundary.

Custody queue

Off-chain netting introduces an operator, balances to reconcile, and another settlement dependency.

ILAL's answer

Verify → match → net → route the residual. Every order is eligibility-gated and signed. Canonical allocation removes permutation discretion within a fixed signed set, atomic settlement removes custody, and Uniswap v4 supplies liquidity only for the unmatched imbalance.

How it works

Four steps.
One atomic batch.

01

Verify eligibility

CNF · EAS · ZK

The candidate uses ILAL's existing eligibility surface. Each order owner must satisfy the pool policy before any matching or AMM interaction can occur.

$ ilal netting order create --side zero-for-one
02

Sign the exact-input order

LOCAL · 0 GAS

EIP-712 binds the owner, side, amount, nonce and deadline. Users retain custody and can cancel a nonce before execution.

✓ Order signed · nonce unique · deadline bounded
03

Canonicalize and match

PERMISSIONLESS

Any solver can sort 2–16 orders by ascending hash and submit the batch. Canonical sequential allocation produces the same fills for every permutation of a fixed signed set; it is not pro-rata or strategy-proof.

✓ 170m gross · 140m internally matched
04

Route only the residual

UNISWAP V4

Matched amounts settle directly between users. One residual leg reaches the AMM under the batch-start tick guard; hook and router end with zero token inventory.

✓ 30m residual routed · settlement atomic
InstitutionalNettingHook.sol — atomic batch path · Uniswap v4
Institution
Signed
orders
→
ILAL Hook + Router
verify + net
✓ eligibility + signature ✓ canonical order ✓ deterministic allocation ✓ direct settlement ✓ nonce consumed
140m matched internally
→
PoolManager
30m residual
executes ✓
Submitted gross volume 170m
Internally matched volume  atomic 140m
Netting fee 0
AMM residual 30m 82.35% AMM exposure reduction
Submitted gross170m
AMM residual30m

Reproducible impact benchmark

Less AMM exposure. Better user output. More execution gas.

Method + JSON ↗
AMM exposure −82.35% 170 gross → 30 residual
Aggregate user output +4.12 bps +0.070000 token vs best vanilla order
LP fee charged −82.35% 0.085000 → 0.015000 token
Local execution gas 3.39× 663,386 vs 195,556
Opposing orderAMM exposure reduced
25
40.00%
50
66.67%
70
82.35%
90
94.74%
100
100.00%
Gas-cost break-even · N / 0.7N flow When does better execution pay for the gas?
Notional sweep + JSON ↗
0.01 gwei$20.80anchor notional
0.1 gwei$208.03anchor notional
1 gwei$2,080.31anchor notional
100 → +$0.070 output · 0.048 gwei break-even 1k → +$0.700 · 0.489 gwei 10k → +$7.000 · 4.894 gwei 100k → +$69.999 · 48.934 gwei
Scenario input: ETH/USD $3,000 · not a live quote Conservative total-gas premium: +485,401 · includes Chainlink guard Fixed candidate depth at 100k/70k: capacity-limited

Controlled Foundry comparison: two 6-decimal mock stablecoins valued at $1, 1:1 initial price, 0.05% pool fee and both vanilla execution orders. The first curve uses fixed liquidity; the break-even sweep scales liquidity with notional. Total gas includes encoded calldata and one ILAL versus two vanilla transaction envelopes, but excludes L1 data fees, production routers, MEV and solver costs. Lower LP fees benefit users but reduce LP revenue on offset flow.

For RWA issuers

Your policy.
Your users. Your control.

Keep KYC and KYB inside your own environment. ILAL turns PII-free eligibility decisions into an encrypted credential tree, publishes only a policy commitment, and lets each wallet prove eligibility locally. The Hook sees a short-lived grant, never the institution's KYC tier, country, provider record, or identity documents.

01
Import decisions Map provider results to a strict PII-free JSON or CSV contract
→
02
Publish policy Commit encrypted-tree roots, KYC tier and jurisdiction rules through your Safe
→
03
Prove privately Export a wallet-bound witness; the institution generates its Groth16 proof locally
→
04
Grant, trade, revoke Short-lived access enables swaps and LP actions; a new policy revision invalidates old grants
V2 issuer sandbox · npm next
npm install -g @ilalv3/cli@next

# Encrypted issuer-owned tree; no identity documents enter ILAL
ilal issuer tree init --issuer "Partner Sandbox" \
  --schema institutional-kyc-v1 --allow-countries 840,826,756 \
  --store ./private/issuer.enc.json --store-password-file ./issuer.password

ilal issuer tree import --file ./issuer-decisions.csv \
  --store ./private/issuer.enc.json --store-password-file ./issuer.password

# Review commitment, publish policy through Safe, export a private witness
ilal issuer tree root --out ./artifacts/policy.json \
  --store ./private/issuer.enc.json --store-password-file ./issuer.password

ilal issuer tree export-witness --wallet 0xInstitution \
  --out ./private/witness.json --store ./private/issuer.enc.json \
  --store-password-file ./issuer.password

# Institution proves locally, activates a short-lived grant, then trades
ilal policy proof generate --input ./private/witness.json
ilal policy grant activate --proof ./artifacts/v2-proof/proof.json \
  --public ./artifacts/v2-proof/public.json

Integration

Install npm next.
Preview before execution.

