Glossary
The stable domain language for BYOS. Every term below is defined here and nowhere else — implementation repos use this vocabulary in issues, ADRs, tests, metric names, and code, and their own CONTEXT.md files define only what is local to them.
If a concept you need is not here, that is a signal. Either you are inventing language the project does not use, or there is a real gap worth flagging.
Source RFP: Bring Your Own Solver (BYOS) · accepted grant application. CoW protocol background: fee collection, slashing policy, auctions, CIPs.
What BYOS is
A bonded CoW solver whose proposed solutions are sourced from a permissionless set of external sub-solvers. Sub-solvers submit signed routing proposals against specific order UIDs, collateralized by an escrow balance held by BYOS. BYOS retains exclusive control over on-chain settlement submission. From the protocol's perspective BYOS is a single, ordinary bonded solver — the sub-solver relationship is entirely internal to BYOS.
v1 targets Ethereum mainnet + Gnosis. Out of scope: a BYOS-operated orderbook, reward pass-through to sub-solvers, cross-chain escrow accounting, and BYOS's own bonding capital.
Two risk classes
The core economic framing. Everything about escrow, penalties, and gatekeeping follows from this split.
| Track A — gas + revert penalty | Track B — EBBO / fairness slash | |
|---|---|---|
| Determined by | On-chain fact (tx reverted) | Off-chain CIP-52 certificate + DAO |
| Timing | Seconds to about one accounting week | Days, up to 3 months |
| Attributable cleanly? | Yes (tx to proposal) | Murky; BYOS chose to settle it |
| Recoverable from escrow? | Yes | Only if funds are still present; otherwise BYOS eats it |
| Primary defense | Escrow debit | BYOS pre-settlement gatekeeping |
Terms
Sub-solver — an external, permissionless party that computes a route for a specific order and submits a signed proposal to BYOS. Never holds submission keys; never calls
settle. Identified by its address, recovered from its EIP-712 signature; that same address is its escrow key and its Trampoline CREATE2 salt. It issub_solver, never plainsolver— in CoW's vocabularysolvermeans BYOS itself.Proposal — an EIP-712-signed message authorizing BYOS to attempt a settlement of a specific route, and consenting to the associated escrow risk. Immutable: amounts, interactions, expiry, nonce, and signature form one signed unit, so there is no update operation. One proposal commits to exactly one order. Field-level definition is in the design document; the wire shape is in
byos-service'scrates/byos/openapi.yml.Trampoline — the contract that receives a route's
sellAmount, executes the sub-solver's interactions as itself, sweeps both trade tokens back toGPv2Settlement, and enforcesbuyAmountas a floor. Confines sub-solver code to a fund-less context so it cannot reach settlement buffers or plant an exploitable approval. One immutable instance per sub-solver, at a deterministic CREATE2 address, deployed at escrow-deposit time. See the design document.Escrow — a per-chain, native-token ERC20 contract holding sub-solver collateral keyed by sub-solver address. Tokens are minted 1:1 with deposited ETH and burned on withdrawal or debit;
balanceOfis the single source of truth. The collateral at risk is the only sub-solver capital BYOS ever touches — trade capital flows atomically throughGPv2Settlementinto the Trampoline and back. See the design document.Owner — the secure wallet (multisig or Safe) that owns the Escrow. Receives debited funds, sets the operator, grants and revokes submitters, configures the cooldown. Ownership transfer is two-step.
Operator — an EOA held by the BYOS service for automated operations: debit, freeze, unfreeze, pause, unpause. Cannot withdraw funds or change configuration. A compromised operator can grief but not steal.
Submitter — an EOA the BYOS service submits settlements from. Holds the Escrow's
SUBMITTER_ROLE;Trampoline.executerequirestx.originto be one. Covers both the allow-listed solver EOA and the auxiliary accounts of CoW'sSolver7702Delegateparallel path, since there the auxiliary account istx.origin. Rotation is a role change by the Owner, not a redeploy.Cooldown — the waiting period between requesting and executing an escrow withdrawal. Withdrawal is all-or-nothing: requesting drops effective balance to zero immediately, so a sub-solver is offline for new proposals for the duration.
Pause — an operator-triggered global emergency brake blocking all ERC20 transfers and withdrawal executions. Deposits, debits, withdrawal requests and cancellations, and debit sweeps stay operational. The first response to detected malicious transfer activity; should be short-lived, minutes rather than hours.
Freeze — the operator blocking withdrawal execution and ERC20 transfers, in both directions, for one sub-solver address while a Track B investigation is open. Does not affect effective balance. Deposits to a frozen address are allowed.
Debit (Track A) — routine, provable recovery of
gas + c_lfrom escrow when a winning settlement carrying a proposal reverts on-chain, misses its deadline, or is abandoned after winning. See the design document.Slash / clawback (Track B) — rare passthrough of a CoW EBBO or fairness penalty (CIP-52) to the responsible sub-solver's escrow, mirroring the process CoW runs against BYOS. The service tracks a 5× off-chain reserve against pending claims. See the design document.
Attribution — mapping a settlement transaction back to the sub-solver whose proposal it contained. Enforced by settling one sub-solver per settlement transaction; the per-sub-solver Trampoline CREATE2 address in the calldata self-evidences which sub-solver's route ran.
Gatekeeping — BYOS's preventive control: validating each proposal (simulation, hook presence, EBBO baseline price) before settling. Distinct from escrow, which is recovery. Best-effort and non-exculpatory — passing gatekeeping does not absolve a sub-solver.
Gas cut — what BYOS keeps back to cover submitting a settlement: exactly the estimated gas cost, in the order's sell token, on every solution it bids. Kept rather than reimbursed. Always on, no rate to configure. Say "gas cut", not "fee": the order's signed
feeAmountis a different field and is zero on every live order, CoW's protocol fee and network fee are applied by the driver rather than by BYOS, and the percentage-of-sellAmount"BYOS fee" of early drafts never shipped. See the design document.c_l— CoW's per-auction lower reward cap, which is the maximum revert penalty: 0.010 ETH on mainnet, 10 xDAI on Gnosis. A BYOS debit per reverted auction is bounded bygas + c_l. Seereference/cow-solver-slashing-policy.Residue — a retired category. Until 2026-07-22, route output above the signed floor and unconsumed sell tokens stranded in the Trampoline instance and were reclaimable by the sub-solver.
executenow sweeps both trade tokens toGPv2Settlement, so that value is BYOS-owned settlement slippage. The term survives only in superseded ADR revisions. See the design document.