# Statement of Work: ZSwap Completion and Night Mode

**Client:** Midnight Foundation
**Prepared by:** Webisoft (Utkarsh Varma, Lead engineer, Midnight programme; Phil Therien, Partner)
**Prepared for:** Ron Gur-Lavi (Midnight), Mahesh Sashital (Midnight), Thomas Humber (Midnight Foundation)
**Reference:** WS-MN-2026-09-ZSWAP-NIGHT · **Version:** v1.0 · **Issued:** September 15, 2026 · **Valid until:** October 15, 2026
**Total investment:** USD 95,000 fixed price across two workstreams (ZSwap completion USD 25,000; Night Mode USD 70,000)
**Confidential**

---

## 0. How to read this document

This is one agreement with two workstreams that share a dependency.

- **Workstream A, ZSwap completion (USD 25,000, 10 weeks).** Closes the existing dark pool grant by porting ZSwap to the current Midnight stack and releasing it open source.
- **Workstream B, Night Mode (USD 70,000, 30 weeks in three phases).** A new programme that turns ZSwap into a privacy service for orders originating on Ethereum, Solana, Hyperliquid and Polkadot.

Night Mode's first phase depends on ZSwap reaching its second milestone. Everything else in the two workstreams can proceed in parallel. The Foundation can accept Workstream A alone, A plus Night Mode phase A, or the full programme, and can stop Night Mode at the end of any phase.

Sections 1 to 3 are for decision makers. Sections 4 to 9 are the scope. Sections 10 to 14 are commercial and governance. A glossary is at the end.

---

## 1. Executive summary

ZSwap is a shielded order book (a dark pool) on Midnight: two parties agree a trade without anyone else seeing who they are, what size, or at what price. It was built to roughly 98 percent under the dark pool grant, then the network changed underneath it: Ledger v9, a new Compact compiler, Stage Net, local proving and fast sync. It no longer compiles or deploys as-is. The Foundation's position is that every open grant is finished by Christmas 2026 or cancelled. Workstream A finishes it: port to Ledger v9, prove it end to end on Stage Net, publish it as an open-source reference dApp, and close the grant.

Night Mode extends that dark pool beyond Midnight. A trader on Uniswap, a Solana meme-coin market, Hyperliquid or a Polkadot DEX flips a switch; their order is committed as a shielded intent on Midnight, matched privately in ZSwap where a counterparty exists, and any remainder is executed on the origin chain from an account that cannot be linked back to the trader. Every private order pays DUST and a routing fee in NIGHT. Midnight becomes the privacy layer other ecosystems rent, without asking their users to move. No new bridge is built; execution uses keyless accounts controlled from Midnight and existing bridges.

| At a glance | |
|---|---|
| Workstream A price and duration | USD 25,000, 10 weeks, 3 milestones, kickoff week of September 21, delivery November 27, 2026 |
| Workstream B price and duration | USD 70,000, 30 weeks, 6 milestones, phase A October 12 to December 18, 2026; full programme to May 28, 2027 |
| Combined | USD 95,000, 9 milestones, all paid on acceptance |
| First demo | Private Uniswap swap from the 1AM wallet on Stage Net and Sepolia, December 18, 2026 |
| Decision points | End of Workstream A; end of each Night Mode phase |
| Team | Utkarsh Varma and Alvaro Gonzalez; Zeinab Alipanahloo joins as the third engineer in Night Mode phases B and C |
| Your decision | Confirm the grant balance for A, choose the Night Mode option, confirm kickoff dates |

---

## 2. Background and why now

### 2.1 What the Foundation has said

- **Thomas Humber (Foundation):** all grant partnership agreements are finished by Christmas or cancelled. For the dark pool grant, the route he suggested is to port it to the current network, open-source it as an ecosystem reference, and get Webisoft fully paid. The Cosmos bridge grant is to be put on ice: no business case and no BD in the Cosmos ecosystem. He separately floated pairing the 1AM wallet with a team running Night Mode so users can trade privately on Uniswap from the wallet, with fees as the revenue line that makes 1AM investable.
- **Ron Gur-Lavi (Midnight):** finish what is committed before anything new; pitch Night Mode on its value rather than on reusing budget; wants Midnight to be "the execution layer and privacy layer for other things" and asked for examples.
- **Mahesh Sashital (Midnight):** introduced Night Mode on the September 3 weekly: add privacy to existing decentralised applications on Ethereum, Solana and other chains by routing their orders through Midnight. Asked whether ZSwap can become "plug and play into any other chain."

### 2.2 What exists today

- **ZSwap** prototype: contracts, matching logic and front end written against an early Compact release and a pre-v9 ledger. Logic is sound; toolchain is incompatible.
- **1AM wallet** 6.3.11 on mobile and extension with local proving up to K17 and fast sync on by default; an internal build migrated to Ledger v9 for Stage Net. Webisoft runs its own node, indexer, proving and fast sync against Stage Net.
- **Fast sync** generalisation returns wallet state in 0.6 to 0.7 seconds on Stage Net in early tests.
- **1AM CLI** with a terminal UI; proves a K15 shielded transaction natively in about two seconds.
- **ViaLabs USDM bridge** integrated in the 1AM in-wallet bridge; the Shielded canonical bridge exists.
- **SIG Network** is building an MPC SDK whose first version will let a Midnight account control a keyless Ethereum account. Passport integration is next in the queue after the current transaction-model work.
- **Cosmos bridge v1** with a GRANDPA light-client round trip, paused by the Foundation.
- **Passport** contract-to-contract settlement cut account-to-account transfers from two to three minutes to under a minute. ZSwap and Night Mode reuse this pattern.

