1Program#
- Program id
- Eag1WgBbZay94E6Z9dLfUcgGUiDZRLD8Qc9qNNK6a7NS
- Cluster
- mainnet, Anchor 0.31.1
- Config account
- QtY87LXgsJUmY4Td1dHZuNqpvHRsxeXmvfaD4MmWTSo
- Bond vault
- 5QMhoX7rFhDmHbcqoAgSAJLp1F471MBSoaqVGRWDMRtq
- Bond mint
- Cj4TSKUjUsaAPGYSoLLqT5xLfdRUVBU7rt5ooptpump ($KORTX)
- Devnet program
- AK6GHxkh1ZJp3YYnpqMmbJiXt5Ft7z6Zu6f4KbKuRqQ3
- Interface
- 37 instructions, 11 account types, 45 events, 100 errors
The IDL ships with the program source and is not yet published in an on-chain IDL account. The SDK and CLI in the repository bundle the same interface and pick the program id by cluster. The id Eag1WgBbZay94E6Z9dLfUcgGUiDZRLD8Qc9qNNK6a7NS first ran on devnet; that devnet deployment was closed on 2026-10-06, and records committed to it are no longer readable there. The same id now carries the current program on mainnet, a new deployment that inherits nothing from the closed one. The program never sees a model, a prompt or a completion, only hashes.
2Instructions#
Provider
register_plateLive on mainnetRegisters a model with its fingerprint and the reproduction policy the provider agrees to be judged by, and moves the provider bond into the vault.
- Signer
- provider
- Arguments
- model_id_hash, model_id, version, weights_hash, model_fingerprint, determinism, bond_amount
commit_traceLive on mainnetCommits one inference. The fingerprint must equal the plate's, so a provider cannot register one model and serve another. Opens the challenge window. No evidence link travels with the commit: attested or proven evidence is attached afterwards with attest_trace or submit_proof. The nonce must exceed the plate's last nonce, so a closed trace address can never be reused. While fees are on, the plate's commit fee is charged.
- Signer
- provider
- Arguments
- nonce, input_hash, output_hash, model_fingerprint, seed, tier
attest_traceLive on mainnetAttaches a hardware attestation quote hash to an attested trace. The quote is recorded, not validated on chain. Writes an Attestation account beside the trace.
- Signer
- provider
- Arguments
- attestation_hash, tee_vendor, signer, quote_uri
submit_proofLive on mainnetAttaches a proof commitment to a proven trace, with the share of the computation the circuit covers. The proof is recorded, not verified on chain. Writes a Proof account beside the trace.
- Signer
- provider
- Arguments
- system, proof_hash, public_inputs_hash, circuit_id, proof_uri, covers_bps
close_traceLive on mainnetCloses a trace once its challenge window has passed with no incident open and no unsettled bounty, returning its rent, and its evidence account's, to the provider. The commit transaction and its events stay in the ledger.
- Signer
- anyone (rent always returns to the provider)
- Arguments
- none
retire_plateLive on mainnetCalled twice: first stops new traces, then releases the bond once the last challenge window has passed and no incident is open.
- Signer
- provider
- Arguments
- none
Dispute
open_incidentLive on mainnetObjects to a trace inside its challenge window, with a bond behind the objection. Starts the commit and reveal clocks. Snapshots the required stake and how many re-run slots are open to non-curated verifiers. While fees are on, escrows the incident fee.
- Signer
- challenger
- Arguments
- index, bond_amount, claim_output_hash, reason_uri
submit_rerunLive on mainnetCommits a blinded re-execution result, then reveals it once the commit phase has closed. The commitment binds the output, a salt, the verifier and the incident. Non-curated verifiers may take only the open slots. A reveal records the verifier's bond as its vote weight and counts as work for the fee epoch.
- Signer
- verifier
- Arguments
- payload: Commit | Reveal
resolve_incidentLive on mainnetTallies the reveals and settles every bond in one transaction: slash, burn, challenger payout, verifier rewards and penalties. Rules by stake, not by head count, and pays the verifier share by stake. Refunds the incident fee if upheld; forfeits it into the fee split if rejected or void.
- Signer
- anyone
- Arguments
- none (every rerun record and its verifier, in ascending order)
slash_samplerLive on mainnetSlashes a verifier whose matched sample an upheld incident contradicted. Each record can be slashed once.
- Signer
- anyone
- Arguments
- none
close_rerun_recordLive on mainnetCloses a settled incident vote, or a sample whose trace is closed and whose liability has lapsed, and returns its rent to the verifier.
