All things Zcash.
On Robinhood Chain.

$ZEAL is the community token behind zealz.fun, the home for Zcash on Robinhood Chain. Trade the Zcash ecosystem, wrap and redeem ZEC as zZEC, and launch tokens that buy back and burn $ZEAL.

$ZEALCommunity token
zZECWrapped Zcash, 1:1
Live
$ZEAL$0.00402+13.7%
zZEC$1,474.13−2.2%
$ZEAL burned965.2K+691.2K today

Put your Zcash to work

Earn with zZEC.

Liquidity

Add zZEC + ETH liquidity

Pair zZEC with ETH in the live pool and earn a share of trading fees while your position is active. Start from ZEC, ETH or zZEC.

Add liquidity ↗Returns vary with trading. Pool value can rise or fall.
Holder rewards

Hold launches, earn zZEC

zealz.fun launches can pay holders a share of every trade in zZEC, with no staking. Hold, and rewards arrive in your wallet.

Earn on zealzMainnet holder rewards start when zealz.fun mainnet trading opens.

How $ZEAL works

Trade Zcash. Burn $ZEAL.

  1. 01

    Zcash comes on chain

    Native ZEC is wrapped 1:1 into zZEC, backed by ZEC in a published reserve and redeemable back to ZEC.

  2. 02

    People trade

    Trades in the zZEC pool pay a small fee today. zealz.fun launches add their own fee split, set in the contracts, once mainnet trading opens.

  3. 03

    Fees burn $ZEAL

    Part of those fees buys back and burns $ZEAL through the Furnace. zealz.fun launches can also pay holders in zZEC.

How the Furnace works →How zealz.fun launches work →

Straight answers

What you’re actually holding.

01

zZEC is reserve-backed, not trustless.

An operator holds the ZEC reserve at a public address anyone can watch. Payouts and attestations are published.

02

zZEC is exposure, not shielding.

On Robinhood Chain it is a transparent token. Redeem to native ZEC to shield it on Zcash.

03

$ZEAL is a memecoin with a job.

Not equity and not a claim on the reserve. Trading fees buy it back and burn it. No staking, no promised returns.

Lore

A zeal is
a group of zebras.

The name is not ours. The Zcash Foundation picked its mascot on stage at Zcon1 in 2019, and the pun stuck. Zebra is the Foundation's node software; enough zebras make a zeal.

Zcash Foundation@ZcashFoundation

The Foundation's mascot is a zeal, a group of zebras. In the future, when many people are running Zebra nodes, that will be a zeal!

Pun courtesy of @kaplannie · #Zcon1

A zeal of zebras, posted by the Zcash Foundation at Zcon1
June 22, 2019Open on X →
Roadmap and build log

Roadmap

Built so far.
What comes next.

A roadmap for the whole ZEAL ecosystem. These workstreams can progress together; planned features are not live services or promised launch dates.

Communitylive

Launch $ZEAL

$ZEAL is live on pons.family. Public contracts, documentation and a dated build log form the ecosystem’s foundation. Creator-fee routing now points at Tap v2; follow live sweep status in the ledger.

Explore $ZEAL →
Wrapped Zcashlive

Bring Zcash to Robinhood Chain

Wrap native ZEC to receive V2 zZEC on the live r4 token. Existing V1 can still Move to V2. V2 native ZEC payouts are open; automatic payouts are 0.01–5 ZEC from the published reserve.

Wrap ZEC →
Liquidityin progress

Deepen zZEC liquidity

The r4 0.50%/0.25% pool is live, including protocol-owned #2646448. Collect and remove stay on Uniswap. Next is liquidity product (easier funding, clearer position flow), not more protocol capital. Additional rewards are not live.

Provide liquidity →
Launchpadin progress

Launch zealz.fun

A token launchpad built around zZEC markets and $ZEAL buybacks and burns. The public test lab is the live product. Public mainnet launching on zealz.fun is closed. The homepage is a sales page with a labelled sample preview, not a factory directory.

See what is built and what remains →
Long-term foundationplanned

Strengthen the foundation

Keep improving reserve transparency, security and reliability, while exploring additional safeguards to strengthen the ecosystem over time.