### 2.3 What this agreement is, and is not

It is the completion of the existing ZSwap grant scope rebased on the live network, plus a new, separately priced Night Mode programme built on top of it. It is not a bridge project, not a token design change, and not a mainnet executor operation. Those are named in the exclusions.

---

## 3. Objectives and outcomes

| Objective | Outcome the Foundation can verify |
|---|---|
| Close the dark pool grant | Public ZSwap repository on Ledger v9, private swap demonstrated on Stage Net, closing report mapping grant deliverables to shipped code, by November 27, 2026 |
| Give Midnight a first public DeFi primitive | ZSwap usable from 1AM, other wallets via the DApp connector, and agents via the CLI, ready for guarded-deployment removal |
| Prove Midnight as a privacy layer for other chains | A trader in 1AM completes a private Uniswap swap on Sepolia and Stage Net; two Night Mode users are matched on Midnight without touching Uniswap, by December 18, 2026 |
| Create utility for NIGHT and DUST from external volume | Every Night Mode order records DUST consumed and a routing fee in NIGHT; fee model agreed with the Foundation's DeFi lead |
| Reach Solana, Hyperliquid and Polkadot | Adapters live on test networks with a solver set and fee accounting by April 2027; Polkadot, SDK and open-source release by May 2027 |
| Leave the ecosystem with reusable assets | Open-source ZSwap, open-source Night Mode stack, a Night Mode SDK for dApps, Build Club onboarding material |

---

## 4. Workstream A: ZSwap completion

### 4.1 In plain terms

The trading logic was finished. The tools it was built with have since changed. Most of the work is rebuilding on the new tools, not inventing new features. Four pieces of work: make it compile, make it trade, make it usable from the wallet, and make it public.

### 4.2 Current state

| Capability | Status | Detail |
|---|---|---|
| Shielded order commitment circuits | Partial | Written for an early Compact release. Compiler surface, standard library and witness handling have changed; circuits must be reworked to compile. |
| Order matching logic | Partial | Implemented against the old ledger state model. Needs re-expression against Ledger v9 contract state and contract-to-contract calls. |
| Shielded token settlement | Partial | Bound to the pre-v9 token and coin model. Ledger v9 changes shielded/unshielded balances and DUST handling. |
| Ledger v9 compatibility | Planned | Not started on ZSwap. Webisoft has already migrated an internal 1AM build to Ledger v9 for Stage Net, so the failure modes are known. |
| dApp front end | Partial | Exists against the old Midnight.js surface. Needs the current DApp connector API and the 1AM connector. |
| Stage Net deployment | Planned | Stage Net is live and Webisoft's infrastructure runs against it. |
| Local proving support | Planned | Circuits sized so order flow proves in the 1AM local prover at K17 or below; CLI prover and proof server as fallbacks. |
| Automated tests | Partial | Contract tests exist for the old toolchain; to be ported and extended for settlement on Ledger v9. |
| Open-source repository and docs | Planned | Deliverable of milestone three. |

### 4.3 Target architecture

Same privacy model, new plumbing: single-transaction settlement on Ledger v9 and circuits sized to prove locally. Nothing safety-critical moves off-chain.

```mermaid
flowchart TB
  subgraph CL [Clients]
    W1[1AM wallet extension and mobile]
    CLI[1AM CLI for agents]
    OTH[Other wallets via DApp connector]
  end
  subgraph DAPP [ZSwap dApp - open source]
    UI[Order UI and history]
    SDK[Midnight.js client]
  end
  subgraph MN [Midnight Ledger v9]
    ORD[Order commitments]
    MAT[Matching contract]
    SET[Shielded settlement]
    DUST[DUST fee handling]
  end
  subgraph INF [Infrastructure - Webisoft operated]
    IDX[Indexer with fast sync]
    PRV[Local prover K17 or CLI prover]
    PS[Proof server fallback]
  end
  W1 --> UI
  CLI --> SDK
  OTH --> UI
  UI --> SDK
  SDK --> ORD
  ORD --> MAT
  MAT --> SET
  SET --> DUST
  SDK --> IDX
  SDK --> PRV
  PRV -.-> PS
```

Private order lifecycle:

```mermaid
sequenceDiagram
  participant A as Trader A
  participant B as Trader B
  participant Z as ZSwap contract
  participant L as Midnight ledger
  A->>A: Build shielded order and prove locally
  A->>Z: Commit order hash and encrypted terms
  B->>B: Build counter order and prove locally
  B->>Z: Commit order hash and encrypted terms
  Z->>Z: Match orders inside the circuit
  Z->>L: Settle shielded balances in one transaction
  L-->>A: Updated shielded balance
  L-->>B: Updated shielded balance
  Note over Z,L: Observers see a settlement occurred, not who traded, what size, or at what price
```

Design principles: shielded by default; single-transaction settlement via contract-to-contract calls; order commitment and reveal circuits at K17 or lower with heavier matching proofs on the native CLI prover; wallet-agnostic through the standard DApp connector; agent-ready through CLI commands.

