NFNetFold

Failure evidence

Try to break the settlement.

Two failure paths are reproducible against live Arbitrum state. The broader attack surface is exercised by the Foundry suite.

Live Arbitrum simulation

Before coverage

Premature settlement

ExpectedBLOCKED
ActualInvalidRunState

selector 0x9c1fa0e0

0x9c1fa0e0000000000000000000000000000000000000000000000000000000000000000100000000000000000000000000000000000000000000000000000000000000030000000000000000000000000000000000000000000000000000000000000002

eth_call simulation reverted with InvalidRunState(runId, COVERED, CLOSED); not broadcast

Live Arbitrum simulation

After final settlement

Double settlement

ExpectedBLOCKED
ActualInvalidRunState

selector 0x9c1fa0e0

0x9c1fa0e0000000000000000000000000000000000000000000000000000000000000000100000000000000000000000000000000000000000000000000000000000000030000000000000000000000000000000000000000000000000000000000000004

eth_call simulation reverted with InvalidRunState(runId, COVERED, SETTLED); not broadcast

Foundry test · not live transactions

Test-suite attack cases

These checks support engineering confidence. They are not a security audit.

Unauthorized acceptance
Self obligation
Duplicate reference
Mutation after close
Funding by non-debtor
Settlement before coverage
Double settlement
Premature refund
Double refund
Foundry methodology
40passing tests
0failures
3 × 256fuzz campaign runs
5 × 128 × 64invariant runs × calls

Explicit limits

Testnet prototype. Unaudited. No legal-netting opinion, KYC/KYB, credit extension, insurance, FX, or default mutualization. Single USDG asset. Maximum 8 participants and 32 obligations per run.