Ethereum's silent auction house.

Encrypted bids. Uniform-price fills. Anti-whale by design. Powered by Zama FHE.

sealed envelope
Sealed bids

Your bid is encrypted in your wallet before it leaves. Sealed on-chain, decrypted never.

uniform paddles
Uniform-price fills

Every wallet fills at the same clearing price. Bidding first buys you nothing.

glass vault
Private holdings

Your allocation lands as a confidential balance. Balances are yours to disclose, if ever.

current epoch open
Epoch 03 is open now.
closes in
{{ closeIn }}
participants
{{ participants }}

participant count only. no bid amounts are shown, ever.

how it works
{{ s.n }}
{{ s.title }}

{{ s.desc }}

LIVE AUCTIONS
ZP
$ZPAD
LIVE
Ethereum · Silent Auction House
?
Your token here
V2
Coming soon ·

Epoch 03

open
closes in {{ closeIn }}
price (per 1M ZPAD)
0.105 ETH
offered supply
13,400,000
participants
{{ participants }}
Your bid status: {{ bidStatus }}
ETH

your bid never touches chain in plaintext. it is encrypted before it leaves your wallet.

{{ bidError }}
✓
Your bid is sealed

it is encrypted on-chain until the round closes and the aggregate is decrypted.

only you can see this · {{ bidAmount }} ETH

no chart, no bonding curve, no leaderboard. there is nothing to front-run here.

SEALED
decrypting

round sealed. aggregate being decrypted.

only the total raised is being revealed. no individual bid is ever decrypted, not by us, not by the committee.

DECRYPTION HANDLE
0x9f3c1a77e04b2d8859c6fb1042aa3e7c...a2e1
threshold committee · 4 of 7 shares responded

a sealed round can sit here while the committee responds. if decryption stalls past 24h, anyone can trigger the emergency refund path.

Epoch 03

settled
aggregate decrypted · clearing price 0.0025 ETH
total raised
312.5 ETH
your fill
68%
your allocation is ready

your bid filled 68% at the uniform clearing price. the unfilled remainder returns to your wallet automatically. claimed tokens arrive as a confidential balance.

✓
allocation claimed

your $ZPAD landed as a confidential balance. the amount is visible only to you.

view claim tx on etherscan →
next round
Epoch 04 opens in {{ nextIn }}
upcoming

Epoch 03

refunding
decryption did not complete within the window.
the round could not settle. refunds are open.

no aggregate was decrypted and no allocation was made. your full sealed amount is returned to your wallet. no bid was ever revealed.

Documentation

An honest account of how zamapad works, what we trust, and what we don't. Read this before you bid.

IN SHORT

Zamapad is a sealed-bid, uniform-price auction protocol on Ethereum. You send ETH with an encrypted bid amount. The pad accumulates every bid as ciphertext. When the round closes, a threshold committee decrypts only the aggregate total. Every bidder who fills pays the same clearing price. No sniping, no gas wars, no ordering advantage.

What is a silent auction?

In a silent auction, every bidder writes their bid on a sealed slip and drops it in a box. Nobody sees anyone else's bid. When the round closes, the auctioneer opens the box, computes the clearing price, and every winning bidder pays the same amount per unit. This is the oldest known cure for the "who bids first" problem.

Zamapad ports that mechanic onchain. The "sealed slip" is a Zama FHE ciphertext. The "box" is a smart contract. The "auctioneer" is a threshold committee that only ever reveals the aggregate raise, never any individual bid.

Uniform-price means whether you were the first or the last to bid, whether you bid 0.01 ETH or 0.1 ETH, the price per token is the same for everyone who fills. Bidding first buys you nothing. Bidding big buys you no advantage over bidding small (except a bigger allocation, capped by the per-wallet cap).

Why sealed bids matter

Every launchpad since 2022 has been won by bots. The pattern is simple: a bot watches the mempool, sees a legit user trying to buy, front-runs the transaction, and dumps into the trailing demand. Bonding curves reward whoever transacts first. Public bid amounts telegraph demand to snipers who then race in ahead of retail.

A sealed-bid auction breaks all three attacks:

  • No mempool signal to front-run. Encrypted bids look identical to observers regardless of size.
  • No ordering advantage. Every bidder pays the same clearing price. Being first is worthless.
  • No demand telegraphing. Bots can't gauge how hot the round is except by counting participants (a public number that doesn't reveal amounts).

