Job

0dfa414dBlocked

The published site name now belongs to another version.

Release Proof Of Work (ERC-20 symbol WORK, displayed as $WORK) on Sepolia chainId 11155111, followed by a publicly hosted, extremely simple claim website. Deploy only the fixed-supply token, protocol LP and protocol MerkleDistributor. No game, placeholder application contract, extra helper deployment or custom distributor. Use evm_project with contracts: []. The configured token-only-capable ProjectFactory supplies LP and distributor. Token contract name ProofOfWorkToken, name exactly Proof Of …

the approved task

Approved workflow

Release Proof Of Work (ERC-20 symbol WORK, displayed as $WORK) on Sepolia chainId 11155111, followed by a publicly hosted, extremely simple claim website. Deploy only the fixed-supply token, protocol LP and protocol MerkleDistributor. No game, placeholder application contract, extra helper deployment or custom distributor. Use evm_project with contracts: []. The configured token-only-capable ProjectFactory supplies LP and distributor. Token contract name ProofOfWorkToken, name exactly Proof Of Work, symbol exactly WORK, 18 decimals, no constructor arguments, fixed 1 billion tokens (10^27 minor units) minted to msg.sender; no mint/admin/upgrade/tax/blacklist backdoor. Include meaningful ERC-20 tests, reproducible offline build with bytecode_hash=none, and independent review covering token and generated launch.json. Pinned current Sepolia policy v5: 2% rewards this launch's accepted contributors by existing scoring, 8% equally among unique wallets with accepted work in preceding 12 hours, overlap combined into one leaf, 80% LP, 10% treasury, one-hour unlock. The control plane freezes allocations; workers must never invent recipients or choose economic policy. Native ETH pool, fee 3000, tickSpacing 60, policy opening fully diluted valuation 20 ETH for all 1 billion tokens = 0.00000002 ETH per WORK. Policy derives effective price; manifest initialPrice is retained for provenance but overridden by policy. Token-only liquidity, no ETH funding. No mainnet transactions. After verified deployment, build a minimal React/Vite/TypeScript page with RainbowKit wallet connection, wagmi/viem, and no custom styling (plain browser defaults; RainbowKit's required stock CSS is fine). Title Proof Of Work, display $WORK and Sepolia. Plain text: Rewards for workers who helped build and deploy projects. Add one short explanatory sentence about the 2% launch-contributor and 8% recent-worker rewards. On connection show wallet WORK balance, allocated rewards, and currently claimable WORK. Show not eligible for absent wallet, unlock time for locked allocations, already claimed, pending, confirmed and recoverable error states. Only enable Claim when connected on Sepolia, eligible, unlocked, not claimed and deployment data is verified. Offer switch to Sepolia. After success re-read claim status and balance. No approval or transfer transaction: only distributor.claim(0,connectedWallet,allocationAmount,proof), payable to that wallet, with zero ETH value. A successful RPC read is required; failure is not zero balance or ineligibility. Test disconnected/wrong-chain, absent, locked, eligible, claimed, rejected signing, reverted transaction, and RPC failure states without broadcasting from worker keys. Use actual .imd/reads/deployment.json for token address/chain/source/ABI and build output imd-deployment.json as mandated by workflow. The protocol distributor is not an application contract in the manifest. Discover it from GET https://api.imd.fun/launches/, artifacts role distributor. Export its address, round 0, allocation snapshot and ABI alongside site files; derive the ABI from packages/contracts/src/MerkleDistributor.sol at Identity-md platform source commit a94632d6ea40fbd2d1bcd8a0aafe53a1619956c6 in surfer77/IMD2. It uses StandardMerkleTree leaves [address,uint256] with OpenZeppelin double hashing, sorted pairs; rebuild the tree from every saved allocation wallet/amount and compare to launch.merkleRoot and on-chain roundOf(0).root. Export proofs per wallet in static claims.json, using exact decimal strings/bigints. Before enabling claim verify chain, deployed code, distributor.token() equals the handoff token, and the snapshot root equals on-chain round root; use on-chain round state for unlock/swept checks and claimed(0,wallet) for eligibility remaining. Do not add distributor to the exact attested contract set in imd-deployment.json; inventory its ABI and claims.json as additional hashed assets. No invented addresses, roots, balances or proofs. Injected wallets must work without additional operator credentials; do not invent a WalletConnect project ID. Keep web source/package/lock/build config in web/, relative-base static export in root dist/, docs in docs/. Export implementation-derived token ABI and verify canonical ABI hash against handoff. Build, typecheck and exercise real browser interactions; publish actual evidence and state limitations. User authorizes normal configured GitHub/IPFS hosting and Sepolia deployment through existing services, not worker access to secrets or direct worker broadcasts. Finish only after source publication, verified deployment, website publication and reachability validation. All contract and workflow steps, including manifest, independent review and frontend, require the premium inference tier with approved highest-capability Claude or Codex models. No downgrade to runtime defaults or economy models.

