Job
The transaction reverted on chain.
Make a Grid Mining Project Similar than this and better https://x.com/s_l_v_r_fun?s=11
Token name: Gold
Token symbol: Gold
the approved task
Approved workflow
Make a Grid Mining Project Similar than this and better https://x.com/s_l_v_r_fun?s=11
Token name: Gold Token symbol: Gold
The requester chose this release: source code published to GitHub, website hosted on IPFS, contracts deployed on chain.
Make a Grid Mining Project Similar than this and better https://x.com/s_l_v_r_fun?s=11
Token name: Gold Token symbol: Gold
the website assignment
Make a Grid Mining Project Similar than this and better https://x.com/s_l_v_r_fun?s=11
Token name: Gold
Token symbol: Gold
Published · Token
- token name
- Gold · $Gold
- supply
1,000,000,000 $Gold · 80% liquidity, 10% agents, 10% IMD
Split three ways by the factory in the one transaction. The contributors' part is claimable from a distributor after 1 hour. The treasury part goes to IMD.
2% of supply is split equally among the wallets that did accepted work on this launch; 8% is split equally among the paired seats connected when it was admitted, one share per seat. A wallet can earn both, combined into one claim.
Liquidity seeded into the pool80%800,000,000 $GoldContributors not allocated yet10%100,000,000 $GoldIMD treasury the operator's wallet on Sepolia, 0xcecc…a55110%100,000,000 $GoldTotal100%1,000,000,000 $Gold- pool
- Uniswap v4: Gold/ETH · 0.3% fee
- github
- identity-md-launches/launch-893-workflow-contract-stage-context
Work
- contracts built
#1409Build contract projectCodex54 files changed
Implemented Gold’s fixed-supply token and grid-mining contracts, with VRF integration, funded rewards, refunds, tests, vendored dependencies, and ABI exports.
Passed
forge build, all 47 tests,forge fmt --check, and ABI consistency checks.Deployment parameters, oracle timeout risks, and independent-review responsibilities are documented in README.md. Production oracle configuration and independent review remain outstanding.
ran oncodex · gpt-6-astra · 7 turns · 17m 37s · 100.4K in · 33.8K out · 1.3M cachedsubmissionf656800f2ca999962e543bca59418d9e7abf7909de8d1f42be184aef60016830device77cba07fd04368e3c0fd9da8d18eb6a497bfe2a2500ffc425db5a95734ebbd89started from0243d7da4a4337ae8b16bcdf15bb4ead736fd68fbundlee640597d52c0cb182f42cd1d4c29cfb5f5c00dea9846fec0e93c326589234d81 · 112 KBverifiedrebuilt and matched · verifier 0.1.0 ·changed · 54 files.gitignoreREADME.mddocs/ABI.mddocs/DEPENDENCIES.mddocs/DEPLOYMENT.mddocs/SECURITY.mddocs/abi/GridMining.jsondocs/abi/LaunchToken.jsonfoundry.tomllib/forge-std/LICENSE-APACHElib/forge-std/LICENSE-MITlib/forge-std/src/Base.sollib/forge-std/src/Script.sollib/forge-std/src/StdAssertions.sollib/forge-std/src/StdChains.sollib/forge-std/src/StdCheats.sollib/forge-std/src/StdError.sollib/forge-std/src/StdInvariant.sollib/forge-std/src/StdJson.sollib/forge-std/src/StdMath.sollib/forge-std/src/StdStorage.sollib/forge-std/src/StdStyle.sollib/forge-std/src/StdToml.sollib/forge-std/src/StdUtils.sollib/forge-std/src/Test.sollib/forge-std/src/Vm.sollib/forge-std/src/console.sollib/forge-std/src/console2.sollib/forge-std/src/interfaces/IERC1155.sollib/forge-std/src/interfaces/IERC165.sollib/forge-std/src/interfaces/IERC20.sollib/forge-std/src/interfaces/IERC4626.sollib/forge-std/src/interfaces/IERC721.sollib/forge-std/src/interfaces/IMulticall3.sollib/forge-std/src/safeconsole.sollib/openzeppelin-contracts/LICENSElib/openzeppelin-contracts/contracts/interfaces/draft-IERC6093.sollib/openzeppelin-contracts/contracts/token/ERC20/ERC20.sollib/openzeppelin-contracts/contracts/token/ERC20/IERC20.sollib/openzeppelin-contracts/contracts/token/ERC20/extensions/IERC20Metadata.sollib/openzeppelin-contracts/contracts/utils/Context.sollib/openzeppelin-contracts/contracts/utils/ReentrancyGuard.solremappings.txtsrc/GridMining.solsrc/LaunchToken.solsrc/interfaces/IVRFCoordinator.soltest/GridMining.t.soltest/GridMiningInvariant.t.soltest/GridMiningOracle.t.soltest/GridMiningSecurity.t.soltest/LaunchToken.t.soltest/helpers/GridFixture.soltest/helpers/MockVRFCoordinator.soltools/export_abi.py - contracts integrated
#122ManifestCodexruntime erroron the agent's machine: the task produced no changes; the agent's last message was: `launch.json` is blocked by missing immutable …retried on #579 (Codex)
the task produced no changes; the agent's last message was:
launch.jsonis blocked by missing immutable constructor inputs: target chain, VRF coordinator address, key hash, and subscription ID. Please provide these; inventing them could permanently misconfigureGridMining.forge build, all 47 existing tests, and all 7 protected token checks passed. No submitted files were changed.ran oncodex · gpt-6-astra · 5 turns · 1m 49s · 43.8K in · 3.8K out · 341K cachedsubmissionb267ca664df33dc44026bbfc3361a7db65c92f4ab11c837e80cef5f6117cd558devicede66cc20c06aee0ae6c16a36cff9e6a32ad49c2d1cd91068f4bae0bf0e086496started fromb1e14e60fd069ddd54301f7f1ff9c2a9a6e4a199bundlenoneapplied one640597d52c0cb182f42cd1d4c29cfb5f5c00dea9846fec0e93c326589234d81changed · 0 filesnothing#579Codex1 file changedrevised
afterBuild contract projectwrites tolaunch.jsonCreated launch.json as the only submitted change.
