arboretum

Option pricing in fixed-point integer arithmetic.

Black-Scholes, Greeks, CRR lattices and implied volatility, as a Rust contract on Arbitrum Stylus. Integer arithmetic only, so a result can be reproduced from the same inputs.

Arbitrum Sepolia · no wallet needed, every method is a view

3336
reference cases
docs/ACCURACY.md
41
tests, none failing
cargo test, forge test
0
float instructions
scripts/verify_no_floats.sh
10 / 10
entry points matching
scripts/verify_onchain.sh

Quote the deployed contract, then compare it with a local build.

Underlying250
Strike240
Tenor3m
Volatility35%
Typecall

Rate and carry are fixed at 5% and 1% so the grid stays finite. Volatility is an input: there is no on-chain implied-volatility surface for tokenised equities to read, so the surface would have to arrive as a signed or committed input.

priceEuropean( 250, 240, 3m, 35%, call )Arbitrum Sepolia
Returned by the contract
the raw integer, at 1e9 scale
Same inputs, local build
 
Noise band
-
Estimated gas
-
Round trip
-
Grid points
1,680

Lattice pricing: early exercise and what it costs in gas.

priceLattice(250, 240, 3m, 35%, call or put)
European call
gas -
European put
gas -
American call
gas -
American put
gas -

Reading the deployed contract.

Verifiable computation: method and applicable scope.

An oracle-supplied price is an off-chain computation delivered as a value. The contract that consumes it cannot inspect the model, and cannot reproduce the number from the inputs it holds. Executing the same formula on-chain replaces that with instructions every node runs identically: integer arithmetic at a fixed scale, no floating point, overflow checked and reverted rather than wrapped.

The cost is measurable. A closed-form price costs 72,442 gas here, and a 512-step lattice costs 12.4 million, which is one to two orders of magnitude above reading a feed. The applicable cases are therefore the ones where the number is contested or final: settlement and expiry prices, fallback marks when a feed is stale, collateral valuation, and reproducible audit. Streaming quotes are outside the scope.

Two properties follow from computing rather than consuming the number.

It is reproducible from public inputs, which is what the comparison panels above measure. And its uncertainty is quantified: the noise band returned with each price is derived from the published error bound of the normal CDF approximation, not chosen for convenience.

Reproduction: the commands that produce these numbers.

scripts/verify_onchain.sh

Calls every method on the live contract and compares each answer against a local build of the same source.

scripts/verify_no_floats.sh

Validates the compiled module and disassembles it. Any f32 or f64 instruction fails the run.

cargo run -p arbreport

Regenerates the accuracy report from 3336 reference cases produced by CPython's math module.

py reference/gen_vectors.py

Rebuilds those reference vectors from scratch, so the report can be audited rather than believed.

cargo stylus check

Rebuilds the contract, recompresses it, and prices the deployment against a live chain.

Deployed deployActivated activation14,668 bytes compressed, against a 96 KB limit

Limitations.

Volatility is an input

There is no live implied-volatility surface for tokenised equities to read yet. The contribution is the transform from inputs to price, and the surface belongs behind a signed or committed input that is designed for but not built.

Accurate, not exact

The normal CDF is Abramowitz and Stegun 26.2.17, with a published absolute error of 7.5e-8 and a measured 7.55e-8 here. Monotonicity in volatility holds to within that, not beyond it.

Small numbers flush to zero

Premiums below one quantum, 1e-9, are returned as zero rather than as cancellation noise. The band where that happens is derived from the CDF's error rather than chosen.

Not audited

The engine, the contract and the fixed-point library have had no external review. Deployment is on a testnet. Treat it as a careful prototype, not as infrastructure.