Technical architectural reference for developers: How Interphase decouples liquidity requesters from market maker solvers using COTI L2 Garbled Circuits as a confidential control plane, while utilizing NEAR Intents native multichain vaults for fund custody and threshold settlement.
A core design constraint of the Interphase Protocol is zero custom custody escrow contracts on source and destination chains. We do not deploy or maintain custom asset bridges, omnibus pool contracts, or custom custody vaults on Ethereum, Base, Solana, Bitcoin, or Sui.
InterphaseCotiRouter.sol) exclusively on COTI L2 to evaluate intents inside Garbled Circuits, screen compliance, and completely unmask source identities before orders reach solvers.
The Mental Model ("The Blind Courier"):
Imagine Alice places $5,000 in a standardized bank vault on Ethereum and receives a cryptographic ticket. She writes her secret delivery instructions inside a sealed envelope and hands it to a group of blindfolded examiners inside a secure room (COTI Garbled Circuits). The examiners check that the money is clean, permanently shred Alice's name and signature off the ticket, and push an anonymous work order out the door: "Deliver 5,000 USDC to single-use address P_stealth on Solana, get reimbursed on Ethereum." An independent courier (The Solver on NEAR Intents) fulfills the delivery without ever knowing Alice exists.
Alice deposits Asset X into the native NEAR Intents Deposit Vault with a 32-byte blind commitment hash H_intent.
InterphaseCotiRouter.sol receives the encrypted intent via a Gasless Paymaster. Garbled Circuits verify compliance and strip Alice's identity.
The sanitized intent is emitted into the intents.near solver pool. Solvers bid blind; winning solver fronts liquidity to P_stealth on destination.
Destination inclusion verified by NEAR Chain Signatures. The NEAR source vault releases Asset X directly to the solver.
When Alice initiates a transfer (e.g. from Ethereum to Solana), her client does not write plaintext routing details to the blockchain. Instead, she deposits into the standard NEAR multichain deposit vault with a cryptographic commitment:
On-Chain Trace: On Etherscan or block explorers, observers only see that 0xAlice transferred 5,000 USDC into the NEAR Multichain Vault matching H_intent. It is mathematically impossible to infer the target chain (Solana), the destination asset, or the recipient.
Alice’s client encrypts the intent parameters using the COTI Network MPC Public Key (@coti-io/coti-ethers). To solve the EVM metadata leak confirmed by Soda Labs (where standard EVM headers expose tx.origin):
from: 0xInterphasePaymaster. Alice’s personal wallet address never appears in the COTI block header.
Inside our deployed contract on COTI L2 (InterphaseCotiRouter.sol), the MPC validator cluster evaluates the encrypted payload inside Yao's Garbled Circuits:
// Pseudocode of Garbled Circuit MPC Logic inside InterphaseCotiRouter.sol
function evaluatePrivateIntent(
bytes calldata encryptedPayload,
bytes32 depositCommitment
) external returns (SanitizedOrder memory order) {
// 1. Decrypt inputs into private wire labels inside MPC
(address sourceSender, uint32 destChain, bytes32 pStealth, uint256 amount) = mpcDecrypt(encryptedPayload);
// 2. Blind Sanctions Screening (ComplianceSMT.sol)
bool isClean = complianceSMT.verifyNonInclusion(sourceSender);
require(isClean, "Sanctions Violation");
// 3. Stateful 24-Hour Rolling Identity Velocity Limiter
enforceRollingVelocityLimit(sourceSender, amount);
// 4. Identity Stripping: Only output wires are revealed!
// sourceSender is permanently erased from memory.
order = SanitizedOrder({
destChainId: destChain,
stealthRecipient: pStealth,
payoutAmount: amount,
depositCommitment: depositCommitment
});
emit PrivateIntentEvaluated(order);
}
The sanitized order is emitted into the NEAR Intents solver market (intents.near / Defuse).
What the Solver Sees:
The market maker only sees: "Deliver 5,000 USDC to Solana stealth address P_stealth. Claim reimbursement for H_intent from NEAR Ethereum Vault." The solver has zero visibility into who deposited on Ethereum.
Destination Address Derivation (ECDH Math):
The recipient’s address P_stealth is generated client-side using non-interactive Elliptic Curve Diffie-Hellman:
The solver transfers 5,000 USDC + an atomic native gas subsidy (e.g. 0.005 SOL) to P_stealth. The recipient sweeps the funds locally using their private spending key p_stealth = s + Keccak256(S_shared).
Once the settlement transaction finalizes on Solana (32-slot commitment gate):
H_intent.Below is the exact data matrix showing what each actor knows vs. what is mathematically concealed from them:
| Information Field | Alice (Requester) | Solver (Market Maker) | NEAR Intents Vaults | COTI MPC (Soda Labs) | Public Observers |
|---|---|---|---|---|---|
| Source Depositor Address (0xAlice) | Known | 100% HIDDEN | Known (Deposit only) | STRIPPED IN MPC | Sees Vault Deposit |
| Target Destination Chain & Token | Known | Known (To fulfill) | 100% HIDDEN | Processed in Dark | 100% HIDDEN |
| Destination Stealth Address (P_stealth) | Known | Known (Payout target) | Verified in proof | Emitted output wire | Sees random burner |
| Real Identity of Recipient | Known | 100% HIDDEN | 100% HIDDEN | 100% HIDDEN | 100% HIDDEN |
| Link between Alice & P_stealth | Known | 100% HIDDEN | 100% HIDDEN | 100% HIDDEN | 100% HIDDEN |
| COTI Transaction Envelope (Metadata) | Masked by OHTTP | Never touches COTI | N/A | Sees Paymaster only | Sees Paymaster only |
When building out or integrating with this architecture, focus exclusively on these key boundaries:
Deployed on COTI L2 (Testnet: chainId: 7082400).
@coti-io/coti-contracts for Garbled Circuit precompiles.ComplianceSMT.sol (Sparse Merkle Tree for sanctions).evaluatePrivateIntent() to emit sanitized orders.packages/contracts-coti/src/InterphaseCotiRouter.solRuns locally in browser/mobile WASM.
@noble/curves (secp256k1 & ed25519).H_intent deposit memo for the NEAR vault.@coti-io/coti-ethers.packages/sdk/src/client.ts