The Zcash-native
perpetual exchange
Hold ZEC. Trade any market. Settle back to ZEC. Zebra lets you put your Zcash to work as collateral on perpetual futures — self-custodial, ZEC-denominated end to end, built on NEAR and Orderly.
Testnet research preview · unaudited · no real funds01 Overview
Zebra is a perpetual-futures exchange where ZEC is the only collateral. You deposit ZEC, trade perpetual contracts on a wide range of markets, and every position's margin and profit-or-loss settles back into ZEC in your own vault. You stay effectively long ZEC the entire time — and use it to try to earn more ZEC.
It's modeled on the great inverse-collateral exchanges (BitMEX's XBT-margined era), rebuilt for Zcash and for a self-custodial, on-chain world. Matching, the order book, and liquidations run on Orderly Network (a production perps engine on NEAR); native ZEC movement rides NEAR Intents; prices come from the Pyth oracle; and your collateral lives in a NEAR smart-contract vault you control.
No other serious perps venue is Zcash-native. Zebra is built for the shielded-money community: ZEC in, ZEC out, no stablecoin detour, no custodian holding your coins.
02 The thesis
The whole design follows one idea: a ZODLer should never have to stop holding ZEC to trade.
- One collateral. You post ZEC and nothing else. Your balance is always denominated in ZEC.
- Any market. Go long or short BTC, ETH, SOL, gold, an index — your ZEC backs the position.
- ZEC settlement. Wins and losses are realized in ZEC and land back in your vault. You walk away with more or less ZEC — never a stablecoin you then have to convert back.
- Self-custodial. Collateral sits in a vault contract keyed to your wallet, not on an exchange's books.
The net effect: Zebra is a way to stack ZEC by trading, while keeping ZEC the unit of account at every step.
03 How it works
The mental model is one line: Zcash is the money, NEAR is the rails, and Orderly is the exchange — and Zebra is the thin layer that stitches them so you only ever touch ZEC. Your ZEC is held by a vault contract on NEAR that you can always exit; you sign your own orders; and an off-chain engine routes them to Orderly for matching but can only ever apply what you signed. The custody-critical parts are enforced on-chain, not by us.
Under the hood, each piece does one job — and the custody-critical ones are enforced on-chain, not by us:
- ZODL wallet — where your ZEC lives and where withdrawals return.
- NEAR Intents — bridges native ZEC in and out as a wrapped-ZEC (NEP-141) token the vault can actually hold.
- Vault contract (NEAR) — custodies your wrapped ZEC (it holds the tokens, not an IOU), tracks margin and PnL, and enforces your withdrawal in code. You can read it and exit directly — including an escape hatch (force-withdraw / force-close) that works even if Zebra goes dark.
- Signed orders (NEP-413) — you sign every order with an in-browser trading key. The engine can only apply orders you signed, within oracle-price bounds — it cannot invent a loss against you.
- Engine — routes your signed orders to Orderly and books each fill back to the vault in ZEC (lock margin, settle PnL) — but only what your signatures and the oracle allow.
- Orderly Network — the production order book, matching, and liquidation layer on NEAR; you tap network-wide liquidity. Liquidations are permissionless — any keeper, only when the oracle says margin is below maintenance.
- Pyth oracle — the ZEC/USD price feeds that bound margin, PnL, settlement, and liquidation.
- Relayer — a convenience that helps bridge and relay; it is not trusted to credit deposits or gate withdrawals — the contract does those.
- Governance — the contract ships an m-of-n multisig + timelock for fund-touching admin (propose → approve → wait → execute, all public events), plus a guardian that can pause new risk but can never freeze your exit. Today's testnet deployment still runs in single-key bootstrap mode; switching governance on is a hard pre-mainnet gate.
Orderly's perps are USDC-margined — ZEC isn't a collateral asset there. Zebra never makes Orderly hold ZEC. Instead your ZEC stays custodied in the vault, the engine trades on Orderly, and each fill is translated into ZEC bookkeeping against your vault (lock margin, release, settle PnL) — applying only fills that match an order you signed. It works cleanly because your collateral and the contract's base unit are both ZEC — the margin and PnL math is in section 04.
The lifecycle of a trade
You bridge ZEC into the vault as wrapped ZEC — to a fresh one-time address each deposit; the contract takes custody and credits your balance on-chain.
You sign an order with your trading key; Orderly matches it; the engine locks initial margin in ZEC — applying only what you signed.