### 4.4 Work packages

| WP | Work package | Deliverables | Milestone |
|---|---|---|---|
| A-WP1 | Compact and Ledger v9 port | Contracts migrated to the current Compact compiler and standard library. Breaking changes resolved. Ledger v9 token, coin and DUST model adopted. Contract unit tests ported and passing. | M1, week 4 |
| A-WP2 | Settlement and proving | Shielded settlement re-verified end to end on Ledger v9. Circuits sized and benchmarked for local proving at K17. CLI prover path for matching proofs. Deployed to Stage Net with test assets. | M2, week 8 |
| A-WP3 | dApp and wallet integration | Front end on the current Midnight.js and DApp connector. 1AM connector, order and history UX, fee display. Mobile SDK compatibility check. CLI commands for agent-driven orders. | M2, week 8 |
| A-WP4 | Open-source release and handover | Public repository under a permissive licence with README, architecture notes, deployment guide and Docker compose for a local stack. Handover session. Four-week defect-fix window. Grant closing report. | M3, week 10 |

### 4.5 Acceptance metrics

| Metric | Target | How it is measured |
|---|---|---|
| Contracts compile and tests pass on current Compact | 100% of ported tests | CI run on the public repository, shared on the weekly call at M1 |
| Order commitment proof in the 1AM wallet | K17 or lower | Circuit size reported by the compiler; proof generated in the extension without the proof server |
| Matched shielded swap settles | 1 Ledger v9 transaction | Two independent wallets complete a swap on Stage Net; settlement is a single contract-to-contract transaction |
| Order placement from the CLI | Works without a browser | An agent places and settles an order using only 1AM CLI commands at M2 |
| Local stack from the deployment guide | Under 30 minutes | A Midnight engineer follows the README on a clean machine at M3 handover |

### 4.6 Out of scope for Workstream A

- Cross-chain order routing (that is Workstream B).
- Embedding ZSwap inside the 1AM wallet UI (roadmap phase two, a joint product decision).
- The multi-market router and partner market standard (roadmap phase three).
- Production asset listings; mainnet asset policy is the Foundation's call.
- Independent third-party security audit (internal review included; external audit quoted separately once code is public).

### 4.7 Timeline

```mermaid
gantt
  dateFormat YYYY-MM-DD
  axisFormat %b %d
  section A-WP1 Port
  Compiler spike and breaking changes :a1, 2026-09-21, 1w
  Contract migration and v9 model :a2, after a1, 2w
  M1 review :milestone, m1, 2026-10-16, 0d
  section A-WP2 Settlement
  Settlement on Ledger v9 :b1, 2026-10-12, 2w
  Circuit sizing and prover paths :b2, after b1, 1w
  Stage Net deployment :b3, after b2, 1w
  section A-WP3 dApp
  Midnight.js and connector update :c1, 2026-10-19, 2w
  Wallet UX and CLI commands :c2, after c1, 1w
  M2 demo :milestone, m2, 2026-11-13, 0d
  section A-WP4 Release
  Docs, licence, Docker, handover :d1, 2026-11-16, 2w
  M3 acceptance :milestone, m3, 2026-11-27, 0d
  section Buffer
  Contingency to long-stop :e1, 2026-11-30, 3w
```

Kickoff the week of September 21. Week three overlaps Token2049 travel (October 6 to 10), absorbed by A-WP1 being a single-owner task that week. Three weeks of buffer remain before the Christmas long-stop.

---

## 5. Workstream B: Night Mode

### 5.1 In plain terms

Night Mode is a privacy switch for trading on other blockchains. Today, when someone trades on Uniswap or a Solana meme-coin market, everyone can see what they are doing, and some people profit from watching. With Night Mode the trader flips a switch, the order is handled privately through Midnight, and the trade completes on the original venue without revealing who made it. Midnight is paid a small fee every time. It is like buying through a discreet agent: the shop still makes the sale, but nobody in the shop knows who the buyer is.

How it works, in four steps:

1. The trader switches on Night Mode in the 1AM wallet, or inside an app that has added the Night Mode switch.
2. The order is placed privately on Midnight. Where possible it is matched with another private order and never touches the public market at all.
3. Anything left over is executed on the original venue from an account that cannot be linked back to the trader. Outsiders see a trade, not a person.
4. Midnight collects a small fee. The trader's balance updates. The fee is shared between the wallet, the executors and the ecosystem.

### 5.2 Today versus with Night Mode

| | Trading today on Uniswap or a Solana DEX | With Night Mode |
|---|---|---|
| Who can see the order before it fills | Everyone watching the mempool or the order book | Nobody; the intent is shielded on Midnight |
| Link between trader and fill | Public, permanent, copy-traded | Broken; fills come from an execution account |
| Front-running and sandwiching | Routine on large swaps | No signal to act on |
| Where the trader keeps their assets | On the origin chain | On the origin chain; nothing moves to Midnight to trade |
| Midnight involvement | None | Every private order is a Midnight transaction paying DUST and NIGHT |
| Wallet changes required | None | A switch in 1AM, or the Night Mode SDK inside the dApp |

### 5.3 Architecture

Three layers: entry points where a user or agent switches privacy on; a Midnight core that holds intents and matches them in the dark; per-chain adapters that settle what could not be matched internally. No funds are pooled in a shared mixer; every user's execution account is their own.

```mermaid
flowchart TB
  subgraph ENTRY [Entry points]
    direction LR
    WAL[1AM wallet toggle]
    SDK[Night Mode SDK in dApps]
    CLI[1AM CLI for agents]
  end
  subgraph CORE [Midnight core]
    INT[Shielded intent registry]
    ZS[ZSwap dark pool matching]
    COORD[Settlement coordinator]
    FEE[Fee and DUST accounting]
  end
  subgraph EXEC [Execution layer]
    direction LR
    MPC[Keyless accounts via SIG Network MPC]
    SOL[Solver and executor set]
  end
  subgraph CHAINS [Origin chains]
    direction LR
    ETH[Ethereum - Uniswap]
    SOLANA[Solana - meme-coin DEXs]
    HL[Hyperliquid]
    DOT[Polkadot - Hydration and Asset Hub]
  end
  WAL --> INT
  SDK --> INT
  CLI --> INT
  INT --> ZS
  ZS --> COORD
  COORD --> FEE
  COORD --> MPC
  COORD --> SOL
  MPC --> ETH
  SOL --> ETH
  SOL --> SOLANA
  SOL --> HL
  SOL --> DOT
```