Schema/ABI checks,
forge build, and all 57 tests passed.The notes explicitly flag the candidate chain/VRF settings and placeholder subscription ID
1for resolution before admission.ran oncodex · gpt-6-astra · 5 turns · 4m 12s · 61.8K in · 6.9K out · 307.5K cachedsubmissionbc12c7edd067d4d0afb1a220ce91fa68df10b51f006e7fc9cb89015328c71d46devicef5dec78d5893d9dc71819bfb5d9668cc6eaca4d79a129bfc1411622281c11397started fromb1e14e60fd069ddd54301f7f1ff9c2a9a6e4a199bundlee38cdfe468205048d53e46cf92a9b0d678487422aa4eda5a18f6b1e19ea03f12 · 114 KBverifiedrebuilt and matched · verifier 0.1.0 ·applied one640597d52c0cb182f42cd1d4c29cfb5f5c00dea9846fec0e93c326589234d81changed · 1 filelaunch.json - contracts reviewed
#954Audit economicsClaude3 findings · 1 medium
afterBuild contract projectThe review is complete. The findings file is at the repository root with three findings and a 15-row coverage record, every snippet anchor matches the tree, and the scratch tests are removed so no tracked file changed.
What I found
The core accounting is sound. I traced every writer of the native liability, the Gold reserve and the per-round remainders, and the pot, dust, refund and atomic-revert behaviour of claim all hold. The economic exposure is at the design seam, where execution, the oracle dependency and the stated purpose meet.
- Medium, src/GridMining.sol:236. A wallet playing alone can never lose its stake: with all 25 tiles it is always the only winner, and with one tile it is either the winner or refunded by the empty-tile path. Rounds are permissionless and 90 seconds long, so one bot runs them back to back, takes the full Gold reward each round at zero risk, and charges the LINK subscription one fulfilment per round. Verified with a scratch test: 10 solo rounds returned every wei of stake, moved all 1,000 Gold of sponsor donations to the bot, consumed 10 requests, and left the next round reverting for everyone. Once the subscription is empty the request reverts and other players' stakes sit locked until the oracle timeout. The security handoff mentions subscription budgeting but not the riskless reward capture.
- Low, docs/SECURITY.md:12. The claim that full cover gives no profit relative to stake is wrong. Full cover's native return is at least its stake against any opponent distribution and strictly more whenever opponents concentrate, plus a Gold share every round. Scratch run over all 25 outcomes: a one-ticket player recovers 13 of 25 units paid, the full-cover bot recovers 637 of 625 plus 24.5 of the 25 rewards.
- Low, src/GridMining.sol:150. Any reserve remainder below the per-round reward is stranded. Fund 150 Gold with a 100 Gold reward, run one round, and 50 Gold can never be paid out or recovered until someone else donates.
All three fixes change agreed economics, so I framed them as requester decisions rather than silent edits.
Coverage. All 11 verifier entry points have rows: claim, expireRound, fundRewards, the VRF callback and the three token functions hold; enter, closeRound and settleRound point at finding 1; startRound at finding 3. Three invariant rows hold. One row is unreached: there is no launch.json in the tree yet, so coordinator, key hash and subscription values could not be checked against a target chain. The slither and aderyn reentrancy lines on fundRewards and closeRound are false positives here because of the reentrancy guard and the fixed token.
ran onclaude · claude-fable-5-1 · 27 turns · 7m 31s · 290 in · 31.6K out · 841.8K cachedsubmission01688c83d7e54a5e6aec7b95dcd19c2c2257f84b6b5850b3ddf938df975e5d78device78d8eb9b16352a1818b45163a221b7d9058c3037be7afef732c817815027e5b1started fromb1e14e60fd069ddd54301f7f1ff9c2a9a6e4a199bundlenoneapplied one640597d52c0cb182f42cd1d4c29cfb5f5c00dea9846fec0e93c326589234d81changed · 0 filesnothingmediumSolo rounds are riskless for the entrant: one actor drains the Gold reserve and burns one subscription-paid VRF request per round at gas cost onlysrc/GridMining.sol:236
SECURITY.md misstates full-cover economics: covering all tiles has native EV >= stake against any opponent distribution and always receives Golddocs/SECURITY.md:12
Reserve remainder below rewardPerRound is stranded with no spend or recovery pathsrc/GridMining.sol:150
Invariant / stranded value. Rounds only ever reserve exactly rewardPerRound, donations are irrevocable, and there is no partial-reward round or sponsor withdrawal. Any availableRewards balance in (0, rewardPerRound) can neither be paid out nor returned; it stays in the contract until some other party donates enough to lift the balance over the threshold.
With rewardPerRound immutable this is a permanent condition whenever sponsorship stops. Fix options (requester decision): let the last round use the remaining reserve when it is below rewardPerRound (pay min(availableRewards, rewardPerRound) and record it in r.remainingGold), or require donations to be whole multiples of rewardPerRound in fundRewards so no remainder can arise.
- contracts reviewed
#766Audit permissionsClaude3 findings · 1 medium
afterBuild contract projectThe review is complete and
.imd-findings.jsonholds three substantiated findings plus coverage for all eleven entry points.What I reviewed. The Access Control, Trust Gap and Asymmetry guides against
src/GridMining.solandsrc/LaunchToken.sol, with the existing test suite (47 tests pass), the ABI exports (they match the compiled output), and the docs. No manifest exists yet. I wrote three scratch tests undertest/scratch/to pin down each finding; all three reproduce.Findings, by severity.
- Medium, coordinator input is unverifiable. The constructor accepts any nonzero coordinator address and nothing later in the pipeline checks it. If the launch chain has no Chainlink VRF v2.5 coordinator at that address, every round with an entry reverts at
closeRound, players wait out the timeout for a refund, and all Gold ever donated is locked forever because donations are irrevocable and Gold only leaves through a settled claim. This is a manifest-stage finding: the reviewer needs on-chain evidence of the coordinator code, the gas lane and the consumer registration. The SECURITY.md claim that an EOA coordinator could rig outcomes is also wrong, since an EOA cannot return a request ID and only causes this dead-game outcome. - Low, solo all-tiles play is risk free. One wallet covering all 25 tiles always gets its stake back plus the full Gold reward, so one actor can sweep the reserve one reward per round while the LINK subscription pays every oracle call. The docs partly acknowledge this, but phrase full coverage as "not profit relative to stake", which only holds when another player shares the winning tile. This is an economics trust assumption for the requester to accept or redesign.
- Info, the coordinator is the single privileged role. Whoever controls that contract picks every winning tile. This is the intended design, reported so the manifest never binds that argument to
$owner, a project contract or a mock.
What holds. Every other entry point traced clean: no owner, initializer, setter, sweep or upgrade path; no
msg.senderrole in the constructor; callback and expiry windows are strictly disjoint; reservation, entry, refund and claim updates mirror each other exactly; the LaunchToken is an unmodified OpenZeppelin ERC-20 with the brief's name and symbol. The slither and aderyn reentrancy leads are guarded paths with a hookless token and did not promote.Not reached.
launch.jsonitself, because the manifest assignment has not run.ran onclaude · claude-fable-5-1 · 33 turns · 7m 33s · 258 in · 28.8K out · 669.9K cachedsubmission61ef11d4ebecd3ef7754e1338092bd97f0b107d8e87704e59fa1e18022f79a2fdevicecbc83f8151b8340db8b1e074e9f146ec16c495f7ba719f8ad8dd610c3163044fstarted fromb1e14e60fd069ddd54301f7f1ff9c2a9a6e4a199bundlenoneapplied one640597d52c0cb182f42cd1d4c29cfb5f5c00dea9846fec0e93c326589234d81changed · 0 filesnothingmediumcoordinator_ is an unverifiable external dependency: a wrong address makes every non-empty round revert at closeRound and permanently locks all donated Goldsrc/GridMining.sol:118
A solo player covering all 25 tiles always wins the full Gold reward with zero stake at risk; the reward reserve and LINK subscription can be drained by one actor at roundDuration cadencesrc/GridMining.sol:281
Trust assumption: whoever controls the coordinator_ address chooses every winning tile; the manifest must bind it to the verified VRF v2.5 coordinator and never to $owner or a contributor-controlled csrc/GridMining.sol:217
- Medium, coordinator input is unverifiable. The constructor accepts any nonzero coordinator address and nothing later in the pipeline checks it. If the launch chain has no Chainlink VRF v2.5 coordinator at that address, every round with an entry reverts at
- contracts reviewed
#550Audit mathClaude2 findings · 1 low
afterBuild contract projectThe findings file is valid and both snippet anchors match the tree. The review is complete.
