A daily official price for tokenised assets on Canton, produced by a defined process and signed by several independent parties instead of asserted by one.
Every one of those is checkable, so it is stated here rather than discovered later. You would be among the first contributors.
An actively traded asset has thousands of prices — one per venue, changing continuously. A contract can reference only one. Settlement needs a single number, struck at a defined moment, that both parties agreed in advance and neither can afterwards move.
This is why EUR/USD trades every millisecond and the ECB still publishes one daily reference rate; why gold trades continuously and the LBMA auction still runs twice a day; and why Bitcoin trades around the clock and CME still settles every future on one daily fixing.
Continuous trading is the reason fixings exist, not the reason they do not.
For the observation window, from your own records: the volume-weighted average price of executed transactions, and the total executed volume. If nothing traded in a partition, you contribute nothing for it. You do not estimate.
This is a lookup, not a judgement. You are not asked what you believe the instrument is worth, and nothing here requires you to change your own internal valuation policy. A conservative marker and an aggressive marker can contribute to the same fixing without either changing anything.
One member proposes a fixing carrying the price, the recipe, and the rationale — the method statement showing how the number was derived. Others confirm.
By confirming you attest only that (a) your own contribution is recorded correctly, and (b) the published aggregation rule was applied correctly. You do not attest that you agree with the value as a matter of your own valuation policy.
| Commitment | What it is |
|---|---|
| Daily | Confirm with your own key. Minutes |
| Quarterly | Oversight review |
| Integration | None for the shadow run |
| Cost | None |
| Binding | Nothing. Either side may stop at any time |
Contributions are disclosed to the committee and the auditor only. The fixing is public; the contributions that produced it are not. This is enforced by Canton's signatory model, not by an API filter and not by policy.
You do not publish your own flow in order to participate — which is not available in a conventional benchmark, where contributing means handing trading data to an administrator that may republish it.
A committee whose members are all asked “do you agree this is the right price?” becomes a rubber stamp within a fortnight — not from bad faith, from economics. Contributors are not paid, and an unpaid member asked for a daily act of judgement will start clicking yes. So the question put to you is narrowed until it is nearly free to answer:
No contributor is ever asked for an opinion about the price. Each asserts a fact only it can see. Two things follow: signing is cheap enough to automate, and a refusal is specific — you decline by naming a condition that failed, not by disagreeing.
The three seats are composed to want different answers, which is what makes the number worth anything. An issuer wants the wrapper marked at par; a lender wants it marked conservatively; a venue wants it marked where it actually traded.
| Seat | What only you can see | What you assert |
|---|---|---|
| Issuer wrapped-asset issuer |
Whether the wrapper can actually be redeemed right now | Attestor quorum is met · proof-of-reserve is under 24h old · reserves cover supply · no redemption is stuck past its window |
| Lender collateral platform |
Whether you will carry this number on your own book | The mark is within your declared tolerance of your own valuation · no liquidation you ran cleared materially away from it · you will mark your own collateral here |
| Venue where the asset trades |
The transaction data — the only observed prints for the wrapped asset | The mark sits inside the range your book traded · the spread is inside tolerance · volume met the declared minimum |
The venue's assertion is enforced by the ledger, not by policy. A venue supplying a traded range that does not contain the proposed price is refused on-chain, as is an inverted range or a half-specified one. The one seat holding real transaction data cannot rubber-stamp even if it wants to.
The issuer's and lender's assertions are recorded but not machine-checked — they rest on your own systems, and on a false attestation being permanent, attributable, and made against your own money. We would rather state that asymmetry than let you discover it.
CF Benchmarks prices Bitcoin. It has never priced wrapped Bitcoin. A wrapped asset is a claim on something priced elsewhere, and its value is the benchmark print multiplied by the market's confidence that redemption works. Marking it at par is not a fact — it is an assertion, and it is the assertion that has broken every wrapped asset that ever broke.
So the benchmark print and the par factor are separate signed fields, and the struck price is computed as their product. That is what lets you decline meaningfully: you are not disputing the price of Bitcoin, you are declining to attest par, and the record shows which.
Every check above is a query against your own systems. None requires a human to form a view, and you should run a checker that confirms automatically when all your conditions pass and halts and escalates when one does not. That is not a convenience — a seat that needs daily human attention is a seat that is dishonest by month six.
A checker must never auto-confirm on a failed condition, and never widen its own tolerances to make a check pass. Both silently convert this back into a rubber stamp, and both are invisible on the ledger because the signature looks identical.
A waterfall, applied in order. The first tier that produces a value is the fixing, and the tier used is published with it.
| Tier | Method | Requires |
|---|---|---|
| 1 | Sealed auction uniform price | Two orders, two distinct parties. One participant can never set a fixing |
| 2 | Contributed inputs, aggregated | Three contributions from three distinct contributors |
| 3 | Carry forward, flagged | Nothing. Three consecutive triggers an oversight review |
Observation window: one hour ending at the strike, in twelve five-minute partitions. Volume-weighted median within each partition; equal-weighted mean across them. This follows the CME CF Reference Rate construction: partitioning defeats volume-based manipulation, the median defeats outliers, and equal weighting stops late volume dominating. A short window — the final five minutes alone, for instance — is deliberately not used, because a short window is inexpensive to move.
The administrator does not trade the instruments it prices. A hard constraint on the business, not a preference. CrossDesk operates no venue and takes no position in any instrument for which it publishes a fixing.
A 90-day shadow run. A daily fixing struck in parallel with whatever you use now. Informational only — not for settlement or valuation. No fee, no integration, and either side may stop at any time.
If the shadow fixing agrees with your existing mark, you have gained an attributable, independently-signed record at no cost. If it diverges, you have learned something worth knowing about a number you currently rely on.
The full Participant Information Pack sets out governance, methodology, corrections and known limitations. The pilot letter is one page and non-binding.
Request the participant pack What CrossDesk is
Listed so you do not have to find them.