Test environment · Solana Devnet · No real-value assets · Not production · Internal validation is not an independent audit

Verification Evidence

Derived from the frozen Othvera closure freezes (L1–L6). These are internal validation results recorded on Solana Devnet — not an independent security audit, and not a claim of production or mainnet readiness.

Closure phases
P11.12H-L1PASS

Successor-stack fuzz

1,000,000 deterministic model-fuzz cases over the successor trust boundaries; all violation counters zero.

Freeze4fda54f7…fbba
P11.12H-L2PARTIAL

Live Squads 3-of-5 + generation-bound proof closure

A real on-chain Squads v4 3-of-5 governs Registry V3 from genesis; generation-bound stale-approval and stale-proof rejection proven live.

Freeze97df525f…ffc8
P11.12H-L3PARTIAL

Vault binding reach

The generation-bound binding reaches the vault layer; legacy bindings rejected at the successor identity gate.

Freeze398b19c7…cf75
P11.12H-L4PARTIAL

Real economic lifecycle

Real full-basket deposit mints canonical shares; proportional in-kind redemption burns them; solvency holds; legacy bindings rejected on the real economic vault.

Freezece742c64…b8fb
P11.12H-L5PARTIAL

Oracle-driven rebalance safety

Oracle-driven rebalance starts on live drift; deposits are locked during rebalance; redemption stays available; abort preserves custody and supply.

Freezecaad480e…ce49
P11.12H-L6PASS

Real adapter leg + route firewall

A real adapter-mediated rebalance leg executes with exact spent/received accounting; the P8D route firewall rejects wrong adapter, custody, tail-injection, and discriminator with zero state mutation.

Freezef229a7bd…dfbd
Security invariants

Each adversarial and safety counter recorded during closure. Every counter is expected to be zero; a non-zero value is a failure, not a pass.

InvariantValueExpectedStatus
unauthorizedGovernanceSuccesses00OK
singleKeyGovernanceBypassSuccesses00OK
staleApprovalProofSuccesses00OK
staleProofBindingSuccesses00OK
legacyBindingCanonicalActivations00OK
wrongBindingAccepts00OK
unauthorizedShareMintSuccesses00OK
custodySideEffects00OK
insolvencyEvents00OK
arbitraryCpiSuccesses00OK
routeFirewallDifferences00OK
spentReceivedParityDifferences00OK
mainnetTransactions00OK
Findings
C-001 — Downstream generation gateCLOSED_INTERNAL
C-002 — Stale-proof activation at bindingCLOSED_INTERNAL
H-001 — Successor identity gateCLOSED_INTERNAL
H-002 — Route firewall parityCLOSED_INTERNAL
Freeze hashes
FreezeHash
L14fda54f72b8dfbba
L297df525fe442ffc8
L3398b19c75dbccf75
L4ce742c646eafb8fb
L5caad480ea1bbce49
L6f229a7bdf33edfbd
Final closure hashf229a7bdf33edfbd

Evidence snapshot generated: 2026-08-29T03:30:02.386Z

These results were produced by internal Othvera validation on Solana Devnet. Internal validation is not an independent audit. Verify hashes and addresses independently.