Outcome: the arithmetic in
src/GridMining.solholds across the Math Precision, Boundary and Numerical Gap checklists. I found one low-severity boundary defect and one informational design note. No critical or high issue, so no proof tests were attached.What I verified
- Every division and multiplication in value paths: entry cost cannot overflow at the uint128 maximum price times 25 tiles, pot and Gold shares conserve exactly, and the last claimant absorbs dust below the winner count. Confirmed by scratch fuzzing with odd prices up to 60 winners in random claim order and with a 1-wei reward split.
- Timestamp windows for close, callback and expiry are disjoint at the exact boundary, so a late callback cannot race a refund.
- Accounting invariants between balances, liabilities and reserves hold on every path, including empty-round, empty-tile and timeout refunds.
- External boundaries: token return values and balance deltas are checked, the coordinator call rolls back atomically, and the callback is ignored safely on every malformed input.
- Slither and Aderyn reentrancy leads: the flagged functions are guarded and the token has no hooks, so none reproduce.
Findings written to
.imd-findings.json- Low. The constructor bounds every parameter except the two economic ones. A per-round reward above the 1e27 total supply deploys fine, accepts irrevocable donations, and then can never start a round. The same class applies to an unpayable entry price. Reproduced with a scratch test.
- Info. At the sole-occupant boundary a lone player covering all 25 tiles always recovers the stake and takes the whole Gold reward at gas cost only. The math is correct and the security doc partly acknowledges it. I recorded it as a design assumption for the judge and sponsors.
Coverage: all 11 listed entry points have rows, plus three invariant rows. No manifest exists yet in the tree, so there was nothing to review there. Scratch tests live under
test/scratch/and are not kept.ran onclaude · claude-fable-5-1 · 29 turns · 7m 51s · 546 in · 29.8K out · 1.6M cachedsubmissione6cfeb0531ce8a809c1143cb0f62406f8dcb5e95eef2a1c4aa332d3b74450cc5device789312fc56d3f4464feae764aea6bc210caaf3e615697b44bae3cb35a62ee0ecstarted fromb1e14e60fd069ddd54301f7f1ff9c2a9a6e4a199bundlenoneapplied one640597d52c0cb182f42cd1d4c29cfb5f5c00dea9846fec0e93c326589234d81changed · 0 filesnothingConstructor accepts rewardPerRound_ above the entire Gold supply (and entryPrice_ beyond any payable amount), producing a permanently unstartable game that still accepts irrevocable donationssrc/GridMining.sol:121
Sole-occupant boundary: a lone player covering all 25 tiles always recovers the full stake and takes the entire Gold reward, so the reserve drains to whoever plays alone at gas cost onlysrc/GridMining.sol:236
- contracts reviewed
#581Audit flowClaude1 finding · 1 low
afterBuild contract projectReview complete. The findings record is written to
.imd-findings.json, the snippet verified against the tree, and the scratch directory removed, so the only change in the working tree is the findings file.Outcome. The control flow of
GridMiningholds under the Execution Trace, Periphery and First Principles checks. I traced every entry point's guards, state writes and failure paths, confirmed the boundaries with scratch Foundry probes, and found no defect in execution flow. One low, design-level finding is recorded.What was verified
- Round state machine. Entry, close, callback and expiry windows are disjoint at the exact deadline timestamps on both the Open and Requested deadlines. A Ready round can never be expired, and only Settled or Refundable rounds let the next one start.
- Claim accounting. All coupled liabilities are written before any transfer, re-entry is blocked, a rejecting recipient rolls back the Gold leg, and the by-count last winner absorbs division dust. Probed with 25 winners and with a winner who never claims.
- Oracle integration. The request selector, callback selector and ExtraArgsV1 tag match Chainlink VRF v2.5. A coordinator that calls back synchronously during the request is ignored because the request id is not yet bound.
- Static-analysis leads. The reentrancy lines on
fundRewardsandcloseRoundare rejected: both are guarded, state is written before the external call, and the supported token has no hooks. - Periphery. OpenZeppelin v5.1.0 and forge-std are plain vendored files with no submodules. The ABI export check passes against the compiled output.
Finding 1, low. A lone wallet covering all 25 tiles in an otherwise empty round is always the single winner, so it recovers its whole stake and takes the full Gold reward for gas alone. Ten such rounds drained a 1,000 Gold reserve in my probe with zero native loss. The builder's security notes acknowledge stake recovery in single-player rounds, but the README sentence claiming full coverage gives no profit relative to stake is contradicted. This is an economic design property, not a control-flow bug. Any mechanism change alters the agreed rules and needs a requester decision, so I flagged it for the judge and the economics reviewer rather than as blocking.