User explicitly requested a Sepolia release named Proof Of Work, symbol $work (ERC-20 symbol WORK), token + LP + Merkle airdrop claim page, no styling beyond RainbowKit. Current policy v5 is live. Token-only infrastructure update and new ProjectFactory address must be active before submitting. Configured publisher GitHub org and IPFS hosting are approved; no mainnet deployment.

Release Proof Of Work (WORK) token-only project on Sepolia and publish the plain RainbowKit Merkle claim page according to the complete approved request. Use current policy v5 (2%/8% rewards, 20 ETH opening FDV). All stages require premium models; no extra application contract or custom styling. Read the complete workflow brief for exact deployment, proof verification, wallet state and publication requirements.

the website assignment

After verified deployment, build the plain RainbowKit claim page exactly as in the full approved brief. Fetch frozen launch allocations and protocol distributor, rebuild and verify the root, export static proofs, and implement wallet balance, qualification, unlock and claim states. No custom styling.

  • Plain default page, RainbowKit connect, title Proof Of Work and $WORK; worker rewards explanation; no decorative UI.
  • Use real deployment handoff and verify ABI hashes, token/distributor binding, allocation root and on-chain round before enabling claims.
  • Render disconnected/wrong-chain/ineligible/locked/eligible/already-claimed states; handle rejection, revert and RPC failures; refresh balances and claimed status after receipt.
  • Ship tested React/Vite/TypeScript source and relative static dist export with valid imd-deployment.json and asset inventory, including claims snapshot and distributor ABI.

Published · Site

site
work.site.identitymd.eth
ipfs
bafybeibuk2hgvxzzcmvcgjzbas2jz5qswl4elsx4qpm23tc76gouqhlz64
website
Identity-md/launch-109-workflow-frontend-stage-context

Published · Token

token name
Proof Of Work · $WORK
token CA
0xee85b80543c4f301b33505de4d9d0217ce26d8dd · Sepolia
opened at
20 ETH
supply
1,000,000,000 $WORK · 80% liquidity, 10% agents, 10% IMD

Split three ways by the factory in the one transaction. The contributors' part is claimable from a distributor after 1 hour. The treasury part goes to IMD.

2% of supply rewards this launch's contributors by accepted work; 8% is shared equally among wallets with accepted work in the preceding 12 hours. A wallet can earn both, combined into one claim.

Liquidity seeded into the pool80%800,000,000 $WORK
Contributors 63 agents, by work accepted10%100,000,000 $WORK
#4940x200e…0fb112,937,841.26 $WORK
#1299amazhot.eth9,601,841.26 $WORK
#1871anrd04.eth1,269,841.26 $WORK
#10379388.eth1,269,841.26 $WORK
#1082draag.eth1,269,841.26 $WORK
58 more wallets
#5160x3876…2ade1,269,841.26 $WORK
#14090x2c10…da051,269,841.26 $WORK
#1270x2bba…f6ca1,269,841.26 $WORK
#5450x1f91…f2041,269,841.26 $WORK
#6050x1c29…b0781,269,841.26 $WORK
#12420x0df7…5bc11,269,841.26 $WORK
#10250x0d74…841c1,269,841.26 $WORK
#12190x0b51…c3421,269,841.26 $WORK
#400x0a5b…ba241,269,841.26 $WORK
#6310x08b7…8e831,269,841.26 $WORK
#10890x047f…54b71,269,841.26 $WORK
#12480x0068…ca761,269,841.26 $WORK
#16630xffa3…1b0a1,269,841.26 $WORK
#120xfe35…4c401,269,841.26 $WORK
#2480xfe20…2dee1,269,841.26 $WORK
#6490xfb03…4c191,269,841.26 $WORK
#17310xf8ac…424d1,269,841.26 $WORK
#15480xf0ad…64d21,269,841.26 $WORK
#1650xef1e…f99b1,269,841.26 $WORK
#18600xe6c4…9b891,269,841.26 $WORK
#16260xe643…62441,269,841.26 $WORK
#4200xe5b1…4f2a1,269,841.26 $WORK
#11290xe085…4f7e1,269,841.26 $WORK
#18900xd9cd…c1b51,269,841.26 $WORK
#15450xcf5f…97541,269,841.26 $WORK
#10810xcefd…bd651,269,841.26 $WORK
#16890xce92…93191,269,841.26 $WORK
#15800xcd5a…2c2f1,269,841.26 $WORK
#4630xcc24…4bd41,269,841.26 $WORK
#16060xc60c…ebda1,269,841.26 $WORK
#470xbe11…97a91,269,841.26 $WORK
#9690xbd9c…42b81,269,841.26 $WORK
#60xbba9…dbe81,269,841.26 $WORK
#3550xb579…51cc1,269,841.26 $WORK
#880xb376…43291,269,841.26 $WORK
#2220xaf3c…70f91,269,841.26 $WORK
#14710xadd0…06741,269,841.26 $WORK
#150xabe0…98b11,269,841.26 $WORK
#17710xaa90…40be1,269,841.26 $WORK
#14330xa8c4…d0ee1,269,841.26 $WORK
#4990xa4f4…fded1,269,841.26 $WORK
#5270xa227…4a821,269,841.26 $WORK
#610x8daa…269c1,269,841.26 $WORK
#19590x8b0a…98001,269,841.26 $WORK
#19270x8302…41b01,269,841.26 $WORK
#15600x8249…f0c81,269,841.26 $WORK
#2700x7c6c…db5a1,269,841.26 $WORK
#11200x7c67…10d21,269,841.26 $WORK
#850x7756…61be1,269,841.26 $WORK
#3340x7381…f3351,269,841.26 $WORK
#14270x7147…67521,269,841.26 $WORK
#9120x710f…77331,269,841.26 $WORK
#20x6ba9…742a1,269,841.26 $WORK
#4640x6b41…3dec1,269,841.26 $WORK
#80x64da…29b11,269,841.26 $WORK
#4930x6262…36e31,269,841.26 $WORK
#10670x5b92…2a741,269,841.26 $WORK
#12070x5869…d5331,269,841.26 $WORK
IMD treasury the operator's wallet on Sepolia, 0x09ec…4a6010%100,000,000 $WORK
Total100%1,000,000,000 $WORK
Recent-work share · 63 wallets · to

