Skip to content
COSMO Trust

Every claim links to a transaction or a hash.

6 settled proofs · Supra Mainnet & SupraFXShow, don't claim

This page collects what has actually settled on Supra Mainnet, the honesty rules this site holds itself to, and the Price Integrity Guard — a read-only research module. Facts and roadmap are kept separate; limits are stated next to the claims they qualify.

Settled proofs

Six settled proofs, each backed by public evidence: four marketplace jobs on Supra Mainnet and two mandated execution cases (a SupraFX trade and a marketplace work delivery). Newest first. Marketplace proofs can be checked against on-chain transactions and published hashes. Full 10/10 verification of the execution cases currently requires the private COSMO verifier.

EXECUTION-CASE-002-G — mandated delivery and acceptance

2026-08-155 wCOSMO escrow released

The double ceremony: the full economic arc of a marketplace job with BOTH irreversible legs under mandate. On live job 10, the solver agent (K1) committed a pre-mandated result hash on-chain under a provider mandate (deliver_result_v2), and the buyer acceptance — atomic escrow release via approve_delivery_v2 — was ALSO executed as its own case, under a one-shot mandate held by an agent-controlled buyer wallet. The approve policy re-verified delivered-and-unsettled, buyer-key binding, hash match, review window and escrow cap before release. Both cases verify offline through the same entry point: ACCEPT, ten of ten criteria each. Honest scope: both ceremonies armed by the same operator; authority separation is cryptographic, not organizational.

deliver mandate_hash 0x7996b572…626652

approve mandate_hash 0x93ba83d6…aa712f

result_hash 0xd71c14ce…04caf6

EXECUTION-CASE-002 — mandated work delivery

2026-08-145 wCOSMO escrow

The generalization case, deliberately not a trade: a solver agent delivered marketplace work under the full execution-case framework — result hash pre-committed in a one-shot mandate, six policy criteria checked against live chain state, human ARM, on-chain commitment via deliver_result_v2 (job 9). On-chain hash == mandated hash exactly. Ends at DELIVERED; the buyer subsequently approved as a separate human step and job 9 settled on-chain (escrow payout to the solver). Ten-criteria offline consistency verification via the private COSMO verifier.

mandate_hash 0x3ad166f7…0b9d01

result_hash 0x5429d300…4ce055

evidence_root 0x318fa77b…d26d44

EXECUTION-CASE-001 — mandated execution case

2026-08-141 SUPRA → 169 µUSDC

First mandated micro-live execution case, not a marketplace job: delegated authority with on-chain caps and an on-chain revoke, a one-shot signed mandate, a pinned policy, a human ARM ceremony — closed EXECUTED at exactly the mandated rate (normalized to 169 micro-USDC from the platform’s float delta). Ten-criteria offline consistency verification currently requires the private COSMO verifier (SupraFX Mainnet).

mandate_hash 0xb0d3911a…6bab11

policy_hash 0x59f7c39f…7dd75d

evidence_root 0x5799bf59…1b50c2

PILOT-001 — marketplace trade

2026-07-172 wCOSMO

First marketplace trade settled end-to-end: escrow, quote, accept, deliver, settle — every step its own mainnet transaction.

spec_hash 0x335f1242…7328be

result_hash 0x96700509…d8040c

PATCH-001 — machine-accepted patch

2026-07-10285 wCOSMO

A software patch fixing a real defect, paid only after a ten-criteria machine acceptance check returned ACCEPT.

input_hash 20eef0578a…6395e5

diff_hash 92b0c80ad1…cfaaa9

result_hash 7a5847bb18…7afdb3

ATTEST-001 — first traded good

2026-07-08200 wCOSMO

The first traded good: a signed attestation of live protocol invariants, delivered against a security deposit and machine-accepted before approval.

input_hash 7516be60f3…b2b6ee

result_hash 665404a859…aec205

JOB-001 — foundation compute job

2026-07-06200 wCOSMO

The foundation: the first real compute job — a deterministic 1,000,000-step SHA3 workload — settled through the full escrow lifecycle.

input_hash 68747dd41a…4d3a36

result_hash ceb6d41ee6…d47e61

Buyer and provider on JOB-001, ATTEST-001 and PATCH-001 are operating-team accounts, disclosed on their detail pages. PILOT-001 settled through the public marketplace flow. EXECUTION-CASE-001 was run by the operating team under its own mandate discipline; its receipt is a self-attestation, stated as such in the bundle.

Earlier milestones: the first autonomous RFQ trade and the full demo round-trip are preserved in the archive.

