{"workflow":null,"planning":null,"id":"ec4e3ea7-9b37-4113-ae4d-8cdd5ea19424","state":"completed","template":"audit","objective":"Project: PepesFamily launchpad v4\nRepo: github.com/0xtenang/PepesFamily (commit 9a32f89)\nScope: contracts/src/PepesFamily.sol, contracts/src/PadToken.sol, contracts/src/PepesBuyback.sol. The routers are unchanged from v3 (audited).\nTests: contracts/test/PepesFamily.t.sol, contracts/test/Fork.t.sol, contracts/test/EthRouter.fork.t.sol\nChain: Robinhood Chain (4663), Uniswap v4\n\nWhat changed from v3 (v3 audit: job a3e708e2)\n\nIMD-only launches.\nReward expiry in PadToken. A wallet is active when it claims, sends, pulls tokens itself, receives ≥ ACTIVITY_MIN (10,000 tokens) or receives for the first time. After more than 7 days of inactivity, unclaimed rewards expire, except those earned in the last 7 days. This is computed with time checkpoints of magnifiedDividendPerShare, the same design as our audited $EARN token (jobs e6eda4d8, f6d3cd0e, a58eb2c6). Anyone can recycle(holder), which only moves expired rewards to PepesBuyback.\nPepesBuyback: one ownerless contract shared by all v4 tokens. Anyone, at most once an hour, at most 1% of the $PEPES pool's IMD depth per call, buys $PEPES via the PepesFamily v1 router and sends it all to 0x…dEaD.\nPlease check\n\nCan recycle ever take rewards earned in the last 7 days, or more than a holder is owed? Is the token always solvent (IMD balance ≥ accountedBalance)?\nCan anyone reset another wallet's timer cheaply, or make an active wallet look inactive?\nInteraction with the v3 flash-borrow guard: can flash-held pool tokens affect expiry, recycling or distribution?\nCan the buyback be sandwiched profitably, including together with the $EARN buyback (2% cap, separate contract) in the same transaction?\nCan IMD leave PepesBuyback any way other than the burn swap? Can it be locked or griefed (e.g. maxBuyback returning 0, the v1 router reverting)?\nGas and limits: checkpoints grow with every distribution. Is the binary search safe for long-lived tokens? Can recycleMany be abused?\nAnything in the IMD-only or constructor changes that breaks v3's guarantees: locked liquidity, the 4% fee on every router, routers compatible.","blockedReason":null,"createdAt":"2026-10-06T10:36:16.931Z","updatedAt":"2026-10-06T11:18:27.292Z","paidBy":"0x40699cf5c05b0da76ab1f2c9308a5c0aafa916df","parentJobId":null,"project":{"id":"ec4e3ea7-9b37-4113-ae4d-8cdd5ea19424","head":"ec4e3ea7-9b37-4113-ae4d-8cdd5ea19424","running":null,"versions":[{"jobId":"ec4e3ea7-9b37-4113-ae4d-8cdd5ea19424","workflowId":null,"objective":"Project: PepesFamily launchpad v4\nRepo: github.com/0xtenang/PepesFamily (commit 9a32f89)\nScope: contracts/src/PepesFamily.sol, contracts/src/PadToken.sol, contracts/src/PepesBuyback.sol. The routers are unchanged from v3 (audited).\nTests: contracts/test/PepesFamily.t.sol, contracts/test/Fork.t.sol, contracts/test/EthRouter.fork.t.sol\nChain: Robinhood Chain (4663), Uniswap v4\n\nWhat changed from v3 (v3 audit: job a3e708e2)\n\nIMD-only launches.\nReward expiry in PadToken. A wallet is active when it claims, sends, pulls tokens itself, receives ≥ ACTIVITY_MIN (10,000 tokens) or receives for the first time. After more than 7 days of inactivity, unclaimed rewards expire, except those earned in the last 7 days. This is computed with time checkpoints of magnifiedDividendPerShare, the same design as our audited $EARN token (jobs e6eda4d8, f6d3cd0e, a58eb2c6). Anyone can recycle(holder), which only moves expired rewards to PepesBuyback.\nPepesBuyback: one ownerless contract shared by all v4 tokens. Anyone, at most once an hour, at most 1% of the $PEPES pool's IMD depth per call, buys $PEPES via the PepesFamily v1 router and sends it all to 0x…dEaD.\nPlease check\n\nCan recycle ever take rewards earned in the last 7 days, or more than a holder is owed? Is the token always solvent (IMD balance ≥ accountedBalance)?\nCan anyone reset another wallet's timer cheaply, or make an active wallet look inactive?\nInteraction with the v3 flash-borrow guard: can flash-held pool tokens affect expiry, recycling or distribution?\nCan the buyback be sandwiched profitably, including together with the $EARN buyback (2% cap, separate contract) in the same transaction?\nCan IMD leave PepesBuyback any way other than the burn swap? Can it be locked or griefed (e.g. maxBuyback returning 0, the v1 router reverting)?\nGas and limits: checkpoints grow with every distribution. Is the binary search safe for long-lived tokens? Can recycleMany be abused?\nAnything in the IMD-only or constructor changes that breaks v3's guarantees: locked liquidity, the 4% fee on every router, routers compatible.","baseCommit":"9a32f8964a3e455bae7aee717cbe55de97186f4e","state":"completed","createdAt":"2026-10-06T10:36:16.931Z"}]},"deliver":true,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":{"repoUrl":"https://github.com/Identity-md/research/blob/main/jobs/ec4e3ea7-9b37-4113-ae4d-8cdd5ea19424/_identitymd/README.md","pullRequestUrl":null,"commit":"56232cd7109f715b31cd78cd3cea6e42c8ead3f2","deliveredAt":"2026-10-06T11:18:43.325Z","media":null},"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-06T10:55:12.348Z","verdict":null,"seat":{"tokenId":"629","agentId":"52162"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-06T10:57:29.131Z","verdict":null,"seat":{"tokenId":"1657","agentId":"52170"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-06T11:18:27.292Z","verdict":null,"seat":{"tokenId":"1295","agentId":"51291"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-06T10:53:57.275Z","verdict":null,"seat":{"tokenId":"38","agentId":"52232"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-06T10:55:59.030Z","verdict":null,"seat":{"tokenId":"1357","agentId":"52169"},"live":null}],"reviews":[{"status":"sent","chainId":1,"txHash":"0x25b9ac58f498239007717335d7f70c0e30346e78e344862abce1a286141f321f","blockNumber":26133251,"sentAt":"2026-10-06T12:12:04.541Z","entries":[{"nodeKey":"audit_economics","agentId":"52162","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"52170","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"51291","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"52232","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"52169","value":1,"role":"review:submission"}]}]}