Hi @MADAR-NETWORK, it is an interesting design. I think the key tradeoff is that users need no account or funds on the MADAR chain, but the payment confirmation is trusted to the registrar (the payment watcher). The suggestions below make that trust auditable.
- Store the payment transaction hash on chain when the sale completes.
Example: The registrar completes a sale, and the name moves to the buyer. Later, the seller says that no payment arrived. The chain shows only that the registrar moved the name. It does not show which payment the registrar used for its decision. Nobody can check if the registrar was correct, made an error, or was compromised.
Solution: Record the hash of the payment transaction on chain with the completed sale. Then the committee, or anyone, can find that transaction on the payment chain and check it. A dispute then has evidence. The dispute can happen inside the sale flow (a challenge window that starts when the registrar confirms the payment and ends before the transfer, making the transfer optimistic) or outside it (a committee decision after the transfer).
- Add a random identifier to the payment amount.
Example: Buyer A locks ahmad.madar at 25 USD, paid to the seller address. Buyer A sends the payment at the end of the window, and it arrives after the lock expires. The seller offer is still valid, so Buyer B locks the same name, at the same price, with the same receiving address. Buyer A’s payment arrives during Buyer B’s window. The registrar sees a payment of 25 USD to the correct address, inside the window, and completes the sale for Buyer B. Buyer B gets the name with Buyer A’s money.
Solution: Give each lock a unique exact amount: the price plus a small random part (for example, 25.000317 for Buyer A and 25.000842 for Buyer B). The registrar accepts only a payment with the exact amount of the active lock. Thus, Buyer A’s payment cannot match Buyer B’s lock. Also record the expected exact amount on chain (for example, in the lock event), so that anyone can later verify that the registrar matched the correct payment.
A sender check also solves this, but it requires the buyer to pay from the same wallet and chain that will own the name (or a previously registered wallet from the payment chain), so it excludes payments from exchanges. The unique amount permits them, if the exchange sends the exact amount (some exchanges deduct the withdrawal fee from it).