Whitepaper

Fair-value settlement for tokenized stocks on Solana

Every order rests on one book per stock and settles at the next official price published by the market: one number, one moment, everyone equal.

Version
v0.3
Updated
September 2026
Sections
9
Reading time
8 min

1. The problem

Tokenized stocks arrived on Solana faster than the markets to trade them. xStocks lists 700+ equities and ETFs; Ondo, Backpack Securities × Sunrise, and PreStocks add hundreds more. Yet almost all on-chain volume runs through AMM curves designed for memecoins. Buy $40,000 of a stock token and you pay a percent over the real price; sell it and you get a percent under. Two people who want opposite sides of the same trade, in the same minute, hand more than 1% to a curve because there was nowhere for them to meet.

Traditional markets solved this decades ago with the auction: every afternoon the closing cross takes every order it has been handed and fills them all at one official number. Index funds worth trillions trade this way because it is the fairest price available.

OpenBell brings that mechanism on-chain, for every tokenized stock, from every issuer.

2. How it works

One standing book per stock. Bids rest in USDC. Asks rest in the stock token. Orders wait; they are not matched against a curve.

Settlement on every print. Each time the oracle (Pyth, with Chainlink support) publishes a new price for the underlying share, anyone can call settle. The book records a round: the print, and pro-rata fill ratios for both sides. The smaller side fills completely; the larger side fills proportionally and the remainder keeps resting for the next print.

Push delivery. A public keeper calls deliver for every order in the round. Tokens land in the trader's wallet. Nobody comes back to claim anything.

One price, plus a premium. Buyers pay the print plus a small premium (25 bps by default). That premium is the only cost in the system. There is no spread, no slippage, no curve.

No pick-offs, no traps. An order can only be cancelled after at least one print has passed since it was placed: you cannot see a bad number coming and pull out ahead of everyone else. Proof is a newer print, not a settled round, so an order with no counterparty is never stuck; and if a feed goes silent for 72 hours the order can leave regardless.

Selected observations. Books do not have to settle on every tick. Each book carries a cadence: every print, at most one round per interval, or open-and-close only. Sparse books batch orders so both sides have time to arrive; liquid books settle continuously. Settlement never creates an empty round.

Guaranteed liquidity. If an ask rests longer than the book's backstop window (30 minutes by default), the book's backstop vault fills it at the same public price. Sellers are never stranded.

Fill now, or fill at print. A seller who does not want to wait can trade straight against the backstop vault at the latest print plus a spread. A dealer quoting an old price is the classic way to lose money in this business, so fill-now is deliberately limited: it only quotes against a print younger than two minutes (so never on a stale weekend close), it caps any single trade at 20% of vault inventory, and the vault's stock is relisted into the auction rather than held. When the market is closed, fill-now is closed. The stress test that set these limits is in the research archive.

3. Issuer-agnostic by design

OpenBell does not issue, custody, or endorse any token. It settles whatever exists. A stock token needs two things to get a book: a mint and a price feed. Registration and book creation are permissionless. The registry is rebuilt daily from the issuers themselves (xStocks product pages, Jupiter's verified list, Pyth's feed catalogue), so a listing that goes live on Sunrise this morning has a book by tonight.

Platforms plug in the same way. A launchpad, terminal, or wallet registers once as an integrator, tags the orders it routes, and earns a share of every premium those orders generate. StonkFun, pump.fun Custom Pairs, Terminal, Jupiter: any of them can offer their users auction-priced stock fills without building an exchange.

4. The $BELL flywheel

MOO, the Robinhood Chain protocol OpenBell descends from, has one widely noted weakness: the premium goes entirely to the seller. Nothing accrues to the protocol, to liquidity providers, or to the platforms that bring order flow, so nothing compounds.

OpenBell is built around one principle: the people who fund fills eat the most. A stock token needs USDC sitting in its backstop vault for "fill now" and guaranteed fills to exist at all. Everything below points revenue at those depositors first, and gives the token a reason to exist on top of them rather than instead of them.

Where the money comes from. Every premium splits on-chain: 59% to the seller, 15% to the integrator that routed the order, 1% to whoever landed the settle transaction, 25% to the treasury. Every fill-now spread pays 75% to the vault that took the trade and 25% to the treasury. Vault LPs are therefore earning before the treasury is even split: they keep the seller's share on every fill they backstop and most of every fill-now spread.

Where the treasury goes.

