Skip to content
Mainnet Live. All executions, addresses and hashes are live.
WORMHOOK
conceptualv0.1 · skeleton docs

Executor model

Who delivers messages, who pays, and why they don't need to be trusted.

Role

An executor watches for delivery requests, fetches the signed VAA, and submits it to the destination gateway. In return it is paid the fee quoted at the source.

What an executor can and can't do

CanCan't
Deliver lateExecute an expired call (the gateway refuses, WH-201)
Decline to deliverChange the call or payload (signatures and hash)
Deliver twiceRun the hook twice (call ID is consumed, WH-302)
Choose gas price within the quoteExceed the hook's gas limit

So the executor affects liveness, not correctness. That's the property WORMHOOK is designed around.

Quote → request → delivery

conceptual
1. quote     SDK asks for a delivery quote for (route, gas limit)
2. request   router tx pays Wormhole fee + quote; delivery request recorded
3. observe   guardians sign the message → VAA
4. deliver   executor submits VAA + payload to WormHookGateway
5. return    gateway posts receipt; return delivery to Solana (same model)

When delivery is slow

The explorer marks a call delayed when the executor hasn't delivered within the route's expected window (WH-202). Nothing is lost, because the VAA is valid. Two outcomes follow:

  • it's delivered before expiry and executes normally; or
  • it's delivered after expiry and the gateway returns a failed receipt (WH-201).

Manual redelivery (anyone submitting the VAA) is planned so liveness doesn't depend on one executor.

See the relay pending demo and the expired demo.