- Signer
- anyone (rent returns to the verifier)
- Arguments
- none
Verifier
register_verifierLive on mainnetJoins the verifier network with a bond. One verifier per key. While registration is permissioned, as it is at launch, the config authority co-signs, and the verifier is marked curated.
- Signer
- verifier
- Arguments
- bond_amount, endpoint_uri
verifier_stakeLive on mainnetAdds to a verifier bond. Never shortens an existing lock.
- Signer
- verifier
- Arguments
- amount
verifier_unstakeLive on mainnetWithdraws bond after the cooldown, and only while no re-run commitment is outstanding. Also refused while a matched sample's liability window is open, and until any fee epoch the verifier worked in has ended.
- Signer
- verifier
- Arguments
- amount
submit_sample_resultLive on mainnetRecords an independent check made outside any dispute: a re-execution, a proof check, or a quote check. Only the first K checks per trace are accepted (default 3). A matched re-execution inside the challenge window locks the bond until the trace can no longer be upheld, and counts as paid work. A diverged sample from a non-curated verifier is recorded but does not touch the trace's badge.
- Signer
- verifier
- Arguments
- kind, rerun_output_hash, divergence_bps, evidence_uri
Fees and bounties
init_fee_vaultLive on mainnetCreates the fee vault, separate from the bond vault, and fixes the fee epoch length. Once.
- Signer
- config authority
- Arguments
- fee_epoch_secs
set_fee_configLive on mainnetTurns fees on or off and sets the fixed $KORTX amounts, the splits, the first-K cap and the bootstrap settings.
- Signer
- config authority
- Arguments
- params: FeeParams
set_plate_fee_classLive on mainnetChooses which commit fee a plate pays. The Condense demo plate is Exempt.
- Signer
- config authority
- Arguments
- fee_class: External | NucleateCall | Exempt
open_fee_epochLive on mainnetCreates the current epoch's fee pool if it does not exist yet.
- Signer
- anyone
- Arguments
- epoch
claim_feesLive on mainnetSettles a finished epoch the verifier worked in and pays out what it is owed, to its wallet.
- Signer
- verifier
- Arguments
- none
sweep_fee_epochLive on mainnetDeals with what a finished epoch could not pay. If nobody worked in it, the verifier share rolls into the current epoch's pool; only after more consecutive no-work epochs than the rollover limit is it burned. Rounding left after everyone settled is burned.
- Signer
- anyone
- Arguments
- none
flush_fee_burnLive on mainnetBurns the accumulated burn share of fees.
- Signer
- anyone
- Arguments
- none
set_fee_rollover_limitLive on mainnetSets how many consecutive no-work epochs a verifier share can roll through before it is burned. Default 30.
- Signer
- config authority
- Arguments
- max_epochs
withdraw_treasuryLive on mainnetPays out of the treasury share, up to what the treasury holds.
- Signer
- config authority
- Arguments
- amount
request_verificationLive on mainnetEscrows a bounty in $KORTX against one trace so that it gets re-run. At least min_bounty.
- Signer
- requester
- Arguments
- amount
settle_bountyLive on mainnetPays a bounty to the samplers that were right, weighted by bond, once the window has passed with no open incident. Refunds it if nobody sampled, and refunds the verifier share if nobody was right.
- Signer
- anyone
- Arguments
- none (the payees' verifier accounts, in entry order)
fund_bootstrapLive on mainnetAdds existing tokens to the bootstrap pool. The pool is empty and inactive by default.
- Signer
- anyone
- Arguments
- amount
sweep_bootstrapLive on mainnetBurns what is left in the bootstrap pool once the subsidy has ended.
- Signer
- anyone
- Arguments
- none
Protocol
initialize_configLive on mainnetCreates the singleton Config and the bond vault, and fixes the bond mint. Runs once. Refuses a mint with a freeze authority, a permanent delegate, a transfer hook, confidential transfers, non-transferability or a default account state.
- Signer
- program upgrade authority
- Arguments
- params: ConfigParams
update_configLive on mainnetRetunes parameters, pauses new activity, or nominates a new authority. Pause does not freeze settlement or withdrawals already in flight. Refuses a rerun quorum below 3.
- Signer
- config authority
- Arguments
- params, paused, pending_authority
set_verifier_permissioningLive on mainnetTurns the curated-verifier gate on or off. Opening the network is one call.