A private Uniswap order, end to end:

```mermaid
sequenceDiagram
  participant T as Trader in 1AM
  participant M as Midnight intent registry
  participant Z as ZSwap dark pool
  participant X as Execution account on Ethereum
  participant U as Uniswap
  T->>T: Enable Night Mode and prove intent locally
  T->>M: Commit shielded intent for pair, size, limit
  M->>Z: Enqueue for dark matching
  alt Counter intent exists
    Z->>Z: Match in the dark
    Z->>M: Settle both sides on Midnight
  else No internal match
    Z->>X: Release net order to execution account
    X->>U: Swap via router
    U-->>X: Fill
    X-->>M: Fill proof and balance update
  end
  M-->>T: Shielded balance updated
  Note over U: Public sees one fill from an execution account, never the trader
```

**Two privacy modes, one product**

- **Mode A, matched in the dark.** Both buyer and seller are Night Mode users. Intents match inside the ZSwap circuit and settle on Midnight. Nothing reaches the origin chain. Strongest privacy, cheapest execution; where volume accrues as the user base grows.
- **Mode B, private execution.** Only one side is on Night Mode. The order is released to an execution account and filled on the origin venue at public prices. The fill is public; the trader is not. Delivers value from day one, before there is internal liquidity to match against.

**Chain adapters**

| Adapter | Phase | Approach | Privacy sold |
|---|---|---|---|
| Ethereum and Uniswap | A | Uniswap v3 router first, v4 hooks evaluated during build. Execution through a keyless Ethereum account controlled from the Midnight account via the SIG Network MPC SDK, with a bonded-executor fallback. | Front-running and sandwich protection for large swaps |
| Solana meme-coins | B | Aggregator routing so any meme-coin market is reachable from one integration. Executes from solver-held Solana accounts. | Hiding a wallet from copy-traders and snipers |
| Hyperliquid | B | Order placement through the Hyperliquid API from executor accounts; positions held by the executor set on the user's behalf with ownership recorded on Midnight. | Hiding position building and size |
| Polkadot | C | Swaps on Hydration and Asset Hub via XCM from an executor parachain account; light-client verification pattern reused from the paused Cosmos bridge. | Private DOT and parachain asset swaps |

**What already exists versus what Webisoft builds**

| Already exists | Webisoft builds under this agreement |
|---|---|
| ZSwap dark pool, being ported to Ledger v9 under Workstream A | Intent registry that wraps ZSwap orders with a destination chain, a time-to-live and an execution policy |
| SIG Network MPC SDK, in development; Passport integration next in the queue | Execution account provisioning, per-user account isolation, the Uniswap adapter that acts through those accounts, and a bonded-executor fallback |
| ViaLabs bridge in the 1AM in-wallet bridge; Shielded canonical bridge | Settlement coordinator that uses existing bridges for asset movement rather than building a new one |
| 1AM wallet, CLI and local proving at K17; mobile app shipped | Night Mode toggle in 1AM, CLI commands for agents, drop-in Night Mode SDK for third-party dApps |
| Cosmos bridge v1 with GRANDPA round trip, paused | Reuse of the light-client verification pattern for the Polkadot adapter in phase C |

### 5.4 Economics: privacy as a service

Chains and their users pay a small fee for privacy they cannot get at home, and that fee is denominated in Midnight's assets. The more trading Night Mode handles on other chains, the more demand there is for Midnight's tokens.

| Participant | Contributes | Earns or gains |
|---|---|---|
| Trader on Uniswap, Solana, Hyperliquid or Polkadot | Pays DUST for the Midnight transaction plus a routing fee on each private order | Privacy of identity, size and intent; protection from front-running, copy-trading and position sniping; better fills when matched in the dark |
| Midnight network | Shielded state, proving, settlement | DUST consumption and NIGHT demand on every order, regardless of which chain the trader lives on |
| 1AM wallet and partner markets | Entry point, user experience, order flow | Share of the routing fee; the revenue line that makes 1AM investable as a standalone product |
| Executors and solvers | Capital and accounts on origin chains, execution | Share of the routing fee plus any price improvement captured within policy |
| Ecosystem treasury | Protocol maintenance, adapter upkeep, incentives | Residual share of the routing fee to fund adapters for new chains |

What we will not overclaim: fee levels, the NIGHT and DUST split, and executor incentives are not fixed here. They are a phase A deliverable produced with the Foundation's DeFi lead. Dark-matching liquidity takes time to build; private execution mode is what makes the product useful on day one.

