Docs·Start here

Start here

Trust model

What is enforced by a contract, what is asserted by an operator, and the boundaries every figure published here inherits.

Version
1.0
Updated
2026-08-29
Source
The Hood — README · Metric definitions v1.2

Every figure published here inherits the assumptions of the thing it was read from. This page separates the two kinds: facts a contract makes true, and facts a person or a process asserts. The second kind is short, and it is named rather than implied.

What a contract enforces#

Properties enforced by deployed, immutable code
PropertyHow it is enforced
No upgradesNo proxies and no upgradeability anywhere. Per-launch contracts are clones with immutable logic, so a launch cannot be changed after it exists.
One venue after graduationA curve cannot be constructed without a graduation adapter, so there is exactly one pool a launch can graduate into.
Liquidity cannot be pulledLaunchLiquidityLocker can only ever call DECREASE_LIQUIDITY with a liquidity delta of literal 0 — a fee collection. Principal cannot leave the position.
A burn lowers supplyEvery burn reads totalSupply(), burns, re-reads, and reverts with BurnDidNotReduceSupply if the supply did not move. No figure here is derived from tokens parked at a dead address.
A refund takes no feeA voided market, or a settled market with one side empty, refunds every staker at par with the protocol and marketing legs both zero.
Measured, not requestedStakes credit the measured balance delta and fee forwards send the measured receipt, so a fee-on-transfer token cannot cause the contract to state money it never received.
Settlement is permissionlessAnyone may settle a market inside its window. There is no signer, no bond, no challenge period and no arbitrator, because the subject is a view on the same chain.
Tiers are computed, never grantedA creator’s tier is derived on every read from their launch history. There is no grantTier and no per-creator lever.

What an operator asserts#

Three facts reach the chain from outside it. Each is an assertion by a process this platform runs, and a figure derived from one inherits that.

Assertions, and what a compromise of each would achieve
AssertionWritten byConsequence if wrong
A KOL is enrolled and verifiedThe attestor keeper, from the platform databaseAny address could be enrolled and marked verified. Every published KOL rank, eligibility and cap inherits this.
A KOL’s lifetime fees earnedThe KOL keeper, via setFeesEarnedA rank could be inflated. The chain’s own record of what was actually paid is the sum of Allocated logs, which this does not affect.
A pool sample’s USD priceA Chainlink ETH/USD feed, read at poke timeA USD-denominated valuation would be wrong. A sample older than 30 hours is recorded unpriced rather than priced badly, and an unpriced sample inside the window makes the seven-day floor uncovered and therefore unpublishable.

A holder count is not sybil-proof#

HolderCensus counts an address when its balance is at least a floor share of supply and it is not excluded, re-reading balances during the sweep so a submitted address that has since sold does not count. That makes faking a distribution cost real supply. It does not make the count sybil-proof, and no on-chain measure can.

The prediction market’s currency listing does not rely on holders alone for that reason: a project token is listed against three bars at once — holders, covered supply and net raised — because each covers the others’ blind spot. Holders can be faked with enough addresses; covered supply cannot be faked with dust; net raise is ETH that actually moved. Per-currency caps and a kill switch bound what a successful fake is worth.

The settlement trade-off#

A contract cannot wake itself at a deadline. Settlement is permissionless within a window — from the deadline until deadline + settlementWindow — and the value read is the value at the settling call, not at the deadline. If the window closes unsettled the market voids: everyone refunded at par, no fee.

Audit#

The contracts were audited by Claude Fable 5 — a full assessment dated 15 August 2026 across the contracts, the prediction market, the frontend, the API, the database and performance. Every Critical and High finding is fixed with an executable exploit and a regression test, and the remainder are published with their status stated, including the ones still open. The report is served at /legal/security.

An audit is evidence that a set of attacks was attempted and defeated. It is not proof that no others exist, and a passing test suite says the failures it models do not happen rather than that there are none.