> ## Documentation Index
> Fetch the complete documentation index at: https://docs.utexo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Swap Security Model

> Escrow isolation, resolver permissions, timeouts and refunds in Utexo Swap.

Utexo does not hold or custody user funds. Every swap is governed by on-chain settlement logic: swaps either complete in full or revert safely. There is no partial execution risk.

On every supported network (Ethereum, Tron, Solana, Bitcoin), a dedicated escrow is created for each swap. User funds are locked inside this escrow and can only be released once the swap is fulfilled.

## Resolver permissions

Resolvers provide liquidity and execute swaps on-chain. Their permissions are strictly limited by the protocol.

**Resolvers can:**

* Move user-approved assets into the swap-specific escrow
* Execute the swap according to the signed intent
* Withdraw escrowed funds **only after** fulfillment is verified

**Resolvers cannot:**

* Withdraw funds before fulfillment conditions are met
* Access funds from any other swap
* Move user assets outside the defined execution flow
* Modify the conditions defined in the signed intent

## Timeouts and refunds

Every swap has a time-to-live (TTL). If the resolver does not complete the swap before the TTL expires, the swap enters a refund path and funds are returned to the `refund_address` specified in the intent. Funds cannot be locked indefinitely.

## Chain-specific settlement mechanisms

| Network | Mechanism |
| - | - |
| Ethereum / EVM | Dedicated escrow smart contract per swap |
| Tron | Same escrow model as EVM |
| Solana | Program-derived escrow account (PDA) per swap |
| Bitcoin | Taproot-based hash time-locked contract (HTLC) |

## Security guarantees

* Funds are segregated at the individual swap level.
* Resolvers cannot access assets outside the swap execution flow.
* Escrow release is conditional on verified fulfillment.
* Swaps automatically revert through the refund path if execution fails.

These mechanisms ensure that swaps either complete successfully or revert safely, without exposing users to partial execution risk.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.