Every trade on Calibri settles against these contracts — see Self-custody for how a signed order becomes an on-chain position.
The contracts and what they do
What “non-custodial” actually guarantees
- You hold the funds — Your USDC sits in your own Safe. Only a key you own can authorize a move. The operator is never an owner and can never move funds without your signature. The one thing that moves without it is the bridge module, and all it can do is carry USDC sent to your address on another network to your own Safe on Polygon.
- The operator can only report — CalibriResolver reports outcomes; it can’t seize collateral. Redemption of winnings happens directly from the CTF, so your winnings are never custodied by the operator between resolution and redeem.
- You sign, the operator pays gas — Deploying your Safe, approvals, order settlement, and redemption are all relayed by the operator. You sign; you never need to hold gas. The one exception you can opt in to is auto-redeem, where a single approval lets winnings be redeemed back into your Safe without signing each one.
- Funds are always recoverable — A permissionless escalation ladder (operator → UMA → deadman void) guarantees every market settles or refunds. See Market resolution.
Cross-network deposits
Four contracts let USDC sent to your Safe address on Ethereum, Base, Arbitrum or Optimism reach the same Safe on Polygon without you signing anything. Each is deployed at the same address on every supported network, which is what gives your Safe the same address everywhere. See Deposits from other networks for the member-facing flow.What the module can and cannot do
The module can act on a Safe without owner signatures — that is what a Safe module is — so its limits are enforced by its own immutable code:- One token: the network’s native USDC, as linked by Circle’s own contracts. Never a token the caller names; never ETH.
- One destination: a CCTP burn whose recipient is the Safe’s own address on Polygon.
- One kind of call: plain calls to USDC and to Circle’s messenger. It never delegatecalls.
- One capped fee: only when the configured relayer calls it, only on a bridge of the Safe’s whole balance, at most 10 USDC and at most 20% of that balance, paid to the configured treasury.
- Above the cap, only a fee the member accepted:
bridgeWithConsentcharges exactly the fee in an acceptance countersigned by the consent signer — for one Safe, once, before its deadline, and only if the Safe has not been bridged since. See When Ethereum gas is high. - Open to anyone at zero fee: so a member can always move stranded USDC to their Polygon Safe, with or without Calibri.
Trust model
Withdrawals to other networks
The outbound direction uses none of the contracts above. A withdrawal from your Safe on Polygon to Ethereum, Base, Arbitrum or Optimism is a Safe transaction you sign, which calls Circle’s messenger directly from the Safe — no module. It is batched through Safe’s own MultiSendCallOnly contract, which can make only plain calls, and the batch is exactly three of them: USDC to Calibri’s treasury for the fee, a USDC approval to Circle’s TokenMessengerV2, anddepositForBurn naming the destination network and your address
as the mint recipient. Circle mints only to that address; delivery on the destination
network is open to anyone. See
Withdrawals to other networks.
Verifying and interacting on-chain
As a non-custodial user you can independently verify every contract and, if you want, interact with them directly:- Read the code and balances on the network’s block explorer.
- Check your Safe holds the USDC you deposited.
- Redeem winnings yourself by signing a Safe transaction that the operator relays — see Redeeming winnings.
Where the live addresses come from
The canonical source for every address you need is the CTF-config API — the same one the app itself reads:GET /api/v2/atlas/account/wallet— your member-level funding config:exchange_address,conditional_tokens_address,usdc_address,chain_id,blockchain_key,domain_name(the exchange’s EIP-712 domain), yourproxy_address(your Safe),owner_address(the owning wallet), andsignature_type.GET /api/v2/atlas/account/wallet/markets/:id— everything above plus the market-specificcondition_id,yes_token_id, andno_token_id.
Related
The Safe
Deploy, fund, and make your Safe trade-ready.
Deployed addresses
Per-network address table and explorer link patterns.
Signed orders
The EIP-712 domain and order struct you sign.
Resolution & recovery
Operator → UMA → deadman void.
Deposits from other networks
How the bridge module moves USDC to your Safe on Polygon.
Withdrawals to other networks
How a withdrawal leaves your Safe through Circle, with no module.