{"assessments":[],"deployments":[],"fuzz":[],"identity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"interpretation":"Records acceptance and evidence. Neither completion nor an AI assessment establishes correctness, safety, or independent review.","jobId":"56fc854c-53d8-4a0c-8989-d652a9d05690","kind":"shape:chain","nodes":[{"acceptedSubmissionHash":"a234fb499420a852da0ae79598a80de30a3e5f09cd62250cc96eadaa2992ba11","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_economics","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"1794b4b9fd80f06b3830ac21d1f5c478c9014d37b0bd2ba9678185854a9cd9d3","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_flow","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"22258ebe80750dc6e7192e5e0aa4afaee715768db6cfe3afa436d9a510567ccd","dependsOn":["build_contract_project","write_foundry_tests","manifest","audit_math","audit_permissions","audit_economics","audit_flow"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"af3aa01159bbf354f621cafa5c0006f6169e0938a8b015be508b7377dbf165bc","skillId":"audit-judge","tools":[]},"key":"audit_judge","kind":"code","role":"review","skillHash":"af3aa01159bbf354f621cafa5c0006f6169e0938a8b015be508b7377dbf165bc","skillId":"audit-judge","state":"accepted"},{"acceptedSubmissionHash":"9b8518d76d4bbefc81a13e1002f1690f64d0e47b88586822960acb82732b5c8d","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_math","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"6c350189de4f900c0bd383edf3286993bf66a1211d7cd0d99566eabc45c4bbdf","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","tools":[]},"key":"audit_permissions","kind":"code","role":"review","skillHash":"e5ac2cb1fd91a56aa40b16487fc230c48de0d317c8266140331dd3219bb40a85","skillId":"audit-specialist","state":"accepted"},{"acceptedSubmissionHash":"0351bf3a02ea2aaab1e7fd51dde706b9e0622a865442a5b3059b46d3997a705b","dependsOn":[],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"6e3e328aa196f6965a2821b098b101e9ff09eef55cdaafaec1d6ea18007b96f6","skillId":"build-contract-project","tools":[]},"key":"build_contract_project","kind":"code","role":"implement","skillHash":"6e3e328aa196f6965a2821b098b101e9ff09eef55cdaafaec1d6ea18007b96f6","skillId":"build-contract-project","state":"accepted"},{"acceptedSubmissionHash":"a166b8522da06265cff4718290e523c9b6f7c727ec2da23641bd622b8856f121","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"tools":[]},"key":"manifest","kind":"code","role":"integrate","skillHash":null,"skillId":null,"state":"accepted"},{"acceptedSubmissionHash":"2ed03577cf997235fb99e0c7a239a09fc29b9e70b016c5a708e6e3740c53787a","dependsOn":["build_contract_project"],"execution":{"network":false,"profile":"foundry","requires":[],"skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","tools":[]},"key":"write_foundry_tests","kind":"code","role":"tests","skillHash":"73431852439ad3a343f3d2b7db1c43cd363b9f48f9bb51497374a0cf6d50b223","skillId":"write-foundry-tests","state":"accepted"}],"objective":"A custom token: On-Chain Oppenheimer (NUKE).\nToken name: On-Chain Oppenheimer\nToken symbol: NUKE\nToken supply: 1,000,000,000 with 18 decimals, all minted once to the deployer in the constructor.","parentJobId":null,"planHash":"6275af2ae26d6e656dc5ad88d4fd96c890841c294a5c9b9fc4ad9a88726bf8f2","previousHash":"0000000000000000000000000000000000000000000000000000000000000000","projectId":"56fc854c-53d8-4a0c-8989-d652a9d05690","publication":{"commit":null,"deliveredAt":null,"repoUrl":"https://github.com/identity-md-launches/launch-1149-on-chain-oppenheimer"},"receiptIdentity":{"adapter":"0xde152afb7db5373f34876e1499fbd893a82dd336","chainId":1,"collection":"0x0000ec93127baa929e58e97dd0095a2bfb38ec1d","registry":"0x8004a169fb4a3325136eb29fa0ceb6d2e539a432"},"registry":"0xb6d0a187b050fa5bb0b87033a203f37becf4a775","research":[],"schema":"identitymd-work-v1","signals":[{"agentId":"51084","feedbackHash":"420f9564d6723b6ce56c46ab136d370a154589dd2b10847d6219ab4068f038eb","nodeKey":"audit_economics","submissionHash":"a234fb499420a852da0ae79598a80de30a3e5f09cd62250cc96eadaa2992ba11","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51315","feedbackHash":"c431e1aead89a4d5cc180c1d79805849c7469342b1567ac864d0a179e8b04fd8","nodeKey":"audit_flow","submissionHash":"1794b4b9fd80f06b3830ac21d1f5c478c9014d37b0bd2ba9678185854a9cd9d3","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"52017","feedbackHash":"94c86a5d3771b854e48305e3b06de623f2aa4bd76939c121cd4f182558d13e3c","nodeKey":"audit_judge","submissionHash":"22258ebe80750dc6e7192e5e0aa4afaee715768db6cfe3afa436d9a510567ccd","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51511","feedbackHash":"1471197091dd7b697c87c9d02ac14c4508d198ede7787ef2644cd088990265a0","nodeKey":"audit_math","submissionHash":"9b8518d76d4bbefc81a13e1002f1690f64d0e47b88586822960acb82732b5c8d","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"51145","feedbackHash":"b7f6d05fa9f928631ec8153a8e4ee7e06fad47d26f47544e23eeb628e40fad0b","nodeKey":"audit_permissions","submissionHash":"6c350189de4f900c0bd383edf3286993bf66a1211d7cd0d99566eabc45c4bbdf","tag1":"review:submission","tag2":"acceptance-v2","value":1},{"agentId":"52481","feedbackHash":"7517a45ab3343df495b0fda99d824cd0ff4c719ff5b4fd26f2b82308d734a941","nodeKey":"build_contract_project","submissionHash":"0351bf3a02ea2aaab1e7fd51dde706b9e0622a865442a5b3059b46d3997a705b","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"51428","feedbackHash":"93181bde11a37052e6d5197361f4087de6e065483bf9b09d25031967113e389e","nodeKey":"manifest","submissionHash":"a166b8522da06265cff4718290e523c9b6f7c727ec2da23641bd622b8856f121","tag1":"verification:checks","tag2":"acceptance-v2","value":1},{"agentId":"51538","feedbackHash":"cd6325c99bfb4d589d23e89fc3cd59472c31fe5582c44c9684b6d91420a3a32f","nodeKey":"write_foundry_tests","submissionHash":"2ed03577cf997235fb99e0c7a239a09fc29b9e70b016c5a708e6e3740c53787a","tag1":"verification:checks","tag2":"acceptance-v2","value":1}],"site":null,"snapshotHash":"de72cc51ab8c420eb7177c716975e57fe1f1fda490c4df44762cc17024e20dfd","state":"completed","submissions":[{"artifacts":[],"attempt":1,"bundleHash":"e59b0f1f8d8f0141a1cc5d0521f27a233fa4c468bf152c1988eb0b551b74d3fc","device":"a4e285247c6f8aed","findings":[],"hash":"0351bf3a02ea2aaab1e7fd51dde706b9e0622a865442a5b3059b46d3997a705b","nodeId":"e25f186d-400d-4bc5-b524-857aa05dfde1","outcome":"completed","summary":"The deliverable is complete and committed on main. The working tree is clean, with 47 tracked files.\n\n**What was built**\n\n- `src/NukeToken.sol`: a plain fixed-supply ERC-20 named On-Chain Oppenheimer, symbol NUKE, 18 decimals. The constructor takes no arguments, makes no external calls, and mints the whole supply to the deployer once. There is no owner, mint, pause, blacklist, fee or burn path, and no delegatecall or selfdestruct in the runtime. The contract name is nine characters, inside the manifest's 32-character limit.\n- `foundry.toml` at the repository root pins solc 0.8.26 with `bytecode_hash = \"none\"` and metadata disabled, and leaves ffi and filesystem access off. The built bytecode carries no CBOR metadata trailer.\n- forge-std v1.11.0 is vendored under lib/ as ordinary files, with its git metadata removed. No submodule exists.\n- A deploy script whose logic is a plain function the tests call directly. It reads no environment.\n- A README covering behaviour, assumptions, the exact manifest values, the 10/88/2 split of the supply, what the requester must control after launch, and the security checklist items reviewed.\n\n**Verification**\n\n| Check | Result |\n|---|---|\n| forge build (clean, empty environment) | passes |\n| forge test (empty environment) | 45 passed, 0 failed |\n| forge fmt --check | passes |\n\nThe tests cover metadata, the one-time mint, every success and failure path of transfer, approve and transferFrom, fuzzed conservation of supply, an invariant suite over random activity, a CREATE2 factory simulation that mirrors the protected launch test's flows, and the absence of any admin selector. The pinned protected test itself needs the launch's pool manager sources and environment, so it could not be run here. The token has no transfer hooks, so its seed and swap flows move exactly what they say.\n\n**Open items for others**\n\n- No launch.json was written, as the brief requires. The README lists the values for the manifest step.