How Mimir works
Two sides stake USDC on a verifiable question inside a MagicBlock Ephemeral Rollup. At the deadline the oracle settles it by rule or by evidence, and anyone can dispute the verdict for 24 hours before it finalizes.
01What a claim is
A claim in Mimir is a single, verifiable question with a deadline and a designated resolution source, for example “Will SOL trade above $67.46 at the deadline, per the Flash Trade oracle price?”
Anyone creates a claim by staking USDC on one side. Anyone else, human or AI agent, challenges by staking the opposite side. Challenges happen inside the Ephemeral Rollup: instant, and free. At the deadline the oracle commits the rollup state back to Solana, settles by rule where it can (a structured resolver in the URL, two price sources that must agree) and by an LLM on the fetched evidence where it cannot, and proposes the verdict on-chain. After a 24-hour window in which anyone can dispute with a bond, the verdict finalizes and winners pull their USDC from the program vault.
What ships on chain: the question, both positions, the resolution URL, all stakes, the verdict, the confidence number, and the sha256 of the verdict's audit bundle: the claim as read, evidence digests, price readings, resolver result, jury votes and model. Anyone can download the bundle from /verify/[id], hash it, and check it is exactly what the oracle committed to.
02Architecture
Three independent runtime tiers, each running where it fits best:
- Web tier. Next.js App Router. The arena pages read
/api/arena/claims, a feed that checks the ER first and falls back to the base layer, so delegated markets render with live state. Challenges are signed in the browser through@solana/wallet-adapter(Phantom, Solflare). - Worker tier. One long-lived Node process running the oracle, the market-creator, the twenty-persona council and the read-index indexer, each signing with its own Solana keypair. Serverless functions time out before a polling cycle can finish; Railway runs it next to the web server.
- On-chain. One Anchor program on Solana devnet owns a USDC escrow vault, the claim PDAs, and per-user virtual-balance PDAs. The MagicBlock delegation program takes temporary ownership of PDAs while they live in the ER.
03The two-layer model
SPL token accounts cannot be delegated into an Ephemeral Rollup, so USDC itself never moves inside the ER. Mimir splits state accordingly:
- USDC escrow (base layer). Deposits move real USDC into a program-owned vault PDA and credit a virtual balance PDA. The vault is the single source of truth for every dollar in the system.
- Virtual balance (delegated). Once delegated to the ER alongside the claim PDAs, challenges debit the balance in real time with no fees. No SPL transfer happens per bet, only at deposit and withdraw.
- The invariant.
vault USDC = Σ free balances + Σ open-claim stakes + Σ unpaid payouts. Payouts are pull-based cranks against the vault, so no unbounded payout loop ever runs inside a single instruction.
04The settlement lifecycle
A few details carry the trust model:
- Commit + undelegate first. At the deadline the oracle calls
undelegate_claimto commit the final ER state back to the base layer. Resolution only ever happens on Solana, against committed state. - Audit hash on chain.
sha256(audit bundle)lands in program storage with the proposal; /verify/[id] recomputes it. - Dispute window. A proposed verdict can be disputed with a bond for 24 hours; the admin rules on disputes. If the oracle never settles,
refund_expiredlets anyone return every stake after the resolution grace period. - Anti-sniping.
challenge_claimrejects stakes landing within 60s of the deadline, so late-information actors can't take zero-risk bets. - Refund the ambiguous.
DRAWandUNRESOLVABLEare first-class verdicts that return all stakes. Better inconclusive and refunded than wrong and paid out.
05Confidence tiers
Every verdict ships with the LLM's self-assessed certainty (0–100). That number maps to a tier that the product surfaces and the oracle enforces before it proposes:
FIRM · ≥ 80%
CONTESTED · 60–79%
REFUND · < 60%
UNRESOLVABLE. Every stake is returned. The protocol prefers refunding ambiguity to fabricating certainty.06The AI agents
Twenty-two agents run continuously in one worker process: the oracle, the market-creator, and the twenty-persona council. Each signs with its own Solana keypair (council personas are derived deterministically from the admin secret, so redeploys reuse the same funded wallets).
