Ducat system architecture
Map every actor, state object, trust boundary, and Bitcoin commitment.
Follow these 9 lessons in order, or choose the topic you need. Each lesson combines an explanation, a worked example and practice inside the Guild.
What Ducat is designed to do
Ducat lets people borrow against bitcoin without first moving that collateral to another blockchain. UNIT is Ducat’s dollar-pegged stablecoin: one output of a wider system of vaults, risk checks, signatures, price data, and Bitcoin transactions.
35 minutes · Open lessonThe end-to-end system lifecycle
A user action moves through client construction, Bitcoin transactions, Guardian authorization, confirmation, validator reconstruction, and, when required, an oracle-triggered liquidation path.
45 minutes · Open lessonActors and responsibilities
Vault owners, Guardians, validators, oracles, relays, liquidators, LPs, and operators have distinct powers, information, and failure modes.
55 minutes · Open lessonVault state
A vault is represented by Bitcoin outputs plus protocol metadata, with each valid action consuming an earlier state and creating its successor.
65 minutes · Open lessonAccounts, reserves, and UNIT debt
Issuance and reserve accounts are UTXO-based protocol objects whose availability and transitions are tracked by validators and coordinated by Guardians.
35 minutes · Open lessonThe Bitcoin enforcement boundary
Bitcoin enforces committed transaction and Script conditions, while richer Ducat state and economic rules are reconstructed and checked by protocol participants.
45 minutes · Open lessonExternal trust and availability
Guardians, oracles, validators, relays, clients, and operators remain explicit honesty or liveness dependencies even where Bitcoin constrains the final spend.
55 minutes · Open lessonProtocol profiles and configuration
Network parameters, Guardian keys, oracle keys, ratios, fees, and feature settings are versioned inputs to clients and validators.
65 minutes · Open lessonCurrent versus target architecture
Repository code, deployed environments, security roadmaps, and public descriptions can differ; every claim must carry a date and status.
35 minutes · Open lesson