ETERNITY
Relaunch Program Brief
Phase: Research & Architecture → Stage-1 live trials (multi-chain) Direction: BINDING · EFT-first (07-19) Updated: 2026-07-23 · every working session Private — CF Access · read-only, act on the Board
0
Launch blockers
LB-1 resolved (Yuriy 07-21) — snapshot-based allocation, legacy keys can't inflate
5
Decisions open
Reserve architecture · launch chain · VIP entitlement · migration · VRF-callback re-cut
3
Founder asks open
Armen 1 · Yuriy 2 · (onboarding + LB-1 custody closed)
4/13
Workstreams done
6 active · 1 needs founders · 2 parked

Decision queue

tap an item → its GitHub issuefull board →

Workstreams

detail lives in the vault + board
Architecture spike ACTIVE
Amoy live game test ACTIVE
Security pipeline — Aikido DONE
Game rebuild — design intake ACTIVE
Security — zero trust NEEDS FOUNDERS
Treasury design ACTIVE
EFT tokenomics DONE
Code inventory DONE
GitLab source recovery DONE
Two-Claude protocol ACTIVE
Shared brain (vault) ACTIVE
VIP page — EFT mint QUEUED
Compliance — markets DEFERRED

Inventory — Stage-1 multi-chain rig

click a value to select it, then copyStage-1 spec #11 →
Deployer key FUNDED
0x1a34e5aE878A4DB6E7ece8AfEcF8b6cA6E2b02Bd
key: GCP Secret Manager · eternity-stage1-deployer-key · value never leaves the store · deploys contracts only · 0.07 ETH on Base Sepolia
Operator key FUNDED
0xAE9432ea6653F659592aBE8E146d2A3c1604aD49
key: GCP Secret Manager · eternity-stage1-operator-key · runs settlement · deployer ≠ operator so drills exercise the real mainnet blast radius · 0.03 ETH on Base Sepolia
Amoy test wallet FUNDED
0xF0C51CFC317eBa73Be4085C79F40f87706c15b5d
key: GCP Secret Manager · eternity-amoy-testnet-key · the original single-key rig, kept for continuity
Base Sepolia LEAD CANDIDATE
chainId84532
RPChttps://sepolia.base.org
currency ETH · VRF 0-conf (only candidate clearing p95<4s) · EIP-2537 7/7 · gas ~0.005 gwei
Polygon Amoy COMPARISON
chainId80002
RPChttps://polygon-amoy-bor-rpc.publicnode.com
currency POL · VRF 3-conf (~4.5–6s floor) · EIP-2537 7/7 · zero-migration baseline · official RPC refuses connections — use publicnode
RNG — drand quicknet MEASURED
cadence3s
verify140,516 gas / round
threshold BLS · free, no provider fee · cannot bias or abort below threshold · live beacon verified on-chain 07-23 · $0.00162/beacon ≈ $840/mo
RNG — Chainlink VRF MISSES GATE
p9510.0 s
under 4s0 / 16
measured on Base at 0 confirmations — the best config on the best chain · latency quantum is the block (3–5 blocks), not a tunable delay → masked by the flip animation (#16)
Eliminated — Immutable zkEVM OUT
VRFnone
EIP-25370 / 7
no Chainlink VRF and no BLS precompiles → only an unaudited ~140k-gas Solidity verifier · TCG pedigree does not transfer to a chance-settlement workload
Draw spec RATIFIED
denominator3,000,000
King6 in 3,000,000
published odds = delivered odds, exactly · rejection sampling from a 64-bit keccak slice · P(re-roll) 8.4e-14 · callback ceiling 2,500,000 gas on every chain

