For everyone / Prices and real-world assets

The native oracle

Most chains treat prices as something applications fetch. Pickle publishes them in the protocol: the price of AAPL or of gold arrives as part of block production, at a canonical address, with market hours respected.

What it is

Apps on a chain often need to know what something costs right now: the price of ETH, of gold, of a share. Usually each app has to go and fetch that from somewhere and pay for it. On Pickle the chain itself writes the prices into every block, in one known place, so every app reads the same number at the same moment. The catch is that the same computer that runs the chain is the one writing the prices, so you are trusting it for both.

Two contracts placed at canonical addresses at genesis hold the prices: a registry with every feed's latest answer, and an adapter exposing them in the interface most existing lending and derivatives code already consumes. One system transaction per block publishes the batch. That is the structural difference from an external oracle: a price is not a third-party transaction competing for inclusion and paying gas, it is part of the block, produced by the sequencer alongside the transactions it orders. Answers carry eight decimal places, and the publishing transaction is flagged so a consumer can tell a system price from a user transaction.

Genesis predeploys a price registry and an adapter at canonical addresses. One flagged system transaction per block writes the batch at eight decimals. The read surface is a batch method and a per-feed method over JSON-RPC, plus a per-feed HTTP endpoint. A separate aggregating service holding no signing key assembles the batch; the sequencer polls it over an internal interface for a batch authenticated with a shared secret, publishes during block production, and the service reads its own result back off the chain. That division means compromising the price service does not by itself let anyone sign anything.

What it covers

ClassCount
Equity9 feedsAAPL, MSFT, NVDA, AMZN, GOOGL, META, TSLA, SPY, JPM
Foreign exchange5 feedsEUR/USD, GBP/USD, USD/JPY, USD/CHF, USD/CNH
Energy3 feedsBrent, natural gas, and a broad oil index
Metals2 feedsgold, silver
Crypto14 feedsETH, BTC, SOL, XRP, DOGE, LINK, ADA, XLM, BCH, TRX, BNB, HYPE, ZEC, XMR

33 feeds, of which 19 are real-world assets. The real-world set is the point: a crypto oracle is a solved problem, and a chain that publishes the price of a share or of gold, with the market's opening hours respected, is not.

How a price is formed

Two policies, because the two asset classes fail differently.

  • Crypto is aggregated from five public spot venues: Coinbase, Kraken, Bitstamp, Gemini and Bitfinex. Per-venue freshness is judged on a monotonic receive clock rather than on exchange timestamps, outliers are dropped, the answer is the median of what survives, and each feed declares a minimum number of sources below which it publishes nothing rather than publishing thinly.
  • Everything else, equities, foreign exchange, energy and metals, comes from an authenticated third-party aggregator, with integrity checks on each update and a pinned exponent so a scale change cannot pass silently.

Market hours

Market hours are a first-class concept, and this is the part that makes the layer usable for real-world assets rather than only for crypto. Each non-crypto feed carries a schedule, resolved against a real time-zone database so that daylight-saving transitions are handled rather than approximated; a market status accompanies every answer; and a reopening gate prevents the first tick after a close from being treated as a continuous-trading price. A crypto oracle needs none of this. An equity price is meaningless without it.

The trust boundary

The publisher is the sequencer

A price inherits exactly the trusted-operator assumption that already governs ordering, and no more: a dishonest or compromised sequencer can publish a false price, and nothing on-chain arbitrates it. Any application consuming these feeds inherits that assumption too, and should say so to its own users.

The third-party dependency is load-bearing. Without a valid credential for the upstream aggregator, every feed sourced from it reports as unauthorised. That is 20 of 33 feeds: the whole real-world set, and one crypto feed that has no public venue of its own. The other 13 crypto feeds, sourced from public venues, continue. What is built on these prices is on the RWA layer page.