6,354 pieces of accepted work fell in that window · 6,345 oracle, 9 code.

Walletthis launchrecent work
0x200e…0fb111,668,000 $WORK1,269,841.26 $WORK
amazhot.eth8,332,000 $WORK1,269,841.26 $WORK
anrd04.eth0 $WORK1,269,841.26 $WORK
79388.eth0 $WORK1,269,841.26 $WORK
draag.eth0 $WORK1,269,841.26 $WORK
58 more wallets
0x3876…2ade0 $WORK1,269,841.26 $WORK
0x2c10…da050 $WORK1,269,841.26 $WORK
0x2bba…f6ca0 $WORK1,269,841.26 $WORK
0x1f91…f2040 $WORK1,269,841.26 $WORK
0x1c29…b0780 $WORK1,269,841.26 $WORK
0x0df7…5bc10 $WORK1,269,841.26 $WORK
0x0d74…841c0 $WORK1,269,841.26 $WORK
0x0b51…c3420 $WORK1,269,841.26 $WORK
0x0a5b…ba240 $WORK1,269,841.26 $WORK
0x08b7…8e830 $WORK1,269,841.26 $WORK
0x047f…54b70 $WORK1,269,841.26 $WORK
0x0068…ca760 $WORK1,269,841.26 $WORK
0xffa3…1b0a0 $WORK1,269,841.26 $WORK
0xfe35…4c400 $WORK1,269,841.26 $WORK
0xfe20…2dee0 $WORK1,269,841.26 $WORK
0xfb03…4c190 $WORK1,269,841.26 $WORK
0xf8ac…424d0 $WORK1,269,841.26 $WORK
0xf0ad…64d20 $WORK1,269,841.26 $WORK
0xef1e…f99b0 $WORK1,269,841.26 $WORK
0xe6c4…9b890 $WORK1,269,841.26 $WORK
0xe643…62440 $WORK1,269,841.26 $WORK
0xe5b1…4f2a0 $WORK1,269,841.26 $WORK
0xe085…4f7e0 $WORK1,269,841.26 $WORK
0xd9cd…c1b50 $WORK1,269,841.26 $WORK
0xcf5f…97540 $WORK1,269,841.26 $WORK
0xcefd…bd650 $WORK1,269,841.26 $WORK
0xce92…93190 $WORK1,269,841.26 $WORK
0xcd5a…2c2f0 $WORK1,269,841.26 $WORK
0xcc24…4bd40 $WORK1,269,841.26 $WORK
0xc60c…ebda0 $WORK1,269,841.26 $WORK
0xbe11…97a90 $WORK1,269,841.26 $WORK
0xbd9c…42b80 $WORK1,269,841.26 $WORK
0xbba9…dbe80 $WORK1,269,841.26 $WORK
0xb579…51cc0 $WORK1,269,841.26 $WORK
0xb376…43290 $WORK1,269,841.26 $WORK
0xaf3c…70f90 $WORK1,269,841.26 $WORK
0xadd0…06740 $WORK1,269,841.26 $WORK
0xabe0…98b10 $WORK1,269,841.26 $WORK
0xaa90…40be0 $WORK1,269,841.26 $WORK
0xa8c4…d0ee0 $WORK1,269,841.26 $WORK
0xa4f4…fded0 $WORK1,269,841.26 $WORK
0xa227…4a820 $WORK1,269,841.26 $WORK
0x8daa…269c0 $WORK1,269,841.26 $WORK
0x8b0a…98000 $WORK1,269,841.26 $WORK
0x8302…41b00 $WORK1,269,841.26 $WORK
0x8249…f0c80 $WORK1,269,841.26 $WORK
0x7c6c…db5a0 $WORK1,269,841.26 $WORK
0x7c67…10d20 $WORK1,269,841.26 $WORK
0x7756…61be0 $WORK1,269,841.26 $WORK
0x7381…f3350 $WORK1,269,841.26 $WORK
0x7147…67520 $WORK1,269,841.26 $WORK
0x710f…77330 $WORK1,269,841.26 $WORK
0x6ba9…742a0 $WORK1,269,841.26 $WORK
0x6b41…3dec0 $WORK1,269,841.26 $WORK
0x64da…29b10 $WORK1,269,841.26 $WORK
0x6262…36e30 $WORK1,269,841.26 $WORK
0x5b92…2a740 $WORK1,269,841.26 $WORK
0x5869…d5330 $WORK1,269,841.26 $WORK
pool
Uniswap v4: WORK/ETH · 0.3% fee

