← Latest papers
💻 computer science

Reveal, Correct, Then Pay: Encrypted Mempools and Perpetual Funding Security

This paper argues that encrypted mempools, while effective against maximal extractable value, inadvertently create a security vulnerability in perpetual futures funding by preventing immediate corrective arbitrage during the commit phase, thereby amplifying state manipulation attacks through economic reaction gaps and reduced price capitalization.

Original authors: Benjamin Marsh

Published 2026-07-16
📖 6 min read🧠 Deep dive

Original authors: Benjamin Marsh

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the digital world of cryptocurrencies as a massive, bustling marketplace where people trade digital assets every second. In this market, there's a special waiting room called a "mempool" where transactions sit before they are officially processed and added to the public record. Usually, this waiting room is like a glass box: everyone can see what you are buying or selling before the deal happens. This transparency has a downside: sneaky bots can peek at your order, jump in front of you to buy the same thing cheaper, and then sell it to you at a higher price a split second later. This is called "front-running," and it's like someone seeing you about to buy a concert ticket and buying the best seat first just to sell it to you for double.

To stop this, engineers invented "encrypted mempools." Think of this as putting every transaction into a locked, unbreakable safe. The safe travels through the system, and no one can see what's inside until the exact moment the transaction is officially placed in line. This stops the sneaky bots from seeing your specific trade and jumping the queue. It sounds like a perfect solution, right? Well, this paper asks a tricky question: What if the person putting the transaction in the safe is the one trying to cheat? What if the attacker knows exactly what they are doing, but the market doesn't? The paper explores whether hiding the transaction actually helps the attacker by blinding the market's natural "correctors"—the people who usually fix price mistakes—while the attacker still knows their own plan.

This paper, titled "Reveal, Correct, Then Pay," investigates a specific type of cheating in the world of "perpetual futures," which are long-term bets on the price of an asset. The authors, Benjamin Marsh from Sei Labs and the University of Portsmouth, argue that while encrypted mempools are great at stopping attacks on other people, they can accidentally make it easier for an attacker to manipulate the market for themselves.

The core of the problem is a timing gap. In a normal market, if someone tries to push a price up or down, other traders see it immediately and jump in to fix it, making the price fair again. But with encrypted mempools, the market has to wait for the "safe" to be opened before it can see the manipulation. By the time the safe opens and the market realizes what happened, the attacker has already set up their trap. The paper shows that this delay creates a "reaction gap." Even if the safe opens in a fraction of a second, that tiny delay is enough to stop the market's natural fixers from acting in the same batch of transactions.

The authors model this using the concept of "funding rates," which are payments made between traders to keep the price of a perpetual bet close to the real market price. An attacker can hide a transaction that slightly distorts this price signal. Because the market is blind during the encryption phase, the distortion lasts longer than it would in a transparent market. The paper proves that this extra time allows the attacker to collect more money. Specifically, they find that the profit an attacker makes isn't just a little bit higher; it is quadratic in the product of the attacker's targeting ability and the response factor (which includes the persistence of the distortion). This means if the attacker's ability to target the market stays the same, but the market's ability to correct the mistake slows down even a little, the attacker's potential profit can still increase significantly, driven by that combination of skill and delay.

The paper explicitly rules out the idea that encryption is a universal shield against all manipulation. It argues that for "self-authored" attacks—where the attacker is the one creating the transaction—hiding the order doesn't hide the attacker's intent from themselves, but it does hide it from the market's defenders. The authors show that if an attacker already holds a position (like a bet on the price going up), they can use encryption to distort the price signal, wait for the market to open the safe, and then collect a payout that is much larger than it would have been if the market could react instantly.

However, the paper doesn't just point out a problem; it offers a solution. The authors propose a new rule for how these markets should work: "Reveal, Correct, Measure, Then Pay." Instead of opening the safe and immediately paying out based on the new price, the system should wait. It should open the safe, let the market's "correctors" see the distortion and fix it, measure the price after that correction, and then pay out. This creates a "correction buffer" that gives the market time to heal the wound before the attacker gets their reward.

The authors are very precise about their findings. They use mathematical models and simulations to show that this "reaction gap" is a real, measurable danger. They calculate that even a small delay can significantly increase the attacker's profit, especially if the market usually corrects mistakes very quickly. They also introduce a "security index" that breaks down the risk into three parts: how blind the attacker is, how well the market is shielded from correcting, and how much the market capitalizes on the predictable payout. Their math shows that encryption can actually be harmful if it protects the attacker's ability to hide their entry price while simultaneously blinding the market's ability to fix the price.

In short, the paper suggests that while locking transactions in a safe is great for protecting innocent users from being sniped, it can backfire if the system doesn't have a built-in "cooling off" period. If the market opens the safe and immediately pays out, it's like letting a thief set a trap and then handing them the keys to the vault before anyone can stop them. The solution is to open the safe, let the guards fix the mess, and then hand over the keys. This ensures that privacy protects users without giving attackers a free pass to manipulate the system.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →