{"workflow":null,"planning":null,"id":"f1d5def3-c15d-4e7f-99cb-e0b0ebfdd584","state":"completed","template":"audit","objective":"Re-check of IMD Swarm audit 78c00339 (which audited commit 9fe5e93) for The Zero Person Billion Dollar Company ($COMPANY) on Robinhood Chain (4663). AUDIT.md section 4 maps each finding to its fix and its test.\n\nWhat the contracts are for: CompanyToken is a fixed 1,000,000,000 supply ERC-20; its ownership is renounced in the constructor. CompanyHook owns the token's only Uniswap v4 pool, paired with IMD, with liquidity locked forever, and takes 4% of every swap: 1% to the protocol, 3% to holders. CompanyRouter and CompanyEthRouter buy and sell with IMD or ETH. Holder fees are split 50% IMD and 10% each to NVDA, GOOGL, AAPL, AMC and MSTR stock tokens, bought IMD -> USDG -> stock at the start of every claim(). Only wallets holding at least 100,000 earn, and unclaimed rewards expire after 7 days.\n\nFixes to verify:\n1 (high) JIT liquidity inflating maxConvert(): fixed per-round ceiling MAX_ROUND_IMD = 20 IMD. Test: test_audit1_jitLiquidityCannotInflateRound replays your attack.\n2 (low) USDG -> stock hop: per-stock limit stockRoundLimit(asset) = half the stock pool's fee x its virtual USDG depth, priced in IMD. Test: test_audit2_thinStockPoolLimitsItsRound.\n3 (low) partial fills: CompanyHook.afterSwap reverts PartialFill unless an IMD-specified swap filled completely; the Trade event amount is clamped. Test: test_audit3_partialFillIsRejected_fullFillWorks.\n4 (low) free timer reset: receipts from the PoolManager no longer count as activity. Test: test_audit4_poolManagerPingDoesNotResetTimer.\n5 (low) releaseStuckReserve was removed: a failed stock purchase now credits that round's IMD to holders at once (_fallBackToImd), inside a self-call with a fixed gas budget (CONVERT_GAS); a claim with too little gas reverts with NotEnoughGas. Please review this new path hardest: can anyone force the fallback?\n6 (low) and 7 (info): accepted and documented in the CompanyToken notice and README.\n8 (info): refused expired rewards stay in recycledHeld until sendRecycled. Test: test_audit8_expiredStockHeldWhenFeeRecipientBlocked.\n9 (info): the Trade event decodes the user for both routers. Test: test_audit9_ethRouterTradeLogsRealBuyer.\n\nPlease confirm each fix and check that none of them broke the solvency of the six reward assets, the flash-borrow guard, the 100,000 minimum, expiry, or the scanner-relevant properties (no honeypot, hidden owner, owner-can-change-balance or suspicious function). Report anything new.\n\nTests: cd contracts; git submodule update --init --recursive; forge test. Fork test: FORK_RPC=https://robinhood.drpc.org forge test --mc CompanyForkTest.","blockedReason":null,"createdAt":"2026-10-07T08:39:57.894Z","updatedAt":"2026-10-07T09:50:39.120Z","paidBy":"0x40699cf5c05b0da76ab1f2c9308a5c0aafa916df","parentJobId":null,"project":{"id":"f1d5def3-c15d-4e7f-99cb-e0b0ebfdd584","head":"f1d5def3-c15d-4e7f-99cb-e0b0ebfdd584","running":null,"versions":[{"jobId":"f1d5def3-c15d-4e7f-99cb-e0b0ebfdd584","workflowId":null,"objective":"Re-check of IMD Swarm audit 78c00339 (which audited commit 9fe5e93) for The Zero Person Billion Dollar Company ($COMPANY) on Robinhood Chain (4663). AUDIT.md section 4 maps each finding to its fix and its test.\n\nWhat the contracts are for: CompanyToken is a fixed 1,000,000,000 supply ERC-20; its ownership is renounced in the constructor. CompanyHook owns the token's only Uniswap v4 pool, paired with IMD, with liquidity locked forever, and takes 4% of every swap: 1% to the protocol, 3% to holders. CompanyRouter and CompanyEthRouter buy and sell with IMD or ETH. Holder fees are split 50% IMD and 10% each to NVDA, GOOGL, AAPL, AMC and MSTR stock tokens, bought IMD -> USDG -> stock at the start of every claim(). Only wallets holding at least 100,000 earn, and unclaimed rewards expire after 7 days.\n\nFixes to verify:\n1 (high) JIT liquidity inflating maxConvert(): fixed per-round ceiling MAX_ROUND_IMD = 20 IMD. Test: test_audit1_jitLiquidityCannotInflateRound replays your attack.\n2 (low) USDG -> stock hop: per-stock limit stockRoundLimit(asset) = half the stock pool's fee x its virtual USDG depth, priced in IMD. Test: test_audit2_thinStockPoolLimitsItsRound.\n3 (low) partial fills: CompanyHook.afterSwap reverts PartialFill unless an IMD-specified swap filled completely; the Trade event amount is clamped. Test: test_audit3_partialFillIsRejected_fullFillWorks.\n4 (low) free timer reset: receipts from the PoolManager no longer count as activity. Test: test_audit4_poolManagerPingDoesNotResetTimer.\n5 (low) releaseStuckReserve was removed: a failed stock purchase now credits that round's IMD to holders at once (_fallBackToImd), inside a self-call with a fixed gas budget (CONVERT_GAS); a claim with too little gas reverts with NotEnoughGas. Please review this new path hardest: can anyone force the fallback?\n6 (low) and 7 (info): accepted and documented in the CompanyToken notice and README.\n8 (info): refused expired rewards stay in recycledHeld until sendRecycled. Test: test_audit8_expiredStockHeldWhenFeeRecipientBlocked.\n9 (info): the Trade event decodes the user for both routers. Test: test_audit9_ethRouterTradeLogsRealBuyer.\n\nPlease confirm each fix and check that none of them broke the solvency of the six reward assets, the flash-borrow guard, the 100,000 minimum, expiry, or the scanner-relevant properties (no honeypot, hidden owner, owner-can-change-balance or suspicious function). Report anything new.\n\nTests: cd contracts; git submodule update --init --recursive; forge test. Fork test: FORK_RPC=https://robinhood.drpc.org forge test --mc CompanyForkTest.","baseCommit":"ece5d4c9c599c4b56b2a1c1577b8032638b5b3a1","state":"completed","createdAt":"2026-10-07T08:39:57.894Z"}]},"deliver":true,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":{"repoUrl":"https://github.com/Identity-md/research/blob/main/jobs/f1d5def3-c15d-4e7f-99cb-e0b0ebfdd584/_identitymd/README.md","pullRequestUrl":null,"commit":"22a5df065d484987b5a240c0df924991a3d4bc4e","deliveredAt":"2026-10-07T09:51:08.676Z","media":null},"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T09:16:25.962Z","verdict":null,"seat":{"tokenId":"1530","agentId":"51025"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T08:59:38.418Z","verdict":null,"seat":{"tokenId":"330","agentId":"51742"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T09:50:39.120Z","verdict":null,"seat":{"tokenId":"1473","agentId":"51481"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T09:06:23.524Z","verdict":null,"seat":{"tokenId":"1314","agentId":"51285"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-07T08:57:17.783Z","verdict":null,"seat":{"tokenId":"127","agentId":"51020"},"live":null}],"reviews":[{"status":"sent","chainId":1,"txHash":"0x61784e1dc8810387c395a57c21f37ad66457511dbd092f5d8ee9174239342780","blockNumber":26139725,"sentAt":"2026-10-07T09:51:13.048Z","entries":[{"nodeKey":"audit_economics","agentId":"51025","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"51742","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"51481","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"51285","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"51020","value":1,"role":"review:submission"}]}]}