
Ondo Finance – which operates an institutional financial transaction platform for tokenised assets – has introduced the Ondo Network, a privacy-first decentralised platform that is already powering Ondo Perps, a high-performance perpetual futures offering. In doing so, Ondo notes that its original plan to build on blockchain technology – dubbed Ondo Chain – needed a rethink.
In a blog post, Ondo describes its Ondo Network as “the execution layer for a new generation of financial markets – fast and private like a centralised exchange, verifiable like a blockchain, and non-custodial in design.”
The first application built on the Ondo Network is Ondo Perps, a perpetual futures platform that just launched. Ondo Perps will deliver deep liquidity, 24/7, professional-grade execution, and native access to tokenised real-world assets as collateral – with fairness, user control over funds, privacy, and multi-chain access built in at the infrastructure layer.
Importantly, the Ondo Network is not a perps-specific system. It is general-purpose infrastructure for any application that needs execution speed, privacy, and distributed, verifiable correctness. Spot markets, structured products, lending markets and trade settlement rails can all be built on it.
But while Ondo designed its infrastructure platform to deliver the decentralised trust benefits associated with blockchain technology – including non-custodial ownership of assets, peer-to-peer and permissionless transactions, and privacy – as it built the Ondo Perps service it realised that an alternative base technology would be needed.
Specifically, Ondo determined that while blockchain networks work well enough for the settlement portion of transactions – recording ownership of assets in a durable and verifiable way – they fall short in terms of performance and privacy for supporting low latency transaction execution.
As a result, the Ondo Network has been built to be a verifiable execution environment: applications run privately and at high speed inside secure enclaves, while a decentralised set of attestors ensures – cryptographically, not contractually – that only approved code is running. This separates the execution of application logic from the verification of that execution and puts each function where it works best.
To drill down on the two main types of components in the design:
Enclaves – also known as Trusted Execution Environments, or TEEs – execute the application code (such as order matching or trading margin calculation) privately and securely inside hardware-isolated environments that even the machine’s administrator cannot inspect or modify.
Attestors – which leverage cryptography to:
- Verify application code. Before an enclave can execute an application, a quorum of attestors checks its code to determine that it is an approved version.
- Hold cryptographic keys securely. The keys critical to the operation and security of applications are split into pieces, with each attestor only receiving a subset of them.
- Connect the Ondo Network to public blockchains. Attestors act as a quorum-verified oracle for asset transfers and other on-chain events.
Once verified and provisioned, enclaves run applications at full speed – and create a cryptographically signed, repayable log of all core state transitions. That log can be replayed against the approved code by all allowed third parties – auditors, counterparties and the like – to independently confirm that every action followed the rules in the approved code.
For trading applications, this means that verification never sits between an order and a fill, slowing trade execution down; it doesn’t have to, because the attestors have already approved the code that’s doing the filling.

Ondo Network Secure Execution Architecture
Source: Ondo Finance
As as result of its Enclave/Attestor architecture, the Ondo Network achieves several design goals, including:
- Low latency. Code execution occurs in near real-time inside enclaves, not through every node replicating every transaction. Attestors verify correctness periodically rather than gating each state transition. The result is transaction latency that is similar to centralised exchanges, but with trust guarantees that are difficult for centralised approaches to make.
- Verifiable fairness. Only approved code can ever execute. Any tampered or altered version won’t run. All core actions performed by the code are recorded in a signed log, so it can be independently verified that the right code ran, unmodified, and produced exactly the results it did. For trading operations, this means that these parties can independently verify that no order was skipped, front-run, or preferentially matched.
- Privacy-focused. Because execution is separated from public data, privacy (or the lack thereof) is a user- or application-level choice rather than a network-wide mandate. Sensitive activity, such as order flow and updates to individual positions, need not be broadcast publicly or exposed on a public ledger.
- Decentralised non-custodial design. The cryptographic key that authorises transfer of assets is assembled only inside a verified enclave running approved code. No individual ever holds this key, and no administrator, even one with full control of the underlying infrastructure, can extract it, trigger the signing process, or alter the code that governs it.
While the Ondo Network – and the Ondo Perps trading application – are now live, the company emphasises that there is much more work to do in terms of improving the platform’s security, privacy and functionality.
The blog post also suggests that in the future, further development of the Ondo Network design, as well as the evolution of blockchain technology in terms of performance, privacy and scalability might bring the two architectures closer. Taking a philosophical and pragmatic view of its technology route, it notes “While the Ondo Network isn’t the blockchain we first described, it’s the truer expression of why we wanted one.”
Subscribe to our newsletter


