An Aspens Market, explained
Pick a token you want to own and look at where your money sits. The asset lives on its own chain. The USDC that would buy it sits on another. Between the two, for almost any asset, there is no direct market: workarounds exist, but no single book where the asset trades against the money that wants it.
An Aspens market is built to be that book. The asset stays on its canonical chain and trades against stablecoins on other chains in one non-custodial market, no bridge inside the trade, every fill backed by a signed record. Direct is doing specific work in that sentence: no bridge and no custodian anywhere between you and the counterparty, the asset never wrapped into a synthetic copy, both legs of a fill settling natively on the chains where the assets live.
Today's routes are plumbing between single-chain markets
The paths that exist today are plumbing between single-chain markets. A centralized exchange listing buys real reach, and it moves the market inside a custodian, on the venue's terms. Bridging into a DEX on the destination chain is permissionless, and it bolts transport onto a single-chain pool, with the price discovered only in that pool. The intent networks deserve real credit here: they took the bridge out of the transfer and made that a commodity, and for small size in the top twenty or so tokens the experience is good. They remain one-sided, though: each trade is a quoted fill with no standing market behind it, and a long-tail asset often gets no quote at all.
Every one of those paths charges in the same four currencies. Spread and fees go to venues you do not control. Custody is surrendered somewhere along the route. Bridge exposure rides along: more than $2.8 billion has been stolen through bridges since 2022, roughly 40 percent of DeFi and Web3 hack value by DefiLlama's attribution. And the execution itself cannot be proven afterward; you reconstruct it from venue exports and hope.
One market is one pair, in one book
An Aspens market is designed so there is nothing to route through. One market is one pair: a base asset on the chain where it lives against a quote stablecoin on the chain where it lives, in one order book. A token on Solana trading against USDC on Ethereum, in a single book, at a price discovered in that book rather than imported from somewhere else. You keep custody until the moment of settlement, and each fill comes back as a signed entry you can hand to a counterparty or an auditor.
That is the outcome in three parts: a market for the route you actually need, custody that never leaves you, and proof that sits in your hands. Two bounds belong beside the claim, stated plainly. A new market opens thin: depth is two sides meeting, and the first two sides are usually the people closest to the asset, its issuer, its treasury, its community. And the reach of "any asset" rests on market deployment built to be close to trivial: if standing a market up is cheap, a market can exist for a pair no listing committee would ever touch, which is exactly where no route exists today.
An order, end to end
The simple version asks you to take three claims on faith. The machinery below is why you would not have to.
A trader connects a wallet on each chain and deposits into the trading contract on that chain: MidribV3 on EVM chains, the Midrib Anchor program on Solana. That deposit is the last on-chain transaction the trader sends until withdrawal, and the funds never leave their native chain; they sit in the contract, under the trader's control, until a trade settles. Placing an order is a signature over the encoded order, EIP-191 on EVM and Ed25519 on Solana. There is no on-chain transaction to wait on, and placing or cancelling costs nothing in gas. The matching engine verifies the signature, recomputes the order's SHA-256 identifier, reserves the committed amount against the trader's off-chain ledger balance, and matches against the book in microseconds. Orders are limit or market. A match moves balances in the ledger immediately; an unmatched remainder rests in the book against its reservation, and a cancel releases it.
Instant off-chain matching, native batched settlement
Real-time is a phrase this industry has stretched, so it deserves a definition. In an Aspens market it means two layers doing two different jobs. The off-chain ledger is instant: balances move the moment a match happens, which is the exchange-speed experience the trader sees. On-chain settlement is batched netting: a background settler folds accumulated net deltas onto each chain through the settleBatch function on the per-chain contracts, and both legs land natively where the assets live. The accurate compression is instant off-chain matching with native, batched on-chain settlement.
The design contains no per-trade on-chain transaction and no bridge at any point in the path. Withdrawals can be requested at any time and require a voucher signed inside the TEE; the trader pays gas only for their own deposits and withdrawals.
Chain support, per the documentation: EVM and Solana are production, Hedera is in progress, and the matching engine itself is chain-agnostic, with new chains added by implementing a chain interface and registering a signing curve.
The trust model: the journal and the attestation
What an outsider can check compresses into one sentence. There are two pieces: the trade log, or the journal, and the stack attestation.
The journal is the first piece. Every fill emits a signed entry carrying the engine version, the signer attestation, the route, and the latencies. The log is append-only, each entry referencing the one before it, and it replays bit for bit. Verifying it is like a Sudoku puzzle on steroids: extremely hard to forge and easy to check. Selective disclosure then lets the holder share exactly the window a counterparty, an auditor, or a supervisor needs, and nothing beyond it.
The second piece is the attestation. The signing keys are minted and used inside an Intel TDX Trust Domain, a hardware-isolated confidential VM, and they do not leave it. Before relying on the signer, a counterparty requests an attestation report and verifies it: the signature chain terminates at an Intel root through PCK certificates, the TCB level checks out, the domain is not running in debug mode, the measured signer build matches a known-good version, and the report is bound to the specific session. Pass those checks and you know which code produced the fill you are looking at.
There are two limits to state as well, because trust claims without them are marketing. TEEs are not perfect. The hardware class carries a documented history of side-channel research, and Aspens does not describe TDX as unbreakable; what attestation buys is a smaller, checkable trust anchor, Intel's supply chain and the hosting environment, in place of a team whose internals you cannot see. The other limit is about reach: the TEE signer signs the settleBatch transactions and the withdrawal vouchers, so it sits directly in the settlement and withdrawal path. The honest description of that position is a threat model policed by attestation, and it is better stated plainly than papered over with a claim that settlement is independent of the signer.
Run by Aspens, run for you, or run by you
Who runs any given market is an implementation conversation that comes after the route and the outcome: a market can be run by Aspens, run for you, or run by you, and if you want it to be yours, it can be.
If there is an asset you hold, issue, or make markets in, and the direct market for it does not exist, come speak with us. Tell us what you want to build and the route it needs, and we will see whether an Aspens market is the right choice.