AQUIX Audit Report #1

Independent reconciliation · 2026-07-23 · methodology v1.0
Report #1 · 2026-07-23 · permanent

948 checks · 854 match · 70 adjudicated · 24 untestable · pipeline findings: 0

1 · What this is

This is an independent reconciliation of AQUIX's published money numbers against the Base blockchain, produced by a separate program that shares no code with the AQUIX pipeline. It re-derives each figure from public chain data and compares. What it is not: not a CPA attestation, not an opinion on the business, not a review of the site's derived metrics. It is a reproducible arithmetic check of on-chain settlement money, and nothing more. Anyone with an archive RPC can reproduce it (§9).

2 · Scope

Period 2026-07-08 → 2026-07-21 · chain Base · rail x402 / EIP-3009 gasless USDC. Strata & checks below (§5). Total checks 948854 MATCH · 70 DISCREPANCY · 24 UNTESTABLE. Method sha (audit lib) 1b4f11de32f473fd · compute ≈ 8.74M CU (stratum-f 3.89M + session-2 shared enums 4.85M) + adjudication probes. In scope: the money primitives — per-day settled USD, settlement counts, streaks, relay retention. Out of scope → Report #2: derived page metrics (Reality Ratio, signals, badges) and the two basis gaps surfaced here — AA-routed inbound (ERC-4337) and rail-scoped outflow.

3 · Method — independence

The auditor imports zero AQUIX pipeline modules. It has its own JSON-RPC client, its own full-day enumeration, and its own keep-rule reimplementation. The chain constants (USDC address, Transfer and AuthorizationUsed topics) are duplicated and verified-equal to the pipeline's, not shared. The keep-rule, in plain words: a USDC transfer counts as an x402 settlement iff its transaction also emitted an EIP-3009 AuthorizationUsed event whose authorizer equals the transfer's sender — and the transaction's submitter (facilitator) is neither the sender nor the receiver of that transfer.

4 · The three stated bases

Where the auditor's raw reading and the published number differ, it is almost always one of three definitions, not an error: (a) The Door-1 confirmation gate. AQUIX only counts settlements from facilitators seen in ≥3 of the last 7 daily windows. A naive reader counts more — every unconfirmed submitter too. That difference is the anti-wash gate working, not a shortfall. (b) Facilitator-is-payer exclusion (L482). When the facilitator is also the payer, the leg is self-dealing and is dropped. Cost: a small amount of genuine-looking volume is excluded to keep the number honest. (c) Daily-rail vs lifetime. The daily figure measures the standard AuthorizationUsed rail; ERC-4337 account-abstraction settlements are in lifetime totals but not yet per-day (disclosed).

5 · Results by stratum

StratumCheckMatchDiscUntestable
b-streak (S1)streak_days vs archived snapshots1000
f-latewrite (S1)completed-day Σ per tracked recipient5832114
a-giant (S2)16 giants via shared full-day enums34180
b-random (S2)40 random REAL agents12710
c-paycount (S2)in+out leg counts2460
d-relay (S2)retained = in − out46140
e-door3 (S2)ERC-4337 presence0010
f-shadow (S2)shadow in/out vs chain30100
Total8547024