ShareRecipientWhy
60%Vault LPs, weighted by boostThey make fills possible
25%$BELL stakers, via buyback-and-distributeHolding is rewarded; staking is rewarded more
15%Protocol operationsAudits, keeper infrastructure, integrations

Boost. A vault position earns at 1x with no $BELL staked. Staking $BELL against your USDC raises the multiplier, up to 2.5x when staked $BELL matches your deposit at the protocol's reference ratio. The token is bought by exactly the people the system needs, in proportion to the capital they have committed. A wallet holding $BELL with no USDC in a vault earns nothing from the LP stream; it gets the buyback tailwind and nothing else.

Priority fills. At every print, bids from stakers are filled before regular bids. Queue position is the one benefit money alone cannot replicate.

Who ends up ahead, in order: a vault LP who also stakes $BELL; a vault LP who doesn't; a $BELL staker with no USDC deposited; a passive $BELL holder. That is the order of how much each one makes the product work, and it is intentional.

The $BELL transfer tax. $BELL is a Token-2022 mint with a 2% transfer fee. Every transfer of the token, buys and sells on any venue included, withholds 2% at the token level; there is no way to route around it and no venue that is exempt. Transfers into and out of the staking contract and the treasury are the only exemptions, so participating in the protocol is never taxed. Withheld fees are harvested by the keeper into the treasury and used for one thing only: buying $BELL on the open market. Purchased tokens are distributed to stakers. Combined with the 25% treasury share of premiums, this gives $BELL two independent revenue streams: one from stock trading, one from its own trading.

The savings ledger. Every fill records the pool price at that moment next to the print it settled at. The difference, summed, is published as a running total and as a leaderboard by integrator.

The loop: more listings → more books → more premium and fill-now spread → deeper vault yield → more USDC in vaults → more $BELL staked to boost it → tighter guaranteed fills → more order flow. Every turn makes the fair-price promise stronger, because the promise is enforced by the mechanism, not by a market maker's goodwill.

5. Why this matters for Solana

Solana carries roughly 95% of tokenized-stock volume on-chain. If that volume keeps settling through memecoin curves, tokenized equities stay a curiosity. If it settles at the official print, Solana becomes the venue where retail and institutions get the same fill quality as the NYSE closing auction, 24 hours a day, for any listed company in the world. OpenBell is that layer: public, permissionless, and indifferent to which issuer's token you hold.

6. Roadmap

  • v0.3 (now): standing books, Pyth settlement, push delivery, cancel lock, premium split, backstop vaults, integrator registry. Live.
  • v0.4: Chainlink Data Streams as a second oracle; per-book oracle choice; print-evidence exit rule, per-book settlement cadence, fill-now freshness and size limits, research replay. Audit.
  • v0.5: $BELL staking contract, fee discounts, treasury distribution. Expanded set of books.
  • v1: governance over config and treasury; integrator SDK packages for launchpads.

7. Measured, not claimed

We do not claim an execution advantage over pools. We measure one, and publish the measurement whether or not it flatters us.

The research archive (research/) contains an economic replay that sends identical demand, with identical capital, through an OpenBell book and a constant-product pool. In the current run (five days, $250k capital, twelve intents an hour, 1,427 intents), the book fills 1,203 of them at a median 91 bps from the reference price at arrival, with a median wait of around ten hours and 179 orders still resting at the end; the pool fills almost everything instantly at a median 167 bps, with a 90th percentile above 2,600 bps on large orders. The book's cost is mostly the price drifting during the wait, not the 25 bps premium. The honest summary is a trade: certainty of price against certainty of time. Fill-now exists to let each trader choose which one they want.

Live, the savings ledger records the pool price beside every settled print. The number on the home page is that ledger, not a projection.

8. Prior work

OpenBell descends from MOO (Market On Open: Standing liquidity at the next reference price, Zenodo 2026, doi:10.5281/zenodo.22730358, CC-BY 4.0), a standing crossing book on Robinhood Chain. We keep its core idea, unmatched deposits that stay active across rounds, and depart from it in: push delivery instead of per-round claims; a premium split that funds integrators, keepers, liquidity providers and the protocol; permissionless backstop vaults with a fill-now path; multi-oracle settlement; priority fills; issuer-agnostic registration across every Solana stock issuer; and a per-book settlement cadence. MOO's own report notes that an execution advantage has not been established; §7 is our answer to that.

9. Risks

  • Transfer-fee tokens. A 2% fee applies to every transfer, which some venues and wallets handle poorly and which makes $BELL unsuitable as collateral or as a routing asset. It is a governance and boost token, not a currency.

Start using it

Place an order on any book, deposit into a backstop vault, or route your platform's order flow through OpenBell.