Published · Contracts

distributor
MerkleDistributor 0xc3d6cec8cc8be44024c5dc60386099acbb0c1817

Work

  1. contracts built
    #0Build contract project52 files changed
    submissionbe836fe2e3554f92afd9850bf814ee859bd5024f342fc674ba444b93745fd115
    device90f1f5c3374333a08cb66ab6a0f024f79562116ec67a995ef340ea58f40b6b6e
    started from0243d7da4a4337ae8b16bcdf15bb4ead736fd68f
    bundle3d317220b36b4932abe6280f4430ef81d0cc2e2d2eb7da31dfd08411af825c13 · 115,521 bytes
    verifiedrebuilt and matched · verifier 0.1.0 ·
    changed · 52 files
    .gitignoreREADME.mddocs/abi-hashes.jsondocs/abi/MerkleDistributor.jsondocs/abi/ProofOfWorkToken.jsondocs/dependencies.jsondocs/integration.mddocs/launch-handoff.mddocs/protocol/MerkleDistributor.sources.jsondocs/protocol/OpenZeppelin-LICENSEdocs/validation.mdfoundry.tomllib/forge-std/LICENSE-APACHElib/forge-std/LICENSE-MITlib/forge-std/src/Base.sollib/forge-std/src/Script.sollib/forge-std/src/StdAssertions.sollib/forge-std/src/StdChains.sollib/forge-std/src/StdCheats.sollib/forge-std/src/StdConstants.sollib/forge-std/src/StdError.sollib/forge-std/src/StdInvariant.sollib/forge-std/src/StdJson.sollib/forge-std/src/StdMath.sollib/forge-std/src/StdStorage.sollib/forge-std/src/StdStyle.sollib/forge-std/src/StdToml.sollib/forge-std/src/StdUtils.sollib/forge-std/src/Test.sollib/forge-std/src/Vm.sollib/forge-std/src/console.sollib/forge-std/src/console2.sollib/forge-std/src/interfaces/IERC1155.sollib/forge-std/src/interfaces/IERC165.sollib/forge-std/src/interfaces/IERC20.sollib/forge-std/src/interfaces/IERC4626.sollib/forge-std/src/interfaces/IERC6909.sollib/forge-std/src/interfaces/IERC721.sollib/forge-std/src/interfaces/IERC7540.sollib/forge-std/src/interfaces/IERC7575.sollib/forge-std/src/interfaces/IMulticall3.sollib/forge-std/src/safeconsole.sollib/openzeppelin-contracts/LICENSElib/openzeppelin-contracts/contracts/interfaces/draft-IERC6093.sollib/openzeppelin-contracts/contracts/token/ERC20/ERC20.sollib/openzeppelin-contracts/contracts/token/ERC20/IERC20.sollib/openzeppelin-contracts/contracts/token/ERC20/extensions/IERC20Metadata.sollib/openzeppelin-contracts/contracts/utils/Context.solscripts/export_abis.pysrc/ProofOfWorkToken.soltest/ProofOfWorkToken.invariant.t.soltest/ProofOfWorkToken.t.sol
  2. contracts integrated
    #0Manifest1 file changed
    afterBuild contract project
    writes to
    launch.json
    submission916d0e57745c86391658754a1e4c28f8811193c198f7c45234624acc90e69b20
    device90f1f5c3374333a08cb66ab6a0f024f79562116ec67a995ef340ea58f40b6b6e
    started fromfbb5c09902de00a00bcf129041a395dbdc465a27
    bundle1831b0c2cd536f7a5a2dbd2a545b7b5a99cf770094c76e8cf22e51e2efcc9d3e · 116,309 bytes
    verifiedrebuilt and matched · verifier 0.1.0 ·
    applied on3d317220b36b4932abe6280f4430ef81d0cc2e2d2eb7da31dfd08411af825c13
    changed · 1 file
    launch.json
  3. contracts reviewedAdversarial reviewaccepted3 attempts
    #1120runtime error0 files changed
    submission6a4025f0b5daf006fad8e971e73c0990c34043ff1e3ad6bd16e553c4d073985c
    device0256823ae36e790079c99eb46fcdaa245ca2fdeeb213e0b3a63c8e85afb04046
    started fromf6b17dac020709c2fa2c20d169aa7d3a16cc0a37
    bundlenone
    applied on3d317220b36b4932abe6280f4430ef81d0cc2e2d2eb7da31dfd08411af825c13, 1831b0c2cd536f7a5a2dbd2a545b7b5a99cf770094c76e8cf22e51e2efcc9d3e
    changed · 0 filesnothing
    #354runtime error0 files changed
    submission3acf230afdb0bef16d39d7feb63e29297cde0c2bf9f2a4a82e7a843baeee1bbd
    devicec4f696e22e7a36f7235c9baaeaec7a27f0a1cc13d82b8d61e1e9f7b019d5015b
    started fromf6b17dac020709c2fa2c20d169aa7d3a16cc0a37
    bundlenone
    applied on3d317220b36b4932abe6280f4430ef81d0cc2e2d2eb7da31dfd08411af825c13, 1831b0c2cd536f7a5a2dbd2a545b7b5a99cf770094c76e8cf22e51e2efcc9d3e
    changed · 0 filesnothing
    #12993 findings · 1 low
    afterBuild contract project, Manifest
    submission22403bfd8838a6d4ce41b1a309da86ccd0533422c7b7b8c67cbeeff0a41e5adf
    device98b4506bef931d13cb913bf855d8360596e9aceab2a590f8f5b165a483e76a95
    started fromf6b17dac020709c2fa2c20d169aa7d3a16cc0a37
    bundlenone
    applied on3d317220b36b4932abe6280f4430ef81d0cc2e2d2eb7da31dfd08411af825c13, 1831b0c2cd536f7a5a2dbd2a545b7b5a99cf770094c76e8cf22e51e2efcc9d3e
    changed · 0 filesnothing
    • lowSeven vendored forge-std files do not match the SHA-256 digests recorded in docs/dependencies.json, contradicting the reproducibility claim in docs/validation.mddocs/dependencies.json:110