### 5.5 Phases

| Phase | Window | Goal | Contents |
|---|---|---|---|
| A: Ethereum and Uniswap | 10 weeks, October 12 to December 18, 2026 | A user in 1AM enables Night Mode and executes a private Uniswap swap on Stage Net and Sepolia; dark matching works between two Night Mode users | Intent registry contracts; Uniswap adapter and execution accounts via SIG Network; Night Mode toggle in 1AM and CLI commands; fee model drafted with the Foundation DeFi lead; Stage Net demo |
| B: Solana meme-coins and Hyperliquid | 12 weeks, January 11 to April 2, 2027 | The same intent can target a Solana meme-coin market or a Hyperliquid order; a first solver set operates executor accounts with accounting on Midnight | Solana adapter via aggregator; Hyperliquid adapter; solver and executor set v1; fee accounting live on Midnight; mobile SDK parity |
| C: Polkadot, SDK and open source | 8 weeks, April 5 to May 28, 2027 | Polkadot adapter ships; third-party dApps can add a Night Mode switch with the SDK; the stack is public for Build Club cohorts | Polkadot adapter via XCM; Night Mode SDK for dApps; open-source release and docs; Build Club onboarding material; security review of adapters |

```mermaid
gantt
  dateFormat YYYY-MM-DD
  axisFormat %b %Y
  section Phase A
  Design and fee model :a1, 2026-10-12, 2w
  Intent registry contracts :a2, after a1, 3w
  Uniswap adapter and execution accounts :a3, 2026-10-26, 4w
  1AM toggle and CLI :a4, 2026-11-16, 3w
  Stage Net demo :milestone, ma, 2026-12-18, 0d
  section Phase B
  Solana adapter :b1, 2027-01-11, 5w
  Hyperliquid adapter :b2, 2027-01-25, 5w
  Solver set and fee accounting :b3, 2027-02-15, 5w
  Phase B demo :milestone, mb, 2027-04-02, 0d
  section Phase C
  Polkadot adapter :c1, 2027-04-05, 4w
  Night Mode SDK and docs :c2, 2027-04-12, 4w
  Open-source release :milestone, mc, 2027-05-28, 0d
```

Phase A starts after Token2049 so the team can present Passport in Singapore and use the October 8 investor breakfast to test the Night Mode story. Phase A completes before the Foundation's year-end.

### 5.6 What phase A must prove

| Metric | Target | How it is measured |
|---|---|---|
| Private Uniswap swap from 1AM | Works on Sepolia and Stage Net | A trader enables Night Mode, places an order, and the fill appears on Uniswap from an execution account with no link to the trader's wallet |
| Dark match between two Night Mode users | Settles on Midnight only | Two wallets place opposite intents; the match settles without any Ethereum transaction |
| Intent commitment proof | K17 or lower | Proof generated by the 1AM local prover; circuit size reported by the compiler |
| Order to fill latency, private execution mode | Under 3 minutes end to end | From intent commitment on Midnight to fill confirmation on Sepolia, median of 20 runs |
| Fee accounting | Every order records DUST and routing fee | Fee ledger on Midnight reconciles with executor records at the A2 demo |
| Agent access | Full flow from the CLI | An agent completes a private order using only 1AM CLI commands |

### 5.7 Work packages

| WP | Phase | Work package | Deliverables |
|---|---|---|---|
| B-A1 | A | Protocol design and fee model | Intent schema, execution policy, time-to-live and cancellation semantics. Fee model drafted with the Foundation DeFi lead. Threat model for execution accounts. |
| B-A2 | A | Intent registry on Midnight | Compact contracts wrapping ZSwap orders with destination chain and policy. Shielded commitment, reveal-to-executor and settlement-proof paths. Tests. |
| B-A3 | A | Uniswap adapter and execution accounts | Per-user keyless Ethereum accounts via SIG Network MPC, with bonded-executor fallback. Uniswap v3 router integration with slippage policy. Fill proof back to Midnight. Sepolia and Stage Net deployment. |
| B-A4 | A | 1AM and CLI entry points | Night Mode toggle in the 1AM extension and mobile app. CLI commands so agents can place private orders. Order history backed by fast sync. |
| B-B1 | B | Solana adapter | Aggregator-based routing to meme-coin markets. Solver-held Solana accounts. Fill proofs to Midnight. Devnet then mainnet-beta. |
| B-B2 | B | Hyperliquid adapter | Order placement and position tracking through the Hyperliquid API from executor accounts. Ownership recorded on Midnight. |
| B-B3 | B | Solver and executor set, fee accounting | Executor registration, capital bonding, fee split accounting on Midnight in DUST and NIGHT. Operator runbook. |
| B-C1 | C | Polkadot adapter | XCM-based swaps on Hydration and Asset Hub from an executor account. Light-client verification pattern reused from the Cosmos bridge work. |
| B-C2 | C | Night Mode SDK | Drop-in TypeScript SDK and UI switch for third-party dApps on the same DApp connector as the mobile SDK. Reference integration and docs. |
| B-C3 | C | Open-source release and security review | Public repositories, architecture docs, Build Club onboarding material, internal security review of all adapters with findings resolved. |

### 5.8 Status and dependencies

| Capability | Status | Detail |
|---|---|---|
| ZSwap dark pool on Ledger v9 | Partial | Delivered under Workstream A by November 27. Night Mode phase A depends on its M2 milestone (November 13). |
| Keyless Ethereum accounts from Midnight | Partial | SIG Network MPC SDK in development; Passport integration next in Utkarsh's queue. Night Mode reuses that integration, with a bonded-executor fallback if it slips. |
| Bridges for asset movement | Partial | ViaLabs bridge integrated in 1AM; Shielded canonical bridge exists. Ethereum-specific movement via SIG Network keyless accounts pending. |
| Local proving in wallet and mobile | Working | 1AM proves locally up to K17; CLI proves natively in about two seconds for K15; mobile app ships native proving. |
| Fast sync for order history | Working | 0.6 to 0.7 seconds on Stage Net in early tests; being generalised. |
| CLI for agents | Working | Assets, summaries, sending and QR receive exist; Night Mode commands are new. |
| Uniswap adapter | Planned | Phase A. |
| Solana and Hyperliquid adapters | Planned | Phase B. |
| Polkadot adapter | Planned | Phase C. |
| Solver and executor set | Planned | Phase B; reference executor on test networks first. |
| Night Mode SDK for dApps | Planned | Phase C. |

### 5.9 Out of scope for Workstream B

- Building a new lock-and-mint bridge; asset movement uses existing bridges and keyless accounts.
- Providing executor capital; Webisoft operates a reference executor on test networks only.
- Independent third-party audits; internal review is included.
- Token design changes to NIGHT or DUST; Night Mode consumes them, it does not alter them.
- Mainnet execution; a separate decision with the Foundation after the Sepolia and Stage Net demos.

