Cardano Modular Restaking

Architecture map

Canonical state boundaries and value flows

No architecture matchesTry another search term.

MVP lifecycle

Release target: every success and rejection must replay through model → UPLC → emulator
1DepositAssets enter a controlled strategy vault.
2DelegatePositions select an operator pool.
3AllocateExposure activates after visible notice.
4Reward / SlashFunded reward or attributable capped loss.
5WithdrawRelease follows every evidence and claim tail.

Evidence-gated delivery, not document-driven completion.

The source-stable model evidence records 71 passing tests, 1,083,082 assertions, direct register/delegate/delegated-deposit/queue coverage, a 15-vector pinned EigenLayer v1.12.0 vault arithmetic differential, and a finite depth-five one-owner/two-operator explorer with 11,550 attempted edges across 2,894 unique state/slot nodes. Its 8,174 expected rejections include 3,375 action-specific single-fault transaction-fact mutations paired with every planned-success non-create edge; each rejects exactly without state interference and the report explicitly declares that these rejected fact edges never create nodes. The accepted graph still covers 764 registrations, 288 delegations, delegation to either operator, delegated deposit, partial/full queue, and attributed completion paths. A deterministic source-inventory corpus binds ten pinned AllocationManager files, 7 interfaces, 21 errors, 11 structs, 15 events, 51 functions, 28 selected test families with 165 named tests, and 31 named but unexecuted Certora declarations. A separate 27-vector exact-bigint TypeScript oracle plus 821 bounded magnitude/rounding and tail checks executes selected source-derived AllocationManager rules without executing Solidity or selecting Cardano behavior. Ten unresolved local service/set/allocation/exit actions remain absent and fail closed. The pinned Catalyst stack builds, a clean detached checkout passes all 26 upstream tests, and two non-protocol UPLC probes execute with captured inputs, hashes, sizes, outcomes, and testing-cost budgets. Repository-controlled Zig 0.15.2 adapters also build all 11 packages in the exact pinned Blaze emulator scope, three selected outputs match fixed hashes, and all 63 selected upstream emulator tests pass. The integrity-locked published Blaze closure separately constructs, signs, and accepts one deterministic generic ADA transfer twice with identical CBOR and transaction ID; that transfer contains no restaking datum, redeemer, validator, policy, or state. The selected Plutus ledger API exposes only V1–V3; the expected missing-V4 compile diagnostic is preserved and no artifact is labeled V4. The source-bound release report still passes PPA-10 only, fails 12 gates, and records NOT_RELEASED. Independent reproduction, validator implementation, protocol-transition UPLC/Blaze execution, implementation refinement, and public-testnet execution remain open.

REVIEWED 2026-08-06
PhaseStateExit evidencePrimary source

Progress discipline

  1. Resolve value-bearing choices in docs/DECISION_LOG.md before implementing their paths.
  2. Keep every incomplete validator and policy fail-closed.
  3. Advance status only with source-bound, reproducible evidence using the repository vocabulary.
  4. Update this explorer in the same change as architecture, transition, phase, or evidence changes.

Claims stop exactly where the evidence stops.

The project uses a deliberately strict vocabulary so pure models, transaction construction, evaluator execution, emulator acceptance, public-ledger inclusion, formal proofs, and release decisions cannot be conflated.

OPEN RELEASE GATES ↗

Release tiers

  1. Pre-production alpha: generated UPLC and Blaze emulator evidence, explicitly not public-chain execution.
  2. Testnet-executed alpha: named public-testnet transactions, reconstructed state, and exercised operational recovery.
  3. Production: additional soak, independent review, deployed governance controls, monitoring, and budget headroom.