\n- Slither and Mythril were not available, so only forge ran. An independent adversarial review is still recommended before admission.","treeHash":"af321ae2106eaec85c632eb374f0a797bfdfdfb4","usage":{"cachedInputTokens":786981,"inputTokens":450,"model":"claude-fable-5-1","outputTokens":26734,"runtime":"claude","turns":27,"wallClockMs":440730}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"e3a598aae0640402","findings":[{"citation":"resolved","description":"Execution trace, sentinel/boundary case amount == 0. `_spendAllowance` only reverts when `current < amount`; with amount 0 that is never true, so `transferFrom(from, to, 0)` succeeds for any `from` (including address(0)) from any caller with zero allowance, and `_transfer` then emits `Transfer(from, to, 0)`. No balance or allowance changes and the supply is untouched, so there is no loss of funds. The consequence is event-level only: an unprivileged account can inject a `Transfer` log that names any holder as sender (the address-poisoning pattern, where a look-alike recipient address is planted in a victim's transfer history) or that looks like a zero-value mint from address(0). This matches EIP-20 (zero-value transfers MUST fire Transfer) and OpenZeppelin/Solmate behaviour, so it is a documented trade-off rather than a defect to fix; it is recorded because the NatSpec at line 13 says balances only move when authorised by the holder, and readers of the event log may assume the same of events. A fix, if wanted, is `if (amount == 0) revert` or requiring `current >= amount` only when amount > 0 with an explicit allowance precheck; either diverges from the standard and is not recommended without a product reason.","line":157,"path":"src/NukeToken.sol","reproduction":"State: deployer calls transfer(victim, 1000e18); allowance(victim, attacker) == 0. Input: vm.prank(attacker); token.transferFrom(victim, lookalike, 0). Expected (per the contract's own NatSpec that only holder-authorised actions touch a holder): revert InsufficientAllowance. Actual: returns true and emits Transfer(victim, lookalike, 0); balanceOf(victim) stays 1000e18. Same with from = address(0): transferFrom(address(0), lookalike, 0) emits Transfer(address(0), lookalike, 0) while totalSupply() stays 1e27. Verified with test/scratch/ZeroValueEvents.t.sol (2 passing tests reproducing both events via vm.expectEmit).","severity":"info","snippet":"        if (current < amount) revert InsufficientAllowance(spender, current, amount);","title":"Zero-amount transferFrom needs no allowance, so anyone can emit Transfer(victim, X, 0) and Transfer(address(0), X, 0) events"}],"hash":"1794b4b9fd80f06b3830ac21d1f5c478c9014d37b0bd2ba9678185854a9cd9d3","nodeId":"7a221517-5f6f-4acd-a99b-796d9e2165c9","outcome":"completed","summary":"The review is complete and the findings file is written and validated.\n\n**Outcome:** no defect of low severity or above in `NukeToken`. The findings file holds one informational item and a full coverage record.\n\n**What I checked, in my assigned area:**\n- **Execution Trace:** traced `transfer`, `approve` and `transferFrom` from entry to final storage. Amounts move exactly, the self-transfer case nets to zero, the unchecked blocks are guarded by the comparison directly above them, and no external call or stale read exists.\n- **Periphery:** the interface, the vendored forge-std, and the deploy script. forge-std is 36 ordinary tracked files with no gitlink or nested `.git`, so the offline verifier can resolve it. The compiled ABI has exactly the three listed mutators plus views, no fallback or receive.\n- **First Principles:** the supply is a compile-time constant and every balance write is a matched debit and credit, so the sum of balances always equals the supply and the credit cannot overflow. Name, symbol, decimals and supply match the brief. An opcode scan of the runtime found no CALL-family opcode at all.\n\n**The one item reported (info):** a zero-amount `transferFrom` passes the allowance check for any `from`, including the zero address, and emits a `Transfer` event the holder never authorised. No balance or supply changes. EIP-20 requires zero-value transfers to fire the event and OpenZeppelin behaves the same, so I flagged it as a documented trade-off rather than a defect, with a passing scratch test reproducing both event shapes.\n\n**Coverage record:** all three verifier entry points are answered (approve holds, transfer holds, transferFrom carries the info finding), plus ten rows for the constructor, the supply and launch-flow invariants, the no-privilege invariant, the opcode invariant, and the periphery files. Nothing in my area was left unreached.","treeHash":null,"usage":{"cachedInputTokens":521694,"inputTokens":226,"model":"claude-fable-5-1","outputTokens":12778,"runtime":"claude","turns":25,"wallClockMs":206188}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"9df7d5d52e83c572","findings":[{"citation":"resolved","description":"`_transfer` (src/NukeToken.sol:135-146) validates only the recipient: the guard at line 136, `if (to == address(0)) revert ZeroAddress();`, has no counterpart for `from`. The one caller that can pass an arbitrary `from` is `transferFrom` (lines 125-129), whose only guard is `_spendAllowance(from, msg.sender, amount)` (lines 154-161), and that guard passes for `amount == 0` whatever the allowance because `current < amount` is `0 < 0`. So any unprivileged account can call `transferFrom(address(0), anyone, 0)`: the allowance check passes (allowance of address(0) is 0, `0 < 0` is false), the balance check passes (`_balances[address(0)] == 0`, `0 < 0` is false), the unchecked block writes `0 - 0` and `+= 0`, and line 145 emits `Transfer(address(0), anyone, 0)`. The repository's own interface documents a Transfer whose `from` is the zero address as a mint (src/interfaces/IERC20.sol:7: 'Minting is `from == address(0)`') and the contract NatSpec at line 8 promises 'Nothing can mint afterwards'. Balances, allowances and `totalSupply()` are untouched: the supply is a compile-time constant, and the non-zero variant reverts with InsufficientAllowance because address(0) can never set an allowance. There is therefore no loss of funds; the harm is to off-chain consumers: explorers and indexers list spurious post-launch 'mint' rows naming any recipient, and monitoring that alerts on Transfer-from-zero after the launch's single mint can be tripped at will by anyone. OpenZeppelin's ERC20 rejects this path with `ERC20InvalidSender(address(0))`; this implementation mirrors OpenZeppelin's other zero-address guards (recipient at line 136, spender at line 149) but drops this one, which is the asymmetry. Merged from four specialist reports of the same root cause: audit_flow 10b8bea9, audit_math c628e1cf, audit_economics d995ca9a and audit_permissions 59f988d6 (whose proof is attached: it fails on this code for the stated reason). The audit_flow facet, that a zero-amount `transferFrom(holder, lookalike, 0)` from a caller with no allowance also succeeds and emits `Transfer(holder, lookalike, 0)`, reproduces as well but is EIP-20-conformant (zero-value transfers MUST fire Transfer; OpenZeppelin and Solmate behave identically), so it is not counted as a defect and the fix below deliberately leaves it alone. Severity low: no balance, allowance or supply guarantee breaks; only event consumers are affected. Minimal fix preserving intended behaviour: add `if (from == address(0)) revert ZeroAddress();` at the top of `_transfer`. The constructor does not use `_transfer`, so the genuine mint event is unaffected, and no launch flow (factory, MerkleDistributor, PoolManager, traders) ever passes `from == address(0)`. Verified on a scratch copy with that one line added: the proof passes, and transfers, pulls with finite and infinite allowances, and self-transfers behave exactly as before.","line":136,"path":"src/NukeToken.sol","proof":"// SPDX-License-Identifier: MIT\npragma solidity 0.8.26;\n\nimport {Test} from \"forge-std/Test.sol\";\nimport {IERC20} from \"src/interfaces/IERC20.sol\";\nimport {NukeToken} from \"src/NukeToken.sol\";\n\n/// @notice `_transfer` rejects `to == address(0)` but not `from == address(0)`. Because the\n///         zero address can never call `approve`, its allowance is always 0, so only a\n///         zero-amount pull slips through: `transferFrom(address(0), to, 0)` succeeds and emits\n///         `Transfer(address(0), to, 0)`, the exact shape of a mint event. Fails on the current\n///         code, passes once `_transfer` reverts for `from == address(0)`.