- Signer
- config authority
- Arguments
- permissioned: bool
set_verifier_curatedLive on mainnetMarks or unmarks a verifier as a curated operator.
- Signer
- config authority
- Arguments
- curated: bool
set_reserved_curated_slotsLive on mainnetSets how many of an incident's re-run slots are held for curated verifiers. Default 5 of 7.
- Signer
- config authority
- Arguments
- slots (at most 7)
set_incident_stake_thresholdLive on mainnetSets the least total revealed stake an incident needs for a verdict. Snapshotted at open. Default 0.
- Signer
- config authority
- Arguments
- min_stake
3Accounts#
Program-derived addresses. Seeds are written as they are passed: string literals in quotes, keys by name, numbers little-endian. A bond vault, seeded ["vault"], holds every bond as a token account owned by the program.
| Account | Bytes | Seeds | What it is | Holds |
|---|---|---|---|---|
| Config | 521 | ["config"] | Every protocol parameter, the two-step authority, the pause switch, and running totals. | bond minimums, windows, slash and split bps, quorums, curation settings, fee settings and fee ledger |
| Plate | 427 | ["plate", provider, model_id_hash] | A bonded model registration and the reproduction policy it will be judged by. | weights hash, model fingerprint, determinism policy, bond, counts, status, last nonce, fee class |
| Trace | 271 | ["trace", plate, nonce] | One committed inference. Closable after its window. | input hash, output hash, model fingerprint, seed, tier, committed slot, challenge deadline, status, confirmations |
| Attestation | 247 | ["attestation", trace] | Hardware attestation evidence, created only for an attested trace that attaches it. | quote hash, vendor, signer, quote link, confirmations |
| Proof | 281 | ["proof", trace] | A proof commitment, created only for a proven trace that attaches one. | proof system, proof hash, public inputs hash, circuit id, covered share, confirmations |
| Incident | 458 | ["incident", trace, index] | A bonded objection to one trace and its settlement. | challenger, bond, claimed hash, deadlines, required quorum and stake, slot caps, votes, verdict, amounts, incident fee |
| RerunRecord | 232 | ["rerun", incident, verifier_authority] or ["sample", trace, verifier_authority] | One verifier's re-execution, inside a dispute or as a sample. Closable once settled. | commitment, revealed hash, divergence, matched, stake weight, liability end, slashed |
| Verifier | 339 | ["verifier", authority] | A bonded node that re-executes traces. | bond, work counts, rewards, slashed amount, lock, endpoint, curated, fee epoch and amounts owed |
| FeeEpoch | 68 | ["fee_epoch", epoch] | One epoch's fee pool, shared by the verifiers who did slashable work in it. | fees, fees carried in from no-work epochs, carry streak, bootstrap released, eligible bond, workers, settled |
| Bounty | 380 | ["bounty", trace] | A requester's escrow against one trace. Closed when it settles. | requester, amount, entries (verifier, weight, matched) |
4Events#
State changes are announced as events. The commit transaction and its TraceCommitted event stay in the ledger even after close_trace removes the account, so history does not depend on the account surviving.
| Event | Carries |
|---|---|
| ConfigInitialized | authority, mint, vault, challenge window, rerun quorum |
| ConfigUpdated | authority, paused |
| AuthorityTransferred | previous, current |
| VerifierPermissioningChanged | authority, permissioned |
| VerifierCurationChanged | verifier, curated |
| ReservedCuratedSlotsChanged | reserved curated slots |
| IncidentStakeThresholdChanged | min incident stake |
| PlateRegistered | plate, provider, weights hash, fingerprint, match policy, tolerance, quorum floor, bond |
| PlateStatusChanged | plate, status, bond, unlock time |
| PlateBondReleased | plate, provider, amount |
| PlateFeeClassChanged | plate, fee class |
| TraceCommitted | trace, plate, provider, nonce, input hash, output hash, fingerprint, tier, challenge deadline |
| TraceStatusChanged | trace, plate, status |
| TraceAttested | trace, attestation hash, vendor, signer |
| ProofSubmitted | trace, system, proof hash, circuit id, covered bps, on_chain_verified (always false) |
| TraceVerified | trace, plate, tier, confirmations |
| TraceClosed | trace, plate, provider, nonce, refund |
| SampleSubmitted | trace, verifier, re-run hash, divergence, matched, confirmations, divergences |
| SamplerSlashed | verifier, trace, incident, amount |
| VerifierRegistered | verifier, authority, bond |