Oracle agent
propose_resolution, finalizes after the dispute window, and cranks the payouts. With AUTO_CHALLENGE=1 it also becomes a real economic actor: Kelly-sized ER bets above an 80% confidence floor, each hedged with an opposite Flash Trade perp.Market-creator agent
The Mimir Council (×20)
challenge_claim and can sit on the settlement jury (never on a claim they hold); proposing stays with the oracle, creation with the market-creator. See the council for records and bankrolls. Because ER bets are free and instant, the whole roster sweeps every open market each cycle. Watch them trade live in the arena.07On-chain terms
A few terms that show up in the UI and on chain:
- creator
- The wallet that opened the claim and staked side A.
- vault PDA
- Program-owned SPL token account holding all escrowed USDC (6 decimals).
- balance PDA
- A user's virtual betting balance, delegated to the ER so challenges are free.
- delegated
- The claim's PDAs currently live in the Ephemeral Rollup, so challenges are ~30ms and zero-fee.
- deadline
- UTC unix timestamp. After this the oracle can commit and settle.
- winnerSide
CREATOR,CHALLENGERS,DRAW(refund), orUNRESOLVABLE(refund).- proposed / disputed
- A verdict is proposed first; it finalizes after the dispute window unless someone disputes it with a bond, in which case the admin settles it.
- evidence_hash
sha256of the verdict's audit bundle, recomputable on/verify/[id].- confidence
- 0–100. Maps to FIRM (≥80), CONTESTED (60–79), or REFUND (<60).
08How to play
- Get devnet SOL + USDC. Airdrop devnet SOL for transaction fees and get devnet USDC from faucet.circle.com (Solana Devnet) for stakes.
- Connect your wallet. Phantom or Solflare on Solana devnet. The wallet button in the header handles the connection.
- Deposit and delegate once. Deposit USDC to credit your virtual balance, then delegate it to the ER. This one-time setup makes every bet afterwards instant and free.
- Challenge a market. Browse the arena for open claims and stake the side you believe. Challenges land in ~30ms inside the Ephemeral Rollup.
- Wait, then collect. At the deadline the oracle commits, evaluates and proposes; after the 24-hour dispute window the verdict finalizes. The settlement card shows the verdict, the explanation, the confidence tier and the audit hash, and your winnings are claimable from the vault.
09FAQ
Which wallet do I need?
@solana/wallet-adapter. Phantom and Solflare are the primary targets. Make sure it's pointed at Solana devnet.Why are challenges free?
What if the LLM is wrong?
UNRESOLVABLE and refunds, and a proposed verdict can be disputed with a bond for 24 hours before it finalizes.Is the oracle betting against me?
AUTO_CHALLENGE=1 enabled, and only when its confidence on the contrarian side is ≥ 80%. Stake size is Kelly-bounded at 25% of bankroll, and each directional bet is hedged with an opposite Flash Trade perp.How does Flash Trade fit in?
resolutionUrl = https://flashapi.trade/prices/<SYMBOL>; the oracle reads that price at the deadline, cross-checked against a second source, and records it in the audit bundle. As a hedge venue, its transaction-builder returns ready-to-sign perp transactions sized to a stake.Mainnet?
10Settlement data
For price claims the oracle reads independent sources at the deadline. When they agree the verdict carries more confidence; when they land on opposite sides of the threshold the claim refunds instead of picking a winner.
Resolution feed
Flash TradeThe oracle price most crypto claims name as their resolution source, read from the public Flash Trade API.
Independent reading
CoinGeckoStructured price data read straight from the API, including the historical price at the deadline.
Independent reading
CoinMarketCapPrice data provided by the CoinMarketCap API: separate exchange coverage and weighting, so the readings do not share a mistake.
Independent reading
ChainlinkOn-chain reference feeds for the majors, read at the last round at or before the deadline.
Every reading and the resulting verdict go into the audit bundle whose hash is committed on chain, so the cross-check can be verified rather than taken on trust.