Concurrent Agent Actions Need One Nonce Owner per Signer
By DX Research Group · · Execution mechanics
Nonce tracking follows the signing wallet. A concurrent-worker fixture defines atomic allocation and separates replay protection from execution sequencing.
Concurrent workers that share a signing wallet need coordinated nonce allocation. We would key the allocator by signer, independently of the model session and destination subaccount. Hyperliquid tracks nonces per signer and recommends an atomic counter for allocation. Giving each worker a local timestamp generator leaves collisions possible when their clocks produce the same millisecond.
The signer is the concurrency boundary
Illustrative case: two workers act during millisecond 1,800,000,000,000. Worker A proposes a buy and worker B proposes a cancellation. Separate local counters both allocate 1,800,000,000,000. A shared atomic allocator instead assigns that value to A and 1,800,000,000,001 to B. Unique nonces prevent this collision; they do not establish whether the cancellation should precede the buy or whether the two actions satisfy a joint exposure constraint. Those are separate policy dependencies.
Persist allocation before handing it to workers
Keep signer identity, allocated nonce, action identity and signing state in one recoverable record. A restarted worker should recover its allocation rather than obtaining a new one for the same unresolved signed action. Coordinate the counter across processes when they share a signer. Test two accounts signed by one wallet, a crash after allocation and out-of-order delivery. Also test clock rollback. The protocol should produce unique allocations while retaining unresolved action identity and explicit business dependencies.
Recovery belongs to the signer
Nonce uniqueness is a mechanical property that can be tested without live trading. Run the allocator under concurrent requests and assert uniqueness per signer, then inspect recovered signed-action associations after a simulated restart. Economic ordering requires a separate fixture because a unique higher nonce alone should never serve as evidence that a prerequisite cancellation has completed.
Our execution and reconciliation framework provides the broader mandate-to-outcome trace. The state and memory contract explains how the verified result should enter the next decision. These notes narrow those published methods to one execution boundary; the worked amounts above are illustrative and the test is a proposed local fixture. The source inspected for the venue-specific statements is the official Hyperliquid nonces and API wallets.
Each worker should receive an allocation receipt rather than infer nonce ownership from a successful signature. Signing proves possession of a key; the allocator record proves which local economic action owns that particular replay-protection value. Each expected outcome remains a proposed test until an implementation run produces its own saved result and reviewable evidence.