Resources

How it works

Every execution intent maps to one blockchain address.

An intent

An intent is seven values, and every one of them is part of its address:

FieldWhat it fixes
tokenThe ERC-20 the address accepts.
amountExactly how much of it the calls spend.
callsThe contracts it calls, the functions and the arguments, in order.
expirationTimestampWhen it stops waiting, and returns what it holds.
recoveryWhere anything that can’t be spent goes.
saltWhat makes it unique among identical intents.
chainIdThe one chain it executes on.

The address is the counterfactual address of a smart contract that isn’t deployed yet, and that’s hardcoded to route your funds and make its calls exactly as you, or an app, intend. That contract is Payment.

Your wallet
Executable address0x092d…F860
ERC-4626 vault
Your wallet
The intent
token
USDC
amount
100 USDC
calls
1. approve(vault, 100 USDC)2. deposit(100 USDC, your wallet)
recovery
your wallet
chainId
8453 (Base)

From payment to execution

You send exactly 100 USDC to the address. Execute detects it, and deploys the Payment contract, which executes your actions. The deployment is a call to PaymentFactory: permissionless, non-upgradeable and non-custodial, and deployed at the same address on every chain.

  1. 01PayYou send exactly 100 USDC to the address, with an ordinary transfer from any wallet or exchange.
  2. 02DetectExecute sees the transfer land and waits for it to confirm.
  3. 03ExecuteExecute calls PaymentFactory.execute, which deploys Payment at the address. Its constructor makes the calls.
  4. 04SettleThe transaction confirms. The vault’s shares are in your wallet, and the address is spent.

Execute holds no funds and no keys to the address: nobody does. It only sends the transaction the terms already decide, and anyone could send it instead.

Recovery

Payment also handles funds that arrive when the intent can’t run as written: the wrong token, part of the amount, after expiry, more than the amount, or a call that fails.

Executable address
recoveryusually your wallet
Too much
Everything above the amount goes to recovery, and the calls run with exactly the amount.
Too little
The address waits for the rest. If it’s still short at expiry, everything goes to recovery.
Too late
After expiry, no call runs: the whole balance goes to recovery.
A call fails
Nothing happens: the calls run together or not at all. Execute retries until expiry, then refunds.
Another chain
Executed on a chain the intent doesn’t name, the address sends its whole balance to recovery.
Another token
Once the address is deployed, anyone can call recover(token), which sends that token to recovery.

Verification

Every executable address can be checked before a single token is sent to it. The address is computed from its terms: the token, the exact amount and every call it will make. Anyone can recompute it before sending, and change one byte and it’s a different address.

Any address can be checked at execute.cash/address/<address>. This is that page’s check, on the vault deposit above: it reads each field from the terms, hashes them in your browser, and compares the result with the address. Change a byte to see the address move.

MorphoSteakhouse Prime USDC · BaseReady
Terms704 bytes
0.00—
#CallOnAmountTo
01——0.00—
02——0.00—
Expires
— 
Refunds to
—
Salt
0x0000…0000
Chain
—
This address0x092dae7201Cc39437042194D671dDae2628dF860
Recomputed0x0000000000000000000000000000000000000000