Reserve order mechanics.
Nordbill pairs a conditional SOL purchase with a live Kamino Lend supply position on Solana devnet. The program escrows the exact receipt-token amount and redeems it during fill or owner cancellation.
Overview
A user chooses a Circle test USDC reserve amount and a maximum purchase price for SOL. The client supplies USDC to the verified Kamino devnet reserve, then the Nordbill program escrows the exact receipt-token amount in the order PDA.
A permissionless filler can settle only by authorizing enough SOL for the encoded price. The program redeems the receipts, recomputes the required SOL from the actual USDC proceeds, and exchanges both assets atomically. The filler cannot change the owner, venue, mints, vault or output destination.
Order lifecycle
- The owner creates an order with reserve amount and maximum USDC price per SOL.
- The wallet supplies Circle test USDC to the configured Kamino reserve.
- The program records and escrows the exact Kamino receipt amount.
- A filler authorizes a maximum SOL input when execution is economically available.
- The program redeems the receipts and transfers the exact target-price SOL output atomically.
- The order closes after one full fill and cannot execute again.
Cancellation
The owner can cancel an unfilled order. The program redeems all recorded receipt tokens and returns the resulting USDC to the owner's canonical token account. No third party can redirect cancellation proceeds.
Program design
| Component | Responsibility |
|---|---|
| Order account | Owner, target price, principal, receipt amount and terminal state. |
| Receipt vault | PDA-controlled Kamino receipt account scoped to one order. |
| USDC vault | Temporary PDA destination used only during redemption and settlement. |
| Fill constraint | Recompute and enforce SOL output from actual redeemed USDC and owner terms. |
| Filler | Permissionlessly provide SOL and receive redeemed USDC atomically. |
| Kamino adapter | Fixed verified devnet market, reserve, authority, receipt mint and supply vault. |
State constraints
Creation, cancellation and fill are mutually exclusive terminal paths. A completed or cancelled order cannot execute again. Every transfer is bound to the recorded mint, vault and owner accounts.
Integrations
The current workspace uses Solana devnet. The reserve program and wallet interface are connected to Circle's devnet USDC and the verified Kamino Lend USDC reserve.
| Network | Solana devnet |
|---|---|
| Program | AeG9rPwdE6Qf37R6iLnUVFAMrzYr4omFkBu7Q2j1zCUV |
| Reserve mint | 4zMMC9srt5Ri5X14GAgXhaHii3GnPAEERYPJgZJDncDU (Circle devnet USDC) |
| Kamino market | 4GiGCkrwHphwrsG8imKSHhjTtmbjorqYrYwMsRtBu77Z |
| Kamino reserve | DJ8gPwXaEX2T8ZJGwZNJc9vL6iwrUUyUrwzeSgjD8RHH |
| Receipt mint | HXsZVsvFLj6BXx7GEgf1E3jG7QEXJ7bgXowjEnyyvcBe |
| Settlement | Permissionless atomic filler, full fill only |
Risks and limitations
- Lending rates change with market utilization and are not fixed. If no borrowers use the reserve, lending interest can be low or zero.
- A target price does not guarantee a fill. A filler must be willing and able to deliver the onchain minimum output.
- Unsolicited token dust can remain in a terminal vault; it does not reduce the recorded principal or block settlement.
- Kamino liquidity, receipt valuation, program availability and withdrawal capacity affect whether redemption can complete.
- Creation requires two signed transactions. If the Kamino deposit confirms and order creation does not, receipt tokens remain in the user's wallet and must be resumed or redeemed separately.
- Smart contract defects, account validation mistakes and compromised executor infrastructure can cause loss or delayed access.
- Devnet assets have no mainnet value and devnet behavior does not prove mainnet readiness.
Current status
The upgraded reserve program is deployed to devnet after unit tests, eight local SVM tests, an independent Kamino deposit/redeem check, and real two-wallet v2 smoke tests. Both owner cancellation and permissionless atomic fill were confirmed with Circle test USDC.
No Nordbill project token or token mint is displayed. A future token section is configuration controlled and stays hidden without a real approved mint.