TOKN / field guide

Version 2 verification scope

TOKN 2 was reviewed by a separate AI security reviewer and tested locally before live deployment. This is not an independent professional audit or a guarantee that every defect has been found. Public contract addresses, deployment transactions, the 100 TOKN self-bond and the operator-controlled work example are available in /v2-receipts.json.

The production Solidity bytecode is compiled with pinned solc 0.8.36, optimizer 200 runs and Paris EVM target. Contract tests exercise exact escrow balances, refunds, timeout fallbacks, permission and replay rejection, signature domains, reentrant and rejecting recipients, staking reward caps, strict council quorum, penalty freezes, full-slash recovery and repeated evidence hashes. EVM time advancement exercises the full production seven-day and 28-day conditions.

An isolated Besu 26.8.1 network first staked 100 TOKN and completed the work example. Its future-height transition activated contract validator selection at block 362, retained its original genesis and historical block hashes, disabled header-voting RPC and survived restart. A separate stopped-state clone then exercised admission of a second distinct validator key, two-signature blocks, removal, a 25 TOKN manual penalty, rejection of early exit and withdrawal of the remaining 75 TOKN. Both keys were controlled by the test operator.

The clone used the unchanged production contract with libfaketime applied only to its two Docker containers. This validates transitions under accelerated wall clock and actual Besu membership changes. It does not prove seven-day real-time liveness, independent governance, sustained availability or Byzantine resistance. The original QA node was stopped throughout the clone run; the clone was stopped before the original resumed. No live key or live chain was used for this test.

Selected isolated Besu transaction receipts:

A real Chromium browser then signed ten transactions on ordinary isolated Besu: funded creation, worker acceptance, local file hashing, delivery, approval, withdrawal, dispute and named-arbitrator resolution. A wrong-chain wallet was rejected. Desktop and 390-pixel mobile pages were checked. Signing checks bind both providers to chain/genesis and deployed code; browser and CLI journals retain exact transaction intent for safe retries. Native HTML form submission is blocked by CSP even if JavaScript fails to load.

The live gate separately verifies creation transaction input against compiled bytecode and constructor arguments, runtime hashes, the 100 TOKN self-bond, liabilities, unchanged fixed supply/reserves, actual QBFT selection, historical hashes, restart persistence and the administrative replica. A matching RPC set alone is not treated as proof of activation: header voting must also be disabled after the scheduled configuration transition.