Trust
Verification report
Every check that has been run, what it proves, how to run it again, and what is still missing.
Last full run: 2026-10-09, by node _tools/verify-all.mjs. The result is saved in VERIFICATION.md and site/assets/data/verification.json, and summarised on the proof page.
Results
| Check | Result | What it proves |
|---|---|---|
| Engine and attester network tests | 34 of 34 | Codes, attestations, the vault rules and the HTTP attester protocol behave as documented, including against attackers. |
| Live reads, four platforms | 6 of 6 accounts | The adapters read real GitHub, YouTube, Twitch and Kick pages today. |
| On-chain tests, local Solana runtime | 22 of 22 | Each instruction, every refusal, the exact freshness boundaries and the real Ed25519 precompile. |
| Differential, JS engine against the program | 60 of 60 histories of 46 operations | The two implementations agree on every balance, to the lamport, and on which operations are refused and why. |
| Real pump.fun programs on a mainnet fork | 1 of 1 | pump.fun accepts the vault as sole shareholder, its own distribution pays it, and the streamer is paid. |
What each one runs
- The differential test draws a random history (fees of odd sizes, cranks, claims and rotations to four wallets, vetoes, waits of minutes to days that cross expiries and rotation delays) and runs it on both implementations, comparing the whole state after every operation. A refused transaction is rolled back on both sides. The clock is driven by the runtime's time-travel cheatcode.
- The on-chain tests go through the real Solana runtime (Surfpool, built on LiteSVM), not a mock, including transaction signature checks and the native Ed25519 program.
- The pump.fun test forks mainnet, so the pump and Pump Fees programs are the real deployed ones.
Run it again
npm test # engine + attesters, no network
node _tools/chain-up.mjs # local Solana runtime
node --test tests-chain/vault.test.mjs
SEEDS=60 STEPS=45 node --test tests-chain/differential.test.mjs
node _tools/chain-up.mjs --fork # mainnet fork
SURFNET=http://127.0.0.1:8810 node --test tests-chain/pump-fork.test.mjs
node _tools/verify-all.mjs # all of the above, plus the report
What is still missing
| Gap | Why it matters |
|---|---|
| An independent audit | The tests are the author's. A second reader finds different things. |
| A run on a real validator cluster | The runtime used is a faithful simulation, not a validator. Devnet is the next step. |
| Deployment, then removal of the upgrade authority | Until then the program can be changed. |
| Independent attester operators | The trust assumption of the whole design. |
| Wrapped-SOL and post-graduation fee paths | Only SOL fees from the bonding curve are covered. |