Source errata
This book is assembled from the project's documents. Several of them still carry a state of the world that has changed. This page says which, so they can be repaired — and so nobody assumes the book contradicts them by mistake.
Corrected while writing this book
| Source | What was wrong |
|---|---|
doc/ECONOMIE.md §10 |
The recap still printed the 4 % schedule while §1 of the same document said 5 %. A document that declares itself the arbiter was contradicting itself in its own summary |
doc/ECONOMIE.md §2, §3, §12 |
Described the bonding curve, graduation, and the invariant "graduation is irreversible" |
doc/BRANDING.md |
The word-for-word mandated sentence named Ondo Global Markets as the issuer |
doc/DECISIONS.md |
The frozen tables still carried 800M curve / 200M LP, the graduation threshold and the graduation fee |
doc/CASE_STUDY.md |
Listed Robinhood Stock Tokens among the rejected rails, "on an unsuitable chain" |
projet/README.md |
The Compliance paragraph named only Ondo |
projet/docs/ACCEPTANCE.md |
Cited three tests under their old …takesFourPercent… names |
projet/dapp/ |
The Treasury Ratio tooltip contained the word redemption, forbidden by BRANDING.md. Fixed on 2026-09-26 |
doc/DIAGRAMS.md |
Four of seven diagrams described the curve and graduation. Redrawn on 2026-09-28 around the two-position launch |
doc/ACCEPTANCE.md, doc/USER_FLOWS.md, doc/PRD.md, doc/TESTNET_RUN.md, doc/CONTRACT_SPEC.md, doc/TREASURY_FLOW.md, doc/DEV_HANDOFF.md, doc/FRONTEND.md, doc/ROADMAP.md |
Described the launch on the bonding curve, with graduation. Rewritten on 2026-09-28, when the launch redesign reached the code |
projet/README.md, projet/docs/RUNBOOK.md, projet/docs/ACCEPTANCE.md |
Described the launch as the code then did, with the bonding curve. Rewritten on 2026-09-28; SECURITY_REVIEW.md, IMPLEMENTATION_DECISIONS.md and projet/contracts/certora/RESULTS.md, which are logs, carry a dated note instead |
projet/dapp/ |
/launch showed "You pay: gas only". Since 2026-09-28 it shows the 0.001 ETH creation fee plus the optional launch buy |
doc/FRONTEND.md, doc/DEV_HANDOFF.md, doc/DECISIONS.md |
Mandated, or named in the frozen stack, a Next.js front end while the dapp in the repository was React + Vite. Resolved on 2026-10-02 by the code, not the documents: the app that replaced that dapp, cairn-app/, is a Next.js app |
Not yet corrected
| Source | What is still wrong |
|---|---|
doc/DIAGRAMS.md |
The architecture diagram shows no bridge |
doc/ACCEPTANCE.md |
The copy criteria still require the Ondo sentence |
doc/TESTNET_RUN.md |
The testnet plan still rests on Ondo mocks |
doc/ACCEPTANCE.md, doc/USER_FLOWS.md, doc/FRONTEND.md, doc/DIAGRAMS.md |
Still place the airdrop on Robinhood Chain, while the 2026-09-28 amendment moves it to Ethereum, in wrapped stocks |
doc/CONTRACT_SPEC.md |
The cross-chain contracts are not specified there |
doc/ROBINHOOD_TOKENS.md |
A historical 20-asset survey. The API listed 194 as of 2026-09-11, MSFT included |
projet/docs/IMPLEMENTATION_DECISIONS.md |
§17 still presents Ondo as the primary rail |
This book before the 2026-10-01 fixes
Earlier versions of this book stated four things that the security audit of 2026-09-29 showed did not hold in the code. They hold since the fixes of 2026-10-01.
