The purse

The network finds a bad root. Now what?

Until now the honest answer was: publish, and hope somebody with standing reads it. The Citizen Challenger Fund is the other answer — we cannot challenge, so we pay somebody who can.

What has to happen, in order

  1. 01
    Five independent nodes flag the same root
    Distinct signing keys, not five reports from one retry loop. This stops a single loud operator arming the treasury alone.
  2. 02
    Holding 15% of network reputation between them
    Fifty brand-new nodes are cheap to spin up and hold almost no points, so their combined share stays near zero however many there are. This is the Sybil guard, and it is why the threshold weighs earned standing rather than head count.
  3. 03
    All within one hour
    Nodes that noticed the same thing inside the hour were watching the chain, not watching each other.
  4. 04
    Verderer-rank operators vote
    Weighted by reputation. Quorum is measured against the whole network’s active standing, not against turnout — so abstaining counts against a proposal.
  5. 05
    The fund pays an allowlisted actor to file
    With the network’s checkpointed attestation log as the evidence. They file; we cannot.

Three states of the vault

Reserve now
Capital held against the day the allowlist opens. Labelled a reserve because that is all it is — no bond is posted and no yield is promised.
Response
Arms automatically on an incident. Senior operators may then vote to release funds. This is what stops the reserve being dead capital while we wait.
Active
Only if the allowlist ever opens. The reserve becomes a real validator bond and the network challenges for itself. No date, and not promised.

Why only the senior rank votes

Verderer takes five thousand confirmed attestations. Months of being right, and it cannot be bought or hurried. Money is being spent on an irreversible external action, on evidence the network itself produced — the people deciding should be the ones with the longest record of correct work.

A token vote would put that decision up for sale. A head count would hand it to whoever can afford the most addresses.

Who could actually file

These are the addresses the rollup permits. A payout can only go to one the operators allowlisted in the contract.

0xa0A1D8cd6f867a583a39232a477ff231aFD8eC4Con the rollup’s validator list
0x992D8d50548fCcCaF11147A9a692c496011C8Aa0on the rollup’s validator list

That contract allowlist is a guard against paying the wrong address, not proof of anything — it lives on Robinhood Chain and cannot read Ethereum. Operators are expected to check the real set themselves, which is why it is printed here.

The obvious objection

A fund that has never paid out, for a challenge nobody here can bring, against a fault that has never been found — zero incidents to date.

All true. What it buys is that the answer to “what do you do about it?” stops being “nothing”.

not deployed
Neither the vault nor the fund is live. Both are written and tested, awaiting the audit in phase 4 — so this page describes a design, and says so rather than showing an empty balance. The rest of what is not built.