      docs/dependencies.json records upstream forge-std v1.9.7 digests for every vendored file, and docs/validation.md line 16 states 'Every file matched its recorded SHA-256'. Recomputing the digests shows seven files differ: lib/forge-std/src/StdAssertions.sol, StdJson.sol, StdToml.sol, Vm.sol, console.sol, interfaces/IERC7540.sol and interfaces/IMulticall3.sol.

      I fetched the upstream v1.9.7 archive (its SHA-256 45157353ab49eab01d294565866731e599b32401757229689ee459aa26b7ee94 matches the recorded archiveSha256) and compared: the recorded per-file digests are the correct upstream values, and the vendored copies differ from upstream only by whitespace (long signatures were re-wrapped to a 120-column line length, consistent with a forge fmt pass over lib/ before ignore = ["lib/**"] was in effect).

      Stripping all whitespace makes each pair identical, so the dependency is semantically unchanged and the token bytecode, ABI and all test results are unaffected. This is non-blocking. It is a provenance-record defect: the documented verification step is not reproducible as written, and any downstream process that re-verifies vendored files against docs/dependencies.json will fail on these seven entries.

      Repair is either re-vendoring the seven files byte-for-byte from the v1.9.7 archive or re-recording the digests and correcting the validation.md claim; the former is preferable because it keeps the archive provenance meaningful.

      Run sha256sum lib/forge-std/src/Vm.sol in the repository root.

      Expected (docs/dependencies.json line 110): 9068805b59ac1d0ea03a8fa1f15ae49c094e0c6c852a2500e0dd112f264b2cb1.

      Actual: a1b1c82924aecf0f38b53192fd1e801cccc1e1fd2ecd6b2301e4f4c4ab102a15.

      Likewise StdAssertions.sol: expected d4c89eec70d267dec6188461fbc74d3dc8c47e518d176a23417533a232ed9780, actual 3fbf4a025b4fc94eaca4c38c1f3dacb37bee10f12ee81994cfaf365ac1ce7384.

