diff --git a/.github/workflows/artifacts/safety-score-missing-data-reviewed-ledger.json b/.github/workflows/artifacts/safety-score-missing-data-reviewed-ledger.json index a423b3f52e..8857253caf 100644 --- a/.github/workflows/artifacts/safety-score-missing-data-reviewed-ledger.json +++ b/.github/workflows/artifacts/safety-score-missing-data-reviewed-ledger.json @@ -740,6 +740,2443 @@ ], "nextReviewTrigger": "Confirm both sentinels absent on the first production replay after the live-reserves producer runs with this adapter.", "factsClosed": 0 + }, + { + "claimGroupId": "ACCESS_REVIEW:usda-anzens", + "taskIds": [ + "V9G-6c9da7164582cf48" + ], + "workType": "ACCESS_REVIEW", + "resolutionMode": "agent-curation", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://github.com/cardano-foundation/cardano-token-registry/blob/8a2cd449b86ac6f27a7de34dd0845160a832266b/mappings/fe7c786ab321f41c654ef6c1af7b3250a613c24e4213e0425a7ae45655534441.json", + "https://developers.cardano.org/docs/developers/curriculum/native-tokens/minting-policies/" + ], + "rationale": "Cardano registry identity and mint-only policy execution support holder-controlled native transfer permissionlessness; existing measured-adverse freeze facts are NOT closed by this review. Production acceptance pending.", + "changeRefs": [ + "35e690d44", + "shared/data/safety-score-v9/transfer-review-overlays-v1.json" + ], + "sentinels": [ + "usda-anzens:gap:access:transfer" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "ACCESS_REVIEW:usdm-moneta", + "taskIds": [ + "V9G-49068cbb410130aa" + ], + "workType": "ACCESS_REVIEW", + "resolutionMode": "agent-curation", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://github.com/cardano-foundation/cardano-token-registry/blob/8a2cd449b86ac6f27a7de34dd0845160a832266b/mappings/c48cbb3d5e57ed56e276bc45f99ab39abe94e6cd7ac39fb402da47ad0014df105553444d.json", + "https://developers.cardano.org/docs/developers/curriculum/native-tokens/minting-policies/" + ], + "rationale": "Cardano registry identity and mint-only policy execution support holder-controlled native transfer permissionlessness; issuer onboarding/redemption remain separate. Production acceptance pending.", + "changeRefs": [ + "35e690d44", + "shared/data/safety-score-v9/transfer-review-overlays-v1.json" + ], + "sentinels": [ + "usdm-moneta:gap:access:transfer" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "ACCESS_REVIEW:aznd-mu-digital", + "taskIds": [ + "V9G-cf562aa0a3b0f245" + ], + "workType": "ACCESS_REVIEW", + "resolutionMode": "agent-curation", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://monadscan.com/address/0x4917a5ec9fcb5e10f47cbb197abe6ab63be81fe8#code", + "https://monadscan.com/address/0xe5f8ec544310d5ae79da0f921d01ce80ffd528eb#code", + "https://monadscan.com/block/102222519", + "https://docs.mudigital.net/technical-reference/smart-contract-architecture/smart-contract-addresses.md", + "https://eth.blockscout.com/api/v2/smart-contracts/0x2e49c14a73210356de9f23a46a98de777b8a0db6", + "https://etherscan.io/address/0x52c66b5e7f8fde20843de900c5c8b4b0f23708a0#code", + "https://etherscan.io/block/25912083" + ], + "rationale": "Verified arbitrary-holder burn plus mutable PrimaryMarket on Monad and mutable OFT on Ethereum support restrictable. Captured role and upgrade simulation results verified. Monad EOA code checked independently; Ethereum EOA wording relies on prior attribution (review RPC 403); posture does not require EOA characterization. Production acceptance pending.", + "changeRefs": [ + "35e690d44", + "shared/data/safety-score-v9/transfer-review-overlays-v1.json" + ], + "sentinels": [ + "aznd-mu-digital:gap:access:transfer" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "MINT_AUTHORITY:kag-kinesis", + "taskIds": [ + "V9G-2a0ba3b6b1eadc20" + ], + "workType": "MINT_AUTHORITY", + "resolutionMode": "agent-curation", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://kinesis.money/silver/", + "https://etherscan.io/address/0x56ba8b58b7d1f6d384a1c4dd553f39ebc8741b8e", + "https://eth.blockscout.com/address/0x0f25045d15C163478bb67C56c5d9D602628F4F62?tab=contract" + ], + "rationale": "External-only representation exception satisfies existing rule; authored sole Ethereum route fully covered and no local mint controls removed. Native parent authority and locking invariant remain explicitly unresolved; bridge materiality/route gaps must remain. Production acceptance pending.", + "changeRefs": [ + "35e690d44", + "shared/data/stablecoins/domains/mint-authority/kag-kinesis.json" + ], + "sentinels": [ + "kag-kinesis:gap:economic-control:mint" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "RESERVE_COMPOSITION:jpysc-sbi-startale", + "taskIds": [ + "V9G-a8361d1714fbc20a" + ], + "workType": "RESERVE_COMPOSITION", + "resolutionMode": "agent-curation", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://www.shinseitrust.com/stablecoin/jpysc.html", + "agents/2026-09-05-safety-score-gap-campaign/research/reserves/review-decisions.json" + ], + "rationale": "Trustee page retrieved through web tool. Issuance/deposit-balance section remains dated June 30, 2026; no newer allocation was published in the reviewed source. June 30 composition date retained.", + "changeRefs": [], + "sentinels": [ + "jpysc-sbi-startale:gap:reserve-composition" + ], + "nextReviewTrigger": "Pharos reserve research: Trustee publishes a newer issuance and reserve-balance disclosure.", + "factsClosed": 0 + }, + { + "claimGroupId": "RESERVE_COMPOSITION:brlv-crown", + "taskIds": [ + "V9G-c172097185960c73" + ], + "workType": "RESERVE_COMPOSITION", + "resolutionMode": "agent-curation", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://dfg4lo8c2lfcn.cloudfront.net/report_brlv_8_2026_1ea3d5e0be.pdf", + "agents/2026-09-05-safety-score-gap-campaign/research/reserves/review-decisions.json" + ], + "rationale": "August 31 memo supports 99.98% bonds and 0.02% Treasury ETFs; cash is below 0.0001%. Fact Finance technical verification is self-reported, not accountant assurance. Actual posting date is unknown, so structured latestReport is omitted. Replay replaces the reserve gap with a mechanism gap: net closure remains zero.", + "changeRefs": [ + "35e690d44", + "shared/data/stablecoins/domains/reserves/brlv-crown.json" + ], + "sentinels": [ + "brlv-crown:gap:reserve-composition" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "RESERVE_COMPOSITION:eurq-quantoz", + "taskIds": [ + "V9G-fc87164254d0a2ea" + ], + "workType": "RESERVE_COMPOSITION", + "resolutionMode": "agent-curation", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://www.quantoz.com/transparency", + "agents/2026-09-05-safety-score-gap-campaign/research/reserves/review-decisions.json" + ], + "rationale": "Transparency page remains explicitly UPDATED June 30th, 2026, EURQ 34% cash / 66% bonds. No newer dated composition surfaced.", + "changeRefs": [], + "sentinels": [ + "eurq-quantoz:gap:reserve-composition" + ], + "nextReviewTrigger": "Pharos reserve research: Issuer publishes a reserve snapshot newer than June 30.", + "factsClosed": 0 + }, + { + "claimGroupId": "RESERVE_COMPOSITION:usdq-quantoz", + "taskIds": [ + "V9G-38c5a4c215f01fe3" + ], + "workType": "RESERVE_COMPOSITION", + "resolutionMode": "agent-curation", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://www.quantoz.com/transparency", + "agents/2026-09-05-safety-score-gap-campaign/research/reserves/review-decisions.json" + ], + "rationale": "Transparency page remains explicitly UPDATED June 30th, 2026, USDQ 30% cash / 70% bonds. No newer dated composition surfaced.", + "changeRefs": [], + "sentinels": [ + "usdq-quantoz:gap:reserve-composition" + ], + "nextReviewTrigger": "Pharos reserve research: Issuer publishes a reserve snapshot newer than June 30.", + "factsClosed": 0 + }, + { + "claimGroupId": "RESERVE_COMPOSITION:idrx-idrx", + "taskIds": [ + "V9G-a4c56b7692e329c4", + "V9G-cf9d467088346069", + "V9G-b8609d5d18bafcc2", + "V9G-cc65606b9f9ef110", + "V9G-c74e85f562aa1537", + "V9G-3d06dc3bf557543b", + "V9G-bb135af197657cde" + ], + "workType": "RESERVE_COMPOSITION", + "resolutionMode": "agent-curation", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://idrx.co/api/documents?page=1&take=100", + "agents/2026-09-05-safety-score-gap-campaign/research/reserves/review-decisions.json" + ], + "rationale": "Direct API returns 15 records; newest ID 16 is July 2026 report created August 10. Stored July 28 composition remains newest published report. No August report in index. Raw API saved idrx-index.txt.", + "changeRefs": [], + "sentinels": [ + "idrx-idrx:gap:reserve:reserve:2fb48797045babd839df7961:stale", + "idrx-idrx:gap:reserve:reserve:a2d69fb3b8126086a91168de:stale", + "idrx-idrx:gap:reserve:reserve:2704e3479acc40f38c2b334e:stale", + "idrx-idrx:gap:reserve:reserve:e0caabb30a060b194a576bd5:stale", + "idrx-idrx:gap:reserve:reserve:6844e403a5152afde98fcc71:stale", + "idrx-idrx:gap:reserve:reserve:ff4051fa938807f328287034:stale", + "idrx-idrx:gap:reserve:reserve:49785466b99abe3671ca321f:stale" + ], + "nextReviewTrigger": "Pharos reserve research: Issuer publishes August or later reserve report; recheck September 10.", + "factsClosed": 0 + }, + { + "claimGroupId": "RESERVE_COMPOSITION:pgold-pleasing", + "taskIds": [ + "V9G-495b30b9858814a4" + ], + "workType": "RESERVE_COMPOSITION", + "resolutionMode": "agent-curation", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://pleasing.gitbook.io/docs/tokenized-gold-pgold/reserve-report", + "agents/2026-09-05-safety-score-gap-campaign/research/reserves/review-decisions.json" + ], + "rationale": "Direct GitBook source still links only June 25, 2026 VISTO report. Page modification age is not a new composition date.", + "changeRefs": [], + "sentinels": [ + "pgold-pleasing:gap:reserve:reserve:27a99a64ae19781ce058c42e:stale" + ], + "nextReviewTrigger": "Pharos reserve research: Issuer publishes newer reserve assurance report covering current bullion and token liabilities.", + "factsClosed": 0 + }, + { + "claimGroupId": "RESERVE_COMPOSITION:xagm-matrixdock", + "taskIds": [ + "V9G-7a0cc872e8ecbffb" + ], + "workType": "RESERVE_COMPOSITION", + "resolutionMode": "agent-curation", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://matrixdock.gitbook.io/matrixdock-docs/english/silver-token-xagm/physical-silver-vault-audit", + "agents/2026-09-05-safety-score-gap-campaign/research/reserves/review-decisions.json" + ], + "rationale": "Official silver vault audit page links July 17, 2026 certificate SGMSG-26-00478, based on June 30 parcel list; downloaded text confirms 66 silver bars. Current product shows 73 bars / 72,927 oz but asset statement index has no documents and no dated current inventory report, so audit/composition dates remain June 30. Silver PDF ee6eb7b6e2001d4997cf0bbcc2892a9eaa3c0e84d74d536a4d0a63c55004646b.", + "changeRefs": [], + "sentinels": [ + "xagm-matrixdock:gap:reserve:reserve:a7d5686cb7b60c4fccb71f16:stale" + ], + "nextReviewTrigger": "Pharos reserve research: Issuer publishes newer dated silver inventory statement or physical audit with full holdings.", + "factsClosed": 0 + }, + { + "claimGroupId": "RESERVE_COMPOSITION:usdm-moneta", + "taskIds": [ + "V9G-66d3e17db586faa6" + ], + "workType": "RESERVE_COMPOSITION", + "resolutionMode": "agent-curation", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://moneta.global/transparency/", + "agents/2026-09-05-safety-score-gap-campaign/research/reserves/review-decisions.json" + ], + "rationale": "Current redesigned transparency page lists bank deposits and government MMFs but exposes no allocation percentages or dated composition. Old 20/80 allocation cannot be date-refreshed from aggregate total reserves or a generic today label.", + "changeRefs": [], + "sentinels": [ + "usdm-moneta:gap:reserve-composition" + ], + "nextReviewTrigger": "Pharos reserve research: Issuer publishes current weighted composition or admissible source payload with allocation/date.", + "factsClosed": 0 + }, + { + "claimGroupId": "RESERVE_COMPOSITION:thbill-theo", + "taskIds": [ + "V9G-9ed8f82b1396ee3f" + ], + "workType": "RESERVE_COMPOSITION", + "resolutionMode": "agent-curation", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://theo.xyz/thbill", + "agents/2026-09-05-safety-score-gap-campaign/research/reserves/review-decisions.json" + ], + "rationale": "Current product discloses ULTRA and FILQ as two underlying funds but no allocation weights or new dated composition. Docs endpoint returned HTTP 403. Existing reserve review already rechecked September 4; June 30 evidence date retained.", + "changeRefs": [], + "sentinels": [ + "thbill-theo:gap:reserve-composition" + ], + "nextReviewTrigger": "Pharos reserve research: Issuer publishes current dated ULTRA/FILQ holdings/allocation or verifiable balance disclosure.", + "factsClosed": 0 + }, + { + "claimGroupId": "MECHANISM_REVIEW:usdf-falcon", + "taskIds": [ + "V9G-3b83029939d9465f" + ], + "workType": "MECHANISM_REVIEW", + "resolutionMode": "issuer-or-onchain-evidence", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/evidence/mechanism-primary-research.md" + ], + "rationale": "Reviewed primary-source search did not establish current component-specific hedge inventory, funding stress or venue margin/liquidation evidence; product mandates and reserve reports cannot substitute.", + "changeRefs": [], + "sentinels": [ + "usdf-falcon:gap:mechanism-review:hedgeReconciliation" + ], + "nextReviewTrigger": "Pharos mechanism curation: Issuer publishes current product-specific hedge, venue-margin or funding-stress disclosure for the unresolved components.", + "factsClosed": 0 + }, + { + "claimGroupId": "MECHANISM_REVIEW:frax-frax", + "taskIds": [ + "V9G-61f6463e7c10ff62", + "V9G-e77383553eb537ab", + "V9G-ce8f43118667535f" + ], + "workType": "MECHANISM_REVIEW", + "resolutionMode": "agent-curation", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/evidence/mechanism-primary-research.md" + ], + "rationale": "Bounded review found no admissible new portfolio maturity, NAV valuation or holder loss-recovery evidence; existing unresolved components remain.", + "changeRefs": [], + "sentinels": [ + "frax-frax:gap:mechanism-review:durationAndLiquidity", + "frax-frax:gap:mechanism-review:lossRecoveryDesign", + "frax-frax:gap:mechanism-review:navValuation" + ], + "nextReviewTrigger": "Pharos mechanism curation: Frax publishes current portfolio maturity, NAV valuation or recovery evidence for the unresolved components.", + "factsClosed": 0 + }, + { + "claimGroupId": "MECHANISM_REVIEW:sfrxusd-frax", + "taskIds": [ + "V9G-90b4f27c6ec94157" + ], + "workType": "MECHANISM_REVIEW", + "resolutionMode": "agent-curation", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/evidence/mechanism-primary-research.md" + ], + "rationale": "Bounded review found no admissible new portfolio maturity, NAV valuation or holder loss-recovery evidence; existing unresolved components remain.", + "changeRefs": [], + "sentinels": [ + "sfrxusd-frax:gap:mechanism-review:lossRecoveryDesign" + ], + "nextReviewTrigger": "Pharos mechanism curation: Frax publishes current portfolio maturity, NAV valuation or recovery evidence for the unresolved components.", + "factsClosed": 0 + }, + { + "claimGroupId": "MECHANISM_REVIEW:mapollo-midas", + "taskIds": [ + "V9G-e5ccdb5e75cb032c" + ], + "workType": "MECHANISM_REVIEW", + "resolutionMode": "issuer-or-onchain-evidence", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/evidence/mechanism-primary-research.md" + ], + "rationale": "Reviewed primary-source search did not establish current component-specific hedge inventory, funding stress or venue margin/liquidation evidence; product mandates and reserve reports cannot substitute.", + "changeRefs": [], + "sentinels": [ + "mapollo-midas:gap:mechanism-review:hedgeReconciliation" + ], + "nextReviewTrigger": "Pharos mechanism curation: Issuer publishes current product-specific hedge, venue-margin or funding-stress disclosure for the unresolved components.", + "factsClosed": 0 + }, + { + "claimGroupId": "MECHANISM_REVIEW:mre7yield-midas", + "taskIds": [ + "V9G-4b572dfbe2cb17cd", + "V9G-67373064b8a0253d", + "V9G-b749e0ae680fdd20" + ], + "workType": "MECHANISM_REVIEW", + "resolutionMode": "issuer-or-onchain-evidence", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/evidence/mechanism-primary-research.md" + ], + "rationale": "Reviewed primary-source search did not establish current component-specific hedge inventory, funding stress or venue margin/liquidation evidence; product mandates and reserve reports cannot substitute.", + "changeRefs": [], + "sentinels": [ + "mre7yield-midas:gap:mechanism-review:fundingBasisStress", + "mre7yield-midas:gap:mechanism-review:hedgeReconciliation", + "mre7yield-midas:gap:mechanism-review:marginAndLiquidation" + ], + "nextReviewTrigger": "Pharos mechanism curation: Issuer publishes current product-specific hedge, venue-margin or funding-stress disclosure for the unresolved components.", + "factsClosed": 0 + }, + { + "claimGroupId": "MECHANISM_REVIEW:usdz-anzen", + "taskIds": [ + "V9G-7ab44e745932b33a", + "V9G-6987562b368ec986", + "V9G-22063c2df11531a3" + ], + "workType": "MECHANISM_REVIEW", + "resolutionMode": "issuer-or-onchain-evidence", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/evidence/mechanism-primary-research.md" + ], + "rationale": "Reviewed primary-source search did not produce new product-specific seniority, recovery or valuation-cadence terms; failed fetches were not treated as evidence.", + "changeRefs": [], + "sentinels": [ + "usdz-anzen:gap:mechanism-review:recovery", + "usdz-anzen:gap:mechanism-review:seniority", + "usdz-anzen:gap:mechanism-review:valuationCadence" + ], + "nextReviewTrigger": "Pharos mechanism curation: Anzen publishes product-specific seniority, recovery and valuation terms.", + "factsClosed": 0 + }, + { + "claimGroupId": "MECHANISM_REVIEW:fpi-frax", + "taskIds": [ + "V9G-6945944a337ba8bd" + ], + "workType": "MECHANISM_REVIEW", + "resolutionMode": "issuer-or-onchain-evidence", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/evidence/mechanism-primary-research.md" + ], + "rationale": "FPI primary overview documents FPIS mint/sale and conversion, not a holder post-loss waterfall or enforceable recovery promise; prior unavailable ruling remains.", + "changeRefs": [], + "sentinels": [ + "fpi-frax:gap:mechanism-review:lossRecovery" + ], + "nextReviewTrigger": "Pharos mechanism curation: Frax publishes a post-loss recovery commitment or documented holder waterfall.", + "factsClosed": 0 + }, + { + "claimGroupId": "MECHANISM_REVIEW:mmev-midas", + "taskIds": [ + "V9G-f10e4cabdc342d3a", + "V9G-1af433cb3a8dd0bf", + "V9G-3ae62e1a3734ad52" + ], + "workType": "MECHANISM_REVIEW", + "resolutionMode": "issuer-or-onchain-evidence", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/evidence/mechanism-primary-research.md" + ], + "rationale": "Reviewed primary-source search did not establish current component-specific hedge inventory, funding stress or venue margin/liquidation evidence; product mandates and reserve reports cannot substitute.", + "changeRefs": [], + "sentinels": [ + "mmev-midas:gap:mechanism-review:fundingBasisStress", + "mmev-midas:gap:mechanism-review:hedgeReconciliation", + "mmev-midas:gap:mechanism-review:marginAndLiquidation" + ], + "nextReviewTrigger": "Pharos mechanism curation: Issuer publishes current product-specific hedge, venue-margin or funding-stress disclosure for the unresolved components.", + "factsClosed": 0 + }, + { + "claimGroupId": "MECHANISM_REVIEW:zarm-mento", + "taskIds": [ + "V9G-d6e24dc6e8e54820", + "V9G-84f14663eb33c947", + "V9G-a4fccdb10d2e9b70" + ], + "workType": "MECHANISM_REVIEW", + "resolutionMode": "agent-curation", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://docs.mento.org/mento-v3/build/deployments/addresses", + "https://docs.mento.org/mento-v3/dive-deeper/security/risk-overview", + "agents/2026-09-05-safety-score-gap-campaign/evidence/mechanism-primary-research.md; pinned reserve API and finalized Celo block 76721442" + ], + "rationale": "Correct fiat-cash archetype and verified shared-reserve inventory support limited claim, custody and reconciliation components; this is not independent attestation or a full cross-chain liability audit.", + "changeRefs": [ + "1212350c2", + "shared/data/safety-score-v9/mechanism-review-overlays-v1.json" + ], + "sentinels": [ + "zarm-mento:gap:mechanism-review:assuranceAndReconciliation", + "zarm-mento:gap:mechanism-review:claimAndSegregation", + "zarm-mento:gap:mechanism-review:custodyContinuity" + ], + "nextReviewTrigger": "Root campaign owner: after 2026-09-06T00:00:00Z, verify date-gated admission and exact production sentinel absence without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "RESERVE_SLICE:usdy-ondo-finance", + "taskIds": [ + "V9G-8172c0427f231b42" + ], + "workType": "RESERVE_SLICE", + "resolutionMode": "agent-curation", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://ondo.finance/usdy (reviewed 2026-09-05; official September 3 holdings)", + "35e690d44", + "shared/data/stablecoins/domains/reserves/usdy-ondo-finance.json" + ], + "rationale": "Suspend scalar NAV feed because price plus supply does not observe holdings. Official September 3 portfolio review remains available as static composition; fresh producer and publication readback are required.", + "changeRefs": [ + "35e690d44", + "shared/data/stablecoins/coins/usdy-ondo-finance.json" + ], + "sentinels": [ + "usdy-ondo-finance:gap:reserve:reserve:75e2f5a8f9b0e270a49c8c3f" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "RESERVE_SLICE:feusd-felix", + "taskIds": [ + "V9G-24c2f40510d64936" + ], + "workType": "RESERVE_SLICE", + "resolutionMode": "agent-curation", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "https://usefelix.gitbook.io/docs/developers/market-1-feusd-cdp.md (reviewed 2026-09-05)", + "35e690d44" + ], + "rationale": "Correct configured kHYPE label from KittenFinance to Kinetiq, aligning the existing branch with its reviewed classified slice through the unchanged unique-name join. Fresh producer and publication readback are required.", + "changeRefs": [ + "35e690d44", + "shared/data/stablecoins/coins/feusd-felix.json" + ], + "sentinels": [ + "feusd-felix:gap:reserve:reserve:84ed09f1febc9b5963e9a7df" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:apxusd-apyx", + "taskIds": [ + "V9G-991bf7c6b206f45f" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: pancakeswap/Ethereum, uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "apxusd-apyx:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:bold-liquity", + "taskIds": [ + "V9G-72f6bdc81575777c" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "bold-liquity:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:cadc-cad-coin", + "taskIds": [ + "V9G-659b2ecc31289b80" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: aerodrome/Base. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "cadc-cad-coin:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:cadd-cad-digital", + "taskIds": [ + "V9G-70d11dcd2af977af" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "cadd-cad-digital:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:ceur-celo", + "taskIds": [ + "V9G-85e519d1b10ad3bd" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v3/Celo. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "ceur-celo:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:cjpy-yamato", + "taskIds": [ + "V9G-3f3022bc05d8e4d1" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "cjpy-yamato:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:crvusd-curve", + "taskIds": [ + "V9G-767fbb3dd4d6e819" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "crvusd-curve:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:dai-makerdao", + "taskIds": [ + "V9G-7f2f809baecca4a6" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: uniswap-v4/Ethereum, uniswap-v4/Polygon. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "dai-makerdao:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:dgld-gold-token-sa", + "taskIds": [ + "V9G-709770c3aece0e5e" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v4/Base, uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "dgld-gold-token-sa:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:dola-inverse-finance", + "taskIds": [ + "V9G-e6d0f1f32f14fa20" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "dola-inverse-finance:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:emxn-telcoin", + "taskIds": [ + "V9G-68ac2ab06824f113" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v4/Polygon. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "emxn-telcoin:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:eurau-allunity", + "taskIds": [ + "V9G-f224ede74544d0e0" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: aerodrome/Base. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "eurau-allunity:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:eurc-circle", + "taskIds": [ + "V9G-ee1c7d71768fa809" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: aerodrome/Base, uniswap-v3/Avalanche, uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "eurc-circle:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:euri-banking-circle", + "taskIds": [ + "V9G-6d319b4d06b0ef42" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "euri-banking-circle:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:eusd-telcoin", + "taskIds": [ + "V9G-aa243acc67eb9808" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v4/Base, uniswap-v4/Ethereum, uniswap-v4/Polygon. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "eusd-telcoin:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:frax-frax", + "taskIds": [ + "V9G-5932db9bed4e52c5" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: uniswap-v3/Avalanche. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "frax-frax:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:frxusd-frax", + "taskIds": [ + "V9G-956eeb321606d38b" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "frxusd-frax:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:jpyc-jpyc", + "taskIds": [ + "V9G-a39c2ebf8718b737" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: uniswap-v4/Ethereum, uniswap-v4/Polygon. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "jpyc-jpyc:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:jpyt-dephaser", + "taskIds": [ + "V9G-234126578f30ba32" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v3/OP Mainnet. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "jpyt-dephaser:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:krwq-iq", + "taskIds": [ + "V9G-c4fd68cfc2373f3a" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: aerodrome/Base. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "krwq-iq:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:meusd-mezo", + "taskIds": [ + "V9G-a78a2a7c0f2fcd6f" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: aerodrome/Base, uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "meusd-mezo:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:musd-metamask", + "taskIds": [ + "V9G-6ac8380f2198fe5f" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "musd-metamask:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:paxg-paxos", + "taskIds": [ + "V9G-408bb734839eb835" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "paxg-paxos:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:pgold-pleasing", + "taskIds": [ + "V9G-e16e347d01693aa7" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v3/Arbitrum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "pgold-pleasing:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:pmusd-precious-metals", + "taskIds": [ + "V9G-fa3171f9353c711f" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "pmusd-precious-metals:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:pusd-polymarket", + "taskIds": [ + "V9G-b341709ed037ffe8" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v3/Polygon. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "pusd-polymarket:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:rlusd-ripple", + "taskIds": [ + "V9G-879c4732476dc22c" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "rlusd-ripple:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:sbc-brale", + "taskIds": [ + "V9G-4f3825fc75d82a23" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v3/Base. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "sbc-brale:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:slvon-ondo", + "taskIds": [ + "V9G-ffd82d791a606ced" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v3/BSC, uniswap-v3/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "slvon-ondo:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:susdd-tron-dao-reserve", + "taskIds": [ + "V9G-09843c3a37e089c2" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "susdd-tron-dao-reserve:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:susde-ethena", + "taskIds": [ + "V9G-c4e3fa3116c9a125" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "susde-ethena:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:susn-noon", + "taskIds": [ + "V9G-5d3c2ee99e43e006" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v3/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "susn-noon:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:syrupusdc-maple", + "taskIds": [ + "V9G-610a8d48cba1f70a" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v4/Arbitrum, uniswap-v4/Base, uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "syrupusdc-maple:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:syrupusdt-maple", + "taskIds": [ + "V9G-74ccd41a950bec34" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v4/BSC, uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "syrupusdt-maple:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:tgbp-tokenised", + "taskIds": [ + "V9G-2f742c1e5d07edf5" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: aerodrome/Base. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "tgbp-tokenised:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:thbill-theo", + "taskIds": [ + "V9G-5922233783aa6a62" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v3/Arbitrum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "thbill-theo:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:u-united-stables", + "taskIds": [ + "V9G-e193ed6f2d1e043a" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v4/BSC. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "u-united-stables:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:usd1-world-liberty-financial", + "taskIds": [ + "V9G-a66fefdd550addb0" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "usd1-world-liberty-financial:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:usdc-circle", + "taskIds": [ + "V9G-2c5a8b56f8e9d0a8" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: aerodrome/Base, uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "usdc-circle:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:usdd-tron-dao-reserve", + "taskIds": [ + "V9G-14b126554953f47f" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "usdd-tron-dao-reserve:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:usde-ethena", + "taskIds": [ + "V9G-285c106b1fa24e48" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: uniswap-v3/Avalanche, uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "usde-ethena:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:usdq-quantoz", + "taskIds": [ + "V9G-c850e63554c2ff65" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "usdq-quantoz:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:usds-sky", + "taskIds": [ + "V9G-fde9ae50fc927734" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "usds-sky:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:usdt-tether", + "taskIds": [ + "V9G-6ae7863ab7bf117f" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "usdt-tether:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:vchf-vnx", + "taskIds": [ + "V9G-79742df833842566" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "defer", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Unresolved retained families remain: aerodrome/Base. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [], + "sentinels": [ + "vchf-vnx:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Pharos DEX producer owner: capture fresh staged candidates, verify exact physical identity and directional quote eligibility; new chain coverage also requires registry, quote validation and capacity review.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:xaut-tether", + "taskIds": [ + "V9G-54a51b8aa3aee3d2" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: uniswap-v4/BSC, uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "xaut-tether:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:xusd-straitsx", + "taskIds": [ + "V9G-95bc7d729bc08686" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "xusd-straitsx:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:zchf-frankencoin", + "taskIds": [ + "V9G-a164564ef765dd77" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05", + "evidence": [ + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-1.md", + "agents/2026-09-05-safety-score-gap-campaign/outputs/dex-latest-quote-status.raw.json", + "agents/2026-09-05-safety-score-gap-campaign/exit/CHECKPOINT-2-FEASIBILITY.md" + ], + "rationale": "Fresh activated targets were blocked by the prior published-route admission gate. Repair removes that bootstrap deadlock within unchanged quote budgets and proof checks; no closure is inferred from admission. Unresolved retained families remain: uniswap-v3/OP Mainnet, uniswap-v4/Ethereum. Physical identity, fresh source candidates, directional coherence or supported chain collectors must be proven; no alias, freshness or capacity relaxation was authorized.", + "changeRefs": [ + "a33d6ba42" + ], + "sentinels": [ + "zchf-frankencoin:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root campaign owner: confirm exact sentinels disappear without adverse replacement in fresh production publication after deployment and relevant producer refresh. Unresolved physical routes still require exact fresh identity evidence.", + "factsClosed": 0 + }, + { + "claimGroupId": "DEPLOYMENT_CONTROLS:sfrxusd-frax", + "taskIds": [ + "V9G-16ce05de8b7d6ec5", + "V9G-6694c7709c37a346", + "V9G-cfcf377815bb3da1", + "V9G-0725c55b49a7d2d0", + "V9G-50796f5b2e2da192", + "V9G-451aee9844312f0d", + "V9G-92177255d43cf4e9", + "V9G-e069204de8bf1e85", + "V9G-f062e87f3949278c", + "V9G-029c206facf407a4", + "V9G-a9d5ed5c0c0bf544", + "V9G-d43cece3c13db82a", + "V9G-e71fb662430ad407", + "V9G-220c2183666e4ac2", + "V9G-16f167b84e4e46f5", + "V9G-1ff643bf053c7d19", + "V9G-d478f017488f9d0f", + "V9G-4a30cd2b18f4b54a", + "V9G-154bd2ad75da461c" + ], + "workType": "DEPLOYMENT_CONTROLS", + "resolutionMode": "agent-curation", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "Codex sfrxUSD route controller campaign", + "evidence": [ + "https://docs.frax.com/protocol/crosschain/addresses", + "https://docs.frax.com/protocol/crosschain/overview", + "shared/data/stablecoins/domains/risk-review/sfrxusd-frax.json: 19 per-chain fixed-block owner, ProxyAdmin, implementation/code and authorized/unauthorized eth_call observations; exact blocks, RPC URLs and export SHA-256 pins in each route note" + ], + "rationale": "Nineteen EVM route controller identities were missing from the conservative route-derived bridge controls. Direct reads identify the actual sfrxUSD owner and matching ProxyAdmin owner; same-state owner peer and upgrade simulations succeed while unauthorized controls revert. Populate controller identity and failure domains only: retain contract authority, unbounded bridge impairment, unknown custody/modules/delay and all non-EVM/umbrella blockers. No grade or public closure is inferred. Regenerated explanatory replay reduces sfrxUSD open points from 27 to 8 with its score 41/D unchanged; this is not production acceptance.", + "changeRefs": [ + "ce8710fcc", + "shared/data/stablecoins/domains/risk-review/sfrxusd-frax.json" + ], + "sentinels": [ + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:06750749b74ff7456b2b", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:151c28400468f34d7140", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:2a2d43c2dc73dba166dc", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:48e394732656bd8ff645", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:4d6cead671ebe0fcd1f1", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:58082f9c0d080c55980f", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:68f1337b8d49bf9a08e9", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:6ce797702f79fc93e1c8", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:715603f58e8e0d3ef8a3", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:7c5c49c6f079623347cf", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:85fefcf813765b0d97d8", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:91b75d90f1c3a8647108", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:a64bd8f6a9bf35be5221", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:a8214d27941f8b110c99", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:aa1b290fd2f8e93ab0ac", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:d3a670affb2abf6792cd", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:e31b8fb898a20c9f7271", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:edde7242f8e24502a72a", + "sfrxusd-frax:gap:deployment-control:bridge-meta:sfrxusd-frax:f844dbd201a57e50577a", + "control:control:bridge-meta:sfrxusd-frax:06750749b74ff7456b2b:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3A06750749b74ff7456b2b", + "control:control:bridge-meta:sfrxusd-frax:151c28400468f34d7140:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3A151c28400468f34d7140", + "control:control:bridge-meta:sfrxusd-frax:2a2d43c2dc73dba166dc:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3A2a2d43c2dc73dba166dc", + "control:control:bridge-meta:sfrxusd-frax:48e394732656bd8ff645:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3A48e394732656bd8ff645", + "control:control:bridge-meta:sfrxusd-frax:4d6cead671ebe0fcd1f1:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3A4d6cead671ebe0fcd1f1", + "control:control:bridge-meta:sfrxusd-frax:58082f9c0d080c55980f:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3A58082f9c0d080c55980f", + "control:control:bridge-meta:sfrxusd-frax:68f1337b8d49bf9a08e9:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3A68f1337b8d49bf9a08e9", + "control:control:bridge-meta:sfrxusd-frax:6ce797702f79fc93e1c8:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3A6ce797702f79fc93e1c8", + "control:control:bridge-meta:sfrxusd-frax:715603f58e8e0d3ef8a3:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3A715603f58e8e0d3ef8a3", + "control:control:bridge-meta:sfrxusd-frax:7c5c49c6f079623347cf:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3A7c5c49c6f079623347cf", + "control:control:bridge-meta:sfrxusd-frax:85fefcf813765b0d97d8:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3A85fefcf813765b0d97d8", + "control:control:bridge-meta:sfrxusd-frax:91b75d90f1c3a8647108:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3A91b75d90f1c3a8647108", + "control:control:bridge-meta:sfrxusd-frax:a64bd8f6a9bf35be5221:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3Aa64bd8f6a9bf35be5221", + "control:control:bridge-meta:sfrxusd-frax:a8214d27941f8b110c99:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3Aa8214d27941f8b110c99", + "control:control:bridge-meta:sfrxusd-frax:aa1b290fd2f8e93ab0ac:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3Aaa1b290fd2f8e93ab0ac", + "control:control:bridge-meta:sfrxusd-frax:d3a670affb2abf6792cd:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3Ad3a670affb2abf6792cd", + "control:control:bridge-meta:sfrxusd-frax:e31b8fb898a20c9f7271:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3Ae31b8fb898a20c9f7271", + "control:control:bridge-meta:sfrxusd-frax:edde7242f8e24502a72a:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3Aedde7242f8e24502a72a", + "control:control:bridge-meta:sfrxusd-frax:f844dbd201a57e50577a:cause:sfrxusd-frax%3Agap%3Adeployment-control%3Abridge-meta%3Asfrxusd-frax%3Af844dbd201a57e50577a" + ], + "nextReviewTrigger": "Root campaign owner: regenerate the catalog, replay with explicit curation attribution, then verify fresh post-deploy production publication consumes these exact controller identities and removes the corresponding sentinels without adverse replacement. Non-EVM authority-family review remains separately deferred.