Trust assumptions recorded, not findings. Fulfillment withheld or unfunded until the deadline turns a draw into a refund, and the coordinator address cannot be verified inside the isolated constructor floor. Both are documented and belong to the manifest and release review. No launch.json exists yet, so coordinator, key hash and subscription values remain open for that reviewer.
ran onclaude · claude-fable-5-1 · 44 turns · 9m 28s · 386 in · 36.7K out · 1.3M cachedsubmission01c6a473058d044ae69f50e4dab06d4c5ca5e80b3d534fc437ca2644d2354685device75052237a39b6e1240106d4c537fd9b1cdacae7a0ac262da58b0451423d675f8started fromb1e14e60fd069ddd54301f7f1ff9c2a9a6e4a199bundlenoneapplied one640597d52c0cb182f42cd1d4c29cfb5f5c00dea9846fec0e93c326589234d81changed · 0 filesnothingA single wallet covering all 25 tiles in an otherwise empty round recovers its full stake and takes the whole Gold reward, so the donated reserve can be farmed for gas alone; README overstates the prosrc/GridMining.sol:191
- contracts tested
#1393Write foundry testsCodex3 files changed
afterBuild contract projectwrites totesttest/**Added 12 tests within
test/, covering failure rollback, payout boundaries, token allowances, and randomized multi-round accounting invariants.Offline
forge buildandforge testpass: 59 passed, 0 failed, 0 skipped.No reproducible contract defects found. Source and configuration files remain unchanged.
ran oncodex · gpt-6-astra · 6 turns · 10m 34s · 86.5K in · 18.6K out · 1.2M cachedsubmission365ff7803e80eeda33d41f4b92811fc411a46f2205a57ad5402be3710f5d4157device3592a9be44170f187fa60471ab49e266cd6aefb6a214ce3d0094b2db82e0ee17started fromb1e14e60fd069ddd54301f7f1ff9c2a9a6e4a199bundle383b8c802124f1f69891a846b8f5c9dd7f537fa33079e7b2534f98d12f365e5d · 120 KBverifiedrebuilt and matched · verifier 0.1.0 ·applied one640597d52c0cb182f42cd1d4c29cfb5f5c00dea9846fec0e93c326589234d81changed · 3 filestest/GridMiningLedgerInvariant.t.soltest/GridMiningProperties.t.soltest/LaunchTokenInvariant.t.sol - contracts reviewed
#1871Audit judgeClaude4 findings · 1 highrevised
afterBuild contract project, Write foundry tests, Manifest, Audit math, Audit permissions, Audit economics, Audit flowThe findings file is in place at the repository root, every snippet matches the tree, and no project file was changed. The scratch tests under test/scratch/ are disposable per the assignment.
Outcome: four findings kept, one high and three low, with a 14-row coverage record answering all 11 entry points.
What I kept and why
- High, launch.json line 14. The manifest binds GridMining to the Ethereum-mainnet VRF coordinator with subscription ID "1", which the manifest's own notes call a placeholder. Chainlink v2.5 subscription IDs are keccak-derived and the coordinator reverts for an unregistered consumer, so with these arguments every nonempty round's closeRound reverts: stakes sit locked for the 86400-second timeout, and all donated Gold is permanently stuck because donations are irrevocable. On a non-mainnet chain the address has no code and the result is identical. I merged the permissions specialist's coordinator and trust-assumption items into this one, and listed the evidence needed before admission: the selected chain,
cast codeat the coordinator, and a real funded subscription with the game registered as consumer. No fail-then-pass proof is attached because the defect is in the manifest, not Solidity. - Low, GridMining.sol line 191. All four specialists reported the solo full-cover case. I merged them into one finding and recalibrated it down: no player loses funds, and at the proposed economics the bot's gas exceeds the Gold it captures, so the real harm is griefing the sponsor reserve and the LINK subscription. The README and SECURITY.md sentences on full-cover risk are inaccurate and the design decision is the requester's.
- Low, lines 121 and 150. Constructor accepts a reward above the fixed supply or an absurd entry price, yielding an unstartable game that still takes donations. A reserve remainder below one reward is stranded. Both reproduced.
What I verified myself
- Full suite passes (59 tests). ABI exports match the build. Libraries are plain vendored files, no submodule.
- Slither and Aderyn reentrancy lines on fundRewards and closeRound are false positives: guard present, plain OZ token, and a synchronous fake callback has no bound request.
- Callback uses about 59k gas, within both the 100k floor and the manifest's 150k.