\ncontract ZeroSenderTest is Test {\n    address internal deployer = makeAddr(\"deployer\");\n    address internal attacker = makeAddr(\"attacker\");\n    address internal victim = makeAddr(\"victim\");\n\n    NukeToken internal token;\n\n    function setUp() public {\n        vm.prank(deployer);\n        token = new NukeToken();\n    }\n\n    function test_transferFromZeroAddressSenderReverts() public {\n        vm.expectRevert();\n        vm.prank(attacker);\n        token.transferFrom(address(0), victim, 0);\n    }\n}","reproduction":"State: fresh NukeToken deployed by `deployer` (balanceOf(deployer) == 1000000000000000000000000000); `attacker` and `victim` are arbitrary EOAs; allowance(address(0), attacker) == 0 and can never become non-zero. Call: `vm.prank(attacker); token.transferFrom(address(0), victim, 0)`. Expected (per the contract's own 'Minting is from == address(0)' and 'Nothing can mint afterwards' documentation, and per the reference implementation): revert with ZeroAddress(). Actual: returns true and the token emits `Transfer(from: 0x0000000000000000000000000000000000000000, to: victim, value: 0)`; afterwards totalSupply() == 1000000000000000000000000000, balanceOf(victim) == 0, balanceOf(address(0)) == 0, allowance(address(0), attacker) == 0. Contrast: `transferFrom(address(0), victim, 1)` reverts with InsufficientAllowance(attacker, 0, 1), so no value can move. Run: `forge test --match-path test/scratch/Proof_59f988d6771f.t.sol` on this tree fails with 'next call did not revert as expected' and the trace shows `emit Transfer(from: 0x0000000000000000000000000000000000000000, to: victim, amount: 0)` followed by `[Return] true`; the same test passes once `_transfer` rejects `from == address(0)` (checked against a copy of the contract with that line added).","severity":"low","snippet":"        if (to == address(0)) revert ZeroAddress();","title":"transferFrom accepts address(0) as `from` for zero amounts, so anyone can emit a mint-shaped Transfer(0x0, to, 0) event after launch"}],"hash":"22258ebe80750dc6e7192e5e0aa4afaee715768db6cfe3afa436d9a510567ccd","nodeId":"09ed24c3-6043-4a0e-bb4a-66227452e481","outcome":"completed","summary":"Review complete. No tracked file changed; the findings file sits at the repository root and my scratch tests under test/scratch, both ignored by git.\n\n**Outcome: one low-severity finding, no blocking defects.** The NUKE token is a plain fixed-supply ERC-20 and every launch flow moves exact amounts.\n\n**What the four specialists reported** was the same root cause four times, three at info and one at low. I reproduced it, merged it, and kept it at low:\n\n- **`transferFrom(address(0), anyone, 0)` succeeds and emits `Transfer(0x0, anyone, 0)`**, a mint-shaped event, from any unprivileged caller. The sender check is missing at `src/NukeToken.sol:136` while the recipient and spender checks exist, and the allowance guard passes for amount zero. The repository's own interface defines a Transfer from the zero address as a mint and the contract promises nothing mints after the constructor. Balances, allowances and supply never change, and the non-zero variant reverts, so the harm is limited to explorers, indexers and mint-alert monitoring. One-line fix: reject a zero `from` in `_transfer`. I verified the specialist's attached proof fails on this code for the stated reason and passes on a fixed copy, and kept it on the finding.\n- The address-poisoning facet from the flow specialist (zero-value `transferFrom` from any holder without allowance) reproduces but is EIP-20-conformant and matches OpenZeppelin, so it is folded into the description as not a defect.\n\n**My own pass found nothing further.** Verified: constructor mints exactly 1e27 to the factory with no arguments or external calls; supply is a pure constant and the only balance writer conserves it; no owner, fallback or receive, so admin selectors and plain ETH revert; unchecked arithmetic is bounded by the constant supply; runtime has no DELEGATECALL, CALLCODE or SELFDESTRUCT; creation and runtime bytecode are well under the factory's limits; launch.json uses only schema keys with correct types, lowercase addresses, supply matching the mint, and an empty constructor argument list matching the no-argument constructor. Both static analysis leads (none from Slither, one large-literal style note from Aderyn) were checked and do not reproduce as defects.\n\n**Coverage record:** all three listed entry points answered (approve and transfer hold, transferFrom carries finding 1), plus rows for the constructor, the supply invariant, deployability, and the manifest. The project's full test suite (81 tests including two invariant suites) passes on this tree.","treeHash":null,"usage":{"cachedInputTokens":1312956,"inputTokens":322,"model":"claude-fable-5-1","outputTokens":33067,"runtime":"claude","turns":39,"wallClockMs":518394}},{"artifacts":[],"attempt":1,"bundleHash":"32d3544bc89198fa834e55950fa7c9f2f6066acef4ce2f2388a6445e9b7d8c8e","device":"b57ae3a96321a0e1","findings":[],"hash":"2ed03577cf997235fb99e0c7a239a09fc29b9e70b016c5a708e6e3740c53787a","nodeId":"7b66e435-a4b4-46a2-88b7-7e0675cdaed9","outcome":"completed","summary":"All checks are green and I am wrapping up with the recap.\n\nDone. The suite now has 81 passing tests across six files, with the two new files below adding 45 of them. I found no defect in the token after an adversarial read, so there is no findings file.\n\n**What I added** (both under `test/`, nothing else touched):\n\n- `NukeToken.model.invariant.t.sol`: a model-based invariant suite. The handler keeps its own ledger of every balance and allowance, predicts from that ledger whether each call must succeed or revert and with which exact error, performs the call, and asserts the outcome. It drives seven signers including a contract holder, plus the token contract and the zero address as recipients. Amounts are steered onto the boundaries (zero, one wei, exact balance, balance plus one) and allowances onto the sentinels (zero, max minus one, max). Ten invariants compare the token against the ledger: balances and allowances match, supply is conserved across every holder, every balance equals inflow minus outflow, the zero address never receives, the token contract is a sink, and pulls never exceed what an owner ever held. It runs 256 sequences of depth 64 via inline config with fail-on-revert on.\n- `NukeToken.edge.t.sol`: 35 unit and fuzz tests at 1000 runs for the inputs the existing suite did not pin. Self as counterparty in both transfer paths, the token contract as recipient, zero-value pulls with zero allowance, the revert ordering of allowance versus zero recipient versus balance, max minus one being finite, revoking an infinite allowance, exact event counts and topics via recorded logs, the standard ABI by signature with return-word checks, value attached to mutators, independent deployments, and fuzzed additivity, round trips, and both boundaries at exactly the limit and one past it.\n\n**Harness grounding.** Before trusting the model suite I ran it in scratch against three deliberately broken token copies: a one-wei skim, a non-decrementing allowance, and a hidden freeze on contract holders. All three failed it, each on the expected invariant.\n\n**One thing worth knowing.** The repo's foundry.toml sets invariant fail_on_revert to false, and under forge 1.8.3 that makes an assertion failure inside a handler count as an ordinary revert and pass silently. I confirmed this with a scratch probe. The existing invariant handler asserts nothing internally so it is unaffected, and my suite overrides the setting inline, but any future handler that asserts needs the same override.","treeHash":"69a2f1e6c7b37587c65d6a6ac7ab9b786984eab6","usage":{"cachedInputTokens":869008,"inputTokens":354,"model":"claude-fable-5-1","outputTokens":33280,"runtime":"claude","turns":22,"wallClockMs":474192}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"3b9f88f55251764d","findings":[{"citation":"resolved","description":"Area: Asymmetry (branch-symmetry diff, Pashov Asymmetry Agent step 3) and Access Control. `_transfer` validates the recipient (`to == address(0)` reverts) but never validates the sender, and `_approve` validates the spender but the owner side is implicitly msg.sender. The one caller that can pass an arbitrary `from` is `transferFrom`. Its only guard is `_spendAllowance(from, msg.sender, amount)` at line 126, which passes whenever `amount == 0` because `current < amount` is `0 < 0 == false`. So any unprivileged account can call `transferFrom(address(0), victim, 0)`: the allowance check passes with an allowance of 0, the balance check passes because `_balances[address(0)] == 0 >= 0`, and line 145 emits `Transfer(address(0), victim, 0)`. Per the IERC20 interface docstring in this repo (src/interfaces/IERC20.sol:7, 'Minting is from == address(0)') and the convention explorers and indexers follow, a Transfer whose `from` is the zero address is a mint. The token therefore lets anyone publish mint events, in any quantity, naming any recipient, after a launch whose brief says the supply is 'minted once'. No balance or the supply changes (totalSupply is a compile-time constant), so the impact is to off-chain consumers: explorers list fake 'mint' rows on the token page and the victim's address, and indexers that derive holder lists or mint history from Transfer-from-zero events record spurious entries. OpenZeppelin's ERC20 `_transfer` reverts with `ERC20InvalidSender(address(0))` for exactly this reason; this implementation drops that check. Minimal fix that preserves the intended behaviour: in `_transfer`, revert with `ZeroAddress()` when `from == address(0)` as well as when `to == address(0)` (the constructor does not use `_transfer`, so the genuine mint event is unaffected). Severity low: no funds move, no guarantee on balances or supply breaks, and the harm is to event consumers only.","line":136,"path":"src/NukeToken.sol","proof":"// SPDX-License-Identifier: MIT\npragma solidity 0.8.26;\n\nimport {Test} from \"forge-std/Test.sol\";\nimport {IERC20} from \"src/interfaces/IERC20.sol\";\nimport {NukeToken} from \"src/NukeToken.sol\";\n\n/// @notice `_transfer` rejects `to == address(0)` but not `from == address(0)`. Because the\n///         zero address can never call `approve`, its allowance is always 0, so only a\n///         zero-amount pull slips through: `transferFrom(address(0), to, 0)` succeeds and emits\n///         `Transfer(address(0), to, 0)`, the exact shape of a mint event. Fails on the current\n///         code, passes once `_transfer` reverts for `from == address(0)`.\ncontract ZeroSenderTest is Test {\n    address internal deployer = makeAddr(\"deployer\");\n    address internal attacker = makeAddr(\"attacker\");\n    address internal victim = makeAddr(\"victim\");\n\n    NukeToken internal token;\n\n    function setUp() public {\n        vm.prank(deployer);\n        token = new NukeToken();\n    }\n\n    function test_transferFromZeroAddressSenderReverts() public {\n        vm.expectRevert();\n        vm.prank(attacker);\n        token.transferFrom(address(0), victim, 0);\n    }\n}","reproduction":"State: fresh NukeToken deployed by `deployer`; `attacker` and `victim` are arbitrary EOAs with no allowance from anyone. Call: `vm.prank(attacker); token.transferFrom(address(0), victim, 0)`. Expected (per OpenZeppelin reference semantics and the 'minted once' brief): revert, so no Transfer event with from == address(0) can ever be emitted after the constructor. Actual: returns true and emits `Transfer(address(0), victim, 0)`; `totalSupply()` stays 1_000_000_000e18, `balanceOf(victim)` and `balanceOf(address(0))` are unchanged. The non-zero variant `transferFrom(address(0), victim, 1)` reverts with `InsufficientAllowance(attacker, 0, 1)`, so only zero-amount forgeries are reachable. The scratch test test_transferFromZeroAddressSenderReverts fails on this code with 'next call did not revert as expected' and passes once `_transfer` also rejects `from == address(0)`.","severity":"low","snippet":"        if (to == address(0)) revert ZeroAddress();\n        uint256 fromBalance = _balances[from];\n        if (fromBalance < amount) revert InsufficientBalance(from, fromBalance, amount);","title":"Asymmetric zero-address check: transferFrom(address(0), to, 0) succeeds and emits a mint-shaped Transfer event anyone can forge"}],"hash":"6c350189de4f900c0bd383edf3286993bf66a1211d7cd0d99566eabc45c4bbdf","nodeId":"9db3cf84-c693-41ad-a89a-1771dc1297e0","outcome":"completed","summary":"Review complete. The findings file is in place, the scratch directory is removed, and the working tree holds nothing but the required output.\n\n**Outcome: one low-severity finding, no critical, high or medium defects in the Access Control, Trust Gap and Asymmetry areas.**\n\n**What I covered**\n\n- **Access control map.** The token has no owner, modifier, initializer, receive, fallback, proxy or delegatecall. The constructor hands the whole supply to its caller and nothing else assigns a role. Each of the three mutators writes only storage the caller is entitled to: `approve` writes the caller's own allowance row, `transfer` debits only the caller, and `transferFrom` is gated by the allowance the owner granted the caller. I confirmed with scratch tests that the deployer has no special path, that allowance is not transitive, that a failed pull keeps the allowance intact, and that the infinite sentinel behaves at its boundary.\n- **Asymmetry.** The transfer and transferFrom pair, the approve and spend pair, the branch pairs inside each, and the lifecycle of both storage mappings are all mirrored, with one exception reported below.\n- **Trust gap.** There is no privileged actor, pricing formula, fee or settable recipient inside the contract, so no seam exists.\n- **Leads.** The aderyn large-literal note at line 43 is a compile-time constant equal to the brief's supply. The existing 45 tests, including the opcode scan for DELEGATECALL, CALLCODE and SELFDESTRUCT, all pass.\n\n**The finding (low).** The sender-side zero check is missing in `_transfer` at src/NukeToken.sol:136. Any account can call transferFrom with the zero address as sender and an amount of zero. The allowance check passes because zero is not less than zero, the balance check passes the same way, and the contract emits a Transfer event from the zero address. That is the shape explorers and indexers read as a mint, on a token whose brief says it mints once. No balance or supply changes. The fix is to revert on a zero sender as well as a zero recipient. The attached proof test fails on the current code and passes on a patched copy.\n\n**Coverage record.** All three listed entry points have rows: approve and transfer hold, transferFrom carries the finding. Five further rows record the constructor, the no-privileged-actor invariant, the supply conservation invariant, the trust-gap seams and the static-analysis lead.","treeHash":null,"usage":{"cachedInputTokens":799762,"inputTokens":354,"model":"claude-fable-5-1","outputTokens":15697,"runtime":"claude","turns":28,"wallClockMs":222900}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"fbcdfc017217af1f","findings":[{"citation":"resolved","description":"Boundary walk of the sentinel-address branches (Boundary guide, step 4): `_transfer` rejects `to == address(0)` but not `from == address(0)`. Nothing can ever credit `_balances[address(0)]` (transfers to it revert and there is no mint), so a non-zero amount always reverts with InsufficientBalance or InsufficientAllowance. The zero-amount case passes every check: `_allowances[address(0)][spender]` is 0 and `0 < 0` is false, `fromBalance (0) < 0` is false, and the function emits `Transfer(address(0), to, 0)`. By ERC-20 convention a Transfer whose `from` is the zero address is a mint, and the contract's own IERC20 NatSpec says so (`Minting is from == address(0)`). Any unprivileged caller can therefore emit an unlimited number of mint-shaped events with value 0 at any time. No balance, allowance or supply changes, so there is no loss of funds; the effect is limited to off-chain consumers that count mint events or derive supply from them, and to a deviation from the OpenZeppelin behaviour (`ERC20InvalidSender`) most integrators assume. Constructor mint, both unchecked blocks, the allowance sentinel, zero and full-balance transfers, self-transfers and the 10/88/2 launch split in minor units were all checked and hold; this is the only edge the code handles differently from the reference implementation.","line":137,"path":"src/NukeToken.sol","reproduction":"State: fresh NukeToken, any caller `alice` with no balance and no allowance. Call: vm.prank(alice); token.transferFrom(address(0), bob, 0). Expected (OpenZeppelin semantics): revert because `from` is the zero address. Actual: returns true and emits Transfer(address(0), bob, 0); totalSupply() stays 1e27 and every balance is unchanged. With amount 1 instead of 0 the call reverts InsufficientAllowance(alice, 0, 1) as expected. Minimal fix that preserves intent: add `if (from == address(0)) revert ZeroAddress();` at the top of `_transfer`.","severity":"info","snippet":"        if (to == address(0)) revert ZeroAddress();\n        uint256 fromBalance = _balances[from];\n        if (fromBalance < amount) revert InsufficientBalance(from, fromBalance, amount);","title":"transferFrom accepts from == address(0) and emits a mint-shaped Transfer(0, to, 0) event"}],"hash":"9b8518d76d4bbefc81a13e1002f1690f64d0e47b88586822960acb82732b5c8d","nodeId":"818077cd-5325-4d1f-aa2f-38aadbcbd952","outcome":"completed","summary":"Review complete. The findings file is written and validated, and the working tree is unchanged apart from the scratch test and the findings file, both of which are ignored or expected.