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:dai-makerdao", + "taskIds": [ + "V9G-7f2f809baecca4a6" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for dai-makerdao: UUID 3f9f64ac-2815-5751-8cd1-eaebafb38016; pool_old 0xf6e8088529094bc485561fa2a03e3d19c9a60f5d99a997e8fe16ab4ca2db277a-ethereum-uniswap-v4; matching Ethereum token contracts 0x6b175474e89094c44da98b954eedeac495271d0f, 0xdac17f958d2ee523a2206206994597c13d831ec7; source timestamp 2026-09-03T07:04:04.874Z.", + "https://app.uniswap.org/explore/pools/ethereum/0xf6e8088529094bc485561fa2a03e3d19c9a60f5d99a997e8fe16ab4ca2db277a", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 7 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "dai-makerdao:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:usdc-circle", + "taskIds": [ + "V9G-2c5a8b56f8e9d0a8" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for usdc-circle: UUID 3c4132bf-ef75-5162-8558-70fd4fa91c81; pool_old 0xbddcef32a41bb9c9fa37b2442433ddffdd6095c7e6b0aeb1b0b979a5b5529e67-ethereum-uniswap-v4; matching Ethereum token contracts 0x9b525165b10e6da960fdfa6b34544771f442d9c4, 0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48; source timestamp 2026-09-03T07:04:04.874Z.", + "https://app.uniswap.org/explore/pools/ethereum/0xbddcef32a41bb9c9fa37b2442433ddffdd6095c7e6b0aeb1b0b979a5b5529e67", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 204 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "usdc-circle:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:usdt-tether", + "taskIds": [ + "V9G-6ae7863ab7bf117f" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for usdt-tether: UUID f71737e5-f02e-4964-b23e-19d1a6c7a6bf; pool_old 0x3b1b1f2e775a6db1664f8e7d59ad568605ea2406312c11aef03146c0cf89d5b9-ethereum-uniswap-v4; matching Ethereum token contracts 0xdac17f958d2ee523a2206206994597c13d831ec7, 0xdc035d45d973e3ec169d2276ddab16f1e407384f; source timestamp 2026-09-03T07:04:04.874Z.", + "https://app.uniswap.org/explore/pools/ethereum/0x3b1b1f2e775a6db1664f8e7d59ad568605ea2406312c11aef03146c0cf89d5b9", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js", + "https://etherscan.io/tx/0x061cfdf6bfc9f34d81a01f8d8c7dd9d84e51d874fb94e9447cc5c3ddb0528801" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 105 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "usdt-tether:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:usds-sky", + "taskIds": [ + "V9G-fde9ae50fc927734" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for usds-sky: UUID 0899ff3d-adc8-4dae-a516-a94998db3332; pool_old 0xe63e32b2ae40601662f760d6bf5d771057324fbd97784fe1d3717069f7b75d45-ethereum-uniswap-v4; matching Ethereum token contracts 0x6c3ea9036406852006290770bedfcaba0e23a0e8, 0xdc035d45d973e3ec169d2276ddab16f1e407384f; source timestamp 2026-09-03T07:04:04.874Z.", + "https://app.uniswap.org/explore/pools/ethereum/0xe63e32b2ae40601662f760d6bf5d771057324fbd97784fe1d3717069f7b75d45", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js", + "https://etherscan.io/tx/0x9dfd17310117acc02bcdd9618161fd6377ac3439b2480c20fbcf5ca66ae74dd5" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 4 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "usds-sky:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:rlusd-ripple", + "taskIds": [ + "V9G-879c4732476dc22c" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for rlusd-ripple: UUID 3b22b8c3-1409-5f4b-affb-4a868ecf9a88; pool_old 0x9035721b23481db3888fd201b9c2b26dbc3af60258bca65e669f2ed98dc8eb4f-ethereum-uniswap-v4; matching Ethereum token contracts 0x8292bb45bf1ee4d140127049757c2e0ff06317ed, 0xdc035d45d973e3ec169d2276ddab16f1e407384f; source timestamp 2026-09-05T15:01:49.539Z.", + "https://app.uniswap.org/explore/pools/ethereum/0x9035721b23481db3888fd201b9c2b26dbc3af60258bca65e669f2ed98dc8eb4f", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 2 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "rlusd-ripple:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:usde-ethena", + "taskIds": [ + "V9G-285c106b1fa24e48" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for usde-ethena: UUID fc8a754a-a8da-48db-aa47-4485d15dbc75; pool_old 0x63bb22f47c7ede6578a25c873e77eb782ec8e4c19778e36ce64d37877b5bd1e7-ethereum-uniswap-v4; matching Ethereum token contracts 0x4c9edd5852cd905f086c759e8383e09bff1e68b3, 0xdac17f958d2ee523a2206206994597c13d831ec7; source timestamp 2026-09-03T07:04:04.874Z.", + "https://app.uniswap.org/explore/pools/ethereum/0x63bb22f47c7ede6578a25c873e77eb782ec8e4c19778e36ce64d37877b5bd1e7", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 3 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "usde-ethena:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:dola-inverse-finance", + "taskIds": [ + "V9G-e6d0f1f32f14fa20" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for dola-inverse-finance: UUID 25876c9f-c801-4c83-adf5-63b6d40998ea; pool_old 0x6ebb515948b39f282ea7a97b5d3cc9e9a1b61efe2796b923ab973ed1c9d4e507-ethereum-uniswap-v4; matching Ethereum token contracts 0x865377367054516e17014ccded1e7d814edc9ce4, 0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48; source timestamp 2026-09-05T15:01:49.539Z.", + "https://app.uniswap.org/explore/pools/ethereum/0x6ebb515948b39f282ea7a97b5d3cc9e9a1b61efe2796b923ab973ed1c9d4e507", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 1 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "dola-inverse-finance:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:syrupusdc-maple", + "taskIds": [ + "V9G-610a8d48cba1f70a" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for syrupusdc-maple: UUID df8851f0-5b1d-4843-88fd-88468d129c78; pool_old 0xcdb422a853a4fa2deb364317db92ad76d1cb7a8e1b82a32219bcb41720a90228-ethereum-uniswap-v4; matching Ethereum token contracts 0x80ac24aa929eaf5013f6436cda2a7ba190f5cc0b, 0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48; source timestamp 2026-09-05T15:01:49.539Z.", + "https://app.uniswap.org/explore/pools/ethereum/0xcdb422a853a4fa2deb364317db92ad76d1cb7a8e1b82a32219bcb41720a90228", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 1 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "syrupusdc-maple:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:frxusd-frax", + "taskIds": [ + "V9G-956eeb321606d38b" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for frxusd-frax: UUID 08707ef3-bcfd-5981-8a9c-a5e2f318feb9; pool_old 0x76dbd3b36d5f0a1fa1c38b75984a9ed57aa1a36a6dbab77b9503ef9349dbb617-ethereum-uniswap-v4; matching Ethereum token contracts 0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48, 0xcacd6fd266af91b8aed52accc382b4e165586e29; source timestamp 2026-09-05T13:02:49.404Z.", + "https://app.uniswap.org/explore/pools/ethereum/0x76dbd3b36d5f0a1fa1c38b75984a9ed57aa1a36a6dbab77b9503ef9349dbb617", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 1 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "frxusd-frax:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:syrupusdt-maple", + "taskIds": [ + "V9G-74ccd41a950bec34" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for syrupusdt-maple: UUID db5fbc78-e618-4e05-8ab2-61b7c702051b; pool_old 0xd861038a98942312d1495dd1313fb66c7e7de48f549a15edf3a45decf7338e1d-ethereum-uniswap-v4; matching Ethereum token contracts 0x356b8d89c1e1239cbbb9de4815c39a1474d5ba7d, 0xdac17f958d2ee523a2206206994597c13d831ec7; source timestamp 2026-09-05T15:01:49.539Z.", + "https://app.uniswap.org/explore/pools/ethereum/0xd861038a98942312d1495dd1313fb66c7e7de48f549a15edf3a45decf7338e1d", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 1 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "syrupusdt-maple:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:xaut-tether", + "taskIds": [ + "V9G-54a51b8aa3aee3d2" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for xaut-tether: UUID eb252614-7a8e-454f-8346-60ebf50dbe62; pool_old 0xa8dd78582e31791c08187169a3343365a1e3282c67bc7f93c1e585ddd0a4c4e0-ethereum-uniswap-v4; matching Ethereum token contracts 0x68749665ff8d2d112fa859aa293f07a622782f38, 0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48; source timestamp 2026-09-05T15:01:49.539Z.", + "https://app.uniswap.org/explore/pools/ethereum/0xa8dd78582e31791c08187169a3343365a1e3282c67bc7f93c1e585ddd0a4c4e0", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 11 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "xaut-tether:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:apxusd-apyx", + "taskIds": [ + "V9G-991bf7c6b206f45f" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for apxusd-apyx: UUID 02d27f9f-e63d-497f-bbd9-826261b0d976; pool_old 0x9f2d9491277a9f2551c1f7533c1789aa6023bba0c5e9397e8a019cac5c10fe7f-ethereum-uniswap-v4; matching Ethereum token contracts 0x98a878b1cd98131b271883b390f68d2c90674665, 0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48; source timestamp 2026-09-05T15:01:49.539Z.", + "https://app.uniswap.org/explore/pools/ethereum/0x9f2d9491277a9f2551c1f7533c1789aa6023bba0c5e9397e8a019cac5c10fe7f", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 10 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "apxusd-apyx:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:musd-metamask", + "taskIds": [ + "V9G-6ac8380f2198fe5f" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for musd-metamask: UUID eac3b5f8-d620-47d6-9f6c-d984d3e653c1; pool_old 0x72daf39b278fab80f18ad2adf73cc8b1ae63de1e508d36aa033285fff506f169-ethereum-uniswap-v4; matching Ethereum token contracts 0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48, 0xaca92e438df0b2401ff60da7e4337b687a2435da; source timestamp 2026-09-03T07:04:04.874Z.", + "https://app.uniswap.org/explore/pools/ethereum/0x72daf39b278fab80f18ad2adf73cc8b1ae63de1e508d36aa033285fff506f169", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 1 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "musd-metamask:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:eurc-circle", + "taskIds": [ + "V9G-ee1c7d71768fa809" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for eurc-circle: UUID 61395c4f-90fc-4a70-851f-86182893705b; pool_old 0x801e07d014537e43d3b2173f241194ef8aa9e877616902f48b274ce807eb52e5-ethereum-uniswap-v4; matching Ethereum token contracts 0x1abaea1f7c830bd89acc67ec4af516284b1bc33c, 0xa3ec40cc9736ad0064630bfd60f2876d7762e3b2; source timestamp 2026-09-05T15:01:49.539Z.", + "https://app.uniswap.org/explore/pools/ethereum/0x801e07d014537e43d3b2173f241194ef8aa9e877616902f48b274ce807eb52e5", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 6 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "eurc-circle:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:zchf-frankencoin", + "taskIds": [ + "V9G-a164564ef765dd77" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for zchf-frankencoin: UUID 57aeb9ec-8200-4156-ae66-679e79416e98; pool_old 0x12718afa3f4488a9ad47a882754c7950611feac52ee7d7f6244e2209066a75aa-ethereum-uniswap-v4; matching Ethereum token contracts 0xb58e61c3098d85632df34eecfb899a1ed80921cb, 0xcedbea37c8872c4171259cdfd5255cb8923cf8e7; source timestamp 2026-09-05T15:01:49.539Z.", + "https://app.uniswap.org/explore/pools/ethereum/0x12718afa3f4488a9ad47a882754c7950611feac52ee7d7f6244e2209066a75aa", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 1 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "zchf-frankencoin:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:usdd-tron-dao-reserve", + "taskIds": [ + "V9G-14b126554953f47f" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for usdd-tron-dao-reserve: UUID 05f8a882-6b50-47c2-bbc1-06df0ec0db07; pool_old 0x086c9a92c31c38c6516ec48f91528cb14e72bb69edbdda152722d9f0fc09d49a-ethereum-uniswap-v4; matching Ethereum token contracts 0x4f8e5de400de08b164e7421b3ee387f461becd1a, 0xdac17f958d2ee523a2206206994597c13d831ec7; source timestamp 2026-09-03T07:04:04.874Z.", + "https://app.uniswap.org/explore/pools/ethereum/0x086c9a92c31c38c6516ec48f91528cb14e72bb69edbdda152722d9f0fc09d49a", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 1 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "usdd-tron-dao-reserve:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:jpyc-jpyc", + "taskIds": [ + "V9G-a39c2ebf8718b737" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for jpyc-jpyc: UUID 96815256-2c5d-5640-9afa-635206c0e454; pool_old 0x90566efa9eeae5db07880719eef46caf9f42fc623adb9dea4db00a27f04816ba-ethereum-uniswap-v4; matching Ethereum token contracts 0x1abaea1f7c830bd89acc67ec4af516284b1bc33c, 0xe7c3d8c9a439fede00d2600032d5db0be71c3c29; source timestamp 2026-08-30T20:01:58.463Z.", + "https://app.uniswap.org/explore/pools/ethereum/0x90566efa9eeae5db07880719eef46caf9f42fc623adb9dea4db00a27f04816ba", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 5 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "jpyc-jpyc:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:euri-banking-circle", + "taskIds": [ + "V9G-6d319b4d06b0ef42" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for euri-banking-circle: UUID ffa845a8-208b-48cd-908e-54f245938be2; pool_old 0xd85173a34c0567501850854604460efff465b40f3121b9ad17b3bcc705e083f8-ethereum-uniswap-v4; matching Ethereum token contracts 0x9d1a7a3191102e9f900faa10540837ba84dcbae7, 0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48; source timestamp 2026-09-03T07:04:04.874Z.", + "https://app.uniswap.org/explore/pools/ethereum/0xd85173a34c0567501850854604460efff465b40f3121b9ad17b3bcc705e083f8", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 1 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "euri-banking-circle:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:meusd-mezo", + "taskIds": [ + "V9G-a78a2a7c0f2fcd6f" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for meusd-mezo: UUID 8b0dcb2f-9dda-4451-8f5d-1c3dfe1e2a4e; pool_old 0xa9bf5691768ef950a99efd74d722961ff2df3fec08d77ec784432c619bd283a0-ethereum-uniswap-v4; matching Ethereum token contracts 0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48, 0xdd468a1ddc392dcdbef6db6e34e89aa338f9f186; source timestamp 2026-09-03T07:04:04.874Z.", + "https://app.uniswap.org/explore/pools/ethereum/0xa9bf5691768ef950a99efd74d722961ff2df3fec08d77ec784432c619bd283a0", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 1 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "meusd-mezo:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:dgld-gold-token-sa", + "taskIds": [ + "V9G-709770c3aece0e5e" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for dgld-gold-token-sa: UUID a26226c4-68b5-426f-8b9f-b237b8b03008; pool_old 0x8a389646a86a483f4ce02a7cff9e3f8a27fd686c1e02c1e38f405dfc553128b9-ethereum-uniswap-v4; matching Ethereum token contracts 0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48, 0xa9299c296d7830a99414d1e5546f5171fa01e9c8; source timestamp 2026-09-03T08:02:00.799Z.", + "https://app.uniswap.org/explore/pools/ethereum/0x8a389646a86a483f4ce02a7cff9e3f8a27fd686c1e02c1e38f405dfc553128b9", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 2 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "dgld-gold-token-sa:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:susde-ethena", + "taskIds": [ + "V9G-c4e3fa3116c9a125" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for susde-ethena: UUID 1117725b-721c-40d5-9641-887209b7906c; pool_old 0xb20351bcf606dcc3525d2ed36760a86a5dec7423b77d41125bd4a416ba93448b-ethereum-uniswap-v4; matching Ethereum token contracts 0x9d39a5de30e57443bff2a8307a4256c8797a3497, 0xdac17f958d2ee523a2206206994597c13d831ec7; source timestamp 2026-09-03T07:04:04.874Z.", + "https://app.uniswap.org/explore/pools/ethereum/0xb20351bcf606dcc3525d2ed36760a86a5dec7423b77d41125bd4a416ba93448b", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 3 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "susde-ethena:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:eusd-telcoin", + "taskIds": [ + "V9G-aa243acc67eb9808" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for eusd-telcoin: UUID 79841f80-6103-422e-bb2f-abb87769c86c; pool_old 0xdda3c47e70fb237fb50e3856169019bf26fe4c09d7b6618c4f9d6e2423903870-ethereum-uniswap-v4; matching Ethereum token contracts 0x14913815bcfde78baead2111f463d038ac9c2949, 0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48; source timestamp 2026-09-05T15:01:49.539Z.", + "https://app.uniswap.org/explore/pools/ethereum/0xdda3c47e70fb237fb50e3856169019bf26fe4c09d7b6618c4f9d6e2423903870", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 1 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "eusd-telcoin:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 + }, + { + "claimGroupId": "EXIT_DEX_COVERAGE:susdd-tron-dao-reserve", + "taskIds": [ + "V9G-09843c3a37e089c2" + ], + "workType": "EXIT_DEX_COVERAGE", + "resolutionMode": "producer-runtime", + "decision": "promote", + "reviewedAt": "2026-09-05", + "reviewer": "orchestrated-campaign/2026-09-05-v4-identities", + "evidence": [ + "https://yields.llama.fi/poolsPro?project=uniswap-v4", + "Primary-response exact identity example for susdd-tron-dao-reserve: UUID ca0646eb-c660-438d-b47a-82ccda7a0b17; pool_old 0xa9ab1284c3c13a2836f1d16b65f0b340e65be81644f85e273d57b45743444368-ethereum-uniswap-v4; matching Ethereum token contracts 0xc5d6a7b61d18afa11435a889557b068bb9f29930, 0xdac17f958d2ee523a2206206994597c13d831ec7; source timestamp 2026-09-03T07:04:04.874Z.", + "https://app.uniswap.org/explore/pools/ethereum/0xa9ab1284c3c13a2836f1d16b65f0b340e65be81644f85e273d57b45743444368", + "https://raw.githubusercontent.com/DefiLlama/yield-server/master/src/api/controllers/enriched.js" + ], + "rationale": "Newly reviewed primary poolsPro data supplies physical pool_old identity for 1 current Ethereum V4 source rows involving this asset. The implementation requires exact UUID/project/chain and both token addresses before attaching identity; measurements remain from the main list. This new evidence supports revisiting the earlier fingerprint-only deferral. Identity attachment is only a prerequisite: current registered candidates, supported zero-hook pools, coherent directional prices and successful measured quotes are still required. Other routes and non-Ethereum V4 remain unresolved; no execution or closure count is inferred.", + "changeRefs": [ + "86d78ff1d", + "worker/src/cron/dex-liquidity/defillama-v4-identity.ts", + "worker/src/cron/dex-liquidity/fetch-primary.ts", + "worker/src/cron/dex-liquidity/execution-targets/uniswap-v4.ts" + ], + "sentinels": [ + "susdd-tron-dao-reserve:gap:exit-portfolio-coverage" + ], + "nextReviewTrigger": "Root DEX campaign owner: observe defillama-v4-identities attachedPoolCount, fresh target publication and measured quotes for the exact physical IDs, then the next DEX score/V9 publication; count closure only when this exact asset gap disappears without adverse replacement.", + "factsClosed": 0 } ] } diff --git a/.gitleaks.toml b/.gitleaks.toml index 541aada047..7b6957c47d 100644 --- a/.gitleaks.toml +++ b/.gitleaks.toml @@ -112,3 +112,16 @@ regexes = [ '''0x6a4854078428eea517e8013827cba9f90583f8a9fdf8610c8791d1b04feb6a3eee428bf506c98ead1e870918f26a1d41f5bfb792b1e4f331679d1ad3e527326f''', ] paths = ['''(?:^|/)shared/data/stablecoins/domains/risk-review/usdcx-movement\.json$'''] + +# Exact Cardano policy-id + asset-name identifiers, pinned to the published +# Cardano Foundation token registry in each transfer review's sources. +[[allowlists]] +description = "Reviewed USDA and USDM Cardano asset identifiers are public, not credentials" +targetRules = ["generic-api-key"] +condition = "AND" +regexTarget = "secret" +regexes = [ + '''^fe7c786ab321f41c654ef6c1af7b3250a613c24e4213e0425a7ae45655534441$''', + '''^c48cbb3d5e57ed56e276bc45f99ab39abe94e6cd7ac39fb402da47ad0014df105553444d$''', +] +paths = ['''(?:^|/)shared/data/safety-score-v9/transfer-review-overlays-v1\.json$'''] diff --git a/docs/dex-liquidity.md b/docs/dex-liquidity.md index 7337d5bbf5..f78cd3fb5a 100644 --- a/docs/dex-liquidity.md +++ b/docs/dex-liquidity.md @@ -38,12 +38,10 @@ carries report-only observability with no formula effect: a fixed-key `fallbackC both the stage and consume runs counting every optimistic default and silent exclusion in the scoring path (unmeasured-balance optimism, durability neutral defaults, the TVL-depth mcap fallback, staged-pool defaults, retained-pool exclusions, Fluid and direct-API measurement-flag -defaults). Half-hourly measured execution remains live, but active admission is capped to target -IDs that match exactly one current published `exitRouteObservations` row with -`scoreEligible=true`, `evidenceKind=measured-executable-depth`, and matching adapter, chain, pool, -and output identity. Targets outside that score-bearing set are rejected before quote admission. -Those intentional exclusions remain visible in failure diagnostics but do not degrade the active -lane; inability to load the published score-bearing set fails closed and degrades the run. +defaults). Half-hourly measured execution admits the fresh active target inventory through its +bounded whole-coin rotation, including new and interrupted routes that need their first proof. +An exact current published measured route remains eligible for the expiry-priority reservation; +inability to load that published route set fails closed and degrades the run. The former daily shadow admission/quote evidence ledger and 240-character `mxLedger*` scalar encoding were removed; shadow target and quote generation persistence remains for compatibility. @@ -348,7 +346,7 @@ Safety Score V9 consumes those evidence fields, plus aggregate `dex_deployment_o Pool, token, and deployment identities use chain-specific casing: EVM addresses remain case-insensitive, while non-EVM native identifiers preserve case. During the rollout from legacy lowercase non-EVM rows, a newer corrected staging or deployment-outcome row supersedes an older lowercase-equivalent row only when the stablecoin, chain, source identity, and native pool/token identity otherwise match; same-time or otherwise ambiguous case-distinct rows remain separate and fail closed rather than being guessed together. -Every active DEX publication row carries explicit route coverage, including zero-scoring-pool placeholders. A placeholder is published as known empty (`populated`, zero retained pools, zero observations) only when its exact current `contracts` plus `tradedContracts` deployment census is unique, no older than that coin's census freshness bound, provider-backed, entirely `verified_no_pools`, and no deployment result predates that deployment's latest attributed discovery attempt. That bound is sweep-aware rather than global: a footprint the discovery crawl finishes in one run keeps the two-dormant-window (two-day) limit exactly, while a footprint whose priced provider queries exceed the 25s per-coin budget is crawled in resumable windows and is therefore allowed its estimated full-sweep period plus half a sweep of slack. `resolveDexDeploymentCensusMaxAgeSec()` (`worker/src/cron/dex-liquidity/deployment-census-coverage.ts`) derives that per-coin value statically - no extra freshness persistence - by replaying the real window selector over the registry footprint to count the windows one sweep needs and pricing each window at the t3 cohort cadence (ten two-hour discovery runs, so 20 hours per window); the six largest footprints currently sweep in 60-120 hours and are allowed 90-180 hours. Without this, the rotating tail of a windowed coin would report a stale or missing outcome forever even though discovery is on schedule. Discovery persists the selected deployments' attempt boundaries before network work without changing backoff counters, so an abort, budget discard, or result-persistence failure supersedes older empty evidence only inside that window. Failed bounded provider crawls also attempt to write an inaccessible outcome for each attempted deployment; an incomplete D1 persistence path retains only those attempt fences and therefore remains a discovery deferral rather than a provider outage. Timeout and 429 misses are retryable: they persist as a bounded-crawl reason and the scoring census treats them as a discovery deferral, not as “all provider queries failed.” A later GeckoTerminal page miss keeps any completed page-1 pools instead of discarding the token. The publication join rejects an older success even if either follow-up write fails. Missing, stale, superseded, malformed, inaccessible, unsupported, or observed-pool outcomes remain `unknown` with generation-bound census counts and reason codes. In particular, an observed pool that is lost before scoring is never converted into known-empty evidence. A persisted empty provider set is a snapshot of a registry fact, not an observation, so the live registry outranks it: an inaccessible row that claims no registered provider supports this chain while `getDexDiscoveryProviders()` resolves one today is counted as a superseded outcome awaiting the next crawl window, never as `deploymentCensusUnsupportedMethod`. Without that rule, every newly registered discovery provider (Aquarius Soroban, the supplemental GeckoTerminal networks) published a solved integration gap as a standing method limit for a full sweep period. `npm run check:dex-census-provider-drift -- --rows=` lists the contradicted rows still waiting for that re-crawl. +Every active DEX publication row carries explicit route coverage, including zero-scoring-pool placeholders. A placeholder is published as known empty (`populated`, zero retained pools, zero observations) only when its exact current `contracts` plus `tradedContracts` deployment census is unique, no older than that coin's census freshness bound, provider-backed, entirely `verified_no_pools`, and no deployment result predates that deployment's latest attributed discovery attempt. That bound is sweep-aware rather than global: a footprint the discovery crawl finishes in one run keeps the two-dormant-window (two-day) limit exactly, while a footprint whose priced provider queries exceed the 25s per-coin budget is crawled in resumable windows and is therefore allowed its estimated full-sweep period plus half a sweep of slack. `resolveDexDeploymentCensusMaxAgeSec()` (`worker/src/cron/dex-liquidity/deployment-census-coverage.ts`) derives that per-coin value statically - no extra freshness persistence - by replaying the real window selector over the registry footprint to count the windows one sweep needs and pricing each window at the weekly t3 cohort cadence. The zero-pool maintenance queue refreshes these censuses faster, targeting an 18-hour full sweep without extending the existing freshness limits. Without this, the rotating tail of a windowed coin would report a stale or missing outcome forever even though discovery is on schedule. Discovery persists the selected deployments' attempt boundaries before network work without changing backoff counters, so an abort, budget discard, or result-persistence failure supersedes older empty evidence only inside that window. Failed bounded provider crawls also attempt to write an inaccessible outcome for each attempted deployment; an incomplete D1 persistence path retains only those attempt fences and therefore remains a discovery deferral rather than a provider outage. Timeout and 429 misses are retryable: they persist as a bounded-crawl reason and the scoring census treats them as a discovery deferral, not as “all provider queries failed.” A later GeckoTerminal page miss keeps any completed page-1 pools instead of discarding the token. The publication join rejects an older success even if either follow-up write fails. Missing, stale, superseded, malformed, inaccessible, unsupported, or observed-pool outcomes remain `unknown` with generation-bound census counts and reason codes. In particular, an observed pool that is lost before scoring is never converted into known-empty evidence. A persisted empty provider set is a snapshot of a registry fact, not an observation, so the live registry outranks it: an inaccessible row that claims no registered provider supports this chain while `getDexDiscoveryProviders()` resolves one today is counted as a superseded outcome awaiting the next crawl window, never as `deploymentCensusUnsupportedMethod`. Without that rule, every newly registered discovery provider (Aquarius Soroban, the supplemental GeckoTerminal networks) published a solved integration gap as a standing method limit for a full sweep period. `npm run check:dex-census-provider-drift -- --rows=` lists the contradicted rows still waiting for that re-crawl. The Stellar Soroban census is intentionally bounded to the eight reviewed Spiko token identities served by the public [Aquarius ticker index](https://amm-api.aqua.network/api/tickers/). Aquarius is registered as a supplemental provider, not a chain-exhaustive census: the 2026-09-04 check returned HTTP 200 JSON but no ticker matched any of the eight exact token identities, so a valid empty response is persisted as `provider_inaccessible` with `Provider census is not exhaustive for this chain` and cannot certify a known-empty footprint. The public [Soroswap pools endpoint](https://api.soroswap.finance/pools) returned HTTP 403 without credentials when checked on 2026-09-04, so no chain-wide alternate is registered. Aquarius transport failures remain retryable and continue through the bounded-pending path; they must never be converted into a fabricated empty census. @@ -368,11 +366,11 @@ The SunSwap V2 adapter (shadow-only since v5.96) was removed in v6.0 along with Fully executable exact reserve-simulation capacity points also retain the realized execution cost from re-running the same invariant at the requested input and valuing its output with the captured token references. The projection is accepted only within the point's cost bound plus a narrow numerical tolerance. Zero capacity, an invalid recomputation, or partial capacity defined by bisection at the 200 bps request ceiling omits it and leaves V9 on the conservative fallback rather than mislabeling the bound as a realized cost. Curve reserve models apply the invariant to full input and deduct the fee from output, matching Curve StableSwap accounting. Ordinary source-only Curve models retain the documented 10 bps source-API fallback where the pools endpoint lacks pool-specific fee state; this is not a claimed per-pool upper bound, and a separately pinned `get_dy` measurement is required for proof-bearing execution cost. This additive V9 field does not affect aggregate liquidity or the standalone Liquidity Score. -Before ordinary whole-coin EVM cursor rotation, the measured lane may reserve one currently published score-bearing direction packet whose adapter-specific expiry is earliest. The reservation is capped at 20 estimated RPC requests, keeps the legacy Curve 3pool directions atomic, shares the 1,220-request admission ceiling, and does not advance the ordinary cursor. All remaining targets retain the existing whole-coin ranking and fairness behavior. +Before ordinary whole-coin EVM cursor rotation, the measured lane may reserve one currently published score-bearing direction packet whose adapter-specific expiry is earliest. The reservation is capped at 20 estimated RPC requests, keeps the legacy Curve 3pool directions atomic, shares the 1,220-request admission ceiling, and does not advance the ordinary cursor. Every fresh target in the active inventory enters the remaining bounded whole-coin rotation, including targets with no prior published observation. Requiring an already measured route created a bootstrap deadlock: new or interrupted routes could never obtain their first proof. The inventory still admits only activated methods and deployments, and all quote, identity, freshness, and publication gates remain mandatory. The 2026-09-05 production inventory of 581 targets estimates 1,134 RPC requests for one rotation, below the unchanged 1,220 admission and 1,300 hard limits; larger inventories rotate behind the same deadline and cursor. The isolated score-bearing `sync-cl-exit-depth` lane retains logical `:00/:30` slots but physically runs at `5,35 * * * *`, before the hourly DEX source stage and consumer. It loads only the latest active target generation, pins one block per chain, verifies reviewed QuoterV2 and factory bytecode, proves each pool through the factory's exact `getPool` binding, and records a $1,000 marginal quote plus the TVL-tiered $100,000/$1 million/$10 million/$25 million ladder with bounded refinement. PancakeSwap, Uniswap V3, and Aerodrome Slipstream target construction admit each direction only when the retained spot does not imply output worth more than `1.02x` the input under independent token references; incoherent directions remain in retained DEX evidence but do not become measured-execution failures. Uniswap V3 target construction resolves each leg's USD reference independently and, when the counter asset is untracked and has no direct reference, pool-implies the output reference from the subgraph candidate's decimal-adjusted spot price times the input leg's direct reference (the same convention the Uni V3 price indexer consumes, mirroring the Raydium pool-implied derivation). Pool-implied references must remain representable by the measured-execution pipeline's 1e8 fixed-point price encoding; smaller values revert to `target-unresolved` and emit a structured diagnostic with the raw pair spot prices instead of creating a guaranteed quote-validation failure. Runtime favorable-output quote mismatches for untracked pool-implied counter assets still persist failed target rows and remain excluded from scoring, but they are diagnostic for cron health because the source spot and pinned quote block can drift after target publication. Identity failures still gate to target-unresolved. Tracked NAV tokens require a trusted live NAV at capture time and never fall back to a static fiat peg for quote sizing. Producers publish target and quote generations atomically in D1. The `:16` hourly consumer joins only a fresh published quote generation from the exact `:10` source-stage graph, publishes DEX prices and challenger snapshots each hour, and publishes the full Liquidity Score plus the next active target generation every two hours. The `:46` invocation retains the hourly CPU-class trigger topology and V9 sequencing but performs no DEX source or scoring work. Score-ineligible EVM targets use separate shadow generations and one serial daily 08:10 UTC collection run; shadow failures cannot degrade score publication. Synthetic `budget-deferred` outcomes are omitted from D1 quote rows only after an exact target-count and target-ID-digest manifest is recorded, then reconstructed on read; any manifest mismatch fails closed. A mature fresh last-known-good profile may remain in the bounded route-only observation set when its physical pool rotates out of the current liquidity/display shortlist, but it never re-enters aggregate TVL, volume, visible pools, price consensus, target publication, or the standalone Liquidity Score. QuoterV2 profiles must pass consumer validation of generation, identity, decimals, price, freshness, provenance, curve monotonicity, cost bracketing, and the `1.5x` retained-TVL capacity ceiling. Score-eligible deployments are the owner-ratified Uniswap V3 cohorts on Ethereum, Polygon, Arbitrum, and Celo; PancakeSwap V3 on Base, BSC, and Ethereum; plus the reviewed Aerodrome Slipstream cohort on Base. For Aerodrome Slipstream alone, the P4 identity check accepts the retained source labels `aerodrome` and `aerodrome-slipstream`; the measured profile must still identify `aerodrome-slipstream`, and exact chain, physical-pool, token, generation, and proof validation remain mandatory. The Solana and Tron native measured-execution lanes and the Fluid measured overlay were removed in v6.0; retained Raydium, Orca, SunSwap, and Fluid pools resolve as shaped evidence outside the strict exact-route denominator. -Uniswap V4 measurement is intentionally narrow. Since v5.993, the reviewed hook-free Ethereum cohort is score-eligible after three productive shadow generations and 129 successful quotes in the latest 130-direction production cohort. The source stage serially reads the [official Ethereum V4 subgraph deployment](https://developers.uniswap.org/api/subgraph/subgraphs-devs/deployments), retains the exact PoolId, ordered currencies, fee, tick spacing, hook address, indexed in-range liquidity, and TVL, and joins a DeFiLlama UUID row only when exactly one same-pair/fee V4 candidate exists within 2% TVL. Hooked and zero-liquidity candidates remain in the collision set, but only one exact hook-free candidate with positive indexed in-range liquidity can become a target. Each direction also applies the existing `1.02x` favorable-output ceiling to the indexed spot and independent token references before admission, so a deterministically incoherent direction remains `target-unresolved` rather than becoming a producer failure. At the pinned quote block, the producer verifies reviewed PoolManager, StateView, and Quoter runtime hashes, proves that both view contracts bind to that PoolManager, checks `getSlot0(poolId)` and `getLiquidity(poolId)`, and decode-binds every `quoteExactInputSingle` call and result. Nonzero hooks, other chains, missing state, runtime drift, malformed or transport-failed quotes, and non-monotonic successful cost curves fail closed; aggregate TVL is never substituted for executable depth. The separate shadow generation and comparison machinery remains available for future V4 cohorts and rollback review. +Uniswap V4 measurement is intentionally narrow. Since v5.993, the reviewed hook-free Ethereum cohort is score-eligible after three productive shadow generations and 129 successful quotes in the latest 130-direction production cohort. The source stage serially reads the [official Ethereum V4 subgraph deployment](https://developers.uniswap.org/api/subgraph/subgraphs-devs/deployments), retains the exact PoolId, ordered currencies, fee, tick spacing, hook address, indexed in-range liquidity, and TVL, and prefers an exact physical PoolId join. A serial, project-filtered `yields.llama.fi/poolsPro?project=uniswap-v4` identity lookup uses only Ethereum rows and maps the main list UUID to `pool_old` only when UUID, project, chain, and both token addresses agree; duplicate UUIDs fail closed. It has a 10-second timeout, no retries, a 4 MiB response limit, and a 2,000-row limit, after the existing DL response bodies are consumed, so trigger concurrency does not increase. The extra endpoint supplies identity only: list TVL, volume, prices, and yield-cache UUIDs remain authoritative. This avoids treating rounded DL fee metadata (5 pips appears as `0.00%`) as an exact fee. On lookup failure the original row remains; the existing unique same-pair/fee candidate path within 2% TVL is still available. Exact identities still require current subgraph PoolKey evidence and every existing target/quote validation. Hooked and zero-liquidity candidates remain in the collision set, but only one exact hook-free candidate with positive indexed in-range liquidity can become a target. Each direction also applies the existing `1.02x` favorable-output ceiling to the indexed spot and independent token references before admission, so a deterministically incoherent direction remains `target-unresolved` rather than becoming a producer failure. At the pinned quote block, the producer verifies reviewed PoolManager, StateView, and Quoter runtime hashes, proves that both view contracts bind to that PoolManager, checks `getSlot0(poolId)` and `getLiquidity(poolId)`, and decode-binds every `quoteExactInputSingle` call and result. Nonzero hooks, other chains, missing state, runtime drift, malformed or transport-failed quotes, and non-monotonic successful cost curves fail closed; aggregate TVL is never substituted for executable depth. The separate shadow generation and comparison machinery remains available for future V4 cohorts and rollback review. Primary pool processing prefers an exact candidate pool identity when one is available, using the token/fee candidate bucket only as a fallback for identity-poor retained rows; multiple candidates or an unproven identity remain `target-unresolved`. The historical SunSwap activation description in this section is superseded twice over: v5.96 returned the adapter to shadow, and v6.0 removed the lane entirely. @@ -570,7 +568,7 @@ Discovery and merge staging tables are documented in the [Discovery Cron](#disco - Both providers are registered by chain **and** denom shape (`ibc/<64 uppercase hex>`, a plain lowercase bank denom, or a `factory/...