Lead publishes a trade
Wallet becomes popular. Followers watch every outbound swap.
Mirror
Private copy trading on Flare.
A lead encrypts a signal. A TEE decrypts it, sizes every follower from live FTSO prices and vault balances, and settles the fill on public contracts — without ever putting the strategy in the mempool.
eToro has 40 million users. Bybit, OKX, and Bitget ship copy trading natively. Retail wants skilled traders’ performance without managing every position. That demand is real. Onchain, the same product destroys itself.
Wallet becomes popular. Followers watch every outbound swap.
Follower txs land seconds after the original, in the clear.
Bots frontrun the lead, then the followers, with higher gas.
Worse price for the lead. Worse still for every copier. Scale inverts the product.
There is no way to make copy trading MEV-resistant with a normal smart contract: a public signal is a public invitation to frontrun.
Flare already has the venue for XRPFi. It does not have a way to follow a skilled trader without leaking the strategy.
DEXes, lending, CDPs, and liquid staking around FXRP
No copy-trading product of any kind
FTSO v2 prices at ~1.8s, plus 90s anchors
No encrypted signal path — a popular lead wallet is a public strategy
FDC proofs for EVM txs, XRPL payments, and Web2 JSON
No FDC-gated settlement of copy fills and lead fees
FAssets and Smart Accounts so XRPL users can enter without FLR
No proportional, private fan-out of one intent into many vaults
FCC / TEE enclaves that can keep intent sealed until execution
No attested, risk-adjusted leaderboard — only raw PnL vanity
That gap is exactly what Mirror fills. FCC is not a bolt-on. It is the primitive that makes the product safe to exist.
Copy a skilled trader on Flare without putting their strategy in the mempool. Scale no longer destroys the edge.
On a public chain
The lead’s wallet is the strategy. Followers race it in the mempool. MEV takes the fill. Popularity is a tax.
With Mirror
The lead encrypts. A TEE copies into FXRP vaults. The chain only sees the fill — after it happens, with a proof.
Intent never hits the mempool. Searchers see ciphertext. The strategy stays an edge, not a public RSS feed.
One signal, sized per vault, priced from live FTSO. Batched execution — not a stampede of copy-cats.
The swap is public. FDC proves it. Vaults and lead fees move only after that proof — not on an operator’s word.
Ciphertext only on-chain. Searchers get noise.
Matching ≠ scoring. Independent code hashes.
Fan-out to each follower. Not one cloned tx.
Sizes from the oracle. 1% floor on expected out.
No FDC attestation, no payout. claim() is blocked.
Sharpe, drawdown, cadence, data. Not an LLM.
Xaman in. No FLR required to follow.
Strategy change and liquidation risk, in-app.
Followers see classification-level summaries only — “mean-reversion lead, ahead on epoch P&L.” An adversarial test asserts Stage B calldata is ciphertext-only.
Three people. After onboarding, they share one vault graph — a lead’s sealed signal copies into each follower’s FXRP.
Sets a fee (0–20%) and encrypts each trade in the browser. Followers copy automatically. The lead sees total AUM, never who is copying or how much.
Has a Flare wallet · already trading
Picks a lead from Discover, chooses risk, deposits. The next encrypted signal is sized into their vault. They never see the trade itself — only the result.
Needs FXRP on Flare
Pays from Xaman. Flare proves the payment, opens a Smart Account, and credits an FXRP vault. From there it is the same as the Flare follower path.
XRP only · no EVM wallet required
sealed / TEEon-chainenclave boundary
Signal body: { asset, direction: SELL, sizePct, nonce, lead } · FCC fee 1e6 wei · FXRP-only because the vault is single-asset.
Risk stays on-chain (conservative / moderate / aggressive). Copying starts on the next encrypted signal — no extra click.
No C2FLR required. Combined Core Vault mint+onboard still needs mint liquidity on Coston2 — the canary proves FDC Payment + onboarder.
Venues: mock-sparkdex default · optional BlazeSwap V2 · Enosys/Firelight if MIRROR_MOCK_VENUES. PMW signing of the settlement tx is still partial (SIGN_PORT).
Withdraw queues via requestWithdrawal — funds return after unwind, not as an instant ERC20 transfer. Proof-free settleBatch is off by default.
Web2Json (DeFiLlama / CoinGecko) is attested in canaries and stored as an attestation id — it is not mixed into the 0–100 weights.