6 · Every discrepancy, adjudicated

All 70 discrepancies resolve to one of: BASIS 35 (a stated definition, above) · AA/DOOR-3 6 (the disclosed ERC-4337 limit) · AUDIT-METHOD 29 (bugs in the auditor, §7).
RowAQUIXIndepΔClassEvidence
0x31d058b5e0@2026-07-0822441.322491.5950.29BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x13bfc43fbc@2026-07-082.943.57250.6325BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x636678e4be@2026-07-082.42856227.21922824.790666BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x03d773c52b@2026-07-089.07310.4511.378AUDIT-METHODfacilitator-is-payer self-settlement; auditor reimpl lacked the L482 filter
0xe742f9df04@2026-07-0845.368169124170.9024124125.534231BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x13bfc43fbc@2026-07-105.0326.791751.75975BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x0e3df9510d@2026-07-10151889.34151890.351.01AUDIT-METHODwhale per-recipient getLogs non-deterministic (819 vs 1)
0x03d773c52b@2026-07-102.6292.9120.283AUDIT-METHODfacilitator-is-payer self-settlement; auditor reimpl lacked the L482 filter
0x636678e4be@2026-07-101.24272115.78206214.539341BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x37b2a541e6@2026-07-101.9622865.0040353.041749BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x03d773c52b@2026-07-113.41212.0538.641AUDIT-METHODfacilitator-is-payer self-settlement; auditor reimpl lacked the L482 filter
0x8581784d3e@2026-07-110.0579150.7846940.726779BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0xe742f9df04@2026-07-11240542.50903740540.509037BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x13bfc43fbc@2026-07-110.5121.114750.60275BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x636678e4be@2026-07-110.6053125.3435024.73819BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x31d058b5e0@2026-07-1221274.7621325.3550.59BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0xf6ee347de6@2026-07-1211.07453711.0886370.0141BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x6e00773187@2026-07-120.2660.2960.03BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x03d773c52b@2026-07-121.1662.6441.478AUDIT-METHODfacilitator-is-payer self-settlement; auditor reimpl lacked the L482 filter
0x636678e4be@2026-07-126.379227.05501220.675812BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x13bfc43fbc@2026-07-120.5681.28150.7135BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x0e3df9510d@2026-07-21188268.04188269.051.01BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x31d058b5e0@2026-07-2152547.7252558.0210.3BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x0e3df9510d@2026-07-21204120421BASISa few unconfirmed-submitter legs (Door-1 gate); whale count re-run STABLE
0x93053f1e7a@2026-07-21retained~02.892.89AUDIT-METHODrail-scoped rawOut missed forwarding outflow; balance trajectory confirms net-zero
0x68396bd358@2026-07-21retained~03204.173204.17AUDIT-METHODrail-scoped rawOut missed forwarding outflow; balance trajectory confirms net-zero
0x0e3df9510d@2026-07-20213080.18213081.21.02AA/DOOR-3ERC-4337 tx (tx.to=router 0x5ff137d4, UserOperationEvent, paymaster in path)
0x31d058b5e0@2026-07-2052384.6452796.37411.73BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0xf6ee347de6@2026-07-201.6300541.6541190.024065BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x0e3df9510d@2026-07-20194619482BASISa few unconfirmed-submitter legs (Door-1 gate); whale count re-run STABLE
0x78f993378f@2026-07-20retained~0105105AUDIT-METHODrail-scoped rawOut missed forwarding outflow; balance trajectory confirms net-zero
0x93053f1e7a@2026-07-20retained~03.263.26AUDIT-METHODrail-scoped rawOut missed forwarding outflow; balance trajectory confirms net-zero
0x68396bd358@2026-07-20retained~03687.33687.3AUDIT-METHODrail-scoped rawOut missed forwarding outflow; balance trajectory confirms net-zero
0x0e3df9510d@2026-07-19172999.19173002.343.15BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x31d058b5e0@2026-07-1927973.4927999.0825.59BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x3803a19280@2026-07-190.0910.2010.11BASISsub-cent rounding on dust
0x0e3df9510d@2026-07-19164216442BASISa few unconfirmed-submitter legs (Door-1 gate); whale count re-run STABLE
0x93053f1e7a@2026-07-19retained~03.693.69AUDIT-METHODrail-scoped rawOut missed forwarding outflow; balance trajectory confirms net-zero
0x68396bd358@2026-07-19retained~04045.744045.74AUDIT-METHODrail-scoped rawOut missed forwarding outflow; balance trajectory confirms net-zero
0x0e3df9510d@2026-07-1898379.6698656.16276.5BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x31d058b5e0@2026-07-1816990.5917836.82846.23AA/DOOR-3ERC-4337 tx (tx.to=router 0x5ff137d4, UserOperationEvent, paymaster in path)
0xf6ee347de6@2026-07-181.0683431.1274790.059136AA/DOOR-3ERC-4337 tx (tx.to=router 0x5ff137d4, UserOperationEvent, paymaster in path)
0x0e3df9510d@2026-07-181574158612BASISa few unconfirmed-submitter legs (Door-1 gate); whale count re-run STABLE
0x93053f1e7a@2026-07-18retained~01.881.88AUDIT-METHODrail-scoped rawOut missed forwarding outflow; balance trajectory confirms net-zero
0x68396bd358@2026-07-18retained~04204.814204.81AUDIT-METHODrail-scoped rawOut missed forwarding outflow; balance trajectory confirms net-zero
shadow:0xe9030014@2026-07-182514.2692712565.0250.75AUDIT-METHODshadow forward-window vs single full-day enum (day-boundary + late arrivals)
shadow:0xa9dd7cc9@2026-07-1844.4055845.741.33AUDIT-METHODshadow forward-window vs single full-day enum (day-boundary + late arrivals)
shadow:0x6c0752c0@2026-07-1832.07639.046.97AUDIT-METHODshadow forward-window vs single full-day enum (day-boundary + late arrivals)
shadow:0x1e8e93cb@2026-07-182422508AUDIT-METHODshadow forward-window vs single full-day enum (day-boundary + late arrivals)
shadow:0x40a8cdd6@2026-07-188.6068.770.17AUDIT-METHODshadow forward-window vs single full-day enum (day-boundary + late arrivals)
shadow:0x5bb4b0c7@2026-07-181.1281.180.06AUDIT-METHODshadow forward-window vs single full-day enum (day-boundary + late arrivals)
shadow:0x0e84dded@2026-07-185.0965.330.24AUDIT-METHODshadow forward-window vs single full-day enum (day-boundary + late arrivals)
shadow:0x9dba4146@2026-07-1826.74527.370.63AUDIT-METHODshadow forward-window vs single full-day enum (day-boundary + late arrivals)
shadow:0x158e90dd@2026-07-1819.37419.870.5AUDIT-METHODshadow forward-window vs single full-day enum (day-boundary + late arrivals)
shadow:0x52e29e0d@2026-07-186.0976.320.22AUDIT-METHODshadow forward-window vs single full-day enum (day-boundary + late arrivals)
0x0e3df9510d@2026-07-17246342.8246371.0628.26BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x8e7769d440@2026-07-172938.4650037529.7848294591.319826BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x31d058b5e0@2026-07-1732337.1132618.02280.91BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0xf6ee347de6@2026-07-171.3790691.4205260.041457BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x0e3df9510d@2026-07-17185418628BASISa few unconfirmed-submitter legs (Door-1 gate); whale count re-run STABLE
0x93053f1e7a@2026-07-17retained~04.134.13AUDIT-METHODrail-scoped rawOut missed forwarding outflow; balance trajectory confirms net-zero
0x68396bd358@2026-07-17retained~03882.473882.47AUDIT-METHODrail-scoped rawOut missed forwarding outflow; balance trajectory confirms net-zero
0xa6a8736f18@2026-07-17retained~08.058.05AUDIT-METHODrail-scoped rawOut missed forwarding outflow; balance trajectory confirms net-zero
0x0e3df9510d@2026-07-16158864.96159497.47632.51AA/DOOR-3ERC-4337 tx (tx.to=router 0x5ff137d4, UserOperationEvent, paymaster in path)
0x8e7769d440@2026-07-163508.4309657464.4108283955.979863BASISdelta submitters UNCONFIRMED (<3/7) — lawful Door-1 exclusion
0x31d058b5e0@2026-07-1621749.2722551.64802.37AA/DOOR-3ERC-4337 tx (tx.to=router 0x5ff137d4, UserOperationEvent, paymaster in path)
0xf6ee347de6@2026-07-161.0779431.1001760.022233AA/DOOR-3ERC-4337 tx (tx.to=router 0x5ff137d4, UserOperationEvent, paymaster in path)
0x0e3df9510d@2026-07-161866187610BASISa few unconfirmed-submitter legs (Door-1 gate); whale count re-run STABLE
0x93053f1e7a@2026-07-16retained~03.913.91AUDIT-METHODrail-scoped rawOut missed forwarding outflow; balance trajectory confirms net-zero
0x68396bd358@2026-07-16retained~03218.73218.7AUDIT-METHODrail-scoped rawOut missed forwarding outflow; balance trajectory confirms net-zero