Honesty principles

These rules apply to every page. They are not centralized here — each page carries its own honesty box next to the claims it qualifies. This section only states the rules.

Fact and roadmap never mix.

Settled means settled on-chain; planned means planned. Anything not yet live is labeled as research, prototype, or roadmap — in the same sentence, not in a footnote.

Applied: status labels on this page, /compute and the market.

Every claim links to a transaction or a hash.

Numbers on this site resolve to a mainnet transaction, an on-chain hash anchor, or a frozen artifact you can re-hash yourself.

Applied: the settled proofs above and the /evidence/ bundles.

Limits are disclosed next to claims.

Every page carries an honesty box listing what the shown result does not prove — including operating-team involvement where it exists.

Applied: honesty boxes on the market, /compute and /cosmo; the limitations box below.

Evidence is frozen, not curated.

Published artifacts are byte-identical copies of the originals, pinned by SHA3-256 to on-chain anchors. Verify with openssl dgst -sha3-256 against the hashes in each bundle’s index.txt.

Applied: /evidence/pilot-001/, /evidence/patch-001/, /evidence/attest-001/.

Assurance module 01 — Price Integrity Guard

Verify the data. Then verify the decision.

Research PrototypeRead-onlyNot Live Protection

A valid oracle update can prove authenticity under its verification model. It does not by itself guarantee that acting on the resulting value is economically safe. COSMO independently evaluates whether critical numerical inputs are plausible enough to use.

Case studies →Technical baseline →

What the Guard evaluates

Freshness

Was the value recent enough to use?

Deviation

How far does it differ from an independent reference?

Magnitude

Is the value within an economically plausible range?

Evidence coverage

Was the required input actually observed?

The principle

No evidence is not zero.
No evidence is UNKNOWN.

COSMO does not issue a clean result for a check that had no supporting input.

Results

SAFE

The evaluated checks stayed within the registered policy boundaries.

WARN

A relevant limitation, uncertainty or material deviation was found.

HALT_RECOMMENDED

The observed value was economically implausible enough that dependent actions should be stopped or independently reviewed.

These are read-only recommendations. COSMO does not currently pause or control the evaluated protocols.

Case studies

Bonzo SAUCE/wHBAR exploit replay

Retrospective detectionNot prevention

COSMO reconstructed the manipulated SAUCE/wHBAR oracle value from frozen public evidence.

The Guard produced HALT_RECOMMENDED at the first manipulated submission in the reconstructed timeline, before the first observed borrowing activity.

The manipulated value differed from the market reference by approximately 12.7 orders of magnitude.

The replay proves what the Guard would have recommended from the frozen evidence. It does not claim that COSMO was operating during the incident.

Solido collateral snapshot

Single read-only snapshotNot continuous monitoring

COSMO compared Solido's SUPRA collateral value with an independent market reference and separately checked the internal stSUPRA-to-SUPRA conversion relationship against the Flow vault share rate.

The observed price relationships remained within the registered limits.

Feed freshness and submission provenance could not be established from the frozen snapshot and were therefore reported as UNKNOWN, never silently treated as zero or passed.

Only the SUPRA market comparison used an independent external reference. The stSUPRA check was an internal consistency check, not an independent oracle validation.

Reusable logic. Explicit integrations.

The evaluation engine is chain-agnostic and oracle-agnostic. Each concrete integration remains explicitly registered, tested and reviewed.

Adding an integration is not a configuration change. It requires new code, new tests, a separately pinned policy and a review.

Technical baseline
Tag
price-guard-subject-registry-v2
Baseline commit
29f0044
Tests
176 offline tests
Test environment
Tests run without network access or a production signing key
V1
V1 remains byte-frozen at commit 4bbf3d6
V2
V2 separates evidence mode from registered subject identity
Gates
Security gates are covered by mutation tests
Failure mode
Policies, subjects and allowed mode/subject combinations fail closed

Provenance, honestly: these identifiers reference a private repository, so you cannot verify them from this page today. Verification materials are available on request; publishing the repository is under consideration.

A guard that no test holds is not a guard.

Comments claim coverage. Mutations demonstrate it.

Economic safety needs a second line of verification.

COSMO publishes settled proofs instead of projections. Assurance explores how protocols and autonomous agents can verify not only whether data is authentic, but whether acting on it is safe.

Explore COSMO

Static research content. No wallet actions and no on-chain interaction on this page. The evidence index links settled mainnet transactions and frozen artifacts; the Price Integrity Guard is the first module under COSMO Assurance — it reads public data and frozen evidence and issues recommendations only.