` denom). MANTRA's Cosmos IBC denom shares that shape but not the chain and is never routed to either index, matching the DEX-scoped GeckoTerminal resolver's MANTRA EVM-only rule. - **Deployment outcome schema**: `dex_deployment_outcomes` stores one exact stablecoin/chain/contract row as `observed_pools`, `verified_no_pools`, or `provider_inaccessible`, including the provider set, reason, observation time, per-deployment `last_attempt_at`, pool count, and optional owned waiver. The provider set is derived per deployment by `getDexDiscoveryProviders()`, and the discovery crawl queries exactly the providers that set names. In addition to the general chain registry, the DEX-scoped GeckoTerminal resolver covers Starknet (`starknet-alpha`), Stacks, Hedera, and Injective, plus only 20-byte `0x` deployments on MANTRA EVM; Cosmos IBC denoms sharing the `mantra` repo chain id remain unsupported rather than being sent to the wrong network. Starknet token queries use GeckoTerminal's 64-hex-digit felt form, Hedera `0.0.N` entity ids use their 20-byte long-zero Solidity form, and Injective EVM, Peggy, IBC, and token-factory denoms use GeckoTerminal's provider-native identities. Provider-native token ids are URL-encoded once in the token-pools path while persisted census rows retain the registry address. The Curve discovery stage is scoped to `CURVE_NATIVE_DISCOVERY_CHAINS`, the same registered chains that credit Curve as a provider, so a Curve result can always be attributed to a named provider; its nested getPools requests run at most two chains at a time with a 4 MiB response ceiling. The liquidity stage reads Curve on a wider chain set for scoring; those extra chains are deliberately not crawled for deployment outcomes. A no-pool result is written only after a provider completes that exact token query and is usable only while that deployment's attempt fence has not superseded it. Before network work, the writer reconciles any unmatched legacy coin fence, advances `last_attempt_at` only for the selected rotating window, and atomically marks the coin fence as attributed. Missing, mismatched, or legacy attribution stays fail-closed; failed result persistence supersedes only attempted deployments, while untouched rows keep their prior evidence. Failed provider crawls materialize inaccessible outcomes for the attempted footprint when D1 is available. The canonical registry owns current inaccessible deployments; full-footprint gaps require explicit, expiring waivers while adapters or provider mappings are evaluated. - **Tiered priority**: - - Refresh: coins with admitted supplemental liquidity in the published source mix receive maintenance opportunities before the 24-hour staging expiry. An 18-hour full-sweep target (six hours before expiry) is divided across the existing estimated deployment-window count, rounded down to the existing two-hour tick (minimum one tick). This queue runs before new discovery and resumes the existing cursor; native-only and verified-empty footprints keep their weekly discovery cadence. + - Refresh: coins with admitted supplemental liquidity in the published source mix, and zero-pool footprints with a supported census provider, receive maintenance opportunities before their evidence expires. This includes verified-empty and incomplete censuses: weekly discovery cannot keep their two-day evidence current. An 18-hour full-sweep target (six hours before expiry) is divided across the existing estimated deployment-window count, rounded down to the existing two-hour tick (minimum one tick). This queue runs before new discovery and resumes the existing cursor; native-only footprints with retained pools keep their weekly discovery cadence. - T1: coins with 0 pools (or effectively eligible baseline), every run. - T2: 1–4 pools or 1 chain, every 84th run (one week at the two-hour cron cadence). - T3: `>=5` pools on `>=2` chains, every 84th run (one week), sharded by stablecoin id. @@ -581,7 +579,7 @@ Discovery and merge staging tables are documented in the [Discovery Cron](#disco - 6–9: floor T3 - 10+: dormant (daily gate) - Any discovery hit resets `consecutiveMisses` to 0, removing the backoff floor; the coin's tier is then recomputed from its pool/chain counts on the next run. - - **Verified-empty census cadence hold**: a crawl that finds zero pools always increments `consecutiveMisses`, so a footprint whose correct answer is "no DEX pools anywhere" used to accrue misses forever and decay to dormant — whose 24-hour-plus per-window cadence is slower than the sweep-aware census freshness bound below, turning a correct zero-pool answer into a permanently stale census. A coin whose current census answers every provider-supported tracked deployment as `verified_no_pools` (no `observed_pools`, no provider-supported `provider_inaccessible`, no missing row) therefore stops at the T3 floor instead of falling to dormant. T3 is exactly the cadence the census bound is priced at, so the coin's own correct answer can no longer age itself out of the reviewed scope. Chains with no registered discovery provider are excluded from the test because the census already carries them as a standing unsupported remainder rather than an unanswered deployment. `readDiscoveryCensusSummaries()` aggregates the census in one grouped read per run, `hasVerifiedEmptyCensus()` applies the test, and cron metadata reports `censusCadenceHolds` — the number of coins the hold kept above dormant this run. + - **Verified-empty census cadence hold**: a crawl that finds zero pools always increments `consecutiveMisses`, so a footprint whose correct answer is "no DEX pools anywhere" used to accrue misses forever and decay to dormant — whose 24-hour-plus per-window cadence is slower than the sweep-aware census freshness bound below, turning a correct zero-pool answer into a permanently stale census. A coin whose current census answers every provider-supported tracked deployment as `verified_no_pools` (no `observed_pools`, no provider-supported `provider_inaccessible`, no missing row) therefore stops at the T3 floor instead of falling to dormant. That hold remains the base-tier diagnostic; the zero-pool maintenance queue now schedules refreshes before the two-day single-window freshness bound instead of relying on the weekly T3 cadence. Chains with no registered discovery provider are excluded from the test because the census already carries them as a standing unsupported remainder rather than an unanswered deployment. `readDiscoveryCensusSummaries()` aggregates the census in one grouped read per run, `hasVerifiedEmptyCensus()` applies the test, and cron metadata reports `censusCadenceHolds` — the number of coins the hold kept above dormant this run. - **Chain-aware source routing**: discovery only queries chains with defined entries in a stablecoin’s `contracts` plus optional `tradedContracts` metadata; this avoids unnecessary API calls against un-deployed chains while preserving wrapper/secondary-market discovery addresses. - **Resumable deployment windows**: each coin crawl is bounded by a 25s per-coin budget shared by all provider stages, and the stages run to completion in order, so a footprint whose paced provider queries exceed that budget would let the first stage consume it and permanently starve every chain only a later stage can serve. `selectDiscoveryTargetWindow()` (`worker/src/cron/dex-discovery/target-window.ts`) prices each deployment at every registered serial provider's pacing floor plus request allowance, and when the footprint does not fit it hands the crawl one window at a time, resuming after the last deployment a provider actually reached on the previous run. The resume markers live in one `kv_config` row (`discovery_target_cursors`); an unknown or missing marker restarts the rotation at the first deployment. Footprints that fit the budget are crawled whole, exactly as before. Deployments outside the current window are not classified, so they keep their previous census row instead of being downgraded to a bounded-crawl deferral, and cron metadata reports `windowedCoins` plus `windowedDeploymentsDeferred`. - **Maintenance capacity**: refresh uses the existing serial provider sequence, 25-second per-coin window, 12-minute run budget, and finalization reserve; no trigger or concurrent connection is added. The 18-hour sweep is a scheduling target, not a promise under provider failure, budget exhaustion, or footprints too large for the existing ticks. Deferred or failed observations still expire after 24 hours; they are never relabeled fresh. Monitor the `refresh` tier count, `budgetExhausted`, and deployment-window deferrals after rollout. diff --git a/docs/live-reserves.md b/docs/live-reserves.md index fb909ebb28..9470bc57b2 100644 --- a/docs/live-reserves.md +++ b/docs/live-reserves.md @@ -528,6 +528,8 @@ the `re-metrics` adapter parses Re Protocol's official metrics page and now extr `solstice-attestation` and `river-protocol-info` are proof-class reserve-sync adapters. They make current issuer/protocol telemetry visible on reserve detail and status surfaces, but their registry evidence class is `weak-live-probe`, so they do not become V9 Backing reserve evidence. Solstice remains proof-class until its aggregate solvency feed exposes timestamped asset-category composition; River remains proof-class because its protocol-info endpoint exposes aggregate TVL/circulating-supply telemetry rather than asset-level collateral composition. River snapshots degrade when the aggregate TVL is below circulating satUSD, and timestampless protocol-info payloads remain freshness-unverified. +`audx-independent-assurance` uses the reviewed July 31, 2026 report: AUD 3,231,371.79 in designated bank accounts against AUD 3,208,057.00 issued supply. Aura Partners signed its limited-assurance report on August 20, 2026; the posting date is unknown. The manifest retains the report's printed AEDT timestamp and exact PDF hash, with freshness measured from the examined period rather than the signature or fetch date. + `usdgo-transparency` is now independent: the Deloitte examination is the authoritative composition/liability source through the independent-assurance manifest (exact PDF SHA-256 binding), with the Avalanche BUIDL balance pinned on-chain and the issuer transparency API demoted to a cross-check that raises informational warnings on later-period drift. `anzen-usdz` is now independent: it reads USDz `totalPooledSPCT()` and actual SPCT holdings on-chain and reconciles them against bridge-adjusted USDz liabilities across the five issuance chains, failing closed on shortfall instead of trusting global SPCT supply. @@ -545,6 +547,8 @@ Yuzu's Fasanara `mGLO` loop remains a high-risk named reserve slice but carries Chainlink NAV note: `chainlink-nav` now supports both standard AggregatorV3 feeds and Ondo router-style NAV lookups. When `oracleMethod = "getAssetPrice"`, the adapter calls `getAssetPrice(token)` on the router and, when available, follows `tokenToRWAOracle(token) -> getPriceData()` to recover a verified freshness timestamp instead of treating the feed as permanently timestampless. +USDY's scalar NAV configuration is suspended: its price and token-supply reads do not measure the multi-asset holdings published by Ondo. Scoring uses the separately dated reviewed holdings composition with the existing static-evidence admission and freshness limits; resumption requires a producer that consumes the holdings themselves. Felix's kHYPE branch uses the reviewed Kinetiq label so the next live observation joins its existing collateral classification. + Chronicle NAV note: `chronicle-nav` reads Chronicle Labs Proof-of-Asset VAO consumer contracts via `readWithAge()` (value + age), validating the value, rejecting stale or future-dated ages, and reading the coin token's on-chain supply with its actual decimals. The v1 path is scalar-only: it emits one configured 100% NAV slice with verified freshness from the consumer age, mirroring `chainlink-nav`'s single-bucket model. Chronicle's IPFS `UPoked` proof objects (position-level composition) are a documented future enhancement, not consumed today. ACRDX and STAC bind this adapter. diff --git a/scripts/maintenance/refresh-independent-assurance-reports.ts b/scripts/maintenance/refresh-independent-assurance-reports.ts index 0b6c50a854..3084e57e09 100644 --- a/scripts/maintenance/refresh-independent-assurance-reports.ts +++ b/scripts/maintenance/refresh-independent-assurance-reports.ts @@ -54,9 +54,9 @@ function profile(product: IndependentAssuranceProduct): CompilerProfile { product, profile: "audx-v1", officialIndexUrl: "https://www.audxtoken.com/transparency", - reportUrl: "https://www.audxtoken.com/_files/ugd/539754_f60cd94b9a5148cfafd351f6157c8036.pdf", - reportDate: "2026-06-30", - reportAsOf: "2026-06-30T23:59:00+11:00", + reportUrl: "https://www.audxtoken.com/_files/ugd/539754_d2b6ce0bfdd947bda8375fe3283a0491.pdf", + reportDate: "2026-07-31", + reportAsOf: "2026-07-31T23:59:00+11:00", reportTimeZone: "AEDT (as printed in the report; normalized conservatively to UTC)", attestor: "Aura Partners", engagement: "Independent limited assurance engagement under ASAE 3000 and ASAE 3100", @@ -82,19 +82,19 @@ function profile(product: IndependentAssuranceProduct): CompilerProfile { { label: "Aura Partners", pattern: /AURAPARTNERS|Aura Partners/i }, { label: "ASAE 3000", pattern: /ASAE 3000/i }, { label: "ASAE 3100", pattern: /ASAE 3100/i }, - { label: "AUDX report date", pattern: /30(?:th)? of June 2026/i }, + { label: "AUDX report date", pattern: /31(?:st)? of July 2026/i }, { label: "favorable AUDX conclusion", pattern: /nothing has come to our[\s\S]*attention/i }, ], rejectedText: [ { label: "qualified/adverse/disclaimed conclusion", pattern: /qualified opinion|adverse opinion|disclaimer of opinion|except for/i }, ], reportedTotals: [ - { label: "AUDX supply total", expected: "3008057.00", pattern: linePattern("TOTAL AUDX Supply") }, - { label: "AUDX reserve total", expected: "3231280.83", pattern: linePattern("TOTAL Australian Dollar Reserves") }, + { label: "AUDX supply total", expected: "3208057.00", pattern: linePattern("TOTAL AUDX Supply") }, + { label: "AUDX reserve total", expected: "3231371.79", pattern: linePattern("TOTAL Australian Dollar Reserves") }, ], - reportedAssetTotal: "3231280.83", - computedAssetTotal: "3231280.83", - reportedLiabilityTotal: "3008057.00", + reportedAssetTotal: "3231371.79", + computedAssetTotal: "3231371.79", + reportedLiabilityTotal: "3208057.00", }; case "EUROP": return { diff --git a/shared/data/live-reserves/independent-assurance/audx.json b/shared/data/live-reserves/independent-assurance/audx.json index cbd2c5b2c7..61d18be73a 100644 --- a/shared/data/live-reserves/independent-assurance/audx.json +++ b/shared/data/live-reserves/independent-assurance/audx.json @@ -3,11 +3,11 @@ "product": "AUDX", "profile": "audx-v1", "officialIndexUrl": "https://www.audxtoken.com/transparency", - "reportUrl": "https://www.audxtoken.com/_files/ugd/539754_f60cd94b9a5148cfafd351f6157c8036.pdf", - "reportSha256": "6f310bc328c9373bb8e645a580d5e2ec5313086a50671ce4ea0e142619cc7eca", - "reportByteLength": 393979, - "reportDate": "2026-06-30", - "reportAsOf": "2026-06-30T23:59:00+11:00", + "reportUrl": "https://www.audxtoken.com/_files/ugd/539754_d2b6ce0bfdd947bda8375fe3283a0491.pdf", + "reportSha256": "e6a260f26d38a318ad36c3d0ed6539b36d053c9a68bce844c6d358db282a3913", + "reportByteLength": 615133, + "reportDate": "2026-07-31", + "reportAsOf": "2026-07-31T23:59:00+11:00", "reportTimeZone": "AEDT (as printed in the report; normalized conservatively to UTC)", "attestor": "Aura Partners", "engagement": "Independent limited assurance engagement under ASAE 3000 and ASAE 3100", @@ -17,25 +17,53 @@ { "code": "designated-bank-accounts", "label": "Australian Dollar reserves held in designated TAU accounts", - "amount": "3231280.83" + "amount": "3231371.79" } ], "liabilities": [ - { "code": "polygon", "label": "Polygon AUDX supply", "amount": "1321016.00" }, - { "code": "ethereum", "label": "Ethereum AUDX supply", "amount": "1435040.00" }, - { "code": "conflux", "label": "Conflux AUDX supply", "amount": "52000.00" }, - { "code": "redbelly", "label": "Redbelly AUDX supply", "amount": "100000.00" }, - { "code": "xdc", "label": "XDC AUDX supply", "amount": "50000.00" }, - { "code": "ink", "label": "Ink AUDX supply", "amount": "50000.00" }, - { "code": "solana", "label": "Solana AUDX supply", "amount": "1.00" } + { + "code": "polygon", + "label": "Polygon AUDX supply", + "amount": "1321016.00" + }, + { + "code": "ethereum", + "label": "Ethereum AUDX supply", + "amount": "1635040.00" + }, + { + "code": "conflux", + "label": "Conflux AUDX supply", + "amount": "52000.00" + }, + { + "code": "redbelly", + "label": "Redbelly AUDX supply", + "amount": "100000.00" + }, + { + "code": "xdc", + "label": "XDC AUDX supply", + "amount": "50000.00" + }, + { + "code": "ink", + "label": "Ink AUDX supply", + "amount": "50000.00" + }, + { + "code": "solana", + "label": "Solana AUDX supply", + "amount": "1.00" + } ], - "reportedAssetTotal": "3231280.83", - "computedAssetTotal": "3231280.83", - "reportedLiabilityTotal": "3008057.00", + "reportedAssetTotal": "3231371.79", + "computedAssetTotal": "3231371.79", + "reportedLiabilityTotal": "3208057.00", "extraction": { "tool": "Poppler pdftotext -layout", "parserVersion": "26.08.0", - "normalizedTextSha256": "0897c66b54cf3c964643cfcd7ed73e9fcf4e29d42256eb67b76c2469b9d25aa2", + "normalizedTextSha256": "4989b32c3d379e755f5715f4d4cbb5013d113422648b5e146362f5149860204e", "pageCount": 4 } } diff --git a/shared/data/safety-score-v9/evaluation-build-manifest-v1.ts b/shared/data/safety-score-v9/evaluation-build-manifest-v1.ts index 08d88b87fd..78730fbe1e 100644 --- a/shared/data/safety-score-v9/evaluation-build-manifest-v1.ts +++ b/shared/data/safety-score-v9/evaluation-build-manifest-v1.ts @@ -10,7 +10,7 @@ export const SAFETY_SCORE_V9_EVALUATION_BUILD_MANIFEST = { }, { "path": "shared/data/safety-score-v9/mechanism-review-overlays-v1.json", - "sha256": "e573e4bd61f70a6ada918cd9c980e4d092de1fda5c8cb7791b3797c7f191fb83" + "sha256": "2da505ee315106f16268ffa1acd16fe27c45d3109dbb9cd467482ba937e6ed2d" }, { "path": "shared/data/safety-score-v9/methodology-policy-candidate-v1.json", @@ -603,7 +603,7 @@ export const SAFETY_SCORE_V9_EVALUATION_BUILD_MANIFEST = { "r2Key": "captures/lusd-liquity/2026-09-03-block-25895460-shock-coverage.json.gz" } ], - "digest": "b2a6be46f7d1369f6f9a27002833d6b3a75344d16a69f5d970d9814b31c0756d" + "digest": "e6b6868f9787a544a8ec28ce685469047ab67cfd73cc53e6a8d5c16f46e78b38" } as const; export const SAFETY_SCORE_V9_EVALUATION_BUILD_DIGEST = diff --git a/shared/data/safety-score-v9/mechanism-review-overlays-v1.json b/shared/data/safety-score-v9/mechanism-review-overlays-v1.json index 6712df7eeb..e8351f09b3 100644 --- a/shared/data/safety-score-v9/mechanism-review-overlays-v1.json +++ b/shared/data/safety-score-v9/mechanism-review-overlays-v1.json @@ -829,64 +829,41 @@ }, { "assetId": "zarm-mento", - "archetype": "cdp", - "reviewedAt": "2026-07-15", + "archetype": "fiat-cash", + "reviewedAt": "2026-09-05", "sources": [ { - "label": "Mento BiPoolManager and FPMM conversion state on Celo", - "url": "https://celoscan.io/address/0x22d9db95e6ae61c104a7b6f6c78d7993b94ec901" + "label": "Mento itemized reserve assets, custody wallets and positions (fetched 2026-09-05)", + "url": "https://mento-analytics-api-12390052758.us-central1.run.app/api/v2/reserve" }, { - "label": "Mento V3 reserve conversion documentation", - "url": "https://docs.mento.org/mento-v3" - } - ], - "notes": "Pinned Celo block 72202985; journaled evidence: shared/data/safety-score-v9/mechanism-measurements/zarm-mento/2026-07-15-block-72202985.json. The producer enumerated all 16 live exchange IDs, found the configured token/USDm pair exactly once, and measured 10000000 USDm of counter-bucket capacity at the journaled 30 bps fee. Conversion capacity is an analogous exit metric rather than dedicated liquidation capital. The bounded virtual USDm counter-bucket provides limited conversion support; pair buckets limit flow but Broker, USDm, reserve, and oracle failure domains remain shared; BreakerBox and trading limits can halt unsafe conversion without supplying an unconditional residual-deficit recapitalization path. Backstop, branch isolation, and shutdown/bad-debt handling are therefore limited.", - "metrics": { - "collateralizationRatio": null, - "liquidationCapacityRatio": null - }, - "metricApplicability": { - "collateralizationRatio": { - "state": "not-applicable", - "rationale": "This reserve/conversion token has no independently collateralized per-token vault system.", - "sourceUrl": "https://docs.mento.org/mento-v3" + "label": "Mento protocol-wide reserve, liquidity and governance risk disclosure", + "url": "https://docs.mento.org/mento-v3/dive-deeper/security/risk-overview.md" }, - "liquidationCapacityRatio": { - "state": "not-applicable", - "rationale": "The measured counter-asset conversion inventory is redemption liquidity, not capital committed to debt-offset liquidation.", - "sourceUrl": "https://docs.mento.org/mento-v3" - } - }, - "analogousMetrics": { - "conversionCapacityCounterUnits": 10000000 - }, - "components": { - "collateralizationParameters": { - "applicability": "not-applicable", - "rationale": "This reserve/conversion token has no independently collateralized per-token vault system.", - "sourceUrl": "https://docs.mento.org/mento-v3" + { + "label": "Mento shared V2/V3 Reserve and StableTokenZAR deployment inventory", + "url": "https://docs.mento.org/mento-v3/build/deployments/addresses.md" }, - "liquidationMechanics": { - "applicability": "not-applicable", - "rationale": "The measured counter-asset conversion inventory is redemption liquidity, not capital committed to debt-offset liquidation.", - "sourceUrl": "https://docs.mento.org/mento-v3" + { + "label": "Sourcify verified ZARm proxy source on Celo", + "url": "https://sourcify.dev/server/v2/contract/42220/0x4c35853a3b4e647fd266f4de678dcc8fec410bf6?fields=abi,metadata,sources" }, - "backstop": { - "applicability": "measured", + { + "label": "Celo finalized block 76721442 (ZARm and Reserve code; ZARm totalSupply reads)", + "url": "https://celoscan.io/block/76721442" + } + ], + "notes": "Reviewed 2026-09-05: replaces the stale CDP overlay to match the existing fiat-cash classification for shared protocol-reserve inventory. The official deployment inventory identifies StableTokenZAR at 0x4c35853a3b4e647fd266f4de678dcc8fec410bf6 and the shared Reserve at 0x9380fa34fd9e4fd14c06305fd7b6199089ed4eb9. The itemized reserve API disclosed $19,959,907.699599963 of collateral across named hot, cold and operational wallets and deployed positions; its CDP rows contain no ZARm debt. At finalized Celo block 76721442, both deployment addresses had contract code and ZARm totalSupply was 10925.176443780387 tokens. These primary disclosures and on-chain anchors support limited claim/segregation, custody continuity, and assurance/reconciliation under the same shared-reserve framing as CADm, KESm and BRLm. Claim/segregation is limited to observable protocol reserve inventory, not a direct legal holder claim or a ZARm-specific partition. Custody continuity is limited because the disclosed reserve wallets and protocol governance remain shared failure domains. Assurance is limited to itemized self-reported assets corroborated by contract and token-supply reads, not an independently attested reserve-to-liability reconciliation or a complete cross-chain balance audit. No independent auditor, enforceable holder seniority, bankruptcy-remoteness, or dedicated ZARm recovery commitment is established. The broad fiat-cash classification is economically broader than ordinary custodial fiat cash. Raw primary responses and block reads are retained in agents/2026-09-05-safety-score-gap-campaign/evidence/zarm-*. No current CDP ratio, liquidation capacity or historical virtual conversion inventory is carried into the fiat-cash overlay.", + "metrics": {}, + "components": { + "claimAndSegregation": { "quality": "limited" }, - "branchIsolation": { - "applicability": "measured", + "custodyContinuity": { "quality": "limited" }, - "shutdownAndBadDebt": { - "applicability": "measured", + "assuranceAndReconciliation": { "quality": "limited" - }, - "structuralRedemption": { - "applicability": "measured", - "quality": "adequate" } } }, diff --git a/shared/data/safety-score-v9/transfer-review-overlays-v1.json b/shared/data/safety-score-v9/transfer-review-overlays-v1.json index 8adcff45d4..781d180dd7 100644 --- a/shared/data/safety-score-v9/transfer-review-overlays-v1.json +++ b/shared/data/safety-score-v9/transfer-review-overlays-v1.json @@ -5006,6 +5006,107 @@ ] } ] + }, + { + "assetId": "usda-anzens", + "reviewedAt": "2026-09-05", + "reviewer": "OpenAI Codex Safety Score gap campaign", + "deployments": [ + { + "chainId": "cardano", + "contractOrTokenId": "fe7c786ab321f41c654ef6c1af7b3250a613c24e4213e0425a7ae45655534441", + "scope": "canonical", + "posture": "permissionless", + "evidence": "The Cardano Foundation token-registry mapping pinned at commit 8a2cd449b86ac6f27a7de34dd0845160a832266b binds this exact policy ID and asset name to Anzens USDA, its issuer domain, and six decimals. Cardano executes the asset minting policy only when a transaction mints or burns that asset; an ordinary transfer of already-minted native tokens spends the holder UTxO without invoking the policy. The issuer therefore has no token-level holder-transfer hook. Issuer account, custody, and direct-redemption restrictions are separate from transferability of holder-controlled native tokens.", + "sources": [ + { + "label": "Pinned Cardano Foundation USDA identity mapping", + "url": "https://github.com/cardano-foundation/cardano-token-registry/blob/8a2cd449b86ac6f27a7de34dd0845160a832266b/mappings/fe7c786ab321f41c654ef6c1af7b3250a613c24e4213e0425a7ae45655534441.json" + }, + { + "label": "Cardano Foundation minting-policy execution semantics (updated July 1, 2026)", + "url": "https://developers.cardano.org/docs/developers/curriculum/native-tokens/minting-policies/" + } + ] + } + ] + }, + { + "assetId": "usdm-moneta", + "reviewedAt": "2026-09-05", + "reviewer": "OpenAI Codex Safety Score gap campaign", + "deployments": [ + { + "chainId": "cardano", + "contractOrTokenId": "c48cbb3d5e57ed56e276bc45f99ab39abe94e6cd7ac39fb402da47ad0014df105553444d", + "scope": "canonical", + "posture": "permissionless", + "evidence": "The Cardano Foundation token-registry mapping pinned at commit 8a2cd449b86ac6f27a7de34dd0845160a832266b binds this exact policy ID and asset name to Moneta USDM, its issuer domain, and six decimals. Cardano executes the asset minting policy only when a transaction mints or burns that asset; an ordinary transfer of already-minted native tokens spends the holder UTxO without invoking the policy. The issuer therefore has no token-level holder-transfer hook. Issuer account, custody, and direct-redemption restrictions are separate from transferability of holder-controlled native tokens.", + "sources": [ + { + "label": "Pinned Cardano Foundation USDM identity mapping", + "url": "https://github.com/cardano-foundation/cardano-token-registry/blob/8a2cd449b86ac6f27a7de34dd0845160a832266b/mappings/c48cbb3d5e57ed56e276bc45f99ab39abe94e6cd7ac39fb402da47ad0014df105553444d.json" + }, + { + "label": "Cardano Foundation minting-policy execution semantics (updated July 1, 2026)", + "url": "https://developers.cardano.org/docs/developers/curriculum/native-tokens/minting-policies/" + } + ] + } + ] + }, + { + "assetId": "aznd-mu-digital", + "reviewedAt": "2026-09-05", + "reviewer": "OpenAI Codex Safety Score gap campaign", + "deployments": [ + { + "chainId": "monad", + "contractOrTokenId": "0x4917a5ec9fcb5e10f47cbb197abe6ab63be81fe8", + "scope": "canonical", + "posture": "restrictable", + "evidence": "At Monad block 102222519, canonical AZND was a direct ERC20 deployment with a zero EIP-1967 implementation slot. Its verified transfer paths have no pause or blacklist, but burn(owner, amount) grants the immutable PRIMARY_MARKET 0xe64730de04aeaf8d38925825d77d7a4c00340c89 authority over an arbitrary holder balance without allowance. The current PrimaryMarket implementation 0xe5f8ec544310d5ae79da0f921d01ce80ffd528eb burns only the redemption caller, but its UUPS replacement is authorized by the AccessManager default admin. At the same block, EOA 0x8b5f269f68d42490dee19fc4ab275cdd80940068 held that role in manager 0x7b14860ecd88fb65a22a1d259d1248bf199fb47f, and read-only eth_call of upgradeToAndCall to the existing implementation succeeded from that EOA. The live upgrade path can replace the holder consent guard around the privileged burn, so transfer posture is restrictable.", + "sources": [ + { + "label": "MonadScan verified canonical AZND source", + "url": "https://monadscan.com/address/0x4917a5ec9fcb5e10f47cbb197abe6ab63be81fe8#code" + }, + { + "label": "MonadScan verified PrimaryMarket implementation and UUPS authority", + "url": "https://monadscan.com/address/0xe5f8ec544310d5ae79da0f921d01ce80ffd528eb#code" + }, + { + "label": "Monad observation block 102222519", + "url": "https://monadscan.com/block/102222519" + }, + { + "label": "Mu Digital canonical and representation address registry", + "url": "https://docs.mudigital.net/technical-reference/smart-contract-architecture/smart-contract-addresses.md" + } + ] + }, + { + "chainId": "ethereum", + "contractOrTokenId": "0x52c66b5e7f8fde20843de900c5c8b4b0f23708a0", + "scope": "material-bridge", + "posture": "restrictable", + "evidence": "At Ethereum block 25912083, the AZND OFT proxy resolved to verified implementation 0x2e49c14a73210356de9f23a46a98de777b8a0db6. ContractBaseUpgradeable authorizes UUPS replacement through the default-admin role of accessManager 0xe683fcd4411dde6fc2be16c2512f9109c907b520. Address 0x8b5f269f68d42490dee19fc4ab275cdd80940068 held that role and a read-only eth_call of upgradeToAndCall to the existing implementation succeeded from that address. Ordinary ERC20 transfers are currently open, but this active token-logic replacement path can change holder transfer behavior, making the representation restrictable.", + "sources": [ + { + "label": "Blockscout verified Ethereum AZND OFT implementation and bundled dependencies", + "url": "https://eth.blockscout.com/api/v2/smart-contracts/0x2e49c14a73210356de9f23a46a98de777b8a0db6" + }, + { + "label": "Ethereum AZND proxy", + "url": "https://etherscan.io/address/0x52c66b5e7f8fde20843de900c5c8b4b0f23708a0#code" + }, + { + "label": "Ethereum observation block 25912083", + "url": "https://etherscan.io/block/25912083" + } + ] + } + ] } ] } diff --git a/shared/data/stablecoins/coins/brlv-crown.json b/shared/data/stablecoins/coins/brlv-crown.json index 87df5ebe0f..f7b1878a2b 100644 --- a/shared/data/stablecoins/coins/brlv-crown.json +++ b/shared/data/stablecoins/coins/brlv-crown.json @@ -17,25 +17,10 @@ "proofOfReserves": { "type": "self-reported", "url": "https://www.crown-brlv.com/transparencia/", - "provider": "Fact Finance Ltda technical verification memos (an RWA oracle firm, not an audit practice; signer is a technical lead, not a licensed accountant; the 'daily audits' claim is marketing copy with no daily artefact, and the monthly memo series shows no June or July 2026 report)", + "provider": "Fact Finance Ltda technical verification memos (an RWA oracle firm, not an audit practice; signer is a technical lead, not a licensed accountant; monthly reports are published through August 2026, while the 'daily audits' claim has no daily artefact)", "attestorTier": "none", - "cadence": "ad-hoc", - "attestorJurisdiction": "Brazil", - "latestReport": { - "periodEnd": "2026-05-31", - "publishedAt": "2026-05-31", - "assuranceMethod": "onchain-proof", - "scope": "assets-only", - "liabilityReconciliation": "none", - "reviewer": "PoR verification sweep 2026-08 (memo carries no assurance standard, no opinion, and no accountant signature; series stalled after May 2026)", - "confidence": "probable", - "sources": [ - { - "label": "Fact Finance BRLV proof-of-reserves report - May 2026", - "url": "https://dfg4lo8c2lfcn.cloudfront.net/report_brlv_5_2026_af8cfa373d.pdf" - } - ] - } + "cadence": "monthly", + "attestorJurisdiction": "Brazil" }, "links": [ { diff --git a/shared/data/stablecoins/coins/feusd-felix.json b/shared/data/stablecoins/coins/feusd-felix.json index 90861bef89..2dec30a267 100644 --- a/shared/data/stablecoins/coins/feusd-felix.json +++ b/shared/data/stablecoins/coins/feusd-felix.json @@ -80,7 +80,7 @@ "risk": "very-high" }, { - "name": "kHYPE (KittenFinance)", + "name": "kHYPE (Kinetiq)", "holder": "0xbfd0b103a49faf426f36864d19f5d871bf411a5a", "token": { "chain": "hyperevm", diff --git a/shared/data/stablecoins/coins/usdy-ondo-finance.json b/shared/data/stablecoins/coins/usdy-ondo-finance.json index ea8c58184a..26c3a7d58c 100644 --- a/shared/data/stablecoins/coins/usdy-ondo-finance.json +++ b/shared/data/stablecoins/coins/usdy-ondo-finance.json @@ -124,6 +124,11 @@ "adapter": "chainlink-nav", "version": 1, "semantics": "single-asset", + "suspended": { + "reason": "The NAV oracle measures USDY price and token supply, not the holdings or weights of its multi-asset reserve portfolio. Use the separately dated reviewed Ondo holdings composition until a holdings producer is integrated.", + "since": "2026-09-05", + "reviewBy": "2026-09-12" + }, "scoring": { "maxSourceAgeSec": 4000000 }, diff --git a/shared/data/stablecoins/domains/mint-authority/kag-kinesis.json b/shared/data/stablecoins/domains/mint-authority/kag-kinesis.json index 163fa95613..8757691a37 100644 --- a/shared/data/stablecoins/domains/mint-authority/kag-kinesis.json +++ b/shared/data/stablecoins/domains/mint-authority/kag-kinesis.json @@ -14,6 +14,22 @@ "Which Kinesis-native deployment and current authority create and govern the parent KAG liabilities?", "What exact Kinesis-side reserve-locking and redemption accounting invariant binds the Ethereum KMS Labs representation to native KAG?" ], + "noLocalIssuance": { + "kind": "external-only-representation", + "reviewedAt": "2026-09-05", + "reviewer": "OpenAI Codex Safety Score gap campaign", + "rationale": "The sole authored deployment is the Ethereum KMS Labs representation. Kinesis identifies that ERC-20 as a 1:1 claim on Kinesis KAG held by KMS Labs S.A., with native KAG issued separately by Kinesis Cayman. The reviewed Ethereum representation route covers the entire authored deployment inventory; its uncapped minter, default-admin and UUPS controls remain scored under Bridge Risk at the opaque-or-unknown route tier. This exception establishes no local canonical issuance, without claiming that the unresolved native Kinesis authority or reserve-locking invariant has been verified.", + "sources": [ + { + "label": "Kinesis Silver product disclosure distinguishing native KAG from the KMS Labs ERC-20 claim", + "url": "https://kinesis.money/silver/" + }, + { + "label": "Authored Ethereum KAG representation contract", + "url": "https://etherscan.io/address/0x56ba8b58b7d1f6d384a1c4dd553f39ebc8741b8e" + } + ] + }, "evidence": "Kinesis official material identifies native KAG as issued by Kinesis Cayman on the Kinesis network and the Ethereum ERC-20 as a KMS Labs 1:1 claim on Kinesis KAG held in KMS Labs reserves. The catalog does not author a Kinesis-native deployment or expose its current issuance authority. The Ethereum representation's ERC20F minter, default-admin, and UUPS upgrade facts are reviewed under Bridge Risk; they do not establish native Kinesis issuance. The semiannual physical-metal audit and redemption wording do not establish a complete KMS Labs ERC-20-supply-to-reserve reconciliation or a mechanical Kinesis-side lock/mint invariant.", "reviewer": "Pharos mint-authority boundary review; FIX-08 migration", "reviewedAt": "2026-08-16", diff --git a/shared/data/stablecoins/domains/reserves/brlv-crown.json b/shared/data/stablecoins/domains/reserves/brlv-crown.json index 58490331c4..884384cf20 100644 --- a/shared/data/stablecoins/domains/reserves/brlv-crown.json +++ b/shared/data/stablecoins/domains/reserves/brlv-crown.json @@ -3,7 +3,7 @@ "reserves": [ { "name": "Brazilian federal government bonds", - "pct": 99.99, + "pct": 99.98, "risk": "low", "assetClass": "government-security", "issuerOrObligor": "Federative Republic of Brazil", @@ -12,7 +12,7 @@ }, { "name": "ETFs linked to Brazilian Treasury securities", - "pct": 0.01, + "pct": 0.02, "risk": "low", "assetClass": "fund-share", "issuerOrObligor": "Undisclosed Brazilian Treasury ETF issuers", @@ -21,37 +21,37 @@ } ], "reserveReview": { - "reviewedAt": "2026-08-08", + "reviewedAt": "2026-09-05", "reviewer": "Pharos reserve research", "confidence": "verified", "sources": [ { - "label": "Fact Finance BRLV proof-of-reserves report - May 2026 (re-opened 2026-08-08)", - "url": "https://dfg4lo8c2lfcn.cloudfront.net/report_brlv_5_2026_af8cfa373d.pdf" + "label": "Fact Finance BRLV proof-of-reserves report - August 2026, dated August 31", + "url": "https://dfg4lo8c2lfcn.cloudfront.net/report_brlv_8_2026_1ea3d5e0be.pdf" }, { - "label": "Crown BRLV reserve transparency (re-opened 2026-08-08)", + "label": "Crown BRLV reserve transparency and monthly-report index (observed 2026-09-05)", "url": "https://www.crown-brlv.com/en/transparency/" } ], - "rationale": "Re-opened 2026-08-08. The Crown transparency page still lists report_brlv_5_2026.pdf as the latest BRLV reserve report; no June, July, or August 2026 BRLV PDF is published. The May 31, 2026 Fact Finance report still records Brazilian Treasury Bonds at 99.99% and ETFs linked to Brazilian Treasury securities at 0.01%, with cash rounded to 0.00%. Because the composition as-of date remains 2026-05-31, the curated rows are stale versus the 31-day admission window.", - "compositionBasis": "Fact Finance BRLV proof-of-reserves report as of May 31, 2026", - "compositionAsOf": "2026-05-31", + "rationale": "Verified both pages of Fact Finance's technical verification memo dated August 