- Every remaining entry point traced and marked holds in the coverage record.
ran onclaude · claude-fable-5-1 · 28 turns · 7m 52s · 290 in · 31.4K out · 794.9K cachedsubmission754c3fa7904f7d8b84dec0a16c3520411ca56e347a1f300d10d1f7847ba0b3e5device2a9662a76cb5f51d178c6d5ff9e9a5da33ad63feb5a9ef85547ee127dbf9fd6fstarted from945ba57dc786a46062d1b24e535d169221089f65bundlenoneapplied one640597d52c0cb182f42cd1d4c29cfb5f5c00dea9846fec0e93c326589234d81, 383b8c802124f1f69891a846b8f5c9dd7f537fa33079e7b2534f98d12f365e5d, 2863275c0b433e00390bf1fae66dda8f00f279a6028135a820d9b714ded2a081changed · 0 filesnothinghighlaunch.json binds GridMining to an unverified Ethereum-mainnet VRF coordinator and the placeholder subscription 1: every nonempty round reverts at closeRound and all donated Gold is locked foreverlaunch.json:14
A lone wallet covering all 25 tiles never risks native value and takes the whole Gold reward each round, so the donated reserve and the LINK subscription can be drained by one actor; README/SECURITY osrc/GridMining.sol:191
Constructor accepts rewardPerRound_ above the fixed 1e27 Gold supply and an unbounded entryPrice_, producing a permanently unstartable game that still takes irrevocable donationssrc/GridMining.sol:121
Any reserve remainder below rewardPerRound is stranded: it can neither fund a round nor be recoveredsrc/GridMining.sol:150
From audit_economics finding 3, reproduced. Rounds reserve exactly rewardPerRound, donations are irrevocable and there is no partial-reward round, sweep or sponsor withdrawal, so any availableRewards balance in (0, rewardPerRound) stays in the contract until someone else donates enough to lift it over the threshold. With rewardPerRound immutable this is permanent once sponsorship stops; the stranded amount is bounded by rewardPerRound-1 per deployment.
Options for the requester (either changes the agreed rules): let the final round reserve min(availableRewards, rewardPerRound) and record it in r.remainingGold, or require fundRewards amounts to be whole multiples of rewardPerRound. Documenting the property in README 'Playing and funding' is the no-code alternative.
Scratch test test/scratch/Judge.t.sol test_remainderBelowRewardIsStranded: rewardPerRound 100e18, sponsor fundRewards(150e18).
After one settled solo round pays 100e18 out: availableRewards()==50e18, token.balanceOf(game)==50e18, and startRound() reverts InsufficientRewards.
Expected: the sponsor's 150 Gold is fully usable as prizes or recoverable.
Actual: 50 Gold is immovable by any function until a further donation of >= 50 Gold arrives.
Passes on the current tree.
- High, launch.json line 14. The manifest binds GridMining to the Ethereum-mainnet VRF coordinator with subscription ID "1", which the manifest's own notes call a placeholder. Chainlink v2.5 subscription IDs are keccak-derived and the coordinator reverts for an unregistered consumer, so with these arguments every nonempty round's closeRound reverts: stakes sit locked for the 86400-second timeout, and all donated Gold is permanently stuck because donations are irrevocable. On a non-mainnet chain the address has no code and the result is identical. I merged the permissions specialist's coordinator and trust-assumption items into this one, and listed the evidence needed before admission: the selected chain,
- contracts updated
#212ManifestCodex1 file changedrevised
afterBuild contract projectwrites tolaunch.jsonReproduced the finding and recorded evidence in
launch.jsonand.imd-responses.json.The deployment blocker remains unresolved: correcting the immutable arguments requires the intended chain and a valid operator-owned VRF subscription. No replacement values were invented.
forge buildsucceeded; all 58 tests passed, including protected checks and failure reproductions.ran oncodex · gpt-6-astra · 6 turns · 7m 18s · 71.3K in · 11.7K out · 482.9K cachedsubmissionb9153aff20627eb7dee30ceb186ecba3c890720bd0321b8d6402482ee52ebf02device080780b6898c22410cdd53034758fe8e4588bd6890b84700c41f367327f0fcb2started fromf82c94c1ca22f3d89e8bb7ff7ed9d8197254876bbundle2863275c0b433e00390bf1fae66dda8f00f279a6028135a820d9b714ded2a081 · 115 KBverifiedrebuilt and matched · verifier 0.1.0 ·applied one640597d52c0cb182f42cd1d4c29cfb5f5c00dea9846fec0e93c326589234d81changed · 1 filelaunch.json - contracts reviewed
#1959Audit judgeCodex1 finding · 1 highrevised
afterBuild contract project, Write foundry tests, Manifest, Audit math, Audit permissions, Audit economics, Audit flowWrote .imd-findings.json with one unresolved high finding and coverage for 11/11 entry points.
Subscription
1still reverts withInvalidSubscription. The author correctly identifies missing operator inputs, but the revised notes do not repair the manifest.All three prior advisory behaviors still reproduce and remain nonblocking: solo full-grid principal recovery, above-supply reward configuration, and reserve remainders needing further donations. None is claimed fixed.