\n\n**Outcome:** the math in `src/NukeToken.sol` holds. The token has no division, no scaling, no narrowing casts, no external calls and no payable path, so the Math Precision, Boundary and Numerical Gap guides reduce to a small surface, all of which I traced and exercised with tests.\n\nWhat I verified, by running the existing suite (53 tests, all pass) plus a scratch test under `test/scratch/`:\n- **Supply constant** evaluates to exactly 1e27 minor units, matching the brief and the manifest value.\n- **Unchecked blocks** are safe. The subtraction is guarded on the line above, and the credit cannot overflow because the sum of balances is the fixed supply. A self-transfer of the whole balance re-reads storage and conserves.\n- **Allowance sentinel** behaves correctly at the boundary. Max is treated as infinite, max minus one decrements exactly, a reverted `transferFrom` leaves the allowance untouched, and the balance check still binds when the allowance exceeds the balance.\n- **Launch split** of 10/88/2 percent is exact in minor units with no dust, and every leg is below the signed 128-bit bound the Uniswap v4 PoolManager uses for deltas.\n- **Invariant** that supply equals the sum of balances held across the fuzzed invariant run.\n\nOne finding, severity info: `transferFrom(address(0), to, 0)` is accepted by anyone and emits a Transfer event from the zero address, which ERC-20 convention and the contract's own interface comment define as a mint. No balance, allowance or supply changes, so there is no fund impact. The reproduction and a one-line fix are in the findings file. The coverage record answers all three listed entry points plus the constructor and two invariants.\n\nNothing in my area was left unreached. The aderyn lead about the large numeric literal on line 43 was checked and is not a defect.","treeHash":null,"usage":{"cachedInputTokens":595636,"inputTokens":258,"model":"claude-fable-5-1","outputTokens":12065,"runtime":"claude","turns":21,"wallClockMs":156835}},{"artifacts":[],"attempt":1,"bundleHash":"419ed3676aa5c9ccb4330a68d92fe81a3b1a64b719280877bcc203ad859c0969","device":"bc1e515ca5c78ac4","findings":[],"hash":"a166b8522da06265cff4718290e523c9b6f7c727ec2da23641bd622b8856f121","nodeId":"05a3e10d-426c-4b3b-bb11-96a2576b6ae6","outcome":"completed","summary":"I wrote launch.json for the On-Chain Oppenheimer (NUKE) launch. It is the only file added or changed in the tree.\n\nWhat the manifest says, matched against the accepted implementation:\n\n- **Token** is contract NukeToken with name On-Chain Oppenheimer, symbol NUKE, 18 decimals and an empty constructorArgs list. The compiled ABI confirms the constructor takes no inputs, and it mints the full supply once to msg.sender.\n- **totalSupply** is the exact minor-unit value of the contract's TOTAL_SUPPLY constant, 1,000,000,000 times ten to the eighteenth.\n- **contracts** is empty. The accepted tree holds only the token, its interface and a standalone deploy script, so there are no application contracts and no initialization calls to describe.\n- **pool and economics** are copied verbatim from the launch reference: IMD as the paired currency, fee 12500, tick spacing 60, the one-to-one provenance price, and the requester's 8800 bps, 2,500 IMD cap and remainder address.\n- **notes** describe the token's fixed-supply, no-admin, no-tax behaviour and why every launch flow arrives whole.\n\nVerification results:\n\n- `forge build` compiled cleanly and `forge test` passed all 45 tests across 4 suites, including the invariant suite.\n- A local script checked the manifest's keys against the schema, string and number types, lowercase addresses, name length and the economics object byte for byte.\n- `git status` shows launch.json as the only new file. No configuration, lib or workflow file was touched.","treeHash":"716c750f079bd8905fb236a72e8b36cc9158b35e","usage":{"cachedInputTokens":211335,"inputTokens":162,"model":"claude-fable-5-1","outputTokens":3412,"runtime":"claude","turns":10,"wallClockMs":49515}},{"artifacts":[],"attempt":1,"bundleHash":null,"device":"7c0191a32541eb74","findings":[{"citation":"resolved","description":"The contract deliberately rejects the zero address as a transfer recipient (`_transfer`, line 136) and as an approval spender (`_approve`, line 149), but `_transfer` never checks `from`. `transferFrom(address(0), to, 0)` therefore succeeds for any unprivileged caller: `_spendAllowance(address(0), msg.sender, 0)` passes because `0 < 0` is false, `_transfer(address(0), to, 0)` passes because the zero address's balance (0) is not below 0, and the contract emits `Transfer(address(0), to, 0)`, the exact shape indexers and explorers interpret as a mint. No value moves and `totalSupply()` is a compile-time constant, so there is no economic impact: this is an event-level asymmetry with the contract's own zero-address guards and a divergence from the OpenZeppelin convention (`ERC20InvalidSender(address(0))`) that the rest of the contract mirrors. A non-zero amount from address(0) reverts (first on allowance, then on balance), so the supply cannot be inflated by this path. Reported for completeness; a one-line `if (from == address(0)) revert ZeroAddress();` in `_transfer` closes it without changing any intended behaviour, and the launch flows (factory, distributor, PoolManager) are unaffected either way.","line":135,"path":"src/NukeToken.sol","reproduction":"State: fresh NukeToken, any caller `alice` with no allowance from anyone. Call: vm.prank(alice); token.transferFrom(address(0), bob, 0). Expected (by the contract's own ZeroAddress convention and OZ semantics): revert ZeroAddress(). Actual: returns true and emits Transfer(from=0x0000000000000000000000000000000000000000, to=bob, value=0); totalSupply() stays 1000000000000000000000000000 and balanceOf(bob) stays 0. Verified with a forge test asserting vm.expectEmit(Transfer(address(0), bob, 0)) on this call: it passes. Contrast: transferFrom(address(0), bob, 1) reverts InsufficientAllowance(alice, 0, 1), so no value can be minted.","severity":"info","snippet":"    function _transfer(address from, address to, uint256 amount) private {\n        if (to == address(0)) revert ZeroAddress();","title":"transferFrom accepts address(0) as `from`, emitting a zero-value mint-shaped Transfer event from any caller"}],"hash":"a234fb499420a852da0ae79598a80de30a3e5f09cd62250cc96eadaa2992ba11","nodeId":"84161a35-a0b4-4bd7-83ed-5b616fa58aaa","outcome":"completed","summary":"The findings file is in place at the repository root, and the harness itself excludes it from git via `.git/info/exclude`, so the tree is otherwise untouched. The scratch directory is removed. The review is complete.\n\n## Result\n\n**No material defect found.** The NUKE token is a plain fixed-supply ERC-20 with no external calls, no owner, no fee, no hooks, and a compile-time constant supply. Almost every failure mode in the Economic Security, Invariant and Flow Gap guides has no surface here, and the ones that do all hold.\n\n**One info-level finding** is recorded in `.imd-findings.json`:\n\n- `transferFrom(address(0), to, 0)` succeeds for any caller and emits a zero-value `Transfer` from the zero address, the shape explorers read as a mint. The contract rejects the zero address as recipient and as spender but never checks `from`. No value moves and the supply is a constant, so this is an event-level asymmetry, not a loss. A non-zero amount from the zero address reverts on allowance. A one-line `from == address(0)` guard in `_transfer` closes it. I verified both behaviours with a Foundry test before reporting.\n\n**What I verified and recorded as holding**, in the coverage record:\n\n- Supply conservation: the only balance writers are the constructor and the internal transfer, which debits and credits the same amount. Self-transfer inside the unchecked block conserves the balance.\n- The infinite-allowance sentinel boundary: an allowance of max minus one is decremented, max is not. Failed calls spend nothing.\n- Launch arithmetic: the 10/88/2 split is exact in minor units with no remainder dust.\n- Launch flows: transfers return true and move exactly the requested amount, so the factory, distributor, Uniswap v4 seed, trader buy and sell, and remainder legs all arrive whole.\n- No privileged path can move, freeze or mint. Unknown selectors and plain ETH revert.\n\n**Coverage:** all three verifier-listed entry points have rows (approve holds, transfer holds, transferFrom carries finding 1), plus five invariant and flow rows. The existing suite of 45 tests, including the invariant campaign, passes. Slither and aderyn reported nothing above a style-level literal, which I confirmed is just the supply constant.