---

## 6. Combined timeline and dependencies

| Date | Event | Workstream |
|---|---|---|
| Sep 21, 2026 | Workstream A kickoff | A |
| Oct 6 to 10 | Token2049 Singapore; Foundation side event October 8 | Both (no milestones scheduled) |
| Oct 12 | Night Mode phase A kickoff, design and fee-model sessions | B |
| Oct 16 | A-M1: contracts compile on Compact and Ledger v9, tests pass | A |
| Nov 13 | A-M2: private swap end to end on Stage Net; B-A1: protocol design and intent contracts | A, B |
| Nov 27 | A-M3: public repository, handover, grant closed | A |
| Dec 18 | B-A2: private Uniswap swap from 1AM on Sepolia and Stage Net; dark match; go or no-go for phase B | B |
| Jan 11, 2027 | Phase B kickoff | B |
| Feb 26 | B-B1: Solana and Hyperliquid orders on test networks | B |
| Apr 2 | B-B2: solver set with fee accounting; go or no-go for phase C | B |
| May 7 | B-C1: Polkadot adapter; Night Mode SDK with reference integration | B |
| May 28 | B-C2: open-source release, docs, Build Club material, security review | B |

Dependencies between the workstreams:

- B-A2 (intent registry) builds on the ported ZSwap contracts from A-WP1 and A-WP2. If A-M2 slipped, Night Mode phase A would still ship private execution mode on time and add dark matching when the port lands.
- Both workstreams use the same Stage Net infrastructure, local proving path and CLI. Fixes land once and serve both.
- Utkarsh leads Passport for Token2049 until 10 October; until then his ZSwap time is architecture and the compiler spike, with Alvaro carrying implementation. From 12 October both are on this work: Alvaro on ZSwap and the 1AM entry points, Utkarsh on the Night Mode protocol and adapters.

---

## 7. Team and responsibilities

| Person | Role | Workstream A | Workstream B |
|---|---|---|---|
| Utkarsh Varma | Lead engineer: architecture, Compact port and settlement, Night Mode protocol and adapters, milestone demos. Leads Passport for Token2049 until 10 October | A-WP1 port, A-WP2 settlement, architecture | B-A1 protocol and fee model, B-A2 intent registry, B-A3 execution accounts, B-A4 Uniswap adapter; B-B2 Hyperliquid, B-C1 Polkadot |
| Alvaro Gonzalez | Proving, 1AM wallet and CLI; shipped 1AM 6.3.11 and the Ledger v9 Stage Net build; carries ZSwap implementation until 12 October | A-WP2 proving paths, A-WP3 dApp and connectors, A-WP4 release | B-A4 1AM toggle and CLI, phase A demonstration; B-C2 Night Mode SDK; mobile SDK parity |
| Zeinab Alipanahloo | Circuits, contracts and security; PhD in privacy-preserving verification; built LayerZero DVN verifier nodes. Joins from 11 January 2027 as the third engineer; fast sync remains her mandate until then | | B-B1 Solana adapter, B-B3 solver set and fee accounting, B-C3 security review |

Two engineers in Workstream A and Night Mode phase A; three from phase B.

What we need from Midnight: two working sessions with the Foundation's DeFi lead in phase A; a direct channel to SIG Network; milestone reviewers on the weekly call; a decision on indexer ownership with the Shielded team (does not block either workstream).

Responsibility matrix (R responsible, A accountable, C consulted, I informed):

| Activity | Webisoft | Midnight engineering | Midnight Foundation | SIG Network |
|---|---|---|---|---|
| ZSwap port, settlement, Stage Net deployment | R | C | I | |
| ZSwap milestone acceptance and grant closure | R | C | A | |
| Licence and repository home | C | C | A | |
| Night Mode protocol design and threat model | R | C | I | C |
| Fee model and executor incentives | R | I | A | |
| Keyless execution accounts | R | I | I | C |
| Chain adapters | R | I | I | |
| Phase demos and go or no-go decisions | R | C | A | |
| Mainnet executor operation | C | I | A | |
| Open-source releases and Build Club material | R | I | A | |

---

## 8. Governance and reporting

- Progress reported on the existing Midnight and Webisoft weekly call; a written completion report after every milestone.
- Code lands through pull requests on public repositories from the first milestone so Midnight can review as work proceeds.
- Each milestone closes with a live demo and a written acceptance from the Foundation on the call or by email. Acceptance is deemed given if no written objection is received within ten working days of the demo.
- Go or no-go at the end of Workstream A and at the end of each Night Mode phase, with no further obligation if the Foundation stops.

