Verifiable,not magic
what is on chain
- matches and registrations: one entry per proven wallet, time-checked.
- stakes and the escrow per match, plus refunds when a match is cancelled or void.
- results: a merkle root of every (player, rank, payout), the link to the published bundle, and a challenge window.
- claims: you pull your prize with a merkle proof once the window closes.
the owner can never withdraw a prize pool. there is no function for it. payouts plus the rake must equal the pool exactly, and the rake is capped in code. stakes and sponsor money never share a match, so a sponsored match is free to enter and a staked one takes no sponsor deposits.
what is off chain
the engine executes simulated orders at oracle prices and computes the crowd penalty, copy delays, fade bounties, liquidations, the storm floor, the blackouts and the ranking. units are simulated: nobody trades a real market from inside a match, and the pool is the only real value.
every action you take is a message signed by your wallet, with a nonce and a timestamp, recorded with its receipt time in an append-only log. the engine cannot invent an action for you, because it does not have your signature.
an order fills only at an oracle price published after the engine received it, and a copy fills at the price current three seconds later. no stale fills, no latency games, no front-running the copier.
what fomo decides, and what it does not
fomo decides who plays: the gate reads a public profile, checks age and trades, and takes a signature from the wallet that profile lists. fomo also seeds divisions, the market list and the mirror prompts.
fomo decides nothing about money. scores come from our own oracle archive. if fomo goes down mid-match, the match is scored normally, the social feed freezes, and verifications queue until it returns. fomout is independent and not affiliated with fomo.
how to verify a match
after each match the engine publishes, on ipfs and as downloads:
- the full signed action log, accepted and rejected, with receipt times;
- every oracle observation it used, with the reference to re-read it at the source;
- the frozen rules and seed, the final ranking, and the merkle tree.
the open-source verifier downloads those files, checks every signature, re-reads the prices, replays the match and rebuilds the root. the blackout times come from the published seed, so a replay reproduces them exactly. if the root does not match the one on chain, say so during the challenge window.
npx fomout-verify <results uri> --match <id> --cluster mainnet-beta --rpc https://api.mainnet-beta.solana.com
same log plus same prices always gives the same result. the engine is deterministic on purpose.
challenge window
results are posted on chain by the operator, then a challenge window runs, 24 hours at launch. during the window the owner can revoke a wrong root and post a corrected one, which restarts the window. after it closes the root is final and claims open. nobody can change it after that.
oracle prices, honestly
- pyth price feeds: every observation the engine uses is a pyth update with its publish time, recorded verbatim in the log. the verifier asks pyth for the update published at that second and compares price and exponent. re-reading needs a pyth account (hermes requires an api key since august 2026); without one the verifier reports the price step as skipped, never as passed.
- the confidence interval pyth publishes is recorded for display and never used for settlement: the price is the price.
a market with a stale price stops taking orders, copies, fades and liquidations. if every market is stale for more than five minutes the match is void and every stake is refunded in full.
anti-abuse
- the gate is the first filter: a signature against the address fomo returns, 14 days, 10 trades.
- one account per proven wallet, and a stake makes duplication expensive.
- collusion is answered by the payout shape: degressive slices over the top 10% mean sacrificing an account costs more than it returns, and coordinated positions are visible and pay the crowd penalty.
- royalty farming is capped: 500 units per copier per match, nothing on a losing copy, five-minute minimum hold.
- bots gain little: execution is on the oracle tick, three positions maximum, no trading api during a match.
- nobody is disqualified automatically. a disqualification needs a human decision and the reason is published with the results.
what you still trust
the operator receives your actions and could delay or refuse one; a missing action shows up in the published log. the owner can cancel a match before results are posted, which refunds every stake. an opt-out from mirror is honoured by us, on our side. those are the trust points. the rest is checkable, and the rules say what the engine is supposed to do.