Docs·Start here
Start here
Trust model
What is enforced by a contract, what is asserted by an operator, and the boundaries every figure published here inherits.
Every figure published here inherits the assumptions of the thing it was read from. This page separates the two kinds: facts a contract makes true, and facts a person or a process asserts. The second kind is short, and it is named rather than implied.
What a contract enforces#
| Property | How it is enforced |
|---|---|
| No upgrades | No proxies and no upgradeability anywhere. Per-launch contracts are clones with immutable logic, so a launch cannot be changed after it exists. |
| One venue after graduation | A curve cannot be constructed without a graduation adapter, so there is exactly one pool a launch can graduate into. |
| Liquidity cannot be pulled | LaunchLiquidityLocker can only ever call DECREASE_LIQUIDITY with a liquidity delta of literal 0 — a fee collection. Principal cannot leave the position. |
| A burn lowers supply | Every burn reads totalSupply(), burns, re-reads, and reverts with BurnDidNotReduceSupply if the supply did not move. No figure here is derived from tokens parked at a dead address. |
| A refund takes no fee | A voided market, or a settled market with one side empty, refunds every staker at par with the protocol and marketing legs both zero. |
| Measured, not requested | Stakes credit the measured balance delta and fee forwards send the measured receipt, so a fee-on-transfer token cannot cause the contract to state money it never received. |
| Settlement is permissionless | Anyone may settle a market inside its window. There is no signer, no bond, no challenge period and no arbitrator, because the subject is a view on the same chain. |
| Tiers are computed, never granted | A creator’s tier is derived on every read from their launch history. There is no grantTier and no per-creator lever. |
What an operator asserts#
Three facts reach the chain from outside it. Each is an assertion by a process this platform runs, and a figure derived from one inherits that.
| Assertion | Written by | Consequence if wrong |
|---|---|---|
| A KOL is enrolled and verified | The attestor keeper, from the platform database | Any address could be enrolled and marked verified. Every published KOL rank, eligibility and cap inherits this. |
| A KOL’s lifetime fees earned | The KOL keeper, via setFeesEarned | A rank could be inflated. The chain’s own record of what was actually paid is the sum of Allocated logs, which this does not affect. |
| A pool sample’s USD price | A Chainlink ETH/USD feed, read at poke time | A USD-denominated valuation would be wrong. A sample older than 30 hours is recorded unpriced rather than priced badly, and an unpriced sample inside the window makes the seven-day floor uncovered and therefore unpublishable. |
A holder count is not sybil-proof#
HolderCensus counts an address when its balance is at least a floor share of supply and it is not excluded, re-reading balances during the sweep so a submitted address that has since sold does not count. That makes faking a distribution cost real supply. It does not make the count sybil-proof, and no on-chain measure can.
The prediction market’s currency listing does not rely on holders alone for that reason: a project token is listed against three bars at once — holders, covered supply and net raised — because each covers the others’ blind spot. Holders can be faked with enough addresses; covered supply cannot be faked with dust; net raise is ETH that actually moved. Per-currency caps and a kill switch bound what a successful fake is worth.
The settlement trade-off#
A contract cannot wake itself at a deadline. Settlement is permissionless within a window — from the deadline until deadline + settlementWindow — and the value read is the value at the settling call, not at the deadline. If the window closes unsettled the market voids: everyone refunded at par, no fee.
Audit#
The contracts were audited by Claude Fable 5 — a full assessment dated 15 August 2026 across the contracts, the prediction market, the frontend, the API, the database and performance. Every Critical and High finding is fixed with an executable exploit and a regression test, and the remainder are published with their status stated, including the ones still open. The report is served at /legal/security.
An audit is evidence that a set of attacks was attempted and defeated. It is not proof that no others exist, and a passing test suite says the failures it models do not happen rather than that there are none.