Contracts · chain 4663 · private fork (anvil) · GH-W1-001 §2.1 §2.2 §2.10

A hardware chip as a Safe owner, sealed parameters, and service credits

Every arm below ran on a private fork of Robinhood Chain 4663 taken at block 55,818,502, with the real A9 ATECC608B chip signing through the Glass Hull signing broker. Refusals are the expected outcome of the refuse arms. The addresses are fork addresses: nothing here is deployed on the live chain yet (zero cash; a live deployment needs gas on a deployer key).

fork block55,818,502run2026-09-06T08:02:08Zledger receiptkind-3 2695479compilersolc 0.8.26, optimizer 200, cancunchipa9-atecc608b-slot0 · serial 0123ADA0711D8597EE

Verified sources

filesha256bytes
FeeSplitHook.sol65bf8cb3fea1fbd372bfffae6cced186bcf3d361bb4b2148f485d5a4c89744da3,991
P256Owner.sol241e4cf128e02966c826312b3a94773beb50b697b79ce797236fafae1060e44d3,538
SealedPolicyRegistry.solb8ad1630288d01ce75f57d522195bebf3963017d4d47d79b3352c4894e2c866a3,315
ServiceCredits.sol47161b85587f1a7c2a888d2b685b6061c7e823276df555a58426020d3cbebb968,032

Addresses (fork)

contractaddress
P256Owner0x572316aC11CB4bc5daf6BDae68f43EA3CCE3aE0e
SealedPolicyRegistry0x8ac87219a0F5639BC01b470F87BA2b26356CB2B9
FeeSplitHook0x94fFA1C7330845646CE9128450F8e6c3B5e44F86
CreditExchange0x742489F22807ebB4C36ca6cD95c3e1C044B7B6c8
Safe (chip + CC test key, 2-of-2)0x355013b8ce32E934b3cDD8CE442D7218673E337c
CreditEcosystemTreasury0xB22C255250d74B0ADD1bfB936676D2a299BF48Bd
ProductVault0x666D0c3da3dBc946D5128D06115bb4eed4595580

Both-arms transcript

armoutcometx / expected
A0 P256Owner.verify(chip signature over the Safe tx hash) via precompile 0x100PASS
A1 Safe.execTransaction with the chip as one of two ownersPASS86fc56c2c8e557ae1d9ffced2c1a95cdb16124bfc5f05a06bd7595c04480a252
A2 REFUSE: corrupted chip signaturePASS (refusal is the expected outcome)revert GS026
B0 chip registers the fee-split policy hash (sealed key via 0x100)PASS2f3e12326ed54c6486a4a16a57a086c712474d496b037fb4bffbf39a6999e4ef
B1 hook.setSplit(sealed split) PASSPASS1db7976b961714d6befc00f77966d909a2b495bf51d5d0a63023c7fabd45f6a0
B2 REFUSE: hook.setSplit(unsealed split)PASS (refusal is the expected outcome)revert HOOK: split not in sealed policy
B3 REFUSE: register without the sealed key's signaturePASS (refusal is the expected outcome)revert SEALED
C0 create credit line (non-transferable ERC-20)PASSa130e124eb427dc040041813e8fe8326fa4f195e275c7c07ff1ecd58bd567982
C1 REFUSE: setRate before the pricing policy is sealedPASS (refusal is the expected outcome)revert EXCHANGE: rate not in sealed policy
C2 chip seals the pricing policy hashPASSe26fb04058f3c579878eca3439e59d5e0a69365d042cf50f0c80475d9657b7ab
C3 setRate(sealed rate) PASSPASS415fc5b848499fa77305ce0134f8a5af337bf6da772375b98d29274d09f18f40
C4 buyWithEth: 0.1 ETH → credits minted, 20 % to treasury contract, 80 % to vault contractPASS9e57516eadd3fe39211cbe924f0e05e09f0d63c8ba43a7ef3a543cc0d201dd20
C5 REFUSE: credit.transfer (non-transferable)PASS (refusal is the expected outcome)revert CREDIT: non-transferable
C6 redeem 1 credit for a service (burn)PASS9aa888b102d3e9c48d766629faeb377e45f1e28fbcb63ec7981fd6a96b9a328e

Digest rule the chain enforces: the broker signs ECDSA-P256 over the 64-character hex of sha256(material) where material is the 0x-prefixed hex of the hash being approved; P256Owner and SealedPolicyRegistry recompute that digest and call the RIP-7212 precompile at 0x100. Re-derive: recompile the sources, deploy on your own fork, replay the run record.