\n\n**Not reached:** nothing in my assigned area. I did not run a live Uniswap v4 pool simulation, since the protected floor test does that at admission and the token has no transfer logic that could change its outcome.","treeHash":null,"usage":{"cachedInputTokens":728464,"inputTokens":290,"model":"claude-fable-5-1","outputTokens":14063,"runtime":"claude","turns":29,"wallClockMs":234012}}],"verification":[{"checks":[{"durationMs":1327,"exitCode":0,"name":"build","output":"Compiling 27 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.23s\nCompiler run successful!\n","passed":true},{"durationMs":446,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 2 tests for test/DeployNukeToken.t.sol:DeployNukeTokenTest\n[PASS] test_deployIsRepeatableAndIndependent() (gas: 1577990)\n[PASS] test_deployMintsWholeSupplyToTheScriptCaller() (gas: 1151170)\nSuite result: ok. 2 passed; 0 failed; 0 skipped; finished in 524.05µs (342.18µs CPU time)\n\nRan 8 tests for test/NukeTokenLaunchFlow.t.sol:NukeTokenLaunchFlowTest\n[PASS] test_create2AddressIsPredictable() (gas: 9424)\n[PASS] test_create2DeploymentMintsToTheFactory() (gas: 15711)\n[PASS] test_creationCodeHasNoConstructorArguments() (gas: 491864)\n[PASS] test_factoryCannotMintAfterLaunch() (gas: 35546)\n[PASS] test_factoryCannotMoveOrFreezeAHolder() (gas: 343034)\n[PASS] test_fullLaunchSplitIsExact() (gas: 203978)\n[PASS] test_poolManagerCanPayOutAndTakeInWhole() (gas: 219828)\n[PASS] test_swarmShareArrivesWholeAndIsClaimableWhole() (gas: 136602)\nSuite result: ok. 8 passed; 0 failed; 0 skipped; finished in 7.90ms (1.11ms CPU time)\n\nRan 34 tests for test/NukeToken.t.sol:NukeTokenTest\n[PASS] testFuzz_chainOfTransfersConservesSupply(uint8,uint256) (runs: 256, μ: 3948442, ~: 1282059)\n[PASS] testFuzz_transferFrom_decrementsAllowanceExactly(uint256,uint256) (runs: 256, μ: 139220, ~: 140207)\nLogs:\n  Bound result 15370634\n  Bound result 2208924\n\n[PASS] testFuzz_transferFrom_revertsAboveAllowance(uint256,uint256) (runs: 256, μ: 95276, ~: 95474)\nLogs:\n  Bound result 15370634\n  Bound result 865173055709570927535421167\n\n[PASS] testFuzz_transfer_conservesSupply(address,uint256) (runs: 256, μ: 96238, ~: 96438)\nLogs:\n  Bound result 28008165077839523808508229\n\n[PASS] testFuzz_transfer_revertsAboveBalance(uint256) (runs: 256, μ: 41805, ~: 42142)\nLogs:\n  Bound result 2244632745158543809782332117305438348518345398425467685142176\n\n[PASS] test_approve_canExceedBalance() (gas: 62527)\n[PASS] test_approve_overwritesRatherThanAdds() (gas: 92399)\n[PASS] test_approve_revertsForZeroSpender() (gas: 32439)\n[PASS] test_approve_setsAllowanceAndEmits() (gas: 64839)\n[PASS] test_constructorEmitsMintTransfer() (gas: 10454)\n[PASS] test_constructorHasNoArgumentsAndMakesNoExternalCalls() (gas: 6615)\n[PASS] test_constructorMintsToWhoeverDeploys_evenAContract() (gas: 180326)\n[PASS] test_constructorMintsWholeSupplyToDeployer() (gas: 25199)\n[PASS] test_deployerCannotMoveAnotherHoldersBalance() (gas: 161858)\n[PASS] test_metadata() (gas: 47208)\n[PASS] test_noMintOrAdminSelectorExists() (gas: 363788)\n[PASS] test_runtimeHasNoDelegatecallCallcodeOrSelfdestruct() (gas: 742162)\n[PASS] test_supplyIsOneBillionWithEighteenDecimals() (gas: 17353)\n[PASS] test_transferFrom_exactAllowanceLeavesZero() (gas: 118139)\n[PASS] test_transferFrom_infiniteAllowanceIsNotDecremented() (gas: 129786)\n[PASS] test_transferFrom_ownerCanSpendOwnTokensOnlyWithSelfAllowance() (gas: 143581)\n[PASS] test_transferFrom_revertsToZeroAddress() (gas: 88045)\n[PASS] test_transferFrom_revertsWhenAllowanceTooSmall() (gas: 92369)\n[PASS] test_transferFrom_revertsWhenOwnerBalanceTooSmall() (gas: 97787)\n[PASS] test_transferFrom_revertsWithoutAllowance() (gas: 44548)\n[PASS] test_transferFrom_spendsAllowanceAndMovesTokens() (gas: 156793)\n[PASS] test_transfer_fullBalance() (gas: 72051)\n[PASS] test_transfer_movesExactAmountAndEmits() (gas: 85256)\n[PASS] test_transfer_revertsOnInsufficientBalance() (gas: 106150)\n[PASS] test_transfer_revertsToZeroAddress() (gas: 36679)\n[PASS] test_transfer_revertsWhenSenderHoldsNothing() (gas: 37606)\n[PASS] test_transfer_toSelfIsANoOp() (gas: 40403)\n[PASS] test_transfer_zeroAmountSucceeds() (gas: 46814)\n[PASS] test_unknownCallsRevert() (gas: 54969)\nSuite result: ok. 34 passed; 0 failed; 0 skipped; finished in 146.25ms (177.38ms CPU time)\n\nRan 1 test for test/NukeToken.invariant.t.sol:NukeTokenInvariantTest\n[PASS]\nNukeTokenInvariantTest invariants:\n[PASS] invariant_noBalanceExceedsSupply\n[PASS] invariant_sumOfBalancesEqualsSupply\n[PASS] invariant_totalSupplyIsConstant\n NukeTokenInvariantTest invariants (runs: 64, calls: 4096, reverts: 0)\n\n╭------------------+--------------+-------+---------+----------╮\n| Contract         | Selector     | Calls | Reverts | Discards |\n+==============================================================+\n| NukeTokenHandler | approve      | 1387  | 0       | 0        |\n|------------------+--------------+-------+---------+----------|\n| NukeTokenHandler | transfer     | 1359  | 0       | 0        |\n|------------------+--------------+-------+---------+----------|\n| NukeTokenHandler | transferFrom | 1350  | 0       | 0        |\n╰------------------+--------------+-------+---------+----------╯\n\nLogs:\n  Bound result 0\n  Bound result 1410068508579434098815231037\n  Bound result 49569\n  Bound result 0\n  Bound result 0\n  Bound result 1\n  Bound result 1\n  Bound result 0\n  Bound result 1\n  Bound result 0\n  Bound result 2000000000000000000000000000\n  Bound result 1\n  Bound result 255\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 1498\n  Bound result 309\n  Bound result 24576\n  Bound result 0\n  Bound result 9862\n  Bound result 0\n  Bound result 0\n  Bound result 429\n  Bound result 28142141643098\n  Bound result 40000000000000000000\n  Bound result 688\n  Bound result 47832\n  Bound result 242\n  Bound result 51591971650484\n  Bound result 26572\n  Bound result 1\n  Bound result 0\n  Bound result 5150\n  Bound result 100000000000000000000000000\n  Bound result 1000000000000000000\n  Bound result 1860\n  Bound result 631\n  Bound result 2897\n  Bound result 2257\n  Bound result 3450528\n  Bound result 19531\n  Bound result 26020563553434\n  Bound result 200000000000000000006901056\n  Bound result 109963371523078958445447038\n  Bound result 178833337096331091075924873\n  Bound result 5306\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 371.86ms (370.58ms CPU time)\n\nRan 4 test suites in 373.25ms (526.54ms CPU time): 45 tests passed, 0 failed, 0 skipped (45 total tests)\n","passed":true},{"durationMs":30,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"NukeToken.approve(address,uint256)\",\"NukeToken.transfer(address,uint256)\",\"NukeToken.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":11,\"README.md\":136,\"foundry.toml\":28,\"remappings.txt\":1,\"script/DeployNukeToken.s.sol\":26,\"src/NukeToken.sol\":162,\"src/interfaces/IERC20.sol\":39,\"test/DeployNukeToken.t.sol\":31,\"test/NukeToken.invariant.t.sol\":92,\"test/NukeToken.t.sol\":385,\"test/NukeTokenLaunchFlow.t.sol\":156},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true},{"durationMs":322,"exitCode":0,"name":"slither","output":"slither: no results at low impact or above","passed":true},{"durationMs":214,"exitCode":0,"name":"aderyn","output":"[low] large-numeric-literal at src/NukeToken.sol:43: Large Numeric Literal","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"0351bf3a02ea2aaab1e7fd51dde706b9e0622a865442a5b3059b46d3997a705b","verifiedTreeHash":"af321ae2106eaec85c632eb374f0a797bfdfdfb4","verifierVersion":"0.1.0+c4d32abc"},{"checks":[{"durationMs":1999,"exitCode":0,"name":"build","output":"Compiling 29 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.89s\nCompiler run successful!