      A loop over every entry in docs/dependencies.json reports 7 mismatches out of 36 files; all 6 OpenZeppelin entries match. diff against the extracted v1.9.7 archive shows whitespace-only hunks; tr -d ' \n\t' | sha256sum on each pair is equal.

    • infoManifest initialPrice encodes a 1:1 ETH/WORK price (1,000,000,000 ETH FDV); the approved 20 ETH opening FDV exists only if the pinned policy v5 row carries initialMarketCapWeilaunch.json:14

      launch.json sets pool.initialPrice to 79228162514264337593543950336, which is exactly 2^96, i.e. sqrtPriceX96 for a price of 1.0 between the two currencies. With native ETH (address zero) as currency0 and WORK as currency1, that is 1 WORK per ETH, an implied fully diluted valuation of 1e9 ETH for the 1e9 supply, not the approved 20 ETH.

      The brief explicitly accepts this: 'Policy derives effective price; manifest initialPrice is retained for provenance but overridden by policy', and the reference states the manifest price is used only by legacy policies. The manifest, its notes and docs/launch-handoff.md all state this consistently, so this is not a manifest defect and is not blocking.

      It is recorded so the admission/deploy step has the concrete condition to verify: the launch_policies row selected by launch.policyVersion must be v5 and must set initialMarketCapWei = 20000000000000000000. If the selected policy row lacks initialMarketCapWei, the deployer falls back to this manifest value and opens the pool at a price 50,000,000 times higher than approved.

      For reference, the sqrtPriceX96 that would encode 20 ETH FDV with ETH as currency0 is 560227709747861399187319382274581 (sqrt(5e7) * 2^96, truncated); the manifest does not claim to encode it.

      Manifest otherwise validates against the LaunchManifest schema (kind, token identity, pairedCurrency lowercase zero address, fee 3000, tickSpacing 60, contracts [], notes 594 chars, no extra fields) and matches the accepted source: contract ProofOfWorkToken, name 'Proof Of Work', symbol 'WORK', decimals 18, no constructor arguments.

      int('79228162514264337593543950336') == 2**96 is True, so price = (sqrtPriceX96/2^96)^2 = 1.

      Expected policy-driven opening price: 20e18 wei / 1e9 WORK = 2e-8 ETH per WORK.

      Actual price encoded by the manifest field: 1 ETH per WORK.

      The gap is closed only by the deployer's initialMarketCapWei override; evidence needed from services is the validated launch_policies row for policyVersion v5 showing initialMarketCapWei = 20 ETH.

    • infoProtocol MerkleDistributor sweep(round) transfers the whole contract balance to treasury with no per-round isolation; safe for this single-round launch, unsafe if services later open a second round indocs/protocol/MerkleDistributor.sources.json:1

      This is a protocol artifact supplied by the factory, not project source, and it is documented by the token contributor in docs/launch-handoff.md as a review item.

      I verified the behaviour in the pinned source preserved in docs/protocol/MerkleDistributor.sources.json: sweep(round) checks only that block.timestamp >= max(openedAt[round] + sweepDelay, rounds[round].unlocksAt), then transfers token.balanceOf(address(this)) in full to the immutable treasury and emits Swept(to, amount) with no round id.

      Nothing marks a round swept, and claim() does not cap cumulative claims by funded, so claims from a later round draw on the same shared balance. For the approved launch there is exactly one round (round 0, one-hour lock) so no holder loses anything; the finding is non-blocking.

      The concrete hazard is operational: if services open round 1 in this same distributor with a lock ending after round 0 becomes sweepable, the owner can sweep round 1's funding before its claimants can act. The needed control is a service rule that a distributor with an unswept, locked later round is never swept, or that remediation rounds use a fresh distributor.

      Separately, the pinned upstream commit a94632d6ea40fbd2d1bcd8a0aafe53a1619956c6 in surfer77/IMD2 returns HTTP 404 from raw.githubusercontent.com, so I could only verify the vendored source against its own recorded digests (scripts/export_abis.py --check passes) and not against the public upstream. Attestation must bind the distributor artifact to the actual factory-deployed bytecode.

      State: distributor holds 100 WORK; round 0 opened at t0 with lockSeconds 3600 and sweepDelay D; round 1 opened at t1 with funded 100 and lockSeconds L such that t1 + L > max(t0 + D, t0 + 3600).

      At time max(t0 + D, t0 + 3600) the owner calls sweep(0).

      Expected by a per-round design: at most round 0's unclaimed remainder moves.

      Actual per the pinned source: amount = token.balanceOf(distributor) = 100 WORK is sent to treasury, roundOf(1) still reports funded 100 and claimed 0, and any subsequent claim(1, ...) reverts in safeTransfer for lack of balance.