31, 2026, linked by Crown's current monthly-report index alongside the June and July reports. The memo reports R$380,315,618.44 of reserves against R$378,063,743.00 of circulating BRLV (100.60% coverage). Its two Brazilian Treasury bond rows total R$380,258,017.98 and its two Treasury ETF rows total R$57,540.25; R$60.21 is cash. Aggregating the stated balances and rounding to two decimals produces 99.98% government bonds and 0.02% ETFs, with cash below 0.0001%. The report identifies the tracked Base contract 0xd7Ca0e2C36d647446b782D1b72308E598373E2F5. It is signed by Fact Finance's technical lead and carries no accountant assurance standard or opinion; freshness does not upgrade that engagement classification.", + "compositionBasis": "Fact Finance BRLV technical verification memo dated August 31, 2026; category percentages computed from its stated reserve balances and rounded to two decimals; PDF SHA-256 68325f70157b6d549f534900917e84d40bdcbc9bc9348de2a717c11f8e01f8cd", + "compositionAsOf": "2026-08-31", "scope": "full-composition", - "knownUnknownExposure": "The report identifies the reserve asset categories but does not disclose security identifiers, maturities, custodian names, or provider-level allocation.", + "knownUnknownExposure": "The report identifies the reserve asset categories but does not disclose security identifiers, maturities, custodian names, or provider-level allocation. Its August 31 report date is verified; its posting date is undisclosed (PDF creation metadata is September 1, and public availability was first observed September 5). No structured latestReport publication date is asserted.", "knownUnknownExposurePct": 0, "nonLinkDispositions": [ { "reserveIndex": 0, "reserveName": "Brazilian federal government bonds", - "pct": 99.99, + "pct": 99.98, "disposition": "untracked-exogenous-asset", "rationale": "Brazilian federal government securities are external reserve assets rather than tracked stablecoin dependencies." }, { "reserveIndex": 1, "reserveName": "ETFs linked to Brazilian Treasury securities", - "pct": 0.01, + "pct": 0.02, "disposition": "untracked-exogenous-asset", "rationale": "Brazilian Treasury-linked ETF shares are external reserve assets rather than tracked stablecoin dependencies." } diff --git a/shared/data/stablecoins/domains/risk-review/sfrxusd-frax.json b/shared/data/stablecoins/domains/risk-review/sfrxusd-frax.json index 7c22efa16e..b73cac52bb 100644 --- a/shared/data/stablecoins/domains/risk-review/sfrxusd-frax.json +++ b/shared/data/stablecoins/domains/risk-review/sfrxusd-frax.json @@ -354,9 +354,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the aurora sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at aurora block 214405247 (2026-09-05T16:20:06.000Z, hash 0xa3ed3ecd739d12b2ad9d4e57514251ee7f12473f08451b31e57114f2c6e622de): symbol()=sfrxUSD, endpoint()=0x1a44076050125825900e736c501f859c50fe728c, owner()=0x73f365d34b81e731825a094c2e722a08574335cd; EIP-1967 implementation=0x192e0c7cc9b263d93fa6d472de47bbefe1fb12ba, admin=0x223a681fc5c5522c85c96157c0efa18cd6c5405c. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 7b972eaf729a47ef82426966982673595fedd541140bfecbd8feecccf6c25ca4; implementation code hex-text SHA-256 a4e35058049f08f7c475d458f0d0f5cbdb9de4da7e3d5543e995f6ff1a91a829.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -365,8 +365,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block aurora sfrxUSD controller reads, block 214405247", + "url": "https://mainnet.aurora.dev" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://aurorascan.dev/address/0x192e0c7cc9b263d93fa6d472de47bbefe1fb12ba" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://aurorascan.dev/address/0x73f365d34b81e731825a094c2e722a08574335cd" + }, + { + "label": "Observation block", + "url": "https://aurorascan.dev/block/214405247" } - ] + ], + "controllerChain": "aurora", + "controllerAddress": "0x73f365d34b81e731825a094c2e722a08574335cd", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:aurora:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", + "contract:aurora:0x73f365d34b81e731825a094c2e722a08574335cd", + "contract:aurora:0x223a681fc5c5522c85c96157c0efa18cd6c5405c" + ], + "observedBlock": 214405247 }, { "id": "avalanche:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", @@ -381,9 +406,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the avalanche sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at avalanche block 94541701 (2026-09-05T16:20:07.000Z, hash 0xb9a92f3b8e39a1870ccb23b6948fa4e52415e384099516f3be1e64a413b596e0): symbol()=sfrxUSD, endpoint()=0x1a44076050125825900e736c501f859c50fe728c, owner()=0xbf1ff4d8b05f0871ca3f49e49ff1ca8aeebd3b4b; EIP-1967 implementation=0x686cabd9b4a41965184fbb95f2ae80c20bef18ab, admin=0x223a681fc5c5522c85c96157c0efa18cd6c5405c. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 fdd4574aea51657de1dc42a10c086d52557ad6a865d921f9308ea91c11eef4f0; implementation code hex-text SHA-256 a4e35058049f08f7c475d458f0d0f5cbdb9de4da7e3d5543e995f6ff1a91a829.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -392,8 +417,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block avalanche sfrxUSD controller reads, block 94541701", + "url": "https://api.avax.network/ext/bc/C/rpc" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://snowtrace.io/address/0x686cabd9b4a41965184fbb95f2ae80c20bef18ab" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://snowtrace.io/address/0xbf1ff4d8b05f0871ca3f49e49ff1ca8aeebd3b4b" + }, + { + "label": "Observation block", + "url": "https://snowtrace.io/block/94541701" } - ] + ], + "controllerChain": "avalanche", + "controllerAddress": "0xbf1ff4d8b05f0871ca3f49e49ff1ca8aeebd3b4b", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:avalanche:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", + "contract:avalanche:0xbf1ff4d8b05f0871ca3f49e49ff1ca8aeebd3b4b", + "contract:avalanche:0x223a681fc5c5522c85c96157c0efa18cd6c5405c" + ], + "observedBlock": 94541701 }, { "id": "berachain:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", @@ -408,9 +458,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the berachain sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at berachain block 25805245 (2026-09-05T16:20:06.000Z, hash 0x91e6533b3763b5de2abfcb9b490731732c0a78da21fbb32881a5c5e3ab229d99): symbol()=sfrxUSD, endpoint()=0x6f475642a6e85809b1c36fa62763669b1b48dd5b, owner()=0x436b303daf4b95e94ad86ca3821d5e50eb0de3aa; EIP-1967 implementation=0xae47a59bf1012d825135ccd6c2c708588e80b2f7, admin=0x223a681fc5c5522c85c96157c0efa18cd6c5405c. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x0000000000000000000000000000000000000000) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 b7ac73e776d51f92c91559836c8afc0705aba8a23e77fa68278b82b15d63da96; implementation code hex-text SHA-256 5ed11fac505c1ac4c34392c814a29b42557147089361f1b3bbf0a435127053ca.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -419,8 +469,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block berachain sfrxUSD controller reads, block 25805245", + "url": "https://rpc.berachain.com" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://berascan.com/address/0xae47a59bf1012d825135ccd6c2c708588e80b2f7" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://berascan.com/address/0x436b303daf4b95e94ad86ca3821d5e50eb0de3aa" + }, + { + "label": "Observation block", + "url": "https://berascan.com/block/25805245" } - ] + ], + "controllerChain": "berachain", + "controllerAddress": "0x436b303daf4b95e94ad86ca3821d5e50eb0de3aa", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:berachain:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", + "contract:berachain:0x436b303daf4b95e94ad86ca3821d5e50eb0de3aa", + "contract:berachain:0x223a681fc5c5522c85c96157c0efa18cd6c5405c" + ], + "observedBlock": 25805245 }, { "id": "bsc:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", @@ -435,9 +510,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the bsc sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at bsc block 120141480 (2026-09-05T16:20:08.000Z, hash 0x18b94135de4e8bd56dcb8783246aaa78fb3dc1883291cd93cb4a189790c8f4cb): symbol()=sfrxUSD, endpoint()=0x1a44076050125825900e736c501f859c50fe728c, owner()=0xb1eff95b323d60cc04b1a44ca1dbcbc935ae2c84; EIP-1967 implementation=0x370dd74dd32d8d47d3cd0abc5fcf2cd1e9912a97, admin=0x223a681fc5c5522c85c96157c0efa18cd6c5405c. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 3123d54bb314f2154e4dc218810bed30def1417486feed3ee24d75cc19d7de94; implementation code hex-text SHA-256 a4e35058049f08f7c475d458f0d0f5cbdb9de4da7e3d5543e995f6ff1a91a829.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -446,8 +521,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block bsc sfrxUSD controller reads, block 120141480", + "url": "https://56.rpc.thirdweb.com" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://bscscan.com/address/0x370dd74dd32d8d47d3cd0abc5fcf2cd1e9912a97" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://bscscan.com/address/0xb1eff95b323d60cc04b1a44ca1dbcbc935ae2c84" + }, + { + "label": "Observation block", + "url": "https://bscscan.com/block/120141480" } - ] + ], + "controllerChain": "bsc", + "controllerAddress": "0xb1eff95b323d60cc04b1a44ca1dbcbc935ae2c84", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:bsc:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", + "contract:bsc:0xb1eff95b323d60cc04b1a44ca1dbcbc935ae2c84", + "contract:bsc:0x223a681fc5c5522c85c96157c0efa18cd6c5405c" + ], + "observedBlock": 120141480 }, { "id": "hyperevm:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", @@ -462,9 +562,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the hyperevm sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at hyperevm block 45108397 (2026-09-05T16:20:09.000Z, hash 0xee6c3bbfb7fe82d7b0b1110841610d983408745b9bab7a6f6ce2b4667e4dced7): symbol()=sfrxUSD, endpoint()=0x3a73033c0b1407574c76bdbac67f126f6b4a9aa9, owner()=0x738ee62157f127c879ff5c4b7102eb0d166c7a6d; EIP-1967 implementation=0x4e7f19d86a81857c46e87182a14b4e894b8ada1a, admin=0x223a681fc5c5522c85c96157c0efa18cd6c5405c. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 0ef919462d51119c4b7e06ee806b77ff32780dcdb8d01d626ed61b29165585c4; implementation code hex-text SHA-256 e667ba7a2a4f566d1654cedc5c85ae47eae388efe03b40f341cfc0fef5365d74.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -473,8 +573,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block hyperevm sfrxUSD controller reads, block 45108397", + "url": "https://rpc.hyperliquid.xyz/evm" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://hyperevmscan.io/address/0x4e7f19d86a81857c46e87182a14b4e894b8ada1a" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://hyperevmscan.io/address/0x738ee62157f127c879ff5c4b7102eb0d166c7a6d" + }, + { + "label": "Observation block", + "url": "https://hyperevmscan.io/block/45108397" } - ] + ], + "controllerChain": "hyperevm", + "controllerAddress": "0x738ee62157f127c879ff5c4b7102eb0d166c7a6d", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:hyperevm:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", + "contract:hyperevm:0x738ee62157f127c879ff5c4b7102eb0d166c7a6d", + "contract:hyperevm:0x223a681fc5c5522c85c96157c0efa18cd6c5405c" + ], + "observedBlock": 45108397 }, { "id": "ink:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", @@ -489,9 +614,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the ink sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at ink block 55126798 (2026-09-05T16:20:09.000Z, hash 0xd08ce2b9ebca444bf8697485742e315773e1463dcac124ed02042534e30bf2b6): symbol()=sfrxUSD, endpoint()=0xca29f3a6f966cb2fc0de625f8f325c0c46dbe958, owner()=0x91ebc17cd330dd694225133455583fbca54b8ec8; EIP-1967 implementation=0x9e951dd846e748e6fcb58bfb76953c4900f819f4, admin=0x223a681fc5c5522c85c96157c0efa18cd6c5405c. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 9923991bc6e9b29979678244c7640de7e6ee70b6367841292bfbf7bd1590f938; implementation code hex-text SHA-256 caf26cfe95a936ec651113007fa2475186fec2fe76827fdabe665b785f4d6832.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -500,8 +625,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block ink sfrxUSD controller reads, block 55126798", + "url": "https://rpc-gel.inkonchain.com" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://explorer.inkonchain.com/address/0x9e951dd846e748e6fcb58bfb76953c4900f819f4" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://explorer.inkonchain.com/address/0x91ebc17cd330dd694225133455583fbca54b8ec8" + }, + { + "label": "Observation block", + "url": "https://explorer.inkonchain.com/block/55126798" } - ] + ], + "controllerChain": "ink", + "controllerAddress": "0x91ebc17cd330dd694225133455583fbca54b8ec8", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:ink:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", + "contract:ink:0x91ebc17cd330dd694225133455583fbca54b8ec8", + "contract:ink:0x223a681fc5c5522c85c96157c0efa18cd6c5405c" + ], + "observedBlock": 55126798 }, { "id": "optimism:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", @@ -516,9 +666,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the optimism sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at optimism block 156513216 (2026-09-05T16:20:09.000Z, hash 0xc85f640c7da772897714cae005a5a25c84b8f59555f1b44f13d3319dd30bd167): symbol()=sfrxUSD, endpoint()=0x1a44076050125825900e736c501f859c50fe728c, owner()=0x419e672d625f998dd07a7ecf2e06b896f8717cb2; EIP-1967 implementation=0x681975ddfebaeeeb7400b2407e4cbfe6c41573ad, admin=0x223a681fc5c5522c85c96157c0efa18cd6c5405c. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 4a2802ff751e1f7bd8e24068bedcd7ec0f4b221c5a26afa3a5dbe58cb2c340c9; implementation code hex-text SHA-256 a4e35058049f08f7c475d458f0d0f5cbdb9de4da7e3d5543e995f6ff1a91a829.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -527,8 +677,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block optimism sfrxUSD controller reads, block 156513216", + "url": "https://mainnet.optimism.io" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://optimistic.etherscan.io/address/0x681975ddfebaeeeb7400b2407e4cbfe6c41573ad" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://optimistic.etherscan.io/address/0x419e672d625f998dd07a7ecf2e06b896f8717cb2" + }, + { + "label": "Observation block", + "url": "https://optimistic.etherscan.io/block/156513216" } - ] + ], + "controllerChain": "optimism", + "controllerAddress": "0x419e672d625f998dd07a7ecf2e06b896f8717cb2", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:optimism:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", + "contract:optimism:0x419e672d625f998dd07a7ecf2e06b896f8717cb2", + "contract:optimism:0x223a681fc5c5522c85c96157c0efa18cd6c5405c" + ], + "observedBlock": 156513216 }, { "id": "plume:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", @@ -543,9 +718,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the plume sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at plume block 91588359 (2026-09-05T16:20:11.000Z, hash 0xa016f9b2cb82edd0ebffc16d35fd46ebba1263f2c53551e9ededbd77c2ae3303): symbol()=sfrxUSD, endpoint()=0xc1b15d3b262beec0e3565c11c9e0f6134bdacb36, owner()=0x77ddd3ec570eeaf2c513de3c833c5e82a721978b; EIP-1967 implementation=0x36c28ef9a8116a64752efd6b9efa3056f24a82ae, admin=0x223a681fc5c5522c85c96157c0efa18cd6c5405c. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 40b4a3a7d1954f30cb74eb03424c1571d8478cf1cbab13e471c8e3569506bc19; implementation code hex-text SHA-256 bb2e38424e64b2a9f4edeef110de2671e8b296b816cc0ad3c17426e8011c4857.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -554,8 +729,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block plume sfrxUSD controller reads, block 91588359", + "url": "https://rpc.plume.org" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://explorer.plume.org/address/0x36c28ef9a8116a64752efd6b9efa3056f24a82ae" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://explorer.plume.org/address/0x77ddd3ec570eeaf2c513de3c833c5e82a721978b" + }, + { + "label": "Observation block", + "url": "https://explorer.plume.org/block/91588359" } - ] + ], + "controllerChain": "plume", + "controllerAddress": "0x77ddd3ec570eeaf2c513de3c833c5e82a721978b", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:plume:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", + "contract:plume:0x77ddd3ec570eeaf2c513de3c833c5e82a721978b", + "contract:plume:0x223a681fc5c5522c85c96157c0efa18cd6c5405c" + ], + "observedBlock": 91588359 }, { "id": "polygon:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", @@ -570,9 +770,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the polygon sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at polygon block 93280119 (2026-09-05T16:20:12.000Z, hash 0xce440421f123a4bfb97037e9e1539f6771a8a67bf94ccd2e11efd562742e9dc7): symbol()=sfrxUSD, endpoint()=0x1a44076050125825900e736c501f859c50fe728c, owner()=0xdbf59eda454679bb157b3b048ba54c4d762b559e; EIP-1967 implementation=0x02a7a4bff1edac698bac1a2380a208f2e6a56697, admin=0x223a681fc5c5522c85c96157c0efa18cd6c5405c. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 823d3680bef93df3258fdbb152d11f12110bad5e422c83db772df338c4adc111; implementation code hex-text SHA-256 a4e35058049f08f7c475d458f0d0f5cbdb9de4da7e3d5543e995f6ff1a91a829.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -581,8 +781,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block polygon sfrxUSD controller reads, block 93280119", + "url": "https://polygon.drpc.org" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://polygonscan.com/address/0x02a7a4bff1edac698bac1a2380a208f2e6a56697" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://polygonscan.com/address/0xdbf59eda454679bb157b3b048ba54c4d762b559e" + }, + { + "label": "Observation block", + "url": "https://polygonscan.com/block/93280119" } - ] + ], + "controllerChain": "polygon", + "controllerAddress": "0xdbf59eda454679bb157b3b048ba54c4d762b559e", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:polygon:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", + "contract:polygon:0xdbf59eda454679bb157b3b048ba54c4d762b559e", + "contract:polygon:0x223a681fc5c5522c85c96157c0efa18cd6c5405c" + ], + "observedBlock": 93280119 }, { "id": "polygon-zkevm:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", @@ -597,9 +822,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the polygon-zkevm sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at polygon-zkevm block 33391890 (2026-07-03T15:55:44.000Z, hash 0x070c57f81880e78cc8a1bee37c927dd44487e6c42d0c6a475bddc76818224b97): symbol()=sfrxUSD, endpoint()=0x1a44076050125825900e736c501f859c50fe728c, owner()=0x57445fd8d544e5d313e4f715220103b091814df4; EIP-1967 implementation=0x7feda252881b9c6166b387d3d11d1bdfc076d5cb, admin=0x223a681fc5c5522c85c96157c0efa18cd6c5405c. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x0000000000000000000000000000000000000000) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 62a1e3186a15628e1677cbeae4520c553f6943f5af6706a5405b0ba3d9d24e89; implementation code hex-text SHA-256 bf0b776de1364ff84119bd8d0f76b875b89df30ab4546f4c0d304b647af748d0.