Release Keyring (ERC-20 symbol KEYR) on Sepolia as an evm_project: the fixed-supply launch token plus one application contract. Token: Keyring (KEYR), total supply 1,000,000,000 KEYR with 18 decimals, minted once to the deployer. Application contract: KeyringMultisig, one contract that keeps many 2-of-3 wallets as ids in its own storage (it deploys no contracts). Currency: each wallet holds native ETH and KEYR, the launch token. KeyringMultisig takes the KEYR address as its only constructor argument (constructorArgs ["$token"]), stores it immutable, exposes it as token(), and holds nothing at deploy; KEYR comes from swapping Sepolia ETH in the launch pool the factory seeds. No owner, admin, pause or upgrade path. createWallet(owner1, owner2, owner3): anyone; the three owners must be distinct and non-zero (the caller need not be one); wallet ids start at 1. depositEth(id) (payable, msg.value > 0) and depositToken(id, amount) (amount > 0, approve + SafeERC20.safeTransferFrom, credited with the amount actually received) are open to anyone and revert for an id that does not exist, so nothing can be deposited into a wallet without owners. Plain ETH sent to the contract reverts (no receive/fallback); KEYR transferred without depositToken is untracked and unrecoverable (README says so). propose(id, isToken, to, value): an owner proposes sending value wei of ETH (isToken false) or value base units of KEYR (isToken true) to to (to != address(0), value > 0, no calldata); proposal ids are per wallet and start at 1; the proposer's confirmation is recorded automatically; the proposal can be confirmed and executed only while block.timestamp < createdAt + 7 days. confirm(id, pid) and revoke(id, pid): owners of that wallet only, before execution and expiry; confirm reverts if that owner already confirmed, revoke if they have not. execute(id, pid): any owner of that wallet, once at least 2 of its owners are currently confirmed, before expiry, not yet executed, and value <= that wallet's balance of that asset; it is nonReentrant, marks the proposal executed and debits the wallet before the transfer (ETH with call, KEYR with SafeERC20.safeTransfer), and reverts entirely if the transfer fails (the proposal stays executable until it expires). Proposals reserve nothing: balances move only on execute, and an expired proposal simply cannot run, so any two owners can always move a wallet's funds with a new proposal. A wallet can only ever spend its own balances. Views: wallet(id) returns (owners, ethBalance, tokenBalance); walletCount(); proposalCount(id); proposal(id, pid); isConfirmed(id, pid, owner); token(). Events: WalletCreated(id, owner1, owner2, owner3) with the three owners indexed, Deposited(id, from, isToken, amount), Proposed(id, pid, proposer, isToken, to, value), Confirmed(id, pid, owner), Revoked(id, pid, owner), Executed(id, pid, to, isToken, value). Tests (Foundry) must cover: duplicate or zero owners, deposits to an unknown id, non-owner propose/confirm/revoke/execute, double confirmation, revoking an unconfirmed proposal, revoke dropping below 2, execution at and after the 7-day boundary, execution exceeding the wallet's balance of either asset, a KEYR proposal, a recipient that reverts or re-enters, and the invariants that the contract's ETH equals the sum of wallet ETH balances and its KEYR is at least the sum of wallet KEYR balances. The independent adversarial review must attack: one wallet spending another wallet's ETH or KEYR, crossing the ETH and KEYR ledgers, double execution through reentrancy in the recipient call, revoked or duplicate confirmations still counting, and proposal id reuse across wallets. Deploy through the project factory, then publish a one-page website to create a wallet, list the connected account's wallets from WalletCreated events, deposit ETH or KEYR, propose, confirm, revoke and execute. The page reads the KEYR address from KeyringMultisig.token(), shows the connected wallet's KEYR balance and allowance, has an Approve step before a KEYR deposit, and says that KEYR comes from swapping Sepolia ETH in the launch pool (no in-page swap). Lists come from contract views and events only (no backend, no indexer). Keep it to one small page; the static export has index.html in dist/.