User Flow
This page describes the intended user journey in plain language.
Before using Oro
The user needs:
- Rabby or another compatible EVM wallet connected to Sepolia.
- an unlocked Azguard profile compatible with the current Aztec testnet.
- test
mXAUTfrom the Oro faucet or an existing test balance. - enough gas or fee balance for the relevant chain.
The current deployment is a public testnet beta. Test assets have no monetary value, usage limits may apply, and the contracts are not approved for mainnet funds.
Bridge into Aztec
The user chooses an amount to bridge from Ethereum to Aztec.
The app asks Rabby for one intent signature, then submits an mXAUT approval when required and a Sepolia deposit transaction. After the lock, the relayer waits for confirmations and claims ZGLD on Aztec.
The interface persists the transfer and shows its progress. The testnet estimate displayed by the app is approximately 1 hour 30 minutes, but network proving and publication can take longer without meaning that the transfer has failed.
Use ZGLD
Once received, ZGLD can be used without borrowing.
This matters: Oro is not only a lending flow. It also gives users a confidential gold-backed asset on Aztec.
Mint ORO
If the user wants liquidity, they can deposit ZGLD and mint ORO.
The app shows the position health before the user signs. If the backend, oracle, or protocol reads are unavailable, minting is blocked until the data is fresh again.
Repay and withdraw
The user repays ORO to reduce debt. After repayment, they can withdraw some or all of their ZGLD, depending on the remaining collateral ratio.
Bridge back to Ethereum
For the Aztec to Ethereum direction, the user provides the destination EVM address, signs the bridge intent in Rabby, then confirms the ZGLD burn transaction in Azguard. The relayer waits for an Aztec Outbox proof, unlocks mXAUT on Sepolia, and submits the Aztec acknowledgement.
On the current testnet, the user burns the full ZGLD amount on Aztec and receives 99% of that amount as mXAUT on Sepolia. The remaining 1% is the configured exit fee. If the fee is disabled in a later deployment, the received asset amount matches the burned ZGLD amount.
The Rabby signature authorizes the intent and binds the EVM recipient. It is not an asset transfer or an Ethereum gas transaction. The Azguard confirmation is the transaction that burns ZGLD.
Interrupted transfers
Do not repeat a deposit or burn that already appears in Rabby or Azguard. Use the transfer history and the Bridge Recovery flow to attach the existing transaction safely.
If a service is offline
The app is designed to fail closed for actions that can change user risk.
- Backend offline: position-changing actions pause.
- Oracle stale: minting pauses.
- Relayer stalled: existing transfers stay visible, new bridge actions may be blocked.
- Aztec RPC unknown: the app shows a separate service warning.
Read-only data may remain visible, but stale data should not be used to create a new transaction.