Marks, funding, and unrealized PnL update live against the Pyth price.
On close, realized PnL is converted to ZEC and settled; your margin is released back to free balance.
You call withdraw and the contract releases your ZEC — no operator approval needed. If Zebra ever went dark, force-withdraw lets you exit anyway.
04 Collateral & settlement
Zebra uses a vault-wrapper collateral model. Because your collateral and your account's base unit are both ZEC, the margin math stays clean:
- Initial margin in ZEC =
size / leverage— and it's independent of price, because converting USD margin back to ZEC at the same price is just the identity. - Realized PnL is computed in USD from the price move, then converted to ZEC at the fill price for settlement:
pnl_zec = pnl_usd / price. - Average entry is size-weighted across adds; partial closes release margin proportionally and realize PnL on the closed fraction.
Internally, ZEC amounts are tracked in zatoshis (1 ZEC = 100,000,000 zat) and prices in 8-decimal fixed point (price_e8), matching Pyth's exponent so there's no lossy floating-point in the money path.
Deposit 10 ZEC. Open a 5× position; the vault locks 2 ZEC as margin. Win, and ZEC is added to your balance; lose, and ZEC is deducted. Close out and your 2 ZEC margin frees up. Everything you see is ZEC.
05 Privacy model
Zebra is built for Zcash, so this part gets said plainly: shielded in, shielded out — transparent while trading.
- Depositing is a deshield, with a fresh address every time. Each deposit gets a one-time deposit address bound to your vault account — never a reused static one — so deposits aren't linkable to each other or to your source wallet by inspection. Sending from your shielded balance reveals the amount and that one-time address on the Zcash chain, but not your wallet history or the notes that funded it. The link backward into the shielded pool is broken.
- While trading, nothing is shielded. Your collateral becomes a transparent token on NEAR, and the vault is public state: balances, locked margin, and every settlement are readable on-chain by anyone. Timing/amount correlation between a Zcash deposit and a vault credit is also possible.
- Withdrawals are shielded-only. Refunds and payouts route only to a shielded address — Zebra blocks transparent targets and never refunds to the transparent address you deposited from. That closes the exact re-linking leak that has burned other Zcash + bridge flows: your trade history can't be tied back to your transparent identity on the way out. Once the ZEC lands shielded in your wallet, the forward link from your trading account ends there.
Zebra gives you Zcash privacy at the edges — one-time deposit addresses on the way in, shielded-only refunds on the way out — not inside the venue. While a position is open, treat your vault balance and positions as public. To be clear about what this is and isn't: it removes address reuse and transparent-refund re-linking, but it is not yet full cryptographic stealth or amount/route privacy (that's on the roadmap). If an unlinkable trading account matters to you, use a fresh account per session.
06 Markets
Zebra is multi-market: a single ZEC collateral balance can back positions across many perpetual contracts at once. The live set is ZEC + crypto majors, plus real-world-asset perps — gold, silver, the S&P 500 and Nasdaq 100, and mega-cap stocks like Tesla, Nvidia, and Alphabet — all margined and settled in ZEC. Crypto prices come from Pyth; the RWA markets are priced from Orderly's mark. Whatever the market, the collateral and the settlement currency stay ZEC. Trade Tesla with your Zcash.
The default market is ZEC/USD. You switch markets from the header; the price, chart, and order ticket all follow the selected pair, while your account stays in ZEC. RWA markets are tagged RWA in the picker.
Market hours. Crypto trades 24/7. The RWA markets follow traditional market hours — US stocks and indices trade weekday sessions (≈09:30–16:00 ET), metals run nearly around the clock on weekdays — so they show a ● CLOSED tag and block new orders nights and weekends. The chart and last price stay visible while a market is closed.
07 Leverage & margin
Leverage on Zebra is set per market by the risk engine, not chosen arbitrarily by us. Each market has a Base Initial Margin Ratio (IMR), and its maximum leverage is simply 1 / Base IMR. Higher-risk assets carry a higher IMR and therefore a lower cap.
| Market | Base IMR | Max leverage |
|---|---|---|
| BTC, ETH, SOL | 1% | 100× |
| LINK, AVAX, ADA, LTC, TON, gold, silver, indices | 5% | 20× |
| ZEC and most alts | 10% | 10× |
| Thin / new markets | 20% | 5× |
ZEC's max is 10× today, not 100×. Only the deepest markets (BTC/ETH/SOL) reach 100×. Two more things shrink your effective max as you scale up: an IMR Factor raises required margin as a position grows, and each market has a max-notional cap. So 100× only applies to small size.
