YONDER docs
One buy becomes one piece, but the last step is the buyer's own. Five parties touch a buy in order: the buyer, the pool, the server, the buyer again to submit the mint, and the collection, which sends the piece to a fresh stealth address instead of the buyer's own wallet.
The buyer shows up twice: once to buy, once to submit the mint. The stealth address at the end is a new address only the buyer's keys can find, not the buyer's own public address.
Transfer log with the pool as the sender. This transaction is public, the same as any buy.Transfer log with the pool as sender and an amount at or above the collection's minimum, and only then signs an EIP-712 MintAuthorization naming the buyer, a buy reference, the amount and a fifteen minute deadline. The signature says nothing about where the piece will land.mintForBuy on the collection directly from Get my pieces, attaching the server's authorisation plus that stealth address, the ephemeral public key and a one-byte view tag. The contract requires the buyer's own wallet to be the sender, so the buyer pays the gas for this transaction. There is no keeper and no relayer paying it for them.Minting the piece is not the end of the story, because it lands somewhere new. Whenever the buyer wants to check, they reconnect the same wallet and scan the announcer's log in bounded block ranges. For every announcement, the site recomputes the shared secret with the buyer's own viewing key, checks the view tag, and derives the candidate stealth address; a match means that piece is theirs. The same signature that built the viewing key also reconstructs the stealth address's own spending key, entirely in the browser, so the buyer can move the piece into an ordinary wallet whenever they choose. That move is its own transaction, and the stealth address needs a little native gas of its own to send it.
A buy under the minimum. If the amount is below the collection's minBuy, the server refuses with "buy under the minimum" and nothing is signed.
A transfer that is not from the pool. A wallet-to-wallet transfer, a transfer of a different token, or a transfer into the pool never qualifies. The server only ever signs for a Transfer whose sender is the pool address.
A replay. Every buy reference can be used once. If the same transaction is submitted again, the collection's own usedBuy mapping and the server's own check both refuse it as "that buy already has its piece."
What the buyer sees in each case is the same thing: no second piece, and no error to act on. A buy that never qualified never had a piece coming; a buy that already has its piece will not get a second one no matter how many times the mint is submitted.