Validation passed: 59 existing tests, 6 reproductions, and 9 protected checks. Temporary tests were removed; production files remain unchanged.
ran oncodex · gpt-6-astra · 5 turns · 8m 47s · 138.9K in · 14.6K out · 1.4M cachedsubmissioneb4650e5e84c2f4a305fadcd68b0e864fd4254bb716a522246a278d19a05244edevice20c10dbba93106ff243d0b0f2d8139affbed683c9cc632746ce155ebac0b4387started from951a99378cdf95f662f76ecbdad0f039b357e6cfbundlenoneapplied one640597d52c0cb182f42cd1d4c29cfb5f5c00dea9846fec0e93c326589234d81, 383b8c802124f1f69891a846b8f5c9dd7f537fa33079e7b2534f98d12f365e5d, 2863275c0b433e00390bf1fae66dda8f00f279a6028135a820d9b714ded2a081changed · 0 filesnothinghighUnresolved: the manifest still binds GridMining to nonexistent VRF subscription 1launch.json:14
- contracts updated
#1966ManifestCodexno change0 files changed
afterBuild contract projectwrites tolaunch.jsonThe blocker is confirmed and remains unresolved. Recorded the evidence in .imd-responses.json.
forge buildsucceeded; all 59 tests passed.launch.jsonremains unchanged. A valid correction requires the selected chain, coordinator, key hash, and an operator-controlled VRF subscription ID.ran oncodex · gpt-6-astra · 6 turns · 6m 36s · 64K in · 11.4K out · 504.2K cachedsubmissionf91efc7bb74250e3b28e768268293afb6420def113dc972168cebaf515cd4411device468e1f512c9ac6caa56363689fcff7573366d964b16a5a9e8eb7f04c3a5f31c2started from4076bbf83b15c4466c7440b544d53dc9c76c4eb1bundlenoneapplied one640597d52c0cb182f42cd1d4c29cfb5f5c00dea9846fec0e93c326589234d81changed · 0 filesnothing - contracts reviewed
judge findings unresolved after 2 revisions: no revision budget left for manifest (2 revisions, 2 from the judge) — Unresolved: launch.json still binds GridMining to VRF v2.5 subscription 1, which does not exist on the candidate chain; every nonempty round reverts and donated Gold has no exit
#1844Audit judgeClaude4 findings · 1 high
afterBuild contract project, Write foundry tests, Manifest, Audit math, Audit permissions, Audit economics, Audit flowThe review is complete and
.imd-findings.jsonholds the result. No tracked file was changed.Outcome: the prior high finding is still open and nothing else blocks.
The one finding from my last round stands unchanged. The revision touched only the notes string in launch.json. Constructor arguments and the Solidity source are byte-identical to what I reviewed before. The author's answer agrees the defect reproduces and only disputes that a manifest-only assignment can fix it, which I accept as the reason there is no fix, not as grounds to close it.
- High, unresolved: launch.json binds GridMining to VRF v2.5 subscription 1. Fresh read-only checks on Ethereum mainnet today confirm the coordinator is real and the key hash is a supported lane, but both getSubscription(1) and a request with the manifest's exact tuple revert InvalidSubscription. VRF v2.5 derives subscription IDs from a keccak hash, so ID 1 can never be created or authorized. Because coordinator, key hash and subscription are immutables with no owner or sweep, every nonempty round would revert at closeRound and donated Gold would have no exit. The permissions specialist's medium and info findings on coordinator identity are merged into this one. Closing it needs the service or operator to supply the launch chain and a controlled subscription, then a manifest edit and re-review.
Specialist leads, reproduced and recalibrated to info:
- Solo all-tiles farming of the Gold reserve and LINK subscription was reported by all four specialists. It reproduces, but it is a documented design property of a prize giveaway, not a broken guarantee. The only inaccuracy is one sentence in docs/SECURITY.md about full cover not being profitable.
- Constructor accepts a reward per round above total supply. The accepted manifest value is 100 Gold, so this launch does not hit it.
- A reserve remainder below the per-round reward idles until anyone tops it up. Inherent to the agreed rules.
Static-analysis reentrancy leads were rejected: every mutating path is guarded and the token is the plain OpenZeppelin ERC20. The full suite passes offline with 59 tests, ABI exports verify, and the manifest is schema-valid apart from the subscription input. Coverage answers all 11 entry points plus two invariant rows.
ran onclaude · claude-fable-5-1 · 24 turns · 6m 9s · 482 in · 23.8K out · 1.3M cachedsubmission1421afa97d5f5586980e6bde18ae0032fe92c15ce5f40d6e9e11e4ca45cee6c8device2d027bc56749d95c339486a49d7394896754c073e11aca8def18842ba91e7a92started frome9427f74c9b7faeab5dbc4645ce5726c85320604bundlenoneapplied one640597d52c0cb182f42cd1d4c29cfb5f5c00dea9846fec0e93c326589234d81, 383b8c802124f1f69891a846b8f5c9dd7f537fa33079e7b2534f98d12f365e5d, 2863275c0b433e00390bf1fae66dda8f00f279a6028135a820d9b714ded2a081changed · 0 filesnothinghighUnresolved: launch.json still binds GridMining to VRF v2.5 subscription 1, which does not exist on the candidate chain; every nonempty round reverts and donated Gold has no exitlaunch.json:16
Design assumption, merged from four specialists: a lone wallet covering all 25 tiles always recovers its stake and takes the whole Gold reward, draining the reserve and the LINK subscription at gas cosrc/GridMining.sol:281
Constructor accepts rewardPerRound_ larger than the fixed Gold supply, which would make startRound revert forever while fundRewards still accepts irrevocable donations; the accepted manifest value is src/GridMining.sol:122
Reproduced the audit_math low lead. Every other constructor parameter has an upper bound but rewardPerRound_ and entryPrice_ only reject zero. With rewardPerRound_ = 1e27 + 1 the deployment succeeds, fundRewards(1e27) succeeds, and startRound reverts InsufficientRewards at line 150 forever because no more Gold can exist.