Two ratios govern your account health. IMR is the bar to open new risk or withdraw. MMR (maintenance margin ratio, always lower) is the floor: cross below it and you're liquidated. The gap between them is your buffer — you lose the ability to add before you're ever liquidated.
08 Liquidation
If your account margin ratio falls below the maintenance margin ratio, the position is liquidated. On Zebra the trigger is permissionless and oracle-driven: the vault contract itself decides an account is liquidatable — equity below maintenance margin at a fresh Pyth price — and any keeper (the engine or anyone else) can call it. The close happens at the oracle price, the loss is realized in ZEC, remaining margin is released, and the keeper earns a small fee from the account's remaining collateral. There is no operator monopoly: a healthy account cannot be liquidated, and the contract rejects stale prices outright. On the Orderly side, its risk engine independently manages the hedge book. The liquidation price shown in the terminal is a close estimate; it ignores fees and funding.
Keep more free margin than the minimum, use stops, and remember that higher leverage moves your liquidation price closer to entry.
09 Funding
Perpetuals have no expiry, so funding payments tether the contract price to the underlying. At each interval, one side pays the other based on the funding rate: when the rate is positive, longs pay shorts; when negative, shorts pay longs. On Zebra, funding is settled in ZEC like everything else, and is independent of price — it's a function of your position size and the rate.
10 Fees
Zebra uses a transparent two-layer fee model. You pay one fee per trade. Underneath, the matching layer (Orderly) charges Zebra a base fee; the gap between what you pay and that base is Zebra's revenue. No hidden charges, and no separate fee just to deposit or withdraw.
Fee schedule
| Order type | Crypto | RWA — stocks · commodities · indices |
|---|---|---|
| Maker — limit order that adds liquidity | 0 bps (free) | 0 bps (free) |
| Taker — market order that takes liquidity | 6 bps (0.06%) | 8 bps (0.08%) |
Maker is free. If your order rests on the book and provides liquidity — a limit order that doesn't fill immediately — you pay nothing. You only pay the taker fee when you take liquidity with a market order (or a limit that crosses and fills right away).
- Where the taker fee goes — of the 6 bps crypto taker fee, the Orderly base is 3 bps and Zebra keeps ~3 bps; on RWA (8 bps) the base is 5 bps and Zebra keeps ~3 bps. It's the standard cost of immediacy and what funds the venue.
- Referral rebates come out of Zebra's share — a referrer earns a slice of the fee and the referee gets a rebate, both paid from Zebra's margin, not added on top (see Referrals).
- Funding is not a fee — it's a periodic transfer between longs and shorts (see Funding), settled in ZEC, paid trader-to-trader — Zebra takes no cut of it.
- Subject to change — fees are adjustable, and maker orders may earn rebates at higher builder tiers as volume grows. Zebra is on testnet today, so no real fees are charged yet.
11 Referrals
Every trade's fee can be split three ways, and Zebra sets the rates: a slice rebates to the referee (the new trader), a matching slice to the referrer, and Zebra keeps the rest. Rebates accrue on real volume and, in Zebra's model, settle as ZEC into your vault — so referrals stack ZEC the same way trading does.
- Share your code or link; a new trader binds it to their account (binding is permanent, and you can't refer yourself).
- You earn on your referees' ongoing activity, credited on a regular cadence.
- Default split (tunable): referrer 15% of the fee, referee 10% back, Zebra ~75%, capped at 30% combined.
12 Points
Points recognize on-exchange activity across a season. You earn for trading volume, referrals, and (later) providing liquidity, scaled by multipliers like an early-user bonus.
Crucially, points are fee-weighted, not volume-weighted — they track the fees you actually pay, which makes wash-trading to farm them cost real money. Self-crossing fills and instant open-close churn earn nothing.
Points are a record of participation. They are not a token, not an allocation, and not a promise of any reward or monetary value. Any future reward is discretionary and undefined.
13 Security & custody
- Self-custodial, enforced in code. The vault contract holds your wrapped ZEC and releases it on a withdrawal you sign. Zebra never takes custody; you can read your balance and exit on-chain.