| Statement | What the audit found |
|---|---|
| Every trade pays 5 % (Fees) | A third-party liquidity position traded against taxed swaps without paying the tax, nor the anti-snipe in the first ten blocks |
| A broken team or buyback wallet parks the fees instead of bricking the pool (The hook and anti-snipe) | A wallet that accepted the payment and then called the PoolManager could halt trading on every pool |
| The keeper chooses neither the assets nor the prices (The treasury) | By skipping stocks, a keeper could move almost all of a treasury into one stock of its basket |
| A contract computes every airdrop share from the holdings the token records (The airdrop) | The token recorded no total over time, so no contract could compute the denominator of a pro-rata share |
This book before the 2026-10-01 security pipeline
Earlier versions of this book stated three things that the security pipeline of 2026-10-01, a second audit round, showed did not hold, or not always. The first holds since its fixes, and the gas figure is corrected on its page. The third is a limit of the code, now stated on the pages concerned; on 2026-10-05 the owner decided to keep the code as it is.
| Statement | What the pipeline found |
|---|---|
| A route that fills only part of the amount fails, and the next candidate is tried (The Robinhood rail, Decision log) | Only on a v3 route's first pool. A partial fill further along left the intermediate token in Uniswap's v3 router, where anyone could take it, while the leg succeeded |
| A token's first swap of each hour costs about 23,000 gas more (The airdrop) | That was measured inside one transaction. As its own transaction, that swap costs about 28,000 to 30,000 gas more, at the prices before Ethereum's Glamsterdam upgrade; under it, 123,216 more on Sepolia |
| A market trades from any router that speaks v4 (Buying and selling) | Not every buy. A router that settles the buyer's ETH after the swap has the tax taken from the ETH the PoolManager already holds, and its buy reverts when the tax is larger |
This book before the audit loops of 2026-10-05
Earlier versions of this book stated two things that the audit loops of 2026-10-05 showed did not hold in the code. Both hold since the fixes of that day.
| Statement | What the loops found |
|---|---|
| A holding recorder named on a live token pays a holder it has not seen move less, and nobody more (The airdrop, Trust model) | Not for a window that started before the switch: measured from the switch only, it overpaid whoever moved after it, 15.7 times over in the test. Since the third loop no such window is measured on the new recorder |
The $STOCKFUN launch operator's holding between the mint and the lock is a tiny share of the first $STOCKFUN cycle (The airdrop) |
A window closing in between counted the operator alone, and paid it the whole first cycle. Since the third loop the launch script excludes the operator, and since the fourth it does so before the mint |
This book before the offchain pass of 2026-10-06
Earlier versions of this book stated the conversion cadence as decided, which the keeper's code did not follow. It holds since the fix of 2026-10-06.
| Statement | What the fifth loop's offchain review found |
|---|---|
| The keeper converts a vault's ETH once every 24 hours, just before the airdrop, if the vault holds the threshold, and crossing it during the day triggers nothing (The keeper, The airdrop, The treasury) | The keeper converted at any of its passes during the session, every five minutes by default, once a vault held the threshold. Since 2026-10-06 it converts once per window, at its first pass after the close |
The 2026-09-27 airdrop decision
The project's source documents in doc/ and the landing specification were aligned with
the airdrop on 2026-09-27. In the code, the creator buyback and the bridge's return path were
removed on 2026-09-28, the airdrop contract was coded on 2026-10-04, and the keeper's
airdrop step and the dapp's claim screen on 2026-10-05, none of it deployed. The stock
adapters are not coded. The app in the repository no longer shows the Treasury Ratio. See
Status.
Test counts
Five incompatible figures circulate in the sources, produced on different dates. This book cites none of them, deliberately. A test count only means something attached to a dated run, and the only thing it proves is what that run covered. The figures this book gives, in Testing and verification, come with the date of their run.
The excluded document
doc/ondo.md is a draft whose markdown is broken, entirely superseded by
projet/docs/ONDO_BRIEF.md and then made moot by the rail change. No page of this book drew
on it.