TECHNICAL DEEP-DIVE & ARCHITECTURE BLUEPRINT

How Sealed Works: End-to-End Protocol Mechanics

Sealed is an unhosted bidding protocol built on zero-knowledge state circuits. It resolves high-value liquidation privacy by decoupling market bid discovery from buyer identity, while maintaining strict legal and financial compliance at local borders.

01

The High-Value Sales Dilemma

Legacy auction platforms force a structural compromise: sellers with urgent liquidity needs (corporate wind-downs, estate liquidations, marital separations) must broadcast their assets publicly, inviting predatory bidding. Simultaneously, prospective buyers who enter open bidding wars expose their financial ceilings to competitors and market watchers.

Traditional luxury houses charge 35–45% commissions to fund physical warehousing and human brokers. Sealed operates as a software-only protocol taking a flat, low settlement commission by delegating physical intake and escrow verification to accredited regional partners.

The Privacy Model (What Is Real vs. What Isn't)

What Sealed Guarantees

  • Market-Blind Bidding: Competitors, network sequencers, and observers cannot see your bid value or wallet address during active bidding.
  • Zero Net Worth Disclosure: A client-side ZK proof verifies balance sufficiency without revealing total wallet holdings.
  • Zero Public Ledger Footprint: Bids sit in encrypted commitments until settlement.

Explicit Technical Limits

  • On-Ramps Are KYC'd: Converting fiat to USDC/USDT/cNGN through licensed exchanges links your identity to that wallet.
  • Winning Bidders Disclose Identity: Legal title transfer, courier waybills, and real estate deeds require buyer identification at closing.
  • Reveal-at-Close (v1): Losing bid amounts become deterministic at auction end to calculate the winner without a centralized comparator.
02

End-to-End Auction Lifecycle

Step 1: Seller Listing & Local Intake

SELLER_PHASE

The seller connects a wallet and verifies identity via decentralized ID (zkMe or Polygon ID) without uploading raw documents to protocol storage. An accredited local partner (e.g., RICS surveyor for property, or Semoty for luxury goods) inspects the asset, signs an intake payload, and releases the listing to the public catalog with a public reserve floor.

Step 2: Client-Side Solvency Verification

BIDDER_PHASE

Before submitting a bid, a local Noir circuit executes in the bidder's browser. It verifies that the bidder's wallet holds enough balance in the specified stablecoin to back the intended bid. The network receives a valid solvency proof without learning the bidder's balance or bid value.

Step 3: Hidden Commitment Escrow

AZTEC_SHIELDED_POT

The bid is hashed and locked into an Aztec private commitment note. During the active bidding window, competitors see only randomized state updates—preventing predatory price ladders or ceiling sniping.

Step 4: Settlement & Immediate Refunds

REVEAL_AT_CLOSE

When the auction timer expires, commitments are evaluated via Reveal-at-Close. The contract deterministically calculates the highest valid bid. Losing bid notes are unlocked immediately and returned directly to wallets without a manual claim process.

03

Jurisdiction-Agnostic Pluggability

Multi-Asset Escrow

Sealed is currency-neutral. Auctions run in any regulated 1:1 stablecoin (USDC, USDT, cNGN, EURC). The ZK settlement and escrow logic remains identical regardless of the underlying token.

Pluggable Verification Partners

Physical intake relies on certified regional authorities: RICS in the UK, NIESV/ESVARBON in Nigeria, or state-licensed appraisers in North America. Real estate transfers pass to licensed legal delegates upon auction completion.

Try the Client Proving Engine

Test the client-side solvency proof simulation directly on our interactive landing environment.

Open Proof Simulator