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -608,8 +833,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block polygon-zkevm sfrxUSD controller reads, block 33391890", + "url": "https://zkevm-rpc.com" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://zkevm.polygonscan.com/address/0x7feda252881b9c6166b387d3d11d1bdfc076d5cb" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://zkevm.polygonscan.com/address/0x57445fd8d544e5d313e4f715220103b091814df4" + }, + { + "label": "Observation block", + "url": "https://zkevm.polygonscan.com/block/33391890" } - ] + ], + "controllerChain": "polygon-zkevm", + "controllerAddress": "0x57445fd8d544e5d313e4f715220103b091814df4", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:polygon-zkevm:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", + "contract:polygon-zkevm:0x57445fd8d544e5d313e4f715220103b091814df4", + "contract:polygon-zkevm:0x223a681fc5c5522c85c96157c0efa18cd6c5405c" + ], + "observedBlock": 33391890 }, { "id": "stable:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", @@ -624,9 +874,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the stable sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at stable block 38251144 (2026-09-05T16:24:25.000Z, hash 0x00074a4a668bae8f1843cd4682398412d34c6926c8a536dd30d6112fabfb7233): symbol()=sfrxUSD, endpoint()=0x6f475642a6e85809b1c36fa62763669b1b48dd5b, owner()=0x0c46f54bf9ef8fd58e2d294b8cea488204ecb3d8; EIP-1967 implementation=0x7feda252881b9c6166b387d3d11d1bdfc076d5cb, admin=0x223a681fc5c5522c85c96157c0efa18cd6c5405c. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 94f8c762c3174214dff2e94432e90eaeeb5a8b7264261949f6cc450b9decc52c; implementation code hex-text SHA-256 958160664a265b86045e8908df5678ff901227ee591c5d12c044a71341eb44bd.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -635,8 +885,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block stable sfrxUSD controller reads, block 38251144", + "url": "https://rpc.stable.xyz" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://stablescan.xyz/address/0x7feda252881b9c6166b387d3d11d1bdfc076d5cb" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://stablescan.xyz/address/0x0c46f54bf9ef8fd58e2d294b8cea488204ecb3d8" + }, + { + "label": "Observation block", + "url": "https://stablescan.xyz/block/38251144" } - ] + ], + "controllerChain": "stable", + "controllerAddress": "0x0c46f54bf9ef8fd58e2d294b8cea488204ecb3d8", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:stable:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", + "contract:stable:0x0c46f54bf9ef8fd58e2d294b8cea488204ecb3d8", + "contract:stable:0x223a681fc5c5522c85c96157c0efa18cd6c5405c" + ], + "observedBlock": 38251144 }, { "id": "unichain:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", @@ -651,9 +926,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the unichain sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at unichain block 57876852 (2026-09-05T16:20:11.000Z, hash 0x538bc2d516405fa4c9eab76f6af97537f23f03c47b64dcfc9d3c3387b9324a6f): symbol()=sfrxUSD, endpoint()=0x6f475642a6e85809b1c36fa62763669b1b48dd5b, owner()=0x6f8fddfd4f6a1456ba5632c919bef74b64dd032d; EIP-1967 implementation=0x4e7f19d86a81857c46e87182a14b4e894b8ada1a, admin=0x223a681fc5c5522c85c96157c0efa18cd6c5405c. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 8dade0d31cf89d81c3b1a05ec9c0f13a342d46544e99c3effa0f1846fafadeec; implementation code hex-text SHA-256 5ed11fac505c1ac4c34392c814a29b42557147089361f1b3bbf0a435127053ca.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -662,8 +937,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block unichain sfrxUSD controller reads, block 57876852", + "url": "https://mainnet.unichain.org/" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://uniscan.xyz/address/0x4e7f19d86a81857c46e87182a14b4e894b8ada1a" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://uniscan.xyz/address/0x6f8fddfd4f6a1456ba5632c919bef74b64dd032d" + }, + { + "label": "Observation block", + "url": "https://uniscan.xyz/block/57876852" } - ] + ], + "controllerChain": "unichain", + "controllerAddress": "0x6f8fddfd4f6a1456ba5632c919bef74b64dd032d", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:unichain:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", + "contract:unichain:0x6f8fddfd4f6a1456ba5632c919bef74b64dd032d", + "contract:unichain:0x223a681fc5c5522c85c96157c0efa18cd6c5405c" + ], + "observedBlock": 57876852 }, { "id": "worldchain:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", @@ -678,9 +978,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the worldchain sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at worldchain block 34644787 (2026-09-05T16:20:13.000Z, hash 0x4dac94fa1559f2287c607bf1ba150943027f594a0c881df8eabdc263f57a2624): symbol()=sfrxUSD, endpoint()=0x6f475642a6e85809b1c36fa62763669b1b48dd5b, owner()=0xf57d47c3ea11c12253dbc0beaf097d5c206e8773; EIP-1967 implementation=0xefdf0dea7048d9784d6289002f65d0f3e9764d6b, admin=0x223a681fc5c5522c85c96157c0efa18cd6c5405c. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 763a24591580762f28cb505c197c29809c2d0f13201fb704425f883e6381732e; implementation code hex-text SHA-256 5ed11fac505c1ac4c34392c814a29b42557147089361f1b3bbf0a435127053ca.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -689,8 +989,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block worldchain sfrxUSD controller reads, block 34644787", + "url": "https://worldchain-mainnet.g.alchemy.com/public" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://worldscan.org/address/0xefdf0dea7048d9784d6289002f65d0f3e9764d6b" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://worldscan.org/address/0xf57d47c3ea11c12253dbc0beaf097d5c206e8773" + }, + { + "label": "Observation block", + "url": "https://worldscan.org/block/34644787" } - ] + ], + "controllerChain": "worldchain", + "controllerAddress": "0xf57d47c3ea11c12253dbc0beaf097d5c206e8773", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:worldchain:0x5bff88ca1442c2496f7e475e9e7786383bc070c0", + "contract:worldchain:0xf57d47c3ea11c12253dbc0beaf097d5c206e8773", + "contract:worldchain:0x223a681fc5c5522c85c96157c0efa18cd6c5405c" + ], + "observedBlock": 34644787 }, { "id": "monad:0x137643f7b2c189173867b3391f6629cab46f0f1a", @@ -705,9 +1030,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the monad sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at monad block 102230529 (2026-09-05T16:20:15.000Z, hash 0x98c9583948c741263879c02f94a62de4ab5c6bde2949f41cb7032a7c3bfaa0b9): symbol()=sfrxUSD, endpoint()=0x6f475642a6e85809b1c36fa62763669b1b48dd5b, owner()=0x47ff5bbab981ff022743aa4281d4d6dd7fb1a4d0; EIP-1967 implementation=0x7e93d4ab01c70b78a5449bf3df648c3aa5f4057f, admin=0xc2871eae630640ce1a16b39a17c498f22d76c21a. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 135ac40d29a2c77d47fb3e430498a5b283d00786087fe285f978ee3883392f93; implementation code hex-text SHA-256 ec0a2c4f219e7333e600ce805a6b46457967f75b7f906d950b59590c64b454fa.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -716,8 +1041,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block monad sfrxUSD controller reads, block 102230529", + "url": "https://rpc.monad.xyz" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://monadscan.com/address/0x7e93d4ab01c70b78a5449bf3df648c3aa5f4057f" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://monadscan.com/address/0x47ff5bbab981ff022743aa4281d4d6dd7fb1a4d0" + }, + { + "label": "Observation block", + "url": "https://monadscan.com/block/102230529" } - ] + ], + "controllerChain": "monad", + "controllerAddress": "0x47ff5bbab981ff022743aa4281d4d6dd7fb1a4d0", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:monad:0x137643f7b2c189173867b3391f6629cab46f0f1a", + "contract:monad:0x47ff5bbab981ff022743aa4281d4d6dd7fb1a4d0", + "contract:monad:0xc2871eae630640ce1a16b39a17c498f22d76c21a" + ], + "observedBlock": 102230529 }, { "id": "base:0x91a3f8a8d7a881fbdfcfecd7a2dc92a46dcfa14e", @@ -732,9 +1082,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the base sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at base block 50917934 (2026-09-05T16:20:15.000Z, hash 0xcba22badff8f498428d367e84b0d9592b82c8b06f31bd8a695bb99f814859b64): symbol()=sfrxUSD, endpoint()=0x1a44076050125825900e736c501f859c50fe728c, owner()=0xcbfd4ef00a8cf91fd1e1fe97dc05910772c15e53; EIP-1967 implementation=0xdc4944793b86c337a0498e31f6bd0f2f814c0f42, admin=0xf59c41a57ab4565af7424f64981523dfd7a453c5. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 43faea0bf6049da1ed77a4cbed2db94773bb00154ef695c1901cb96f9e21c097; implementation code hex-text SHA-256 a4e35058049f08f7c475d458f0d0f5cbdb9de4da7e3d5543e995f6ff1a91a829.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -743,8 +1093,37 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block base sfrxUSD controller reads, block 50917934", + "url": "https://mainnet.base.org" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://basescan.org/address/0xdc4944793b86c337a0498e31f6bd0f2f814c0f42" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://basescan.org/address/0xcbfd4ef00a8cf91fd1e1fe97dc05910772c15e53" + }, + { + "label": "Observation block", + "url": "https://basescan.org/block/50917934" + }, + { + "label": "Base supplementary fixed-block authority reads", + "url": "https://base-rpc.publicnode.com" } - ] + ], + "controllerChain": "base", + "controllerAddress": "0xcbfd4ef00a8cf91fd1e1fe97dc05910772c15e53", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:base:0x91a3f8a8d7a881fbdfcfecd7a2dc92a46dcfa14e", + "contract:base:0xcbfd4ef00a8cf91fd1e1fe97dc05910772c15e53", + "contract:base:0xf59c41a57ab4565af7424f64981523dfd7a453c5" + ], + "observedBlock": 50917934 }, { "id": "linea:0x592a48c0fb9c7f8bf1701cb0136b90dea2a5b7b6", @@ -759,9 +1138,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the linea sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at linea block 31942641 (2026-09-05T16:20:09.000Z, hash 0x1609e2ffe988748c1725c37df8c03298c2d2c7da5011d63e5fc2e65a93492a62): symbol()=sfrxUSD, endpoint()=0x1a44076050125825900e736c501f859c50fe728c, owner()=0x0e5a5284820e350ffce7fe7ba3364fac1c53eafd; EIP-1967 implementation=0xc83a8d6d758f52f6226da964cbe80e097b1e534e, admin=0x3cf371c128b092b085b7732069ceaf3fd863f270. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 83c0e925da0ab463f8ada91a6c70f90b3b0f5c4cc0b41c8559dc0c3837a8a17a; implementation code hex-text SHA-256 88bbdf872bdfef81162d6bc829c7535e7c55699c7ed95352d3eeec8c7553eca6.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -770,8 +1149,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block linea sfrxUSD controller reads, block 31942641", + "url": "https://rpc.linea.build" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://lineascan.build/address/0xc83a8d6d758f52f6226da964cbe80e097b1e534e" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://lineascan.build/address/0x0e5a5284820e350ffce7fe7ba3364fac1c53eafd" + }, + { + "label": "Observation block", + "url": "https://lineascan.build/block/31942641" } - ] + ], + "controllerChain": "linea", + "controllerAddress": "0x0e5a5284820e350ffce7fe7ba3364fac1c53eafd", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:linea:0x592a48c0fb9c7f8bf1701cb0136b90dea2a5b7b6", + "contract:linea:0x0e5a5284820e350ffce7fe7ba3364fac1c53eafd", + "contract:linea:0x3cf371c128b092b085b7732069ceaf3fd863f270" + ], + "observedBlock": 31942641 }, { "id": "scroll:0xc6b2be25d65760b826d0c852fd35f364250619c2", @@ -786,9 +1190,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the scroll sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at scroll block 34922412 (2026-09-05T16:19:30.000Z, hash 0x4e1fd835e58fa397bd79bc7ea6648a46bf8e8961054c1f91f7810ec113f6fa49): symbol()=sfrxUSD, endpoint()=0x1a44076050125825900e736c501f859c50fe728c, owner()=0x73f365d34b81e731825a094c2e722a08574335cd; EIP-1967 implementation=0x36c28ef9a8116a64752efd6b9efa3056f24a82ae, admin=0x8f1b9c1fd67136d525e14d96efb3887a33f16250. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 489526dddf1135716c7e630fa12dbc18470a0a56815bb836226741b13856abff; implementation code hex-text SHA-256 a4e35058049f08f7c475d458f0d0f5cbdb9de4da7e3d5543e995f6ff1a91a829.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -797,8 +1201,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block scroll sfrxUSD controller reads, block 34922412", + "url": "https://rpc.scroll.io" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://scrollscan.com/address/0x36c28ef9a8116a64752efd6b9efa3056f24a82ae" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://scrollscan.com/address/0x73f365d34b81e731825a094c2e722a08574335cd" + }, + { + "label": "Observation block", + "url": "https://scrollscan.com/block/34922412" } - ] + ], + "controllerChain": "scroll", + "controllerAddress": "0x73f365d34b81e731825a094c2e722a08574335cd", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:scroll:0xc6b2be25d65760b826d0c852fd35f364250619c2", + "contract:scroll:0x73f365d34b81e731825a094c2e722a08574335cd", + "contract:scroll:0x8f1b9c1fd67136d525e14d96efb3887a33f16250" + ], + "observedBlock": 34922412 }, { "id": "zksync:0x9f87fbb47c33cd0614e43500b9511018116f79ee", @@ -813,9 +1242,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the zksync sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at zksync block 71855627 (2026-09-05T16:20:15.000Z, hash 0x1766a5fa52f58442400f63926b46834b7f6ee7c9b11a632122a40fd2a1e68a63): symbol()=sfrxUSD, endpoint()=0xd07c30af3ff30d96bdc9c6044958230eb797ddbf, owner()=0x66716ae60898dd4479b52ac4d92ef16c1821f420; EIP-1967 implementation=0xf559acaa7283c78a7ec244fcf62c6b01f5676442, admin=0xe59dcae52a4ffa39be99588486c84bc2dc1ba52f. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 41d9eb897e09293be39a463ec574302ee2abbf8d29b0de20f565b83d129c0f43; implementation code hex-text SHA-256 204e8f67bb2f7365ff4095d8ceb0bf8d79e0e47803afae74af82757f61e964df.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -824,8 +1253,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block zksync sfrxUSD controller reads, block 71855627", + "url": "https://mainnet.era.zksync.io" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://explorer.zksync.io//address/0xf559acaa7283c78a7ec244fcf62c6b01f5676442" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://explorer.zksync.io//address/0x66716ae60898dd4479b52ac4d92ef16c1821f420" + }, + { + "label": "Observation block", + "url": "https://explorer.zksync.io//block/71855627" } - ] + ], + "controllerChain": "zksync", + "controllerAddress": "0x66716ae60898dd4479b52ac4d92ef16c1821f420", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:zksync:0x9f87fbb47c33cd0614e43500b9511018116f79ee", + "contract:zksync:0x66716ae60898dd4479b52ac4d92ef16c1821f420", + "contract:zksync:0xe59dcae52a4ffa39be99588486c84bc2dc1ba52f" + ], + "observedBlock": 71855627 }, { "id": "abstract:0x9f87fbb47c33cd0614e43500b9511018116f79ee", @@ -840,9 +1294,9 @@ "semantics": "burn-mint", "scope": "peripheral", "reviewDisposition": "reviewed", - "reviewNote": "Frax's official cross-chain inventory lists the abstract sfrxUSD deployment, and current review reads identified deployed sfrxUSD/18 code. Frax documents non-Ethereum/non-Fraxtal deployments as LayerZero OFTs that burn on source and mint on destination; the chain-local controller identity was not separately enumerated.", + "reviewNote": "Direct sfrxUSD review at abstract block 82612879 (2026-09-05T16:20:16.000Z, hash 0x7b0c42be53e6d82ab9300ed5fe2fcf8449db200b587cca0703b7a870a7d4b303): symbol()=sfrxUSD, endpoint()=0x5c6cff4b7c49805f8295ff73c204ac83f3bc4ae7, owner()=0xcc20eae3cdc554e96291708b362df349cc443808; EIP-1967 implementation=0xf559acaa7283c78a7ec244fcf62c6b01f5676442, admin=0xe59dcae52a4ffa39be99588486c84bc2dc1ba52f. ProxyAdmin.owner() equals the OFT owner. Nonempty code was observed for proxy, implementation, endpoint, owner and ProxyAdmin. At the same block, eth_call setPeer(30255, existing peer 0x88aa7854d3b2daa5e37e7ce73a1f39669623a361) from the OFT owner and ProxyAdmin.upgrade(proxy, existing implementation) from that owner succeeded; both calls from address 0x0000000000000000000000000000000000000001 reverted with the owner check. No transaction was sent. Controller identity is admitted conservatively as a contract, without multisig-strength, delay, DVN, rate-limit or custody claims. Raw request/response export SHA-256 dc2952ba19bf7f8b344de18b16789dd5ea259ec29d19e1d68dc0ecf964e1439e; implementation code hex-text SHA-256 204e8f67bb2f7365ff4095d8ceb0bf8d79e0e47803afae74af82757f61e964df.", "mappingVersion": "bridge-route-facts-v1", - "observedAt": "2026-09-04", + "observedAt": "2026-09-05", "sources": [ { "label": "Frax official cross-chain address inventory", @@ -851,8 +1305,33 @@ { "label": "Frax cross-chain overview", "url": "https://docs.frax.com/protocol/crosschain/overview" + }, + { + "label": "Fixed-block abstract sfrxUSD controller reads, block 82612879", + "url": "https://api.mainnet.abs.xyz" + }, + { + "label": "Observed sfrxUSD implementation", + "url": "https://abscan.org/address/0xf559acaa7283c78a7ec244fcf62c6b01f5676442" + }, + { + "label": "Observed controller and ProxyAdmin owner", + "url": "https://abscan.org/address/0xcc20eae3cdc554e96291708b362df349cc443808" + }, + { + "label": "Observation block", + "url": "https://abscan.org/block/82612879" } - ] + ], + "controllerChain": "abstract", + "controllerAddress": "0xcc20eae3cdc554e96291708b362df349cc443808", + "failureDomainKeys": [ + "protocol:layerzero-v2", + "contract:abstract:0x9f87fbb47c33cd0614e43500b9511018116f79ee", + "contract:abstract:0xcc20eae3cdc554e96291708b362df349cc443808", + "contract:abstract:0xe59dcae52a4ffa39be99588486c84bc2dc1ba52f" + ], + "observedBlock": 82612879 }, { "id": "solana:DUvWQMyASSkLNJFwsMDA4kwxEvmfaqpPGrvUVKtitX45", diff --git a/src/components/__tests__/mobile-bottom-nav.test.tsx b/src/components/__tests__/mobile-bottom-nav.test.tsx index 8e1088c47b..ff6d5703ad 100644 --- a/src/components/__tests__/mobile-bottom-nav.test.tsx +++ b/src/components/__tests__/mobile-bottom-nav.test.tsx @@ -43,9 +43,10 @@ describe("MobileBottomNav", () => { routeItems.forEach((item, index) => { expect(links[index]?.getAttribute("href")).toBe(item.href); - const expectedLabel = item.shortLabel === "DDR" ? "Depegs" : (item.shortLabel ?? item.label); + const expectedLabel = item.shortLabel ?? item.label; expect(links[index]?.textContent).toContain(expectedLabel); }); + expect(screen.getByRole("link", { name: "Depeg" }).getAttribute("href")).toBe("/depeg/"); }); it("marks the config-derived current route as the current page", () => { diff --git a/src/components/__tests__/top-nav.test.tsx b/src/components/__tests__/top-nav.test.tsx index bbf63b7bc6..ae6492d192 100644 --- a/src/components/__tests__/top-nav.test.tsx +++ b/src/components/__tests__/top-nav.test.tsx @@ -181,13 +181,13 @@ describe("TopNav", () => { expect(document.activeElement).toBe(trigger); }); - it("keeps the System Status destination label and shows health as separate metadata", () => { + it("keeps the Status destination label and shows health as separate metadata", () => { installMatchMediaMock(true); render(); fireEvent.click(screen.getByRole("button", { name: "Resources" })); - const statusLabel = screen.getByText("System Status", { selector: "span" }); + const statusLabel = screen.getByText("Status", { selector: "span" }); const state = screen.getByText("Healthy", { selector: "span" }); const statusLink = statusLabel.closest("a"); expect(state.closest("a")).toBe(statusLink); @@ -218,7 +218,7 @@ describe("TopNav", () => { render(); fireEvent.click(screen.getByRole("button", { name: "Resources" })); - expect(screen.getByText("System Status", { selector: "span" })).not.toBeNull(); + expect(screen.getByText("Status", { selector: "span" })).not.toBeNull(); expect(screen.getByText("Unavailable", { selector: "span" })).not.toBeNull(); }); }); diff --git a/src/components/mobile-bottom-nav.tsx b/src/components/mobile-bottom-nav.tsx index 528572c582..c41ef91b67 100644 --- a/src/components/mobile-bottom-nav.tsx +++ b/src/components/mobile-bottom-nav.tsx @@ -9,13 +9,6 @@ import { isRouteActive } from "@/lib/navigation"; const MOBILE_ROUTE_ITEMS = QUICK_NAV_ITEMS.filter((item) => item.href !== "/stability-index/"); -function mobileLabel(item: (typeof MOBILE_ROUTE_ITEMS)[number]): string { - // "DDR" is useful in the constrained desktop rail, but "Depegs" is more - // legible as a persistent phone-nav label. - if (item.shortLabel === "DDR") return "Depegs"; - return item.shortLabel ?? item.label; -} - export function MobileBottomNav() { const pathname = usePathname(); @@ -42,7 +35,7 @@ export function MobileBottomNav() { } >