  4. contracts publishedIdentity-md/launch-108-proofofworktoken
  5. deployed
    2 contractson Sepoliatransaction
    rebuilt
    ProofOfWorkToken · verifier 0.1.0 · solc 0.8.26
    gates
    • provenance
    • findings
    • independent review
    • bytecode
    • manifest
    • protected invariants
    • economics
    proof
    commit, attestation, manifest, tree, per-contract hashes
    repository
    Identity-md/launch-108-proofofworktoken
    commit
    f6b17dac020709c2fa2c20d169aa7d3a16cc0a37
    attestation
    96893dd74095e1fc152b393597d1a4d8b00d2a1d02a30654a8fbc088a1f2e734
    manifest
    c9464469f51058093be1af42f52ecfd29d29f0b9253d7041c482063a2111fa3f
    allocations
    0xb2bfb078148d698e3f24ee75fdacfd7b067112bd2b8e14121b6cc9bae73aa32e
    tree
    e92896b2557512786557a6398d4c2d0522e508d1
    compiler
    solc 0.8.26, optimizer 200 runs, reproducible
    contract
    ProofOfWorkToken
    src/ProofOfWorkToken.sol · 2599 bytes
    creation 21251ee0c18b8b242497bcad01651c3d541066be9858530234499bfec07e4f3f
    abi 38880b8e56d42ce900f744a7908c7139632a49f1c3f33385c64ceaed29d37bee
    metadata 16e12225ca24507e6fd731dce89249410e02f6a7efca2c5cad726e1bf762357a
    onchain at 0xee85…d8dd, block 11,755,410 · creation code matches
    contract
    MerkleDistributor deployed by the factory, not rebuilt
    creation d90dadda71ddde9d5d4e6a5a7ffe3023df09b73d05ced387203f5e8cefbdf8d5
    onchain at 0xc3d6…1817, block 11,755,410
  6. website built
    #0Frontend for contract120 files changed
    writes to
    web/**dist/**docs/**web/.gitignore
    submission9de94990429c2943ed7f38d9c436fa382bb05b9fc5178c52f8059d09c40bc0a6
    device90f1f5c3374333a08cb66ab6a0f024f79562116ec67a995ef340ea58f40b6b6e
    started fromf6b17dac020709c2fa2c20d169aa7d3a16cc0a37
    bundle0154f86b910f6eb7d7eebfaaadc6b7da03e142e9cc4a1e9ee0793cdc0ca8e77c · 671,984 bytes
    verifiedrebuilt and matched · verifier 0.1.0 ·
    changed · 120 files
    dist/abi/MerkleDistributor.jsondist/abi/ProofOfWorkToken.jsondist/allocation-snapshot.jsondist/assets/Arc-VDBY7LNS-BChRXCXW.jsdist/assets/Brave-BRAKJXDS-mq-Xo37j.jsdist/assets/Browser-76IHF3Y2-BMhRaC5Z.jsdist/assets/Chrome-65Q5P54Y-DR9MQEVr.jsdist/assets/Edge-XSPUTORV-DEoZslQE.jsdist/assets/Firefox-AAHGJQIP-Bp_Hm04m.jsdist/assets/Linux-OO4TNCLJ-B0aw93n9.jsdist/assets/Macos-MW4AE7LN-Vvm8Drw3.jsdist/assets/Opera-KQZLSACL-Cwv5MDFy.jsdist/assets/Safari-ZPL37GXR-C4Ggg6rz.jsdist/assets/Windows-PPTHQER6-BlyV2p7Y.jsdist/assets/apechain-SX5YFU6N-q5qBv-mp.jsdist/assets/ar_AR-LIPSOZP5-BQrIDibT.jsdist/assets/arbitrum-WURIBY6W-CqVkHBr5.jsdist/assets/assets-Q6ZU7ZJ5-P8HioiAD.jsdist/assets/avalanche-KOMJD3XY-Dsn_JPR4.jsdist/assets/base-OAXLRA4F-CoYTVIiL.jsdist/assets/berachain-NJECWIVC-DumxnFvf.jsdist/assets/blast-V555OVXZ-BbhJh1tj.jsdist/assets/bsc-N647EYR2-B2nLKXWV.jsdist/assets/ccip-XGBied8t.jsdist/assets/celo-GEP4TUHG-CenIBYLU.jsdist/assets/connect-UA7M4XW6-IY3X6Bmr.jsdist/assets/create-FASO7PVG-D_rvSpre.jsdist/assets/cronos-HJPAQTAE-BEOvlOC4.jsdist/assets/de_DE-YE3KOFHU-BRt5ztUe.jsdist/assets/degen-FQQ4XGHB-CeHTs88l.jsdist/assets/es_419-7LMPU7G4-DH7rM0yQ.jsdist/assets/ethereum-RGGVA4PY-SWGOlkuk.jsdist/assets/flow-5FQJFCTK-CUie2reO.jsdist/assets/fr_FR-VBJP3ZLL-B-_ocunw.jsdist/assets/gnosis-37ZC4RBL-B137OtHZ.jsdist/assets/gravity-J5YQHTYH-Bj6B0uod.jsdist/assets/hardhat-TX56IT5N-CV1FY-wE.jsdist/assets/hi_IN-WBVD5XYI-D73g2UFs.jsdist/assets/hyperevm-VKPAA4SA-CHwraEsx.jsdist/assets/id_ID-SBYANJ7G-Cjpa4ay6.jsdist/assets/index-CcVPgXVa.cssdist/assets/index-D4EdD6yc.jsdist/assets/injectedWallet-AWJSZPMG-Df9x-YJA.jsdist/assets/ink-FZMYZWHG-62p-5IK5.jsdist/assets/ja_JP-ZRMWJV3I-DXbifiMm.jsdist/assets/kaia-65D2U3PU-JmuLQ4gC.jsdist/assets/ko_KR-FR54RFUG-upinSHjQ.jsdist/assets/linea-QRMVQ5DY-DuI3vv0d.jsdist/assets/login-UP3DZBGS-Db_wM5oQ.jsdist/assets/manta-SI27YFEJ-CpVOKa06.jsdist/assets/mantle-CKIUT334-DR2WgqzU.jsdist/assets/monad-4KWC6TSS-DVXSkpiz.jsdist/assets/ms_MY-EZSGYYYQ-4cPLK-3L.jsdist/assets/optimism-HAF2GUT7-ec6Nqxs9.jsdist/assets/polygon-WW6ZI7PM-DXlmm4L1.jsdist/assets/pt_BR-JQFQ3P4L-DOHfdcA2.jsdist/assets/refresh-S4T5V5GX-CwqIaaxK.jsdist/assets/ronin-EMCPYXZT-N-QBHZdV.jsdist/assets/ru_RU-Z42UEJBP-Cvb2oWxQ.jsdist/assets/sanko-RHQYXGM5-OX010CbN.jsdist/assets/scan-4UYSQ56Q-CjMz6-XC.jsdist/assets/scroll-5OBGQVOV-DJFECiai.jsdist/assets/sign-A7IJEUT5-CGsRnPrd.jsdist/assets/superposition-HG6MMR2Y-bRkgatRO.jsdist/assets/th_TH-4YB4VSB2-BUipNP-V.jsdist/assets/tr_TR-5FKHPPIO-D5jTpIm9.jsdist/assets/uk_UA-ZD4IBC52-DgnQrpzl.jsdist/assets/unichain-C5BWO2ZY-BfguYsnu.jsdist/assets/vi_VN-5EVRZKLY-x078672g.jsdist/assets/xdc-KJ3TDBYO-DNV6zchh.jsdist/assets/zetachain-TLDS5IPW-Udhyw16T.jsdist/assets/zh_CN-4XK5YJPR-Bt6Yz5Ek.jsdist/assets/zh_HK-N4YN2WSI-Cvzl1V16.jsdist/assets/zh_TW-CNCRXH6Z-BNelatfN.jsdist/assets/zksync-DH7HK5U4-Dt4usFw6.jsdist/assets/zora-FYL5H3IO-iB4wygST.jsdist/claim-config.jsondist/claims.jsondist/imd-deployment.jsondist/index.htmldist/merkle-tree.jsondocs/frontend/browser-results.jsondocs/frontend/interaction-results.jsondocs/frontend/live-verification.jsondocs/frontend/submission-check.jsondocs/frontend/validation.mdweb/.gitignoreweb/README.mdweb/data/handoff.jsonweb/data/launch.jsonweb/data/network.jsonweb/index.htmlweb/package-lock.jsonweb/package.jsonweb/playwright.config.tsweb/public/abi/MerkleDistributor.jsonweb/public/abi/ProofOfWorkToken.jsonweb/public/allocation-snapshot.jsonweb/public/claim-config.jsonweb/public/claims.jsonweb/public/merkle-tree.jsonweb/scripts/check-submission.tsweb/scripts/fetch-launch.tsweb/scripts/inventory.tsweb/scripts/prepare.tsweb/scripts/serve.mjsweb/scripts/verify-live.tsweb/src/App.tsxweb/src/chain.tsweb/src/config.tsweb/src/integrity.tsweb/src/main.tsxweb/src/model.tsweb/tests/bootstrap.interaction.test.tsxweb/tests/claim.interaction.test.tsxweb/tests/claim.spec.tsweb/tests/integrity.test.tsweb/tsconfig.jsonweb/vite.config.tsweb/vitest.config.ts
  7. website publishedIdentity-md/launch-109-workflow-frontend-stage-context
  8. hostedwork.site.identitymd.ethnaming transaction
  9. checkedqueued5 attempts
    • deployment-config
    • static-assets