The two largest exclusions in this report — $124,125 (2026-07-08) and $40,540 (2026-07-11) — were routed by a submitter that has never met our facilitator confirmation threshold on any day. A raw reader of the chain would count them as revenue; we do not. The receiving address forwards essentially all of what it receives (received and outflow are equal to the cent across $2.04M lifetime) on a payer set of two to three addresses behind 14,743 payments. Both flows are shown here rather than omitted: the confirmation gate is what excludes them, and every transaction is verifiable on-chain.

Pipeline findings: 0. No published money figure was wrong.

7 · Where the auditor was wrong

These are errors in the checking program, not in the published data. Each was found, named, and fixed mid-audit: · L482 omission. Session-1's reimplementation didn't drop facilitator-is-payer self-settlements, flagging lawful exclusions as misses. Added mid-audit; the four session-1 rows above retain the AUDIT-METHOD class, and the family collapsed to MATCH thereafter (b-random 127/128). · Whale non-determinism. Per-recipient getLogs on high-volume relays returned different results run-to-run (819 vs 1). Switched giants to deterministic full-day enums. · Settlement-scoped outflow. The relay stratum summed only settlement-tx outflow, missing forwarding legs → a false ~$4k/day "retention." The USDC balance trajectory proved net-zero (Δ +$52 over four days).

8 · Limits

· Sample, not census — strata across selected days, not every settlement. · Point-in-time — reproducible at the audited blocks; later chain state may differ. · AA deferred — ERC-4337 per-day measurement is Report #2. · Shared source — both AQUIX and this auditor read the same Base chain; a chain-level error would fool both.

9 · Reproduce it

For a day D: find its Base block range by timestamp; eth_getLogs the USDC AuthorizationUsed and Transfer events over that range; keep a transfer iff its tx has an AuthorizationUsed with authorizer == transfer.from and the submitter (tx.from) is neither side; sum per recipient; compare to the published /day figure.
for tx with AuthorizationUsed{authorizer A}:
  for USDC Transfer{from F, to R, value V} in tx:
    if A == F and submitter != F and submitter != R:
      settled[R] += V           # cent-exact vs x402_daily.processed_usd
Audited rows (all 948): audit-rows.csv.