escrow, and stay there until they settle past the deep-reorg check; refunds pay out of the same escrow with the program signing as its authority. The operator float lives in a plain treasury system account and its associated token accounts, and fulfillments are signed by the treasury key itself. Settled escrow funds move to the treasury through the release instructions.
Prefer the
router_address (program id) and treasury returned on the quote and by GetChains over these constants.
Deposit instructions
deposit_token transfers SPL tokens from the depositor’s token account into the escrow’s associated token account and emits Deposit with the amount actually credited, so transfer-fee mints are accounted at the escrow, not assumed. deposit_native transfers lamports to the escrow directly; the mint in its event is the default pubkey.
swap_program with the caller-supplied accounts and data, then requires the escrow’s token account to have grown by at least min_bridge_out, emitting SwapDeposit with the credited amount. buildSvmSwapDeposit in the SDK assembles this transaction from the GetSwapInstructions payload; see Swap instructions.
Operator instructions
Restricted to the treasury signer, listed for completeness.fulfill_token pays the recipient’s token account from the treasury and optionally transfers gas_drop lamports to the recipient, requiring the recipient to be credited the full amount. The refund variants pay the depositor back from the escrow, with the program signing as the escrow authority. The release variants move settled deposits from the escrow to the treasury and are submitted by the operator once the released amount crosses a per-token threshold.
Voucher redemption
Events
The indexer matches
Deposit and SwapDeposit against stored quotes by quote_hash. Native amounts carry the default pubkey as mint.