Betto Custodial Operations
How Betto's custodial balances, trading, withdrawals, and launch gates work.
Betto Custodial Operations
Betto customers sign in with email and password. They do not connect wallets, hold crypto, or sign Kuest orders.
Customer wallet model
Each customer receives two hidden Polygon addresses:
- A generated signer wallet identifies the customer to Kuest and signs server-side actions.
- A derived Kuest Deposit Wallet holds that customer's USDC and prediction positions.
The signer private key is encrypted with CUSTODIAL_MASTER_KEY. The customer never receives or sees it. Staging and production must use different master keys. Production should use managed key storage when available.
BUSINESS_WALLET_ADDRESS is the operator treasury address. Completed withdrawals return USDC from the customer's Deposit Wallet to this address before the customer receives fiat.
Customer balance flow
- The customer pays the operator outside Betto.
- An admin verifies the payment and completes a top-up entry.
- The admin converts the fiat amount to USDC and deducts the 2.5% deposit fee.
- The admin sends the net USDC to the customer's unique Kuest Deposit Wallet and records the transaction proof.
- Betto reads the customer's real on-chain USDC balance and submits orders with the customer's hidden signer.
- Kuest positions and winnings remain isolated in that customer's Deposit Wallet.
- Kuest auto-redeem returns resolved winnings to the same wallet when supported.
Custodial accounts are buy-and-hold accounts. Customers see simple fiat-style balances and Yes/No actions, never wallet controls.
Withdrawal flow
- The customer requests a withdrawal in Betto.
- The requested amount is immediately reserved so it cannot be bet again.
- When the admin completes the request, Betto signs a gasless transfer from that customer's Deposit Wallet to
BUSINESS_WALLET_ADDRESS. - The operator pays the customer in fiat or cash.
- An admin records the blockchain proof and marks the withdrawal complete.
Launch gate
Amoy (CHAIN_ID=80002) is test-only. Before real money, configure Polygon mainnet (CHAIN_ID=137), production Kuest credentials, managed PostgreSQL and storage, a production domain, key management, KYC/AML controls, and jurisdiction-specific approval.