Skip to main content
Trading on Calibri runs on a Conditional Token Framework (CTF) deployment on Polygon. Every contract is public and verifiable — you never have to trust that funds are where we say they are, because you can check on-chain. This page explains each contract’s role in plain language; the deployed addresses page has the live values and how to verify them.
Every trade on Calibri settles against these contracts — see Self-custody for how a signed order becomes an on-chain position.

The contracts and what they do

What “non-custodial” actually guarantees

  • You hold the funds — Your USDC sits in your own Safe. Only a key you own can authorize a move. The operator is never an owner and can never move funds without your signature. The one thing that moves without it is the bridge module, and all it can do is carry USDC sent to your address on another network to your own Safe on Polygon.
  • The operator can only report — CalibriResolver reports outcomes; it can’t seize collateral. Redemption of winnings happens directly from the CTF, so your winnings are never custodied by the operator between resolution and redeem.
  • You sign, the operator pays gas — Deploying your Safe, approvals, order settlement, and redemption are all relayed by the operator. You sign; you never need to hold gas. The one exception you can opt in to is auto-redeem, where a single approval lets winnings be redeemed back into your Safe without signing each one.
  • Funds are always recoverable — A permissionless escalation ladder (operator → UMA → deadman void) guarantees every market settles or refunds. See Market resolution.

Cross-network deposits

Four contracts let USDC sent to your Safe address on Ethereum, Base, Arbitrum or Optimism reach the same Safe on Polygon without you signing anything. Each is deployed at the same address on every supported network, which is what gives your Safe the same address everywhere. See Deposits from other networks for the member-facing flow.

What the module can and cannot do

The module can act on a Safe without owner signatures — that is what a Safe module is — so its limits are enforced by its own immutable code:
  • One token: the network’s native USDC, as linked by Circle’s own contracts. Never a token the caller names; never ETH.
  • One destination: a CCTP burn whose recipient is the Safe’s own address on Polygon.
  • One kind of call: plain calls to USDC and to Circle’s messenger. It never delegatecalls.
  • One capped fee: only when the configured relayer calls it, only on a bridge of the Safe’s whole balance, at most 10 USDC and at most 20% of that balance, paid to the configured treasury.
  • Above the cap, only a fee the member accepted: bridgeWithConsent charges exactly the fee in an acceptance countersigned by the consent signer — for one Safe, once, before its deadline, and only if the Safe has not been bridged since. See When Ethereum gas is high.
  • Open to anyone at zero fee: so a member can always move stranded USDC to their Polygon Safe, with or without Calibri.
Changing any of those limits would take a new module at a new address, and therefore a new factory and different Safe addresses.

Trust model

On other networks, anything other than USDC sent to a passkey member’s Safe cannot be moved today — it needs an owner signature that cannot be produced there. The module never moves it.

Withdrawals to other networks

The outbound direction uses none of the contracts above. A withdrawal from your Safe on Polygon to Ethereum, Base, Arbitrum or Optimism is a Safe transaction you sign, which calls Circle’s messenger directly from the Safe — no module. It is batched through Safe’s own MultiSendCallOnly contract, which can make only plain calls, and the batch is exactly three of them: USDC to Calibri’s treasury for the fee, a USDC approval to Circle’s TokenMessengerV2, and depositForBurn naming the destination network and your address as the mint recipient. Circle mints only to that address; delivery on the destination network is open to anyone. See Withdrawals to other networks.

Verifying and interacting on-chain

As a non-custodial user you can independently verify every contract and, if you want, interact with them directly:
  • Read the code and balances on the network’s block explorer.
  • Check your Safe holds the USDC you deposited.
  • Redeem winnings yourself by signing a Safe transaction that the operator relays — see Redeeming winnings.

Where the live addresses come from

The canonical source for every address you need is the CTF-config API — the same one the app itself reads:
  • GET /api/v2/atlas/account/wallet — your member-level funding config: exchange_address, conditional_tokens_address, usdc_address, chain_id, blockchain_key, domain_name (the exchange’s EIP-712 domain), your proxy_address (your Safe), owner_address (the owning wallet), and signature_type.
  • GET /api/v2/atlas/account/wallet/markets/:id — everything above plus the market-specific condition_id, yes_token_id, and no_token_id.
These endpoints are the source of truth. The Deployed addresses page lists the live mainnet values and walks through verifying each one on the explorer.

The Safe

Deploy, fund, and make your Safe trade-ready.

Deployed addresses

Per-network address table and explorer link patterns.

Signed orders

The EIP-712 domain and order struct you sign.

Resolution & recovery

Operator → UMA → deadman void.

Deposits from other networks

How the bridge module moves USDC to your Safe on Polygon.

Withdrawals to other networks

How a withdrawal leaves your Safe through Circle, with no module.