This is why we chose uniform-price sealed-bid over Dutch auctions, English auctions, or bonding curves. Uniform-price is the only mechanism where every dimension of bidder strategy converges on the same thing: bid your true valuation. There's nothing to game.

How the encryption works

Zamapad is built on Fully Homomorphic Encryption (FHE) via Zama's Ethereum protocol. FHE has one remarkable property: a computer can add up encrypted numbers without ever seeing them individually. It only ever sees the encrypted result.

Concretely, when you bid:

  1. Your browser generates an FHE ciphertext for your bid amount using Zama's public key.
  2. You send the ciphertext + a zero-knowledge proof (that the ciphertext is well-formed) to the pad contract.
  3. The pad calls FHE.add(encTotal, yourBid). The running total stays encrypted.
  4. When the round closes, the pad marks the aggregate encrypted total as "publicly decryptable" and emits an event.

The Zama threshold committee (a distributed network of KMS nodes) sees the emitted request, cooperates to decrypt only that one ciphertext, and returns the plaintext with a signed proof. Anyone can submit that proof back to the pad. The pad verifies the proof, records the raise, and computes each bidder's allocation.

About Zama

Zama is the team that built and shipped the Fully Homomorphic Encryption protocol we depend on. Founded in 2020 by cryptographers Rand Hindi and Pascal Paillier, Zama's mission is to bring confidentiality to public blockchains without giving up verifiability.

Zama shipped their Confidential Blockchain Protocol to Ethereum mainnet in early 2026. The protocol enables assets to be issued, traded, and computed on with encrypted state, while remaining fully verifiable by validators. It powers confidential ERC-20s, private DEXs, sealed-bid auctions, and confidential payments.

Zamapad is one of the first production applications built on top of the Zama protocol. We use Zama's FHE.sol library for on-chain FHE operations and their @zama-fhe/relayer-sdk for client-side encryption. Every FHE operation the pad performs is priced in ZAMA tokens paid to the coprocessor network.

Auction lifecycle

1
Bid

You send ETH to the pad with an encrypted bid amount. The pad silently clamps to the per-wallet cap and adds to the encrypted running total. One bid per wallet per epoch. Repeat attempts revert.

2
Seal

Once the bid-count cap is hit or the deadline passes, anyone can call seal(id). The pad marks the encrypted aggregate as publicly decryptable and transitions to Decrypting phase. Fully permissionless.

3
Decrypt

The Zama threshold committee (a distributed set of KMS nodes) cooperates to decrypt just the aggregate handle. Typically takes 30-120 seconds. The result comes back with a signed proof.

4
Settle

Anyone submits the decrypted aggregate + proof via settle(id, cleartext, proof). The pad verifies via FHE.checkSignatures, computes the uniform pro-rata factor (scalePpm), and transfers the filled portion of raised ETH to the treasury.

5
Reveal + claim

You call reveal(id) to make your own bid ciphertext publicly decryptable, fetch the plaintext + KMS proof off-chain, then call claim(id, cleartext, proof). The pad mints your confidential $ZPAD allocation and refunds any unfilled ETH from your escrow.

Threshold trust, not math trust

Your privacy holds because the aggregate is decrypted by a committee that splits the key across multiple parties. It holds as long as those parties do not collude above the threshold (typically 2/3 or 3/4). This is a distributed trust assumption, not a mathematical guarantee.

We do not claim:

  • Trustless privacy (like a zero-knowledge proof would give)
  • That your bid is mathematically impossible to see
  • That this is a zero-knowledge system

We claim exactly one thing: no single party can see your bid. Not the operator, not the issuer, not the coprocessor, not any individual committee member. Only a colluding supermajority could, and doing so would burn Zama's protocol.

Escrow ETH is public. The bid amount inside it is private during the round. It becomes derivable when you reveal to claim.

Safety mechanisms

Zamapad has two permissionless escape hatches so your ETH is never permanently trapped, even if Zama has an outage.

Decrypt timeout (24h)

If seal() was called but no keeper submits settle() within 24h, anyone calls emergencyRefund(id). Epoch flips to Refunding. Bidders withdraw full escrow.

Stuck epoch (30d)

If seal() itself is failing for a Zama-side reason and the epoch stays Open past deadline + 30 days, anyone calls emergencyRefundStuck(id). Same outcome: bidders recover full escrow with a plain ETH transfer, no FHE call required.