| VerifierBondChanged | verifier, delta, bond, active |
| IncidentOpened | incident, trace, challenger, bond, required quorum, required stake, deadlines |
| RerunCommitted | incident, verifier, commitment |
| RerunRevealed | incident, verifier, re-run hash, divergence, matched, stake weight, running votes |
| RerunSettled | incident, verifier, won, reward, penalty |
| IncidentResolved | verdict, votes, match and mismatch stake, slashed, burned, challenger payout, reward pool |
| IncidentFeeSettled | incident, challenger, amount, refunded |
| RerunRecordClosed | record, verifier, subject, refund |
| FeeVaultInitialized | fee vault, epoch length |
| FeeConfigUpdated | fees enabled, every fee amount, split and bootstrap setting |
| FeeCollected | source, payer, amount, to verifiers, to burn, to treasury, epoch |
| WorkRegistered | verifier, epoch, weight, bootstrap released |
| FeeEpochSettled | verifier, epoch, share |
| FeesClaimed | verifier, amount |
| FeeEpochRolledOver | from epoch, to epoch, amount, carry streak |
| FeeEpochSwept | epoch, amount burned |
| FeeRolloverLimitChanged | max fee rollover epochs |
| FeeBurnFlushed | amount |
| TreasuryWithdrawn | destination, amount |
| BootstrapFunded | funder, amount, pool |
| BootstrapSwept | amount |
| VerificationRequested | trace, bounty, requester, amount |
| BountySettled | trace, amount, paid, payees, burned, to treasury, refunded |
5Parameters#
Read from the devnet Config account on 2026-10-06. Bond amounts are in whole tokens of the devnet test mint (6 decimals), not $KORTX. These are devnet readings, not the mainnet values; the mainnet Config account above holds those. The right-hand column is the constraint each mainnet value has to satisfy, from the security and economics reviews.
| Parameter | Devnet | Meaning | Mainnet value must |
|---|---|---|---|
| min_provider_bond | 1,000 | Least bond behind a plate. | High enough that a false plate costs more than it earns. |
| min_verifier_bond | 500 | Least bond behind a verifier. | High enough that many verifier keys cost something real. |
| min_challenge_bond | 100 | Least bond behind an objection. | Low enough that an honest challenger can afford it. |
| challenge_window_secs | 1,800 (30 min) | How long after commit a trace can be challenged. | Hours, so an honest verifier has time to sample. |
| rerun_commit_secs | 600 (10 min) | Blinded commit phase of a dispute. | Long enough to actually re-run the model. |
| reveal_window_secs | 600 (10 min) | Reveal phase after the commit phase closes. | Long enough to reveal; not so long it stalls bond release. |
| verifier_cooldown_secs | 3,600 (1 h) | Wait before a verifier bond can be withdrawn. | Above zero, and longer than any dispute a verifier can be in. |
| retire_cooldown_secs | 1,800 (30 min) | Wait between retiring a plate and releasing its bond. | At least the challenge window. |
| slash_bps | 3,000 (30%) | Share of the provider bond taken when a dispute is upheld. | Deterrent without making a false ruling ruinous. |
| verifier_slash_bps | 2,000 (20%) | Share of a verifier bond lost by a wrong or missing reveal, or by a matched sample an upheld incident contradicts. | Above zero, so withholding a reveal or echoing a hash is never free. |
| burn_bps | 7,000 (70%) | Share of every penalty pool that is burned. | Dominant, so a captured ruling is not profitable. |
| challenger_bps | 1,500 (15%) | Share of an upheld pool paid to the challenger. | Small: repays an honest challenger, does not fund an attack. |
| verifier_bps | 1,500 (15%) | Share of the pool for winning verifiers. Takes the remainder. | Small. |
| rerun_quorum | 3 | Reveals needed for a ruling. Fewer and the dispute is void. The program refuses less than 3. | Raised with the number of independent operators. |
| min_incident_stake | 6,000 | Least total revealed stake for a verdict, beside the quorum. | Above what outside keys in the open slots can reach together. |
| sample_quorum | 2 | Matching samples needed to mark a trace verified. | Under review. |
| permissioned_verifiers | on | register_verifier needs the config authority to co-sign. | On at launch. |
| reserved_curated_slots | 5 of 7 | Re-run slots per incident only curated verifiers can take. Others share the rest. | Kept until independent operators are admitted. |
Fee settings
Also read from devnet on 2026-10-06, when fees were off and the fee vault was not initialised. Fee amounts are fixed $KORTX values the config authority sets and adjusts when the price moves.
