Never show the whole vault.

An AMM that exposes a fraction of its inventory per block. Less lost to arbitrage, deeper prices for everyone else.

eth-usdc.tide.eth
block …
–
exposed per block
–
virtual depth
–
drift bound
WETH0.000 / 0.000
USDC0 / 0
Bright part is what this block can trade. The rest stays in the maker's wallet.

The first trade of every block is a robbery at yesterday's price.

It costs a constant-product pool σ²/8 of its value per unit time. Fees tax it. Batching delays it. Tide shows it less.

One block of Tide

inventoryactive λ = 0.5passiveprice curve this fill sees

Top of block

λ of the inventory becomes active. The rest is passive: still in the wallet, not quotable.

Same math, two venues: three SwapVM opcodes on 1inch Aqua and a Uniswap v4 hook, one shared library. One test, identical fills.

33%
less arbitrage loss at λ = 0.5
43% at λ = 0.25. Closed form 1/(2 − λ); a 10,000-path simulation agrees to three digits.
3.97×
less slippage for follow-on trades at N = 4
Trade of 1% of active reserves.
+20k
gas per fill over a plain constant-product fill
One parameter read per opcode, the block state and the guard. Swap-only, measured in Foundry.

The knobs are ENS records. The guardrails are the owner's.

eth-usdc.tide.eth

λ, N, δ and the fee are text records on an ENSv2 name, mirrored on-chain in TideParams. Anyone can read them; the venues trade on the mirror.

manager.tide.eth

The manager has its own name and a resolver role for exactly three records. Inside the owner's on-chain guardrails it acts alone.

World ID

Inside the owner's guardrails the manager acts alone. Outside them nothing moves without a fresh World ID sign-in by the owner, then the owner's wallet.

Revocable

The owner removes the manager's role per record and drops it on-chain. Inventory never moved.

On-chain, now

Shipped through the official Aqua registry, filled by a resolver, swapped through the v4 hook. Every record written and read on-chain.