\n","passed":true},{"durationMs":16003,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 2 tests for test/DeployNukeToken.t.sol:DeployNukeTokenTest\n[PASS] test_deployIsRepeatableAndIndependent() (gas: 1577990)\n[PASS] test_deployMintsWholeSupplyToTheScriptCaller() (gas: 1151170)\nSuite result: ok. 2 passed; 0 failed; 0 skipped; finished in 821.11µs (415.30µs CPU time)\n\nRan 35 tests for test/NukeToken.edge.t.sol:NukeTokenEdgeTest\n[PASS] testFuzz_allowanceBoundaryIsExact(uint256) (runs: 1000, μ: 175641, ~: 176322)\nLogs:\n  Bound result 1596\n\n[PASS] testFuzz_anyoneCanSpendWhatTheyAreAllowed(address,address,uint256) (runs: 1000, μ: 164914, ~: 165335)\nLogs:\n  Bound result 629888744852159055436397241885517291692029314885\n  Bound result 1322091965514674305038409502346555889781973683450\n  Bound result 671697390032733429234992564\n\n[PASS] testFuzz_approveReadsBackExactly(uint256) (runs: 1000, μ: 62031, ~: 62419)\n[PASS] testFuzz_insufficientBalanceReportsRealNumbers(uint256,uint256) (runs: 1000, μ: 99314, ~: 99479)\nLogs:\n  Bound result 244\n  Bound result 1234567000000000000000000\n\n[PASS] testFuzz_onlyTheExactSentinelIsInfinite(uint256,uint256) (runs: 1000, μ: 139742, ~: 140422)\nLogs:\n  Bound result 650098705104227177534465375795979599242165900291205009138298504578\n  Bound result 999999999999999999999999999\n\n[PASS] testFuzz_roundTripRestoresBothBalances(uint256) (runs: 1000, μ: 110643, ~: 110784)\nLogs:\n  Bound result 2021748103479\n\n[PASS] testFuzz_transferBoundaryIsExact(uint256) (runs: 1000, μ: 171203, ~: 171884)\nLogs:\n  Bound result 32\n\n[PASS] testFuzz_transferFromTouchesOnlyFromAndTo(uint256,uint256) (runs: 1000, μ: 249130, ~: 250265)\nLogs:\n  Bound result 13334307\n  Bound result 295613505290221502207026972\n\n[PASS] testFuzz_transfersAreAdditive(uint256,uint256) (runs: 1000, μ: 119084, ~: 119727)\nLogs:\n  Bound result 244\n  Bound result 1234567000000000000000000\n\n[PASS] test_allowance_unsetPairsReadZero_includingZeroAddresses() (gas: 38200)\n[PASS] test_approve_canRevokeInfiniteAllowance() (gas: 128170)\n[PASS] test_approve_isPerSpenderAndPerOwner() (gas: 88641)\n[PASS] test_approve_sameValueTwiceEmitsTwice() (gas: 90556)\n[PASS] test_approve_selfAllowanceIsOrdinary() (gas: 60077)\n[PASS] test_deploymentEmitsExactlyOneMintEvent() (gas: 9668)\n[PASS] test_eventSignaturesAreTheStandardOnes() (gas: 591)\n[PASS] test_failedCallsEmitNothing() (gas: 61161)\n[PASS] test_mutatorsRefuseAttachedValue() (gas: 166507)\n[PASS] test_standardSelectorsAnswerAndDecode() (gas: 225992)\n[PASS] test_transferFrom_checksAllowanceBeforeRecipientAndBalance() (gas: 145630)\n[PASS] test_transferFrom_emitsExactlyOneTransferAndNoApproval() (gas: 123471)\n[PASS] test_transferFrom_fromEqualsTo_keepsBalanceSpendsAllowance() (gas: 107845)\n[PASS] test_transferFrom_infiniteAllowanceStillRequiresBalance() (gas: 95077)\n[PASS] test_transferFrom_infiniteAllowanceSurvivesSpendingTheWholeSupply() (gas: 136729)\n[PASS] test_transferFrom_maxMinusOneAllowanceIsFiniteAndDecremented() (gas: 123364)\n[PASS] test_transferFrom_toSpender() (gas: 127893)\n[PASS] test_transferFrom_zeroAmountToZeroAddressReverts() (gas: 37743)\n[PASS] test_transferFrom_zeroAmountWithoutAllowanceOrBalanceSucceeds() (gas: 52453)\n[PASS] test_transfer_emitsExactlyOneEvent() (gas: 66622)\n[PASS] test_transfer_toSelfAboveBalanceStillReverts() (gas: 94387)\n[PASS] test_transfer_toSelfOfExactBalanceIsANoOp() (gas: 40410)\n[PASS] test_transfer_toTokenContractSucceedsAndIsIrrecoverable() (gas: 116616)\n[PASS] test_transfer_zeroAmountToZeroAddressReverts() (gas: 32528)\n[PASS] test_twoDeploymentsDoNotShareState() (gas: 159719)\n[PASS] test_viewsAreStatic() (gas: 28072)\nSuite result: ok. 35 passed; 0 failed; 0 skipped; finished in 70.13ms (621.83ms CPU time)\n\nRan 8 tests for test/NukeTokenLaunchFlow.t.sol:NukeTokenLaunchFlowTest\n[PASS] test_create2AddressIsPredictable() (gas: 9424)\n[PASS] test_create2DeploymentMintsToTheFactory() (gas: 15711)\n[PASS] test_creationCodeHasNoConstructorArguments() (gas: 491864)\n[PASS] test_factoryCannotMintAfterLaunch() (gas: 35546)\n[PASS] test_factoryCannotMoveOrFreezeAHolder() (gas: 343034)\n[PASS] test_fullLaunchSplitIsExact() (gas: 203978)\n[PASS] test_poolManagerCanPayOutAndTakeInWhole() (gas: 219828)\n[PASS] test_swarmShareArrivesWholeAndIsClaimableWhole() (gas: 136602)\nSuite result: ok. 8 passed; 0 failed; 0 skipped; finished in 70.13ms (1.34ms CPU time)\n\nRan 34 tests for test/NukeToken.t.sol:NukeTokenTest\n[PASS] testFuzz_chainOfTransfersConservesSupply(uint8,uint256) (runs: 256, μ: 3885274, ~: 1071038)\n[PASS] testFuzz_transferFrom_decrementsAllowanceExactly(uint256,uint256) (runs: 256, μ: 138688, ~: 140225)\nLogs:\n  Bound result 1324\n  Bound result 25\n\n[PASS] testFuzz_transferFrom_revertsAboveAllowance(uint256,uint256) (runs: 256, μ: 95301, ~: 95479)\nLogs:\n  Bound result 1324\n  Bound result 123000000000000000000\n\n[PASS] testFuzz_transfer_conservesSupply(address,uint256) (runs: 256, μ: 96054, ~: 96426)\nLogs:\n  Bound result 627098355729085075392912234\n\n[PASS] testFuzz_transfer_revertsAboveBalance(uint256) (runs: 256, μ: 41830, ~: 42142)\nLogs:\n  Bound result 115792089237316195423570985008687907853269984665640124097050243816472827663223\n\n[PASS] test_approve_canExceedBalance() (gas: 62527)\n[PASS] test_approve_overwritesRatherThanAdds() (gas: 92399)\n[PASS] test_approve_revertsForZeroSpender() (gas: 32439)\n[PASS] test_approve_setsAllowanceAndEmits() (gas: 64839)\n[PASS] test_constructorEmitsMintTransfer() (gas: 10454)\n[PASS] test_constructorHasNoArgumentsAndMakesNoExternalCalls() (gas: 6615)\n[PASS] test_constructorMintsToWhoeverDeploys_evenAContract() (gas: 180326)\n[PASS] test_constructorMintsWholeSupplyToDeployer() (gas: 25199)\n[PASS] test_deployerCannotMoveAnotherHoldersBalance() (gas: 161858)\n[PASS] test_metadata() (gas: 47208)\n[PASS] test_noMintOrAdminSelectorExists() (gas: 363788)\n[PASS] test_runtimeHasNoDelegatecallCallcodeOrSelfdestruct() (gas: 742162)\n[PASS] test_supplyIsOneBillionWithEighteenDecimals() (gas: 17353)\n[PASS] test_transferFrom_exactAllowanceLeavesZero() (gas: 118139)\n[PASS] test_transferFrom_infiniteAllowanceIsNotDecremented() (gas: 129786)\n[PASS] test_transferFrom_ownerCanSpendOwnTokensOnlyWithSelfAllowance() (gas: 143581)\n[PASS] test_transferFrom_revertsToZeroAddress() (gas: 88045)\n[PASS] test_transferFrom_revertsWhenAllowanceTooSmall() (gas: 92369)\n[PASS] test_transferFrom_revertsWhenOwnerBalanceTooSmall() (gas: 97787)\n[PASS] test_transferFrom_revertsWithoutAllowance() (gas: 44548)\n[PASS] test_transferFrom_spendsAllowanceAndMovesTokens() (gas: 156793)\n[PASS] test_transfer_fullBalance() (gas: 72051)\n[PASS] test_transfer_movesExactAmountAndEmits() (gas: 85256)\n[PASS] test_transfer_revertsOnInsufficientBalance() (gas: 106150)\n[PASS] test_transfer_revertsToZeroAddress() (gas: 36679)\n[PASS] test_transfer_revertsWhenSenderHoldsNothing() (gas: 37606)\n[PASS] test_transfer_toSelfIsANoOp() (gas: 40403)\n[PASS] test_transfer_zeroAmountSucceeds() (gas: 46814)\n[PASS] test_unknownCallsRevert() (gas: 54969)\nSuite result: ok. 34 passed; 0 failed; 0 skipped; finished in 196.63ms (336.11ms CPU time)\n\nRan 1 test for test/NukeToken.invariant.t.sol:NukeTokenInvariantTest\n[PASS]\nNukeTokenInvariantTest invariants:\n[PASS] invariant_noBalanceExceedsSupply\n[PASS] invariant_sumOfBalancesEqualsSupply\n[PASS] invariant_totalSupplyIsConstant\n NukeTokenInvariantTest invariants (runs: 64, calls: 4096, reverts: 0)\n\n╭------------------+--------------+-------+---------+----------╮\n| Contract         | Selector     | Calls | Reverts | Discards |\n+==============================================================+\n| NukeTokenHandler | approve      | 1373  | 0       | 0        |\n|------------------+--------------+-------+---------+----------|\n| NukeTokenHandler | transfer     | 1377  | 0       | 0        |\n|------------------+--------------+-------+---------+----------|\n| NukeTokenHandler | transferFrom | 1346  | 0       | 0        |\n╰------------------+--------------+-------+---------+----------╯\n\nLogs:\n  Bound result 5094\n  Bound result 0\n  Bound result 6\n  Bound result 1\n  Bound result 0\n  Bound result 0\n  Bound result 8540\n  Bound result 1\n  Bound result 4186\n  Bound result 745\n  Bound result 1305\n  Bound result 1158\n  Bound result 5372\n  Bound result 1497\n  Bound result 0\n  Bound result 4622\n  Bound result 1954\n  Bound result 2352470310253597\n  Bound result 0\n  Bound result 0\n  Bound result 4682686495047154\n  Bound result 317\n  Bound result 357507281656764900882381\n  Bound result 0\n  Bound result 2815\n  Bound result 0\n  Bound result 1292541846441089\n  Bound result 242\n  Bound result 127\n  Bound result 91\n  Bound result 157198259\n  Bound result 1\n  Bound result 87\n  Bound result 7\n  Bound result 1999999999995295059379483253\n  Bound result 0\n  Bound result 1480\n  Bound result 232424988820980\n  Bound result 209\n  Bound result 303\n  Bound result 390\n  Bound result 3966\n  Bound result 49569\n  Bound result 1000\n  Bound result 96\n  Bound result 2556073107382909\n  Bound result 5651\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 407.73ms (406.36ms CPU time)\n\nRan 1 test for test/NukeToken.model.invariant.t.sol:NukeTokenModelInvariantTest\n[PASS]\nNukeTokenModelInvariantTest invariants:\n[PASS] invariant_allMovementWentThroughTheTwoTransferPaths\n[PASS] invariant_allowancesMatchTheLedger\n[PASS] invariant_balancesMatchTheLedger\n[PASS] invariant_callSummary\n[PASS] invariant_everyBalanceIsInflowMinusOutflow\n[PASS] invariant_noBalanceExceedsSupply\n[PASS] invariant_pullsNeverExceedWhatTheOwnerEverHeld\n[PASS] invariant_supplyIsConservedAcrossEveryHolder\n[PASS] invariant_tokenContractIsASink\n[PASS] invariant_zeroAddressNeverReceives\n