All Case Studies

02 / CASE STUDY · BASE · COMPOUND III · CERTORA AUDITED · ERC-4337

ChainPot

Formally verified communal savings & credit protocol.

ChainPot product interface
18 / 18CERTORA FINDINGS REMEDIATED

100% remediation of all 18 security findings (H-01, M-01, L-01–L-10, I-01–I-06) plus design directives DR-02 and DR-03 under the Certora Prover.

48 / 48FOUNDRY & COMET FORK SUITE

Complete invariant, unit, and live Base mainnet fork verification against production Compound III Comet (cUSDCv3) and Chainlink VRF V2.5.

80 / 20YIELD & SAFETY MODULE SPLIT

80% of time-weighted Compound III yield distributes pro-rata to members; 20% routes to the ChainPot Safety Module (POL insurance reserve).

< 15%TARGET ONBOARDING DROP-OFF

Joint Certora × Web3Spell UX scale-up replacing seed phrases and native gas prompts with WebAuthn passkeys and ERC-4337 sponsored USDC transactions.

ClientChainPot Protocol (Supported by Compound · Audited by Certora)
RuntimeBase (EVM · Chain ID 84532)
ReleaseV4 Remediated · Certora UX & GTM Stage
On-Chain ArtifactCircleEn...atorV4
02 / EXECUTIVE THESIS

Designing for the real constraint.

Every architectural decision begins by isolating the structural failure modes of existing solutions and engineering directly against them.

01 / THE PROBLEM

Vulnerability & Friction Surface

Rotating Savings and Credit Associations (ROSCAs), known globally as chit funds, tandas, and susus, mobilize hundreds of billions of dollars across two billion people, yet informal physical circles suffer from unpenalized late-stage defaults, opaque manual ledger fraud, 0% yield on idle cash, and 5–9% remittance drag. Conversely, institutional DeFi lending demands >125% over-collateralization, pricing out the exact communities that rely on cooperative credit.

02 / OUR APPROACH

Protocol & Product Strategy

Web3Spell engineered ChainPot V4 on Base, backed by Compound Protocol and formally verified by Certora. After remediating 18/18 Certora Prover security findings and 2 design directives with 100% invariant compliance, Web3Spell and the official Certora team launched a joint operational scale-up: replacing seed phrases and ETH gas hurdles with ERC-4337 Account Abstraction, WebAuthn passkeys, and USDC Paymaster sponsorship across a phased Go-to-Market rollout.

03 / DELIVERED

Shipped Production System

A 7-contract Solidity 0.8.24 suite uniting CircleEngineV4 (payment-gated Chainlink VRF V2.5 social lotteries) and AuctionEngineV4 (reverse-discount SME bidding pots) over RoscaEngineBaseV4, non-custodial pull-only VaultV4 custody, an ERC-4626-hardened CompoundIntegratorV4 supplying idle float into Compound III Comet (cUSDCv3) with an 80/20 yield-and-insurance split, and MemberRegistryV4 reputation scoring.

SYSTEM ARCHITECTURE

Certora-verified ROSCA & Compound III pipeline.

Hover any node for technical detail
01Passkey ClientERC-4337 Account
02MemberRegistryV4Merkle Access & Score
03Circle & Auction V4Dual ROSCA Engines
04VaultV4 CustodyPull-Only Escrow
05Compound III80/20 Yield & Reserve
VERIFICATION LOOP

Live cUSDCv3 balance queries stream 80% yield to members and 20% to the Safety Module reserve.

TECHNICAL ARCHITECTURE & PROOF

Architecture & verification.

Explore the defense-in-depth matrix, formal cryptographic equations, end-to-end execution trace, and systems engineering trade-offs.

03 / CERTORA FORMAL VERIFICATION MATRIX

Mathematically proving solvency across recursive states.

Because pooled communal capital represents the household savings and working capital of participants, empirical unit testing is insufficient. Certora applied formal verification alongside manual security review across four core audit dimensions.

LAYER 01

Solvency & Compound III Accounting

VaultV4.sol · CompoundIntegratorV4.sol (L-01, L-02, L-09, H-05)
THREAT ELIMINATED (VERIFIED V4 INVARIANT)

Replaced cached internalPrincipal (L-09) with live cUSDCv3 balance queries (L-01) and virtual share offsets; proved that contract balances strictly match unallocated deposits + locked collateral (backing == 0 post-claim).

IF OMITTED (EXPLOIT / INSOLVENCY VECTOR)

ERC-4626 donation/inflation attacks, token rounding leakage, and ledger drift between internal principal accounting and live Compound III Comet balances.

LAYER 02

Payout Distribution & Payment-Gated VRF

CircleEngineV4.sol · VRFProviderV4.sol (H-01, F-01, C-03, DR-03)
THREAT ELIMINATED (VERIFIED V4 INVARIANT)

Enforced payment-gated per-cycle draws (_drawGated fires only when ≥2 eligible members pay; single-payer assigns directly) and 2-step store-then-finalize pull settlement.

IF OMITTED (EXPLOIT / INSOLVENCY VECTOR)

Unfunded Circle pots spamming _onStartPot() to drain the shared Chainlink VRF V2.5 subscription (H-01), payout reentrancy during claims, and skipped-cycle race conditions.

LAYER 03

Reverse-Auction & Slashing Mechanics

AuctionEngineV4.sol · MemberRegistryV4.sol (M-01, M-03, F-05, L-07)
THREAT ELIMINATED (VERIFIED V4 INVARIANT)

Enforced strict 2% minimum bid steps, strictly-lower re-bids, deterministic deadline default flagging, permanent reputation slashing, and protocol-wide repeat-default blacklisting.

IF OMITTED (EXPLOIT / INSOLVENCY VECTOR)

Bid manipulation during active payment windows (F-10), bids exceeding totalCollected (H-03), unpenalized late-stage walkaways, and multi-bid reputation farming (M-02).

LAYER 04

Lifecycle & Governance Boundaries

RoscaEngineBaseV4.sol · VaultV4.sol (M-01, L-10, I-05, I-06, DR-02)
THREAT ELIMINATED (VERIFIED V4 INVARIANT)

Proved absolute immutability of pot parameters and Merkle-whitelisted rosters once startPot() executes, paired with timelocked engine binding and bounded admin safety guards.

IF OMITTED (EXPLOIT / INSOLVENCY VECTOR)

Mid-cycle parameter tampering, unauthorized roster mutations after pot launch, griefing during pool finalization, and privilege escalation during initialization.

HAVE A RELATED CHALLENGE?

Let's make
it ship.

Whether you are architecting zero-knowledge circuits, formally verified DeFi primitives, or a 250-builder ecosystem hackathon, you work directly with our founders and senior engineers.