| Field | Devnet | Meaning |
|---|---|---|
| fees_enabled | false | Nothing is charged until the authority turns fees on. |
| external_commit_fee | 0 | Fixed $KORTX per commit on an External plate. |
| nucleate_call_fee | 0 | Fixed $KORTX per commit on a NucleateCall plate. |
| incident_open_fee | 0 | Fixed $KORTX escrowed on open. Refunded if upheld, forfeited if rejected or void. |
| min_bounty | 0 | Least bounty a verification request may escrow. |
| fee_verifier / burn / treasury_bps | 6,000 / 3,000 / 1,000 | Split of commit fees and forfeited incident fees. |
| bounty_verifier / burn / treasury_bps | 9,000 / 500 / 500 | Split of a bounty. Bought verification work, so most of it pays the work. |
| sample_cap | 3 | First K checks accepted per trace, raised to the sample quorum if that is higher. |
| fee_epoch_secs | 0 (fee vault not initialised) | Length of a fee epoch, fixed by init_fee_vault. |
| max_fee_rollover_epochs | 30 | Consecutive no-work epochs a verifier share rolls forward through before it is burned. |
| bootstrap_per_work / epoch_cap / end_ts | 0 (inactive) | Finite per-work subsidy from existing tokens. Tapers as real fees fill the epoch cap, ends at end_ts, remainder burned. |
Bounds the program enforces
| Constant | Value | Why |
|---|---|---|
| MAX_RERUNS | 7 | Every rerun record settles in one transaction. Measured worst case: 970 bytes with 7 votes and fee accounts, under the 1,232-byte limit. |
| MIN_RERUN_QUORUM | 3 | The chain never re-runs the model, so no single verifier may settle a slash, under any match policy. |
| MIN_TOLERANT_QUORUM | 3 | A tolerance policy is judged on verifiers' reported divergence, so it needs several voices. |
| MIN_CHALLENGE_WINDOW_SECS | 30 | Floor only. The devnet Config read 1,800. |
| MAX_CHALLENGE_WINDOW_SECS | 2,592,000 (30 days) | Caps how long a bond can be held open. |
| MAX_URI_LEN | 128 | Account space is allocated at the maximum. |
6SDK#
@kortx/sdk hashes locally and synchronously; issuing a receipt needs no network. The Solana packages are optional peers, loaded only to submit. It is in the KORTX repository and not yet published to npm.
Issue a receipt
import { createKortx } from '@kortx/sdk';
const kortx = createKortx({
plate: PLATE_ADDRESS, // the plate you registered
provider: PROVIDER_ADDRESS, // the key that signs commits
model: 'my-model', // short label for the badge
});
const receipt = await kortx.trace({
input: { prompt: 'What is a cloud chamber?' },
output: { text: 'A vessel of supersaturated vapour.' },
});
receipt.inputHash; // 64 hex characters, canonicalised under kcf-1/strict
receipt.committed; // false -- nothing has been submitted
receipt.warnings; // says what this receipt does not establishCommit on chain
import { createKortx, createSolanaChainAdapter } from '@kortx/sdk';
const chain = await createSolanaChainAdapter({
endpoint: 'https://api.mainnet-beta.solana.com',
wallet, // { publicKey, signTransaction }
});
const kortx = createKortx({ chain, plate: PLATE_ADDRESS, provider: PROVIDER_ADDRESS });
const receipt = await kortx.trace({
input,
output,
modelFingerprint, // 32 bytes or 64 hex; must equal the plate's
seed: 42,
tier: 'sampled',
evidenceUri, // on the receipt and its content id; the program does not take it
nonce: 7n, // sequence under the plate
});
receipt.committed; // true
receipt.signature; // the transaction signature
receipt.traceAddress; // the trace accountRead the index
import { IndexerClient, IndexerUnavailableError } from '@kortx/sdk';
const indexer = new IndexerClient({ baseUrl: INDEXER_URL });
try {
const res = await indexer.listTraces({ provider, limit: 50 });
res.data.length; // 0 here is a measurement: no traces
} catch (err) {
if (err instanceof IndexerUnavailableError) {
// HTTP 503: the index could not answer. Not the same as zero.