The manifest sets 100000000000000000000 (100 Gold), far below the 1e27 supply, so this launch does not instantiate the hazard; it is recorded as information for a possible bound (rewardPerRound_ > gold totalSupply) rather than as a defect in the accepted deployment.
test/scratch/Review2.t.sol test_rewardAboveSupplyAccepted (passes): new GridMining(token, 0xC001, keyHash, 1, 3, 150000, 90, 86400, 1, 1e27+1) does not revert; approve and fundRewards(1e27) succeed; startRound() reverts InsufficientRewards.
Expected: InvalidConfiguration at construction.
Actual: a dead game that still accepts donations.
A reserve remainder below rewardPerRound cannot open a round or be returned until some donor tops it up; inherent to the fixed per-round reward and irrevocable donationssrc/GridMining.sol:150
Reproduced the audit_economics low lead. Rounds reserve exactly rewardPerRound and there is no partial-reward round or sponsor withdrawal, so any availableRewards in (0, rewardPerRound) is idle until a further donation of at least the shortfall arrives from anyone. This follows directly from the documented rules (donations permanent, fixed reward per round) and is not loss or misdirection of funds; any Gold holder can unlock it with a top-up.
Recorded as information for the requester; requiring whole multiples in fundRewards or paying min(availableRewards, rewardPerRound) in the last round would be design changes.
test/scratch/Review2.t.sol test_remainderStranded (passes): fundRewards(150e18); startRound() leaves availableRewards == 50e18; after that round finishes, availableRewards is 50e18 and startRound() would revert InsufficientRewards until at least 50e18 more is donated.
- contracts publishedidentity-md-launches/launch-893-workflow-contract-stage-context/pull/1
- deployed
0 contractson Robinhood Chainfindings: 1 blocking finding(s) never resolved — audit_judge: Unresolved: launch.json still binds GridMining to VRF v2.5 subscription 1, which does not exist on the candidate chain; every nonempty round reverts and donated Gold has no exit
- rebuilt
- GridMining, LaunchToken (Gold $Gold) · verifier 0.1.0 · solc 0.8.26
- gates
- 6 of 7 passed
- provenance
- findings
- independent review
- bytecode
- manifest
- protected invariants
- economics
- parked
- findings: 1 blocking finding(s) never resolved — audit_judge: Unresolved: launch.json still binds GridMining to VRF v2.5 subscription 1, which does not exist on the candidate chain; every nonempty round reverts and donated Gold has no exit
- proof
commit, attestation, manifest, tree, per-contract hashes
- repository
- identity-md-launches/launch-893-workflow-contract-stage-context
- commit
- ddd26c4d082e0e2c431640ac8ec4123cb224170d
- attestation
- c9c6758e3d28cd66cfc2ca6272f26557b64cde5299b6f9759a8df96f970b3b99
- manifest
- dbd23efa4343300d7165c9a229e0d92dd2c7c12a05e04a9c2d6b03cf1b7489b3
- constructor
- GridMining: $token, 0xd7f86b4b8cae7d942340ff628f82735b7a20893a, 0x8077df514608a09f83e4e8d300645594e5d7234665448ba83f51a50f842bd3d9, 1, 3, 150000, 90, 86400, 1000000000000000, 100000000000000000000
- tree
- a7be3b253f06ced1f1db37599db68fb2b073dfee
- compiler
- solc 0.8.26, optimizer 200 runs, reproducible
- contract
- GridMining
src/GridMining.sol · 9012 bytes
creation ca40ed0dec33e8e1ef73308b71b34a7dfa8d3abc045869faa18d03c18020fc15
abi e017fd32db8372fd760038ac1039c50abcbdc8ebea3223817063e64229cf6de5
metadata d1d92f692c392bff0ed52cae558e269c0fc6e0fa3f2af165b0d9a1054881979c - contract
- LaunchToken · Gold $Gold
src/LaunchToken.sol · 2672 bytes
creation 0874d24dbe3523a9f19a6ccad53be6698ba5d321c265da7c99d5231b6679538b
abi 38880b8e56d42ce900f744a7908c7139632a49f1c3f33385c64ceaed29d37bee
metadata 3d444e658dc3f5f56d3468f34fe592b81f53be53026485fbe139cba012d06a93
- website builtafter deployment
- website publishedafter the website is accepted
- hostedWorkflow paused. Waiting for the website build and GitHub publication.
- checkednot reached