Proof

What the scripted runs produced. A script wrote every number on this page into a result file, and every file is linked. LocalNet and DevNet results are kept apart.

The live site right now: DevNet, HackCanton shared node. DRAW’s backend login signs for every demo seat, and a different login reads each settlement back.

The canonical run

DevNet

The newest DevNet run that passed every check.

83/83

checks passed

End to end PASSPrivacy checks PASSCustody PASS
Run
20261007T130259Z
Canton
3.5.19
Commit
0a2238be44ad
Package
0.3.0, 733ba37d82f44d827f37…
Fund
FUND-20261007t130259z
Instrument
Amulet, the ledger’s name for Canton Coin

How this run signed

  • One ledger login submitted for every party and read each settlement back. It could not act for a party without that party’s signature.
  • Every party signed its own transactions with its own key. All the keys sat on the machine that ran the script, so this shows the ledger needs each party’s signature, not that separate people held the keys.
  • Skipped “credential: lpA token cannot read as lpB”: one shared login acts for every party on this node, so LP credentials cannot be separated here.
  • Skipped “credential: verifier token cannot submit as admin”: the verifier reads as one of the seats' ledger users.

What probe 20261007T125624Z found about DRAW’s logins

  • As expected the demo seats' backend client acts for the five demo parties and nothing else
  • As expected the verifier's client only reads, as the fund's party

result.json

Who could read what

DevNet

Each row is one party’s own ledger query after the call settled, made through the one login that submitted for every party. Leaks counts any contract a party saw that it is not a party to.

ReaderFundCall headerCommitmentsNoticesPaymentsLeaks
Fund managerYesYesLP A, LP B, LP CLP A, LP B, LP CNone0
LP ANoneNoneLP ALP ANone0
LP BNoneNoneLP BLP BNone0
LP CNoneNoneLP CLP CNone0
Unrelated partyNoneNoneNoneNoneNone0

visibility-final.json

Settlements, read back from the ledger

DevNet

After each settlement, a read-back step reads the transaction and the fund’s holdings from the ledger and writes the receipt before the notice counts as funded. In this DevNet run that step read as the same ledger user that submitted for every party.

40 CC

Verified funded
Notice
DRAW-f85667ed46f10411
Business amount
$400,000
State
PaymentPending to Funded
Checks
14 of 14 passed
Update
122044147196184467a493c1…

35 CC

Verified funded
Notice
DRAW-13979f83a74ff723
Business amount
$350,000
State
PaymentPending to Funded
Checks
14 of 14 passed
Update
1220d988c9ea5cfbef7e6207…

Fund totals, recomputed

DevNet

The fund manager's totals equal the sum of the notices and the coin the fund actually received.

Funded

$750,000

Unresolved

$250,000

Call total

$1,000,000

Coin received

75 CC

totals.json

Refused without funding

DevNet
  • Held overdue refused before due time
  • Held lpA cannot exercise on lpB obligation
  • Held lpA cannot change its own obligation state
  • Held wrong amount does not fund
  • Held wrong payer does not fund
  • Held wrong reference does not fund
  • Held replayed allocation from lpA does not fund lpB
  • Held replayed allocation does not fund lpA twice
  • Held verifier rejects lpA settlement evidence offered for lpB
  • Held lpB still unfunded after every bad attempt
  • Held rejected allocations withdrawn, none left for admin to execute
  • Held lpC obligation is Overdue after the due time, not Funded

In a browser, on the live site

DevNet

A real browser clicks through the deployed site against the ledger. Each journey wrote its own steps and screenshots as it ran. This is the newest run of each. The sign-in runs so far all used the team’s own HackCanton login as the LP.

A capital call on the demo seats

PASS 10/10
  1. landing loads
  2. LP A committed
  3. fund manager onboarded
  4. call issued
  5. LP A locked its payment
  6. LP B cannot open LP A notice
  7. fund manager settled, read-back confirmed
  8. LP A sees verified funded
  9. a second browser gets its own demo fund
  10. starting over leaves this browser without a fund

When it ran: DevNet, HackCanton shared node. DRAW’s backend login signs for every demo seat, and a different login reads each settlement back.

web-journey-20261007205208 against drawcalls.xyz

An LP with its own HackCanton login approves the call in its Canton Coin wallet

FAIL 0/9

    When it ran: DevNet, HackCanton shared node. DRAW’s backend login signs for every demo seat, and a different login reads each settlement back.

    web-hackcanton-wallet-20261007205753 against drawcalls.xyz

    An LP with its own HackCanton login pays from its wallet in DRAW

    FAIL 0/7

      When it ran: DevNet, HackCanton shared node. DRAW’s backend login signs for every demo seat, and a different login reads each settlement back.

      web-hackcanton-20261007205441 against drawcalls.xyz

      Each party holds its own key

      LocalNet

      A LocalNet run in which every party signed its own transactions with an Ed25519 key, on package 0.2.0. The participant can’t act for a party without its signature, and another party’s key is refused.

      76/76

      checks passed

      Custody PASS
      Run
      20261004T183146Z

      100 generated capital calls

      LocalNet

      Seeded calls with good and bad payments, compared against an independent reference model. Seed 20261002, verdict PASS, package 0.2.0.

      Capital calls

      100

      Notices

      191

      Calls passed

      100

      Calls failed

      0

      Falsely funded

      0

      Paid but not funded

      0

      Privacy violations

      0

      Replays accepted

      0

      Total mismatches

      0

      Payments misclassified

      0

      Sent to manual review

      9

      False claims contradicted

      39

      Pending, correctly not funded

      15

      Early overdue refused

      10

      Bad payments refused

      38

      Errors

      0

      result.json, cases.jsonl

      Same attacks, database versus ledger

      LocalNet

      The same capital call run on an operator database with a paid flag, and on DRAW.

      AttackDatabase with a paid flagDRAW on Canton
      Mark an unpaid investor fundedSucceedsStopped
      Read another investor’s noticeSucceedsStopped
      Reuse one payment for another noticeSucceedsStopped
      Funded with no coin movedSucceedsStopped
      Investor changes its own noticeStoppedStopped

      result.json

      Contract tests

      LocalNet
      • Daml Script suites PASS, 9 suites, package 0.3.0. result.json
      • Deliberately broken guards caught by the tests: 15 of 15. result.json