---

## 9. Assumptions

1. The Foundation confirms the remaining dark pool grant balance of around USD 25,000 and the Workstream A plan before September 21.
2. Stage Net stays on Ledger v9 for the duration; a breaking Compact release during the port triggers a repeat of the week-one spike and a re-baseline.
3. Midnight reviewers are available within five working days of each milestone demo.
4. The existing ZSwap code and design notes are available to the full team from day one; test assets on Stage Net can be minted by Webisoft or provided within two weeks.
5. The ZSwap port reaches A-M2 by November 13, which Night Mode phase A depends on for dark matching.
6. SIG Network provides SDK access and a technical contact during phase A; if it slips, the bonded-executor fallback is used for the B-A2 demo.
7. The Foundation's DeFi lead is available for two sessions in phase A to shape the fee model.
8. Test networks throughout: Stage Net, Sepolia, Solana devnet, Hyperliquid testnet. Mainnet is a separate decision.
9. Ownership of the Night Mode name and any existing SDK effort inside the Foundation is settled at the first review so this programme is the reference implementation.

---

## 10. Investment

### 10.1 Options

| Option | Scope | Price | Duration |
|---|---|---|---|
| 1 | Workstream A only: ZSwap completion and grant closure | USD 25,000 | 10 weeks |
| 2 | Workstream A plus Night Mode phase A (Uniswap) | USD 56,000 | To December 18, 2026 |
| 3 (recommended) | Workstream A plus full Night Mode programme | USD 95,000 | To May 28, 2027, stop at any phase |

### 10.2 Milestone schedule

| Milestone | Workstream | Acceptance | Target | USD |
|---|---|---|---|---|
| A-M1 | A | Contracts compile on current Compact with the Ledger v9 model; ported tests pass | Oct 16, 2026 | 7,500 |
| A-M2 | A | End-to-end private swap on Stage Net from 1AM with local proving; CLI order placement | Nov 13, 2026 | 10,000 |
| A-M3 | A | Public repository, documentation, deployment guide, handover, grant closing report | Nov 27, 2026 | 7,500 |
| **Workstream A subtotal** | | | | **25,000** |
| B-A1 | B, phase A | Protocol design, threat model, fee model draft, intent registry contracts passing tests | Nov 13, 2026 | 12,000 |
| B-A2 | B, phase A | Private Uniswap swap from 1AM on Stage Net and Sepolia; dark match between two users; CLI order | Dec 18, 2026 | 19,000 |
| B-B1 | B, phase B | Solana meme-coin swap and Hyperliquid order through Night Mode on test networks | Feb 26, 2027 | 14,000 |
| B-B2 | B, phase B | Solver set v1 operating with fee accounting live on Midnight | Apr 2, 2027 | 11,000 |
| B-C1 | B, phase C | Polkadot adapter live; Night Mode SDK with reference integration | May 7, 2027 | 8,000 |
| B-C2 | B, phase C | Open-source release, docs, Build Club material, security review findings resolved | May 28, 2027 | 6,000 |
| **Workstream B subtotal** | | Phase A 31,000 · Phase B 25,000 · Phase C 14,000 | | **70,000** |
| **Total** | | Nine milestones | | **95,000** |

### 10.3 Commercial terms

- Fixed price per milestone, invoiced on acceptance, net 30.
- Workstream A is priced to the remaining dark pool grant balance; work completed on ZSwap before the retainer began is part of the delivered scope and is not billed again. On acceptance of A-M3 the grant is fully delivered and can be closed.
- Workstream B is priced per phase; the Foundation may stop at any phase boundary with no further obligation.
- Both workstreams are priced separately from the monthly retainer. Passport delivery for Token2049 keeps priority until 10 October; the work is scheduled around it and around the fast sync mandate.
- Executor capital on mainnet, external audits, production asset listings, and new-chain adapters beyond the four named are quoted separately.
- Four-week defect-fix window after A-M3 and after each Night Mode phase, at no extra charge.

### 10.4 Change control

Either party can raise a change by email. Webisoft replies within three working days with the effect on scope, schedule and price. Changes under USD 2,500 and one week on Workstream A, or under USD 5,000 and two weeks on Workstream B, are agreed on the weekly call and recorded in the repository. Anything larger, including a new target chain, is a written change note signed by both parties before work starts.

---

## 11. Risk register

| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
| Compact breaking changes run deeper than a mechanical port | Medium | High | Week one is a time-boxed compiler spike across every contract; compiler-team questions raised on the first weekly call |
| Matching circuit too heavy for local proving | Medium | Medium | Commitment and reveal kept at K17 or below; matching on the native CLI prover; browser proving improves roughly 1.8 times once Chrome ships the WASM flag; proof server as last resort |
| Stage Net and preview diverge on Ledger v9 | Medium | Low | Deploy to Stage Net first, re-verify on preview when it matches; patches carry over |
| Team capacity around Token2049 and year-end | High | Medium | Alvaro carries ZSwap implementation until 12 October; Utkarsh joins fully after Token2049; no milestones during Token2049 week; three weeks of buffer before Christmas |
| Christmas long-stop missed on ZSwap | Low | High | Delivery November 27 with three weeks of buffer; contracts release not blocked by dApp work |
| Execution account key custody | Low | High | Keys never held by Webisoft; keyless MPC accounts controlled from the user's Midnight account, TEE-backed signing evaluated in the threat model |
| No dark-matching liquidity at launch | High | Medium | Private execution mode delivers value from the first user; 1AM's user base seeds matching |
| Privacy routing on public DEXs draws regulatory attention | Medium | High | No pooled funds, no mixing; per-user execution accounts; selective disclosure available; design documented for the Foundation's legal review in phase A |
| SIG Network readiness slips | Medium | Medium | Bonded-executor fallback path so the Uniswap demo does not depend on SIG Network timing |
| A parallel Night Mode SDK effort inside the Foundation | Medium | Medium | Ownership aligned at the first review so Webisoft builds with that effort |
| Indexer maintenance responsibility unresolved | High | Low | Both workstreams use standard indexer queries; the fast-sync-specific discussion with the Shielded team does not block them |

Open questions for the Foundation: licence preference (Apache-2.0 or MIT) and repository home; test assets on Stage Net; contracting route for Night Mode (new grant partnership agreement or retainer extension); fee denomination preference; who operates the first mainnet executors; whether Uniswap on Ethereum mainnet or an L2 such as Base is the first production venue; whether the Foundation wants a Night Mode segment in the Passport presentation on October 8.