}
throw err;
}7CLI#
kortx-cli installs a kortx command, Node 20 or newer. Like the SDK it is in the repository and not yet on npm. Reading commands need no wallet.
kortx trace <trace-id>
kortx trace list --provider <address> --tier sampled
kortx plate get <plate-address>
kortx incident get <incident-address>
kortx track [<provider-address>]
kortx ionize verifiers --active-only
kortx verify <trace-id> --input request.json --output response.jsonkortx plate register --model-id <id> --weights-hash <hex> --fingerprint <hex> \
--bond <n> --backend <text> [--dry-run] [--keypair <path>]
kortx trace commit --input <path|-> --output <path|-> --plate <address> \
--nonce <n> --fingerprint <hex> [--tier <tier>] [--dry-run]
kortx incident file --trace <address> --claim-hash <hex> --reason <uri> \
--bond <n> [--index <n>] [--dry-run]| Exit | Meaning |
|---|---|
| 0 | The command ran. For verify: the commitment re-derived and matched. |
| 1 | Runtime failure: network, chain or filesystem. |
| 2 | The invocation was wrong. Nothing was attempted. |
| 3 | A comparison completed and came back FAIL. |
| 4 | The index could not answer (HTTP 503 or unreachable). Not a verdict. |
| 5 | The record is absent from the index (HTTP 404). |
8What changed#
How the current program differs from the first one, whose devnet deployment was closed on 2026-10-06.
Curated verifiers and reserved slots
Live on mainnetRegistration needs the config authority's co-signature while permissioned_verifiers is on, and co-signed verifiers are marked curated. Each incident holds 5 of its 7 re-run slots for curated verifiers; everyone else shares 2.
Open registration let someone with enough verifier keys fill every slot and force a ruling against an honest provider. The security review reproduced it, then reproduced the fix: seven outside keys get two slots and the curated majority keeps the verdict.
Stake-weighted rulings, quorum 3, minimum stake
Live on mainnetEach reveal is weighed by the bond behind it, snapshotted at reveal. A verdict needs at least 3 reveals and, if set, a minimum revealed stake; otherwise the dispute is void. The verifier share is paid by stake.
Splitting one bond across many keys buys no extra weight or reward, and a swarm of small keys without enough stake can no longer reach a slash.
Burn-dominant split
Live on mainnetslash_bps 30%, and the penalty pool split 70% burned, 15% to the challenger, 15% to the verifiers who voted with the ruling. Set with update_config on devnet on 2026-10-06; the same values are the mainnet launch profile. A parameter the authority can change, not code.
At the first split (50% slash, 50/30/20) a captured ruling paid its attacker a quarter of an honest provider's bond. When most of the pool burns, capturing a ruling stops paying.
Fee vault
Live on mainnetCommit fees, verification bounties and incident fees, each a fixed $KORTX amount in Config that starts at zero, settle in a vault separate from bonds. Verifiers who did slashable work in an epoch share that epoch's fees by bond; an epoch where nobody worked rolls its verifier share forward instead of burning it. A share is burned; a share funds the treasury. A finite bootstrap pool exists and ships inactive.
Before it, a verifier was paid only out of bonds someone else lost, so an honest network paid its verifiers nothing. The vault is in the program; fees start switched off.
Paid samples with liability
Live on mainnetOnly the first 3 checks per trace count. A matched re-execution inside the window locks the sampler's bond until the trace can no longer be upheld, and an upheld incident slashes it. Samples after the window are recorded, not paid.
A sample that matched a public hash may only have copied it. Payment is capped, and copying an output that later fails costs the bond.
Non-curated divergence does not touch the badge
Live on mainnetA diverged sample from a non-curated verifier is recorded, but neither counts against the trace nor removes its verified badge. A curated verifier's divergence still does.
A diverged sample carries no bond liability, so any new key could otherwise deny a trace its badge for the price of rent. A real mismatch goes through a bonded incident.
close_trace and a smaller trace
Live on mainnetA trace is 271 bytes, with attestation and proof moved to accounts created only when that evidence exists. After its window, with no incident or unsettled bounty open, it can be closed and its rent returned to the provider. Nonces only go up, so a closed address cannot be reused.
The first program had no close, so every commit locked 897 bytes of rent for good.
Rerun records close too
Live on mainnetclose_rerun_record returns a vote's rent to its verifier once the incident has settled, and a sample's once its trace has closed and its liability has lapsed.
Verifiers otherwise lock rent for every check they ever made.
Mint guard
Live on mainnetinitialize_config refuses a bond mint with a freeze authority, a permanent delegate, a transfer hook, confidential transfers, non-transferability or a default account state.
Each of those would let someone freeze or drain the vault, or stop bonds from moving.