Trust model: who can do what
This page puts the weaknesses in writing. The owner's wallet decides who owns a name. The platform pays for gas and issues names — and it holds one permission we would rather not have: the registry admin is an operational hot wallet, it can add itself to the registrar list, and a registrar can rewrite any name's address records.
1. True today
- Ownership follows the owner's signature: the registrar requires a signature from the beneficiary, and a signed label cannot be swapped for another name or another person. The platform pays the gas and does not get the name.
- The registry has no burn and no admin transfer, and the platform has no call that takes a name back or moves it.
- Resolution works on real mainnet (
bruce.musepass.ethresolves to the owner's address), and when its RPC fails the gateway returns an error rather than signing an empty answer. - Exactly one thing is issued today: the name, an ERC-721 that sits in your wallet. The card is an on-chain record, not a token, and the stamps on a passport are not tokens either. There is no second collection, no invitation token and no seat sale. If something claims to be one of those and it is not in this repository, it is not ours.
2. False today, which is why we do not write it
- “The platform cannot change your name.” Measured on chain on 2026-09-29: the registry admin is the operational hot wallet
0x66F499e8…, it can calladdRegistrarto add itself (the call does not revert), and a registrar can rewrite any name's address and text records. Until that permission is moved, the sentence does not hold. - “Independently verified.” The only verifier today is our own AI2Human engine, from the same team. We do not say independent.
- “Records cannot be changed.” The append-only record contract is not deployed. What exists on chain is one zero-value self-transfer with a digest root in its calldata (see anchored batches).
3. What we do about that permission
Rather than move the admin permission to a multisig right now, the project made misuse detectable: anyone can run node scripts/security-power-inventory.mjs, which reads chain state and exits 1 the moment the hot wallet becomes a registrar. That is the attacker's first step, and normal operation never needs it, so the alarm has no false positives — the price is that it can only tell you after that first step, not stop it.
4. When that permission goes away
When the registry admin, the registrar owner and the resolver owner are moved to a hardware wallet or a multisig with an outside signer, and the hot wallet is left with the gas-paying role alone, we will publish the transaction hashes. Then the first item in section 2 comes off this page. Until then it stays.
There is no on-call rota and no SLA. This is a single-machine project; the sentence is here so nobody assumes otherwise.