What changed

newest firstall handoffs →
07-23The session ritual is now symmetric and three-surfaced — overlap is guarded, tracking can't drift — the two-Claude protocol gained a real start and end discipline. At start, both Claudes read the last day of the shared Slack line and post what they're about to work on before touching anything, so two live sessions can't silently land on the same file (the Slack post is the same-day claim that closes the gap before the GitHub assignee shows it). At end, a session isn't done until all three places we track state agree: the vault handoff, the kanban board (every touched issue moved to its true column, board status matching issue state), and this status page (edited and deployed — a push is not a deploy). Recorded in the collaboration protocol; a shared-surface change, flagged for Armen's async review
07-23Both founders' Claudes are now on the same board — the two-instance workspace is live — Armen connected armen-claude tonight; it ingested the full vault, all issues and the spike, and is actively monitoring this program and the channel. Onboarding is complete (#3 closed — kardashi confirmed, repo + board access accepted). Division of labor is claimed on the board: armen-claude takes the architecture split (#13) and independent re-verification of the vault criticals; yura-claude holds security and tooling. First real exchange already happened — Armen asked how to make the game gasless with minimal latency (Polymarket-style); the answer: sponsored gas is viable only as an optional layer over a permissionless self-pay path, and it will not speed the reveal (latency is randomness delivery, not gas) — a founder call, flagged not decided. Underneath it: attribution is now enforced, not just policy (#17) — every shared note must name the Claude or human that wrote it or the write is blocked, and the guard hooks now travel with the repos to both machines, so shared work is auditable by construction
07-23The legacy game frontend was mined for the rebuild — Armen shared the shipped Vue game frontend and it was copied clean and inventoried in full. It is production evidence, not a mockup, and it confirmed four things we had decided on paper: the flip is purely cosmetic (the backend picks the card before any animation runs), the card model is the ratified 53-slot / 13-rank deck, and both settlement models we are choosing between were already built — so the spike's deposit-vs-direct question is not greenfield. The old GameTreasury / TreasuryReserve contracts already split the pool two ways — a first draft of the #14 design — but the reserve exposes a withdraw-to-any-address that is exactly the single-key pattern zero-trust forbids: reference the shape, reject the trust model. One housekeeping find: live RPC/provider keys are committed in that repo — read-only data keys, not fund keys, but flagged for rotation (#18, Armen)
07-23The treasury architecture is on the table — four contracts, ready to ratify — the #14 session first pulled three unrecorded founder rulings out of the late-night Q&A (the fee never routes into the bankroll — it burns for EFT games or goes to the investor DAO for USDC; tier pricing ratified; Joker deferred), then Yuriy re-scoped to contract mechanics and the design landed: Game / GameTreasury / ReserveTreasury / FeeRouter per collection — claims auto-borrow from the reserve, every incoming payment repays the loan first (the legacy one-way flaw inverted into structure), bankroller principal at par with fee income streamed from the router, exits queue while a loan is out (the bank-deposit principle, ruled) · per-collection bankrolling ruled: EFT = company-bankrolled, fee burns · USDC = external bankrollers paid a fee share · the merge question was steelmanned both ways and settled — the treasuries stay separate (the token balance itself is a free conservation check) · spike question #1 answered: direct settlement — pay at mint, receive at claim, the game never holds unwagered player money; the deposit-once feel comes from a one-time allowance instead · P1–P7 await founder yes/no — ratifying closes #14's architecture; every rate, split, cap and lock stays a timelocked parameter
07-22The vocabulary is now binding — 36 terms, one meaning each — a Socratic session with Yuriy produced the glossary, normative for contracts, code, notes and player-facing copy (the legacy money bug was a cap defined in two places; a word meaning two things in two places is the same fault one level up). Yuriy defined the money layer himself: bankrollers deposit into a capped, locked reserve treasury that lends to the game treasury, and are paid a share of fees — the investor DAO is a separate class. Four things it changed rather than recorded: the collection price is now a free parameter (the odds are pure ratios, so the same game runs at $100k or 1 BTC — the reserve target is 1.73 collections, whatever a collection costs) · a draw-table flaw caught before build (five of thirteen ranks cannot divide evenly by four suits, so one design option needs a 4× larger draw space — priced, nothing broken) · three inherited rules deleted by being made impossible to state · and the "2% house edge" everyone has been saying is really a 2% fee (the house edge is 1.9608%)
07-22Stage-1 is now multi-chain, and the field narrowed to two — the Amoy-only plan was re-cut into a multi-chain spec (#11). Structural finding: chain choice and RNG choice are the same decision — Chainlink’s minimum confirmations is a per-chain constant we cannot tune (Base 0, Polygon 3, Ronin 3, Immutable none at all), so a 3-conf chain puts a ~4.5–6s floor under every reveal and likely fails the 4s gate outright. The blocking RNG pre-check ran and came back favorable: the BLS precompiles drand needs are live on every candidate chain except Immutable (Ethereum, Base, Polygon, Ronin, Arbitrum, Optimism all 7/7; Immutable 0/7, re-verified). So drand stays primary — free, no provider fee, and cryptographically unable to bias or abort — at roughly half Chainlink’s cost (~$805/mo on Base, ~$1,876 on Polygon, ceilings that hold no matter how many players show up). Immutable is eliminated (no VRF and no precompiles — its only path would be an unaudited verifier in the most security-critical position; and per Yuriy the Gods Unchained pedigree does not transfer, since this is a game of chance, not a TCG). Base leads on both pillars, Polygon stays as the zero-migration comparison. Deployer and operator keys generated into GCP Secret Manager, separated from day one so the drills exercise the real mainnet blast radius — two founder asks remain: a Coinbase Developer Platform account (Base Sepolia gas + test USDC in one claim) and testnet LINK