1 · Choose a deposit wallet
Pick a pair. The withdraw wallet is not a choice — it is the wallet committed alongside this one in the vault's delegate root, and it is the only wallet that can pull this deposit back out.
2 · Fund the pair, then check it
Send the gas and the USDT to these two addresses yourself, from wherever you keep the float — the platform never moves your money. Then press Check gas & USDT. It reads the chain and reports what each wallet is short, for the amount set in step 3; the actions below stay locked until the wallets actually hold what each one needs.
3 · Deposit, then withdraw
Set the amount, then press the button. The deposit wallet signs the deposit and the withdraw wallet signs the withdrawal. Your wallet signs neither, and the vault pays the caller — so the USDT lands in the withdraw wallet.
4 · Relay to a final wallet
The last hop is the only one that needs a human signature. Name the destination, pick the asset, sign the authorisation in your wallet, and the engine moves it out of the withdraw wallet. Without that signature it will not move. The asset is part of what you sign, so an authorisation for USDT can never be replayed to move POL.
Engine wallets
Every wallet is derived on demand from one mnemonic. Nothing is stored per wallet, and the deposit/withdraw pairing is fixed by the delegate root the vault was deployed with.
Operators
An operator may drive every step of the flow and sign settlement authorisations. Only the master can add or remove one, and removing an operator kills its live session immediately. Master only.
Recovery
Every wallet the platform uses comes from one twelve-word phrase and one derivation path. Re-deriving reproduces the same addresses, the same trees and the same two roots the vault is enforcing — which is what makes the set recoverable rather than merely backed up.