NukeTokenModelInvariantTest invariants (runs: 256, calls: 16384, reverts: 0)\n\n╭-----------------------+--------------+-------+---------+----------╮\n| Contract              | Selector     | Calls | Reverts | Discards |\n+===================================================================+\n| NukeTokenModelHandler | approve      | 5460  | 0       | 0        |\n|-----------------------+--------------+-------+---------+----------|\n| NukeTokenModelHandler | transfer     | 5523  | 0       | 0        |\n|-----------------------+--------------+-------+---------+----------|\n| NukeTokenModelHandler | transferFrom | 5401  | 0       | 0        |\n╰-----------------------+--------------+-------+---------+----------╯\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 15.92s (15.91s CPU time)\n\nRan 6 test suites in 15.92s (16.66s CPU time): 81 tests passed, 0 failed, 0 skipped (81 total tests)\n","passed":true},{"durationMs":38,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"NukeToken.approve(address,uint256)\",\"NukeToken.transfer(address,uint256)\",\"NukeToken.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":11,\"README.md\":136,\"foundry.toml\":28,\"remappings.txt\":1,\"script/DeployNukeToken.s.sol\":26,\"src/NukeToken.sol\":162,\"src/interfaces/IERC20.sol\":39,\"test/DeployNukeToken.t.sol\":31,\"test/NukeToken.edge.t.sol\":514,\"test/NukeToken.invariant.t.sol\":92,\"test/NukeToken.model.invariant.t.sol\":363,\"test/NukeToken.t.sol\":385,\"test/NukeTokenLaunchFlow.t.sol\":156},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"2ed03577cf997235fb99e0c7a239a09fc29b9e70b016c5a708e6e3740c53787a","verifiedTreeHash":"69a2f1e6c7b37587c65d6a6ac7ab9b786984eab6","verifierVersion":"0.1.0+c4d32abc"},{"checks":[{"durationMs":1242,"exitCode":0,"name":"build","output":"Compiling 27 files with Solc 0.8.26\nSolc 0.8.26 finished in 1.15s\nCompiler run successful!\n","passed":true},{"durationMs":421,"exitCode":0,"name":"test","output":"No files changed, compilation skipped\n\nRan 2 tests for test/DeployNukeToken.t.sol:DeployNukeTokenTest\n[PASS] test_deployIsRepeatableAndIndependent() (gas: 1577990)\n[PASS] test_deployMintsWholeSupplyToTheScriptCaller() (gas: 1151170)\nSuite result: ok. 2 passed; 0 failed; 0 skipped; finished in 753.86µs (313.58µs CPU time)\n\nRan 8 tests for test/NukeTokenLaunchFlow.t.sol:NukeTokenLaunchFlowTest\n[PASS] test_create2AddressIsPredictable() (gas: 9424)\n[PASS] test_create2DeploymentMintsToTheFactory() (gas: 15711)\n[PASS] test_creationCodeHasNoConstructorArguments() (gas: 491864)\n[PASS] test_factoryCannotMintAfterLaunch() (gas: 35546)\n[PASS] test_factoryCannotMoveOrFreezeAHolder() (gas: 343034)\n[PASS] test_fullLaunchSplitIsExact() (gas: 203978)\n[PASS] test_poolManagerCanPayOutAndTakeInWhole() (gas: 219828)\n[PASS] test_swarmShareArrivesWholeAndIsClaimableWhole() (gas: 136602)\nSuite result: ok. 8 passed; 0 failed; 0 skipped; finished in 888.82µs (1.11ms CPU time)\n\nRan 34 tests for test/NukeToken.t.sol:NukeTokenTest\n[PASS] testFuzz_chainOfTransfersConservesSupply(uint8,uint256) (runs: 256, μ: 3419983, ~: 1000717)\n[PASS] testFuzz_transferFrom_decrementsAllowanceExactly(uint256,uint256) (runs: 256, μ: 138237, ~: 140231)\nLogs:\n  Bound result 647753923199028585920930\n  Bound result 228186760385471940877366\n\n[PASS] testFuzz_transferFrom_revertsAboveAllowance(uint256,uint256) (runs: 256, μ: 95224, ~: 95505)\nLogs:\n  Bound result 647753923199028585920930\n  Bound result 904786233651774600763218155\n\n[PASS] testFuzz_transfer_conservesSupply(address,uint256) (runs: 256, μ: 96291, ~: 96438)\nLogs:\n  Bound result 1000000000\n\n[PASS] testFuzz_transfer_revertsAboveBalance(uint256) (runs: 256, μ: 41799, ~: 42142)\nLogs:\n  Bound result 1000000000000000000000000001\n\n[PASS] test_approve_canExceedBalance() (gas: 62527)\n[PASS] test_approve_overwritesRatherThanAdds() (gas: 92399)\n[PASS] test_approve_revertsForZeroSpender() (gas: 32439)\n[PASS] test_approve_setsAllowanceAndEmits() (gas: 64839)\n[PASS] test_constructorEmitsMintTransfer() (gas: 10454)\n[PASS] test_constructorHasNoArgumentsAndMakesNoExternalCalls() (gas: 6615)\n[PASS] test_constructorMintsToWhoeverDeploys_evenAContract() (gas: 180326)\n[PASS] test_constructorMintsWholeSupplyToDeployer() (gas: 25199)\n[PASS] test_deployerCannotMoveAnotherHoldersBalance() (gas: 161858)\n[PASS] test_metadata() (gas: 47208)\n[PASS] test_noMintOrAdminSelectorExists() (gas: 363788)\n[PASS] test_runtimeHasNoDelegatecallCallcodeOrSelfdestruct() (gas: 742162)\n[PASS] test_supplyIsOneBillionWithEighteenDecimals() (gas: 17353)\n[PASS] test_transferFrom_exactAllowanceLeavesZero() (gas: 118139)\n[PASS] test_transferFrom_infiniteAllowanceIsNotDecremented() (gas: 129786)\n[PASS] test_transferFrom_ownerCanSpendOwnTokensOnlyWithSelfAllowance() (gas: 143581)\n[PASS] test_transferFrom_revertsToZeroAddress() (gas: 88045)\n[PASS] test_transferFrom_revertsWhenAllowanceTooSmall() (gas: 92369)\n[PASS] test_transferFrom_revertsWhenOwnerBalanceTooSmall() (gas: 97787)\n[PASS] test_transferFrom_revertsWithoutAllowance() (gas: 44548)\n[PASS] test_transferFrom_spendsAllowanceAndMovesTokens() (gas: 156793)\n[PASS] test_transfer_fullBalance() (gas: 72051)\n[PASS] test_transfer_movesExactAmountAndEmits() (gas: 85256)\n[PASS] test_transfer_revertsOnInsufficientBalance() (gas: 106150)\n[PASS] test_transfer_revertsToZeroAddress() (gas: 36679)\n[PASS] test_transfer_revertsWhenSenderHoldsNothing() (gas: 37606)\n[PASS] test_transfer_toSelfIsANoOp() (gas: 40403)\n[PASS] test_transfer_zeroAmountSucceeds() (gas: 46814)\n[PASS] test_unknownCallsRevert() (gas: 54969)\nSuite result: ok. 34 passed; 0 failed; 0 skipped; finished in 121.99ms (154.58ms CPU time)\n\nRan 1 test for test/NukeToken.invariant.t.sol:NukeTokenInvariantTest\n[PASS]\nNukeTokenInvariantTest invariants:\n[PASS] invariant_noBalanceExceedsSupply\n[PASS] invariant_sumOfBalancesEqualsSupply\n[PASS] invariant_totalSupplyIsConstant\n NukeTokenInvariantTest invariants (runs: 64, calls: 4096, reverts: 0)\n\n╭------------------+--------------+-------+---------+----------╮\n| Contract         | Selector     | Calls | Reverts | Discards |\n+==============================================================+\n| NukeTokenHandler | approve      | 1380  | 0       | 0        |\n|------------------+--------------+-------+---------+----------|\n| NukeTokenHandler | transfer     | 1379  | 0       | 0        |\n|------------------+--------------+-------+---------+----------|\n| NukeTokenHandler | transferFrom | 1337  | 0       | 0        |\n╰------------------+--------------+-------+---------+----------╯\n\nLogs:\n  Bound result 2000000000000000000000000001\n  Bound result 1\n  Bound result 1\n  Bound result 1\n  Bound result 0\n  Bound result 0\n  Bound result 5660\n  Bound result 0\n  Bound result 0\n  Bound result 0\n  Bound result 1\n  Bound result 651588254743325098099369718\n  Bound result 0\n  Bound result 4258\n  Bound result 4043\n  Bound result 937\n  Bound result 6146\n  Bound result 0\n  Bound result 1\n  Bound result 0\n  Bound result 68\n  Bound result 1\n  Bound result 1\n  Bound result 1636\n  Bound result 252\n  Bound result 2774\n  Bound result 1\n  Bound result 76\n  Bound result 1\n  Bound result 1604\n  Bound result 5803\n  Bound result 1\n  Bound result 95\n  Bound result 2\n  Bound result 0\n  Bound result 3966\n\nSuite result: ok. 1 passed; 0 failed; 0 skipped; finished in 349.61ms (348.39ms CPU time)\n\nRan 4 test suites in 351.01ms (473.24ms CPU time): 45 tests passed, 0 failed, 0 skipped (45 total tests)\n","passed":true},{"durationMs":37,"exitCode":0,"name":"source-index","output":"{\"v\":1,\"entryPoints\":[\"NukeToken.approve(address,uint256)\",\"NukeToken.transfer(address,uint256)\",\"NukeToken.transferFrom(address,address,uint256)\"],\"files\":{\".gitignore\":11,\"README.md\":136,\"foundry.toml\":28,\"launch.json\":24,\"remappings.txt\":1,\"script/DeployNukeToken.s.sol\":26,\"src/NukeToken.sol\":162,\"src/interfaces/IERC20.sol\":39,\"test/DeployNukeToken.t.sol\":31,\"test/NukeToken.invariant.t.sol\":92,\"test/NukeToken.t.sol\":385,\"test/NukeTokenLaunchFlow.t.sol\":156},\"excluded\":[\"lib/\",\"node_modules/\"],\"truncated\":false}","passed":true}],"detail":"all checks passed","evaluation":"checks","profile":"foundry","status":"accepted","submissionHash":"a166b8522da06265cff4718290e523c9b6f7c727ec2da23641bd622b8856f121","verifiedTreeHash":"716c750f079bd8905fb236a72e8b36cc9158b35e","verifierVersion":"0.1.0+c4d32abc"}]}