TaifoonTAIFOON
[ foonBTC · VAULT LIFECYCLE · PROVEN ON-CHAIN ]

The mechanism works.
Here’s the proof.

foonBTC’s custody isn’t a promise — it’s a mechanism we ran end-to-end on-chain: 10 real 3-of-5 Gnosis Safes, a full genesis → propagate → wave lifecycle with actual multisig-signed transactions, and a supply invariant that held to the unit. This page publishes that run. Every address below is a throwaway devnet artifact with no live value — a demonstration, deliberately not a live custody map.

Cluster Safes
10
5 hot · 5 reserve · each 3-of-5
Lifecycle
genesis→wave
real multisig-signed txns
Supply invariant
HELD
nothing created or destroyed
Environment
Devnet
throwaway — no live value
[ The run ]

Six steps, every one a real on-chain action.

Executed 2026-07-24 on devnet 36927 (local anvil — throwaway). Each propagate and wave move is a genuine Safe.execTransaction signed by that cluster's 3-of-5 — not a simulation.

01
Deploy infra
Safe singleton + factory + foonBTC token
3 contracts live
02
Deploy clusters
10 cluster Safes, each independent 3-of-5
A–J deployed
03
Genesis
mint float → seed cluster A
2,100,000 foonBTC into A
04
Propagate
A fans out to all clusters at band targets — real 3-of-5 exec each
A remainder 1,018,500
05
Wave
clusters A & B each serve a payout
10,000 foonBTC delivered
06
Invariant
clusters + recipient vs total supply
EQUAL — nothing created or destroyed
● Invariant: clusters + recipient = 2,100,000 = total supply 2,100,000 foonBTC — EQUAL
[ The Safes ]

Ten independent 3-of-5 vaults, hot and cold.

Each cluster is its own Gnosis Safe with 5 owners and a threshold of 3 — no single key moves funds. Hot tier (A–E) serves payouts; reserve tier (F–J) backs them. This is the exact custody shape foonBTC's mainnet reserve will use, born from the council seed rather than these devnet keys.

A0x1048D4ec6b6B1fe6D31E7D4B4ab633587D666413hot
B0xAD9b34cF5C75168b5BA4A50D379f22e1772e22E7hot
C0x5Ce20Aa317e2D8D50213B338f8Ce866cD4f30C63hot
D0x10889E2462c4Ab8096Df32153f5D9B75a36f0A51hot
E0x1a0b6b6E4eDE3064Af6570CFEeFe3827C59bBF78hot
F0xf357627988abbF740061B9227afB7Fcc9badDaf2reserve
G0xd7072c62bf32d445c8F70C623812502B130c242dreserve
H0xA656cc08B47987577950c9369a2c09066b3494A2reserve
I0x53b9968500A513235ECF83FA15eBf4581A06F1c1reserve
J0x2Ef61194742B93C564868e5BE0186F7b6B983aB2reserve
[ Infrastructure ]

Deployed contracts (devnet).

The Safe stack and demo token this run deployed. Throwaway addresses on a local devnet — published so the run is fully checkable, not because they hold anything.

Safe singleton0x5FbDB2315678afecb367f032d93F642f64180aa3Gnosis Safe 1.3.0 master copy
Safe proxy factory0xe7f1725E7734CE288F8367e1Bb143E90bb3F0512deploys the cluster proxies
foonBTC token (devnet)0x9fE46736679d2D9a65F0992F2272dE9f3c7fa6e08 decimals · devnet demo token
[ Read this ]

What this proves — and what it deliberately isn't.

It proves

The custody mechanism runs end-to-end on-chain: real multisig Safes, real threshold signing, a real lifecycle, an invariant that holds. Not slideware — executed.

It isn’t

A live custody map. Every address is a devnet throwaway with no value. Mainnet foonBTC custody uses Safes owned by the council seed, on the real chain, and those addresses are not published here — deliberately.

/rgb/proof · devnet demonstration · no live value · 2026-07-24