Skip to main content

Architecture Overview

Dark Matter is a set of independent contracts around a single core reactor. Each component has its own admin, its own safety model, and its own payment role. Nothing shares an upgradeable proxy — if one part fails, the others keep working.

Component map

Admin & safety model

Every contract follows the same four principles: 1. Two-step ownership. Transfers of admin/owner/treasury roles never take effect immediately — the current role proposes, the new role accepts:
2. One-shot wiring for money destinations. The vaults and pools on the reactor (setStockDividendVault, setRewardPools, setStardust, setGasSponsorSkim) can only be set once, ever. A compromised owner cannot redirect established payment flows. 3. Fail-safe fee forwarding. A rejected downstream transfer never reverts the user’s deposit. The reactor records failed pool credits as pendingPoolCredits which anyone can retry permissionlessly (retryPoolCredits()):
4. Allowance-capped automation. The treasury’s operator (the cron) can spend only within a rolling 30-day allowance, and (when the allowlist is enforced) only to pre-approved targets. A leaked operator key cannot drain the treasury.

The custody split — one sentence per surface

  • Reactor deposits land in the UltimateSingularityProtocol contract balance itself; yield is paid out of a shared balance curve (see Reactor Yield).
  • Casino balances are held by CrashVault, which the server never controls — withdrawals require the player’s own EIP-191 signature, enforced on-chain (see Two Vaults).
  • Earn positions are minted directly to the user’s address — the zap router holds no custody and no approvals over user funds (see Earn Zap).

Trust boundaries (read this before integrating)

Next: The Two Vaults & Custody.