Neither hatch depends on the operator, an admin key, or continued Zama liveness. They are pure timeouts baked into the contract.

How zamapad compares

ZAMAPADBONDING CURVEDUTCH
Bid visibilityEncryptedPublicPublic
Fair clearingUniformFirst-moverTime-weighted
Sniper protectionYesNoPartial
Per-wallet capsEnforced onchainRareRare
Gas per bid~450k (FHE)~150k~150k
Failure recoveryPermissionless refundRug-proneRug-prone

The gas premium buys you cryptographic privacy. Choose the tradeoff based on what your bidders value.

Fees and gas

Zamapad charges no protocol fee on the $ZPAD launch. In v2, launches by third-party issuers will pay a fee (TBD, likely 1% of raise).

Gas is paid in ETH for the underlying EVM operations plus a per-FHE-op fee in ZAMA tokens paid to Zama's coprocessor. Approximate gas at typical mainnet prices:

ACTIONGAS~USD @ 10 gwei
Bid~450k~$8
Reveal~110k~$2
Claim~460k~$8
Full lifecycle~1.02M~$18

Bid during low-gas windows (weekend UTC nights) for the cheapest total cost.

Security and audits

The pad contract is ~430 lines of Solidity. It's designed to be small enough to audit visually, with heavy use of Zama's audited FHE library for all cryptographic operations. The test suite covers 31 cases including oversubscription math, sybil resistance, one-bid-per-wallet enforcement, and both emergency escape paths.

Formal audit status:

  • $ZPAD launch (v1): self-audited. Small surface, minimal storage, no admin keys, no upgradability.
  • v2 (multi-tenant factory): will require a third-party audit before mainnet.
  • Zama's underlying FHE contracts: audited by Zama and multiple firms during mainnet rollout.

Bug bounty: coming soon alongside v2. Until then, report security issues privately via the founders page.

epoch schedule

epochprice (per 1M $ZPAD)offered supply
{{ row.epoch }}{{ row.price }}{{ row.supply }}

capacities are derived from price and supply and are deliberately not shown here.

contract addresses

{{ c.name }}{{ c.desc }}
{{ c.addr }} →

known limitations

  • !{{ l }}

interested in launching your own token via zamapad?

V2 · COMING SOON

Run your own silent auction.

$ZPAD is our first auction — a proof of concept for the mechanic. v2 opens the venue to any issuer: deploy a sealed-bid launch for your token in one tx, same encryption, same anti-whale caps, same uniform-price clearing.

Still building. Drop your email to be one of the first auctions when v2 opens.

launch your token with FHE.

we'll only reach out when v2 opens. no marketing, no lists.

WHAT YOU GET
  • 1
    sealed-bid privacy during your entire launch

    bidders' amounts stay encrypted through every epoch. nothing to front-run. bots can't see who's serious.

  • 2
    uniform-price fair fills

    no gas wars, no ordering advantage. everyone who fills pays the same clearing price per epoch.

  • 3
    per-wallet caps + anti-whale distribution

    set a percentage cap per wallet. concentration is bounded by construction, not vibes.

  • 4
    automatic LP creation to your treasury

    raised ETH + your remaining supply pair into a Uniswap V3 LP after the last epoch. LP NFT lands in your deployer wallet.

  • 5
    no team allocation, no vesting cliffs

    100% of supply goes through the pad + LP. optional: reserve a portion for treasury or airdrops via a separate contract you control.

FAQ
what tokens can launch here?

any ERC-20 or ERC-7984. we're focused on early-stage projects doing a fair launch. no vesting-heavy tokenomics, no VC-tranche games.

what's the cost to launch?

deploy gas + zamapad protocol fee (TBD, likely ~1% of raise). no upfront fee. no gatekeepers.

why sealed-bid over a bonding curve?

bonding curves reward whoever transacts first. bots have won every bonding-curve launch since 2022. sealed-bid uniform price makes ordering irrelevant.

how long does a typical launch run?

The operator picks the schedule when they call openLaunch. $ZPAD is running 5 epochs × 12h = 60h total (2.5 days).

when does v2 open?

after $ZPAD launches successfully. we're pressure-testing the mechanic with our own token first. waitlist folks get first access.

want to see the mechanic live before v2 opens?