- An escape hatch that always works. If the engine and relayer go silent, you can
force-withdrawyour free collateral and, after a longer window,force-closepositions at the oracle price and exit — with zero operator cooperation. Operator disappearance never means trapped funds. - The engine can't steal. Settlement only applies orders you signed (NEP-413) within oracle-price bounds — the engine can't invent a loss or move your funds to itself. Liquidations are permissionless, triggered by the oracle, not an operator monopoly.
- Bounded admin. The contract's governance module puts fund-touching changes behind a multisig + timelock with public events, and a guardian can pause new risk but can never block your exit. Today's testnet vault still runs single-key bootstrap; activating governance is a pre-mainnet gate.
- Keys stay yours. Zebra never asks for your seed phrase or private keys. No one legitimately will.
- Honest about the limits. This is trust-minimized, not trustless: the operator can stall or misorder but cannot steal, and you can always exit. The weakest link is the ZEC bridge — wrapped-ZEC is only as trust-minimized as the bridge holding the real ZEC — which is why Zebra is testnet, unaudited, and gated behind independent audits + proof-of-reserves before any real funds (see Status).
- Privacy with responsibility. Zebra is built for the privacy community, which also means access may be restricted in some jurisdictions and the project moves deliberately on the legal front rather than ignoring it.
14 Status & roadmap
Zebra is a testnet research preview. It is unaudited and uses no real funds. Here's what's real versus in progress:
| Piece | State |
|---|---|
| Vault contract (NEAR testnet) | Deployed & live |
| Engine → vault settlement (user-signed orders · on-chain apply_fill) | Live on testnet |
| Oracle keeper (engine → Pyth price push) | Live on testnet |
| Trading terminal & demo | Playable |
| Multi-market UI & Portfolio (65+ perps incl. RWA) | Live on testnet |
| Referrals & Points | Live on testnet |
| Mainnet rails proof — deposit, signed trade, escape hatches, withdraw with real ZEC (own funds only, no users) | Done · July 2026 |
| Public mainnet & real user funds | Gated |
The mainnet gate is deliberate: real funds wait on an audit, a legal entity, market-maker liquidity, and native-ZEC rails on mainnet. Privacy plus leverage is exactly the surface that gets exchanges in trouble when done carelessly — Zebra would rather be slow and standing than fast and indicted.
Zebra is testnet-only today. Want a heads-up when mainnet goes live? Follow @zebraperps on X, or join the waitlist on the home page. No token, no airdrop, no returns — just a launch ping. Not an offer or solicitation.
15 Risk disclosures
- Leverage cuts both ways. It magnifies losses as much as gains; you can be fully liquidated.
- Principal is at risk. Trading, and any future vault, can lose ZEC. Never risk what you can't afford to lose.
- Testnet only. Do not send real ZEC to testnet addresses; balances here have no monetary value.
- Not financial advice. Nothing here is a recommendation to trade or a solicitation. Availability may be restricted by jurisdiction.
16 Glossary
A long-term Zcash holder, and (here) the wallet you connect to Zebra.
The smallest ZEC unit; 1 ZEC = 100,000,000 zatoshis. Zebra accounts in zat to avoid rounding.
A futures contract with no expiry, kept near spot by funding payments.
A contract collateralized in the coin itself (here, ZEC) rather than a stablecoin.
Initial and Maintenance Margin Ratios — the bars to open risk and to avoid liquidation. Max leverage = 1 / Base IMR.
The periodic payment between longs and shorts that tethers the perp to the index price.
Forced closure of a position when account margin falls below maintenance.
17 FAQ
No. You deposit ZEC, trade, and withdraw ZEC. There's no stablecoin step in your experience.
Not today — ZEC's cap is 10×. 100× exists only on the deepest markets (BTC/ETH/SOL), and only for small size. We show the real cap per market.
You do. Collateral lives in a vault contract keyed to your wallet; Zebra is non-custodial.
No. Zebra is on testnet and unaudited. Real ZEC is gated behind audit, legal, and liquidity work.
No. Points record activity only. They are not a token, allocation, or promise of one.
◆ Support development
Zebra is an independent, open build. If it's useful to you and you'd like to help fund its development, you can send shielded ZEC to the address below. This is a donation toward open-source development only — no token, no presale, no equity, and no promise of any return. Just support for the work.
Scan with ZODL or any Zcash wallet. Shielded only — your support stays private, the way Zcash intends. Thank you for backing an independent build.