---

## 12. Next steps

1. **Review with Ron and Mahesh.** Confirm the architecture for both workstreams, the Uniswap-first sequencing, and the open questions. Mahesh introduced Night Mode; we want his view on the economics.
2. **Send to Thomas.** Confirm the grant balance for Workstream A, choose the Night Mode option, and settle the contracting route.
3. **Discuss in Singapore, October 6 to 10.** Phil and Utkarsh are at Token2049; a sit-down with Thomas and the DeFi lead, and a Night Mode mention at the October 8 investor breakfast.
4. **Kickoffs.** Workstream A the week of September 21; Night Mode phase A on October 12. First milestone demo October 16 on the weekly call.

---

## 13. Acceptance

Signing below, or a written confirmation by email referencing WS-MN-2026-09-ZSWAP-NIGHT, accepts the scope, milestones, timeline and commercial terms in this document for the option selected. This offer is valid until October 15, 2026.

| Webisoft | Midnight Foundation |
|---|---|
| Phil Therien, Partner | Thomas Humber, Authorised signatory |
| Signature / Date | Signature / Date |

Option selected: ☐ 1 (A only) ☐ 2 (A + Night Mode phase A) ☐ 3 (A + full Night Mode)

Contacts: Utkarsh Varma, utkarsh@webisoft.com · Phil Therien, phil@webisoft.com

---

## 14. Glossary

| Term | Meaning |
|---|---|
| ZSwap | Webisoft's shielded order book on Midnight, funded under the dark pool grant. Orders, sizes and counterparties are private; only the fact that a settlement occurred is public. |
| Dark pool | A venue where orders are not visible before execution. On Midnight this is enforced by zero-knowledge proofs rather than a trusted operator. |
| Night Mode | A switch, in a wallet or in a dApp, that turns a public order on another chain into a shielded intent on Midnight. Name introduced by the Midnight team. |
| Intent | A signed statement of what a trader wants, without specifying how it is executed. Night Mode intents are shielded on Midnight. |
| Dark match | Two opposite Night Mode intents matched inside the ZSwap circuit and settled on Midnight; nothing reaches the origin chain. |
| Private execution | An intent with no internal match, executed on the public venue from an execution account; the fill is public, the trader is not. |
| Execution account | An account on the origin chain that places the order on the trader's behalf, controlled from Midnight and not linkable to the trader. |
| Keyless account, MPC | An account whose private key never exists in one place; SIG Network's multi-party computation SDK lets a Midnight account control such an Ethereum account. |
| Solver, executor | A party that supplies capital and accounts on origin chains and executes released intents for a share of the routing fee. |
| Adapter | The per-chain module that translates a released intent into a transaction on the target venue and reports the fill back to Midnight. |
| Compact | Midnight's smart contract language and compiler; circuits written in Compact produce the zero-knowledge proofs that validate a transaction. |
| Ledger v9 | The current Midnight ledger version, live on Stage Net; changed the token, coin and DUST model and the contract-to-contract call path. |
| Stage Net, Sepolia | Midnight's pre-production network on Ledger v9, and Ethereum's public test network. |
| NIGHT, DUST | Midnight's token and its resource token; DUST pays for transactions and is generated by NIGHT holders. |
| K15, K17, K20 | Circuit size parameters; higher K means larger, slower proofs. The 1AM wallet proves locally up to K17. |
| Local proving | Generating the zero-knowledge proof on the user's own device instead of a proof server; available in 1AM, mobile and the CLI. |
| Fast sync | Webisoft's technique for pre-computing wallet state on a server so a client processes only the final 100 to 150 blocks. |
| Contract-to-contract call | A Ledger v9 capability where one contract invokes another in the same transaction, letting matching and settlement land in one block. |
| XCM | Polkadot's cross-consensus messaging format, used by the Polkadot adapter. |
| Long-stop | The Foundation's final date, Christmas 2026, by which open grants must be delivered or cancelled. |

---

## Appendix: notes for building the site from this document

- Sections map to the existing proposal template blocks: 1 → summary + stats; 2 → prose + callout; 3 → table; 4.2 and 5.8 → status matrix; 4.3 and 5.3 → diagram blocks (Mermaid source is fenceless in the content file; strip the ```mermaid fences); 4.4, 5.7 → table; 4.5, 5.6 → metrics; 5.2 → compare; 5.4 → table + callout; 5.5 → phases + gantt diagram; 6 → timeline; 7 → cards + raci; 10.1 and 10.2 → options block (three options, milestones tagged with the options that include them) + table; 10.3 and 10.4 → prose; 11 → risks + list; 12 → next steps; 13 → signoff (add the option checkboxes to the acceptance note); 14 → glossary.
- Every technical section (4, 5.3, 5.4, 5.8) opens with a plain-language panel; use the "In plain terms" text above each.
- Decision bar: Investment USD 95,000 (Option 3) · Timeline Sep 21, 2026 to May 28, 2027 · Next decision: Ron review, then Thomas.
- Keep ViaLabs (not Wire Labs), SIG Network "in development", and the mobile SDK described as the shipped mobile app plus a package still to be published.
