Security
What the chain refuses to trust
When a sentence is already unambiguous, every validator runs the same code. When it is not, they redo the work and accept the leader only if the decision matches. You sign writes in the connected wallet. The server is an index.
Prompt injection
Instruction-like forecast text is rejected before any model runs. Web pages have those lines stripped, and a page that is only instructions cannot become evidence.
Source policy
Resolution URLs must be HTTPS, public, and on the forecast’s frozen domain snapshot. Localhost, IP literals, userinfo, and fragments never render.
Equivalence
Imports and resolutions use a custom equivalence rule. Validators may use different words. They may not disagree on whether the page contained the sentence, on the verdict, or on whether the evidence was enough. A live price may print two different integers. They still have to agree whether the frozen comparison holds.
No server keys
Contract writes are signed in the browser wallet. The API has no endpoint that accepts a private key, and it will not attach a transaction that was sent to a different contract or that locks a different sentence.
Write-once verdicts
A failed resolution leaves the forecast open. A recorded verdict cannot be overwritten.
Reputation
Accuracy is correct divided by correct plus incorrect. Open calls, drafts, and unscored results are not treated as misses.