Step 01

Install the preview CLI

@ilalv3/cli@next contains the netting and V2 candidate tooling. npm latest remains v0.3.3 and ilal init continues to select that active deployment.

npm install -g @ilalv3/cli@next
ilal init
ilal --version # 0.4.0-v2-poc.7

# Public testnet prototype.
# Production use requires audited contracts
# and a real KYC/KYB attester.
Step 02

Create and sign an order

Create an exact-input order bound to its side, amount, nonce and deadline, then sign it locally with an encrypted keystore or supported RPC account.

ilal --keystore institution.json \
  netting order sign --zero-for-one \
  --amount-in 100000000 \
  --min-amount-out 99000000 \
  --max-amm-input 30000000 -o order-a.json

# Output:
# exact-input order + EIP-712 signature
# private key never leaves the signer
Step 03

Preview canonical allocation

Sort the batch canonically and inspect deterministic matched fills and the AMM residual before sending a transaction.

ilal netting batch preview \
  --orders order-a.json order-b.json

# Output:
# submitted gross: 170000000
# internally matched: 140000000
# AMM residual: 30000000 token0
Step 04

Execute the batch

Any solver can submit the exact same canonical batch. Execution verifies eligibility and signatures, settles matched flow, and sends only the residual to Uniswap v4.

ilal --keystore solver.json \
  netting batch execute \
  --orders order-a.json order-b.json

# Output:
# ✓ atomic settlement
# ✓ router inventory: 0
# ✓ hook inventory: 0
Step 05

Cancel an unused nonce

An order owner can cancel a nonce on-chain before execution. Replays, expired orders and duplicate nonces revert.

ilal --keystore institution.json \
  netting nonce cancel --nonce 0x...

# Output:
# ✓ nonce cancelled
# subsequent batch execution reverts

Full CLI reference

ilal statusDashboard: credential · issuer config · pool policy
ilal netting order signCreate and locally sign an exact-input candidate order
ilal netting batch previewInspect canonical allocations and the AMM residual
ilal netting batch executeSubmit an atomic permissionless batch with a residual output floor
ilal netting nonce cancelCancel an unused order nonce on-chain
ilal credential statusCheck whether a wallet holds a valid CNF credential
ilal credential zk-rootCompute the ZK Merkle root for a wallet and expiry
ilal credential proveTrader flow: local ZK proof → mint or renew CNF
ilal swapCompliant swap via ILALRouter with a required slippage floor
ilal oracleTimelocked root, verifier, and proof-domain updates
ilal pool add-liquidityAdd liquidity with maximum token spend bounds
ilal pool remove-liquidityRemove liquidity with minimum token receive bounds
ilal pool policy setRegister compliance policy for a pool
ilal session signSign a standalone SessionToken
ilal policy proof generateGenerate and locally verify a private V2 eligibility proof
ilal policy grant activateCache a short-lived pool grant after on-chain proof verification
ilal deploy --admin 0xSafeDeploy an issuer-owned stack with custom EAS trust domain

Base Sepolia · candidates + active demo

Every claim linked.
Every status explicit.

Current public candidate · Chainlink-guarded netting

Oracle checked first.
Only residual reached the AMM.

Equal-decimal ERC-20 stablecoin PoC: exact-input, raw-unit 1:1 matching, zero netting fee, 2–16 orders and a batch-start ±100 tick guard. Permissionless solver; unaudited.

Current Chainlink candidate pool

Pool ID 0xeab91a…fbc87
Deployment classification institutional pilot evidence · unaudited · not production-ready

Active · Base Sepolia v0.3.3

Verified-flow demo.
Safe-controlled and reproducible.

UHI10 · July 2026
beforeSwap() hook entry point
dynamic fee flag 0x800000
IUnlockCallback router pattern

Pool

Pool ID (dynamic fee, verified flow 0.05%) 0x1a05b4…82d1ad
PoolManager (Base Sepolia) 0x05E733…3408

Public candidate · V2 ZK policy grants

Prove private eligibility once.
Trade on a cached grant.

Base Sepolia PoC only. This separate V2 candidate demonstrates Groth16 policy grants and one-time sessions for direct LP / swap; it does not perform SOEE netting. The Hookathon netting candidate checks current v1 Policy + CNF credentials on signed orders. The proving key uses a development ceremony and the testnet admin remains an EOA.

Fresh public V2 flow · 2026-08-30 Deploy → proof → grant → LP → swap passed on Base Sepolia BaseScan source + ABI verified · reproducible CLI flow · development ceremony · shared test admin/trader/treasury EOA · unaudited

V2 candidate pool

Pool ID 0xdcf7ee…1c4405
Deployment classification public testnet PoC · unaudited