The strategy itself is never shown. Portfolio language stays at classification level: “mean-reversion lead — ahead on epoch P&L.”
| Primitive | How Mirror uses it | Why it is required |
|---|---|---|
| FCC / TEE | Matching + scoring FCEs on Confidential Space (AMD SEV). Decrypt, size, score stay sealed. | A public contract cannot hide intent until after execution. Without the enclave, copy trading is MEV bait. |
| FCE + code hash | Registered extensions, published hashes (fce:compare-hashes). InstructionSender / AiAgentSender latch extension ids. | Anyone can verify matching logic is unmodified without reading a live signal. |
| Tee registries + payments | sendInstructions with 1e6 wei fee. TeeManager logs yield the instruction id the UI waits on. | Decentralised relay into the enclave — not a private API the operator can silently swap. |
| FTSO v2 (~1.8s) | TEE + FtsoPriceReader + MockSparkDexRouter quote FXRP/USD and USDT0/USD from ContractRegistry. | Follower size and min-out must not be manipulable by a stale pool tick. |
| FTSO anchor (~90s) | AnchorDivergenceGuard on large notionals: revert if |block−anchor| / anchor exceeds maxDivergenceBps. | Second, slower reference stops a short FTSO blip from oversizing a copy wave. |
| Primitive | How Mirror uses it | Significance |
|---|---|---|
| FDC EVMTransaction | Relayer attests the venue Swap. InstructionSender checks router, amounts, unique hash, status 1. | Vault settle and lead fee release are trust-minimised — not an operator “yes, it filled.” |
| FDC Payment | XRPL Payment → MasterAccountController.executeInstruction. | Proves the XRP actually moved before a Flare sub-account is created. |
| FDC Web2Json | Score canary attests DeFiLlama TVL / CoinGecko vol into attestation ids on the leaderboard. | External market context is cryptographically referenced, even if not in the 0–100 weights. |
| FAssets / FXRP | Sole vault asset (6 decimals). TEE resolves via AssetManagerFXRP.fAsset(). | Native XRP exposure on Flare DeFi — no wrapped-bridge custody story. |
| Flare Smart Accounts | PersonalAccount + MirrorFsaOnboarder.registerFollowerAs / depositFor. | Opens Mirror to 40M+ XRP addresses that have never held FLR. |
| Venues | SparkDEX V3 ABI (mock on Coston2 — no bytecode). BlazeSwap self-seeded pair. Kinetic / Enosys / Firelight interface mocks; real Firelight vault reserved. | Same calldata path swaps to mainnet routers later. Coston2 honesty: mocks are labeled, not hidden. |
They want skilled flow without leaking intent, getting sandwiched, or trusting a black-box operator. Mirror is the platform where copy trading stays private until filled and public once proven.
They have FXRP in-wallet. Discover + one deposit is the whole job. They need risk-adjusted scores (Sharpe, drawdown) instead of a PnL leaderboard that hides blow-ups.
They will not publish a wallet if popularity is a MEV tax. Encrypted signals + batched fills let them sell a 0–20% performance fee without donating the strategy to searchers.
Why this helps them specifically
High-frequency arb desks that need sub-block exclusive orderflow. Mirror is proportional copy of vault FXRP, not a dark pool for professional flow.
Harden the enclave path until fills are boring. Then take the same contracts to mainnet and grow through XRPL.
Audit Registry, Vault, Fee, Sender, FSA onboarder, and both FCE code hashes
Deploy to Flare mainnet (chain 14) with the live SparkDEX V3 router
Finish TEE-resident PMW signing so the executor key is not a human EOA
Seed a small set of verified leads — scores stay 0 until real fills
Fill-worker uses TEE-sized amounts instead of re-deriving size
GTM through Xaman / XRPL: follow from XRP, never buy FLR first
Route the 10% protocol cut into FIRE / FIP.16
Liquidity partnerships so FXRP/USDT0 can absorb copy waves
Swap mock SparkDEX / Kinetic / Enosys for live venue addresses
Lead acquisition via performance fees, not token incentives
One-shot FSA mint so XRPL → vault credit does not need an EOA top-up
Optional Firelight stXRP tier, then Kinetic / Enosys strategy leads
Always-on drift and health monitors, plus multi-operator FCC as the network matures
Only after fills are boring: FBTC markets, Songbird canary, and a mobile shell
Thank you