PUBLIC ALPHA · AUDIT READINESS

PROVE THE
SECURITY.

Geek Protocol is building toward independent review of the complete Web3 stack—not a badge for one narrow component. Every security claim must point to a control, test, report, or unresolved launch gate.

INDEPENDENT AUDIT
NOT COMPLETED
ON-CHAIN PAYOUTS
DISABLED
WALLET IDENTITY
SERVER VERIFIED · ALPHA
SECURITY EVIDENCE
IN REPOSITORY
MAINNET GATES
12 OPEN

Controls before claims.

The Alpha is designed to fail closed around settlement while producing evidence an outside reviewer can inspect and reproduce.

01

Server authority

Ranked answers stay private. The server owns clocks, one-use attempts, scoring, balances, and leaderboards.

02

Audit evidence

Payout changes, moderation transitions, C.C.E. credits, and Alpha balance mutations create pseudonymous security events.

03

Tamper detection

Production can HMAC-sign audit records with SHA-256. Private exports verify record integrity without exposing bearer credentials.

04

Change protection

Every payout-address change begins a 72-hour future-settlement cooldown. Linked players must re-sign; only the identity wallet is ownership-verified.

05

Automated evidence

Integration tests, syntax checks, dependency review, and a machine-readable control map run for proposed releases.

06

Non-custodial mint boundary

The public mint page can request one user-approved Kasware mint. It cannot sign for users or activate Alpha reward transfers, withdrawals, or redeemability.

07

Recoverable identity

Five-minute, single-use wallet challenges are verified by the server. Recovery invalidates older sessions; protected payout changes require a fresh signature.

08

Exact-origin proof

Wallet challenges sign the requesting HTTPS origin, and verification rejects a challenge replayed through the other production hostname.

09

Payout risk review

Changed, unverified, recently recovered, or repeatedly changed destinations create a persistent player notice and enter a private review queue.

Two reviews.
One complete stack.

WEB3 PENETRATION TEST

Browser, APIs, business logic, Redis, wallet integration, moderation, audit export, CI/CD, cloud configuration, and future settlement endpoints.

SETTLEMENT CODE AUDIT

Every future KRC-20 transfer, treasury, signing, batching, cap, replay, reconciliation, emergency-pause, and upgrade path.

NO CRITICALS.
NO HIGHS.
NO SHORTCUTS.

On-chain settlement stays disabled until independent reviewers test the exact release, every Critical and High finding is resolved and retested, treasury controls are exercised, and a staged low-cap launch can be stopped safely.