Understand the current trust model →

Build log

413 entries · dated · linked · nothing here is a promise

Sep 19

Trading went live on zealz.fun mainnet. $ZEAL, $ANONZEAL and zZEC are buyable and sellable in the terminal, and any Robinhood Chain token with an ETH-paired Uniswap v4 pool can be traded by pasting its contract address. The token is read from its own contract and its pool is quoted through before it is offered, so a pool that cannot actually be traded is refused rather than listed.

zealz.fun →
Sep 19

Every trade pays 0.4%: 0.2% to the platform, 0.1% that buys back and burns $ZEAL through the Furnace, and 0.1% credited back to the trader as zZEC. A wallet holding only dollars can still trade, because the order is signed and a relayer submits it.

Sep 19

Two privacy settings, deliberately different sizes. Shield your address takes the wallet address off your profile and withholds trade receipts, keeping your name, trades and P/L visible. Private profile hides trades, positions, P/L and zZEC earned, and posts your zonks unsigned.

Full build archive · every update
Trading went live on zealz.fun mainnet. $ZEAL, $ANONZEAL and zZEC are buyable and sellable in the terminal, and any Robinhood Chain token with an ETH-paired Uniswap v4 pool can be traded by pasting its contract address. The token is read from its own contract and its pool is quoted through before it is offered, so a pool that cannot actually be traded is refused rather than listed.zealz.fun ↗
Every trade pays 0.4%: 0.2% to the platform, 0.1% that buys back and burns $ZEAL through the Furnace, and 0.1% credited back to the trader as zZEC. A wallet holding only dollars can still trade, because the order is signed and a relayer submits it.
Two privacy settings, deliberately different sizes. Shield your address takes the wallet address off your profile and withholds trade receipts, keeping your name, trades and P/L visible. Private profile hides trades, positions, P/L and zZEC earned, and posts your zonks unsigned.
Fixed a P/L error that counted money you added as profit: adding cash converts ETH to dollars through the same pool a trade uses, and the leaderboard was reading those deposits as realised gains. Also found and fixed trades that were indexed without a dollar price and so were invisible to the feed, P/L, the leaderboard and rebates.
The burn now reaches the fees it was missing. The Furnace can only turn ETH and zZEC into burned $ZEAL, and almost every trade pays in dollars, so the dollar share of the burn fee had been collecting somewhere it could never be spent. It is converted and forwarded on a schedule now.
The hero zebra scene is upgraded: sharper ink, cleaner paper, and greens and golds graded to the exact brand colours, with a retina version for large screens. The looping hero video is retired, so the homepage loads about 2.3 MB lighter.See the homepage ↗
Docs rewritten for the live system: V2 zZEC, the 0.50% LP + 0.25% burn-hook pool, the Foundry split, redemption limits and zealz.fun as the app. V1 fee material now sits only in clearly labelled Legacy V1 notes, diagrams read their numbers from the site config, the reserve coverage gauge uses the V2 contract’s own reserve and liability, and the docs are about half as long.Read the docs ↗
zealtoken.com homepage simplified to one short page: what $ZEAL and zZEC are, one grid of links into zealz.fun (trade the Zcash ecosystem, wrap and redeem ZEC, the live ledger, launch on testnet), how fees feed $ZEAL in three steps, straight answers on what you hold, lore, FAQ, and the roadmap and build log tucked into one expandable section. Old homepage links to #wrap, #redeem, #liquidity and #ledger now open the matching page on zealz.fun.See the new homepage ↗
The live ledger (fees routed, reserve backing, buybacks and burns, liquidity) now also opens inside zealz.fun and the test lab as Ecosystem ledger in the sidebar. Same ledger and data as zealtoken.com. Wrap and redeem links across zealtoken.com and zealz.fun now open the Wrap & redeem ZEC page on zealz.fun; app.zealtoken.com still works.Open the Ecosystem ledger ↗
zealz.fun now opens straight into the mainnet terminal, with no password: the Zcash ecosystem tokens ($ZEAL, $ANONZEAL, zZEC) with live prices and charts, plus Feed, Board, Burns and Wrap & redeem ZEC. Trading and launching on mainnet are still off until the audit; the header links to the public test lab instead. Both zealz.fun and the test lab now open on the live Feed rather than a preselected token, and the sidebar links to the docs and zealtoken.com.Open zealz.fun ↗
The ZEAL App (wrap ZEC, redeem zZEC, add liquidity) now also opens inside the zealz.fun mainnet terminal in its dark style. Same code, contracts and payout limits as app.zealtoken.com; only zealz.fun may frame the new embed page, and every other page still refuses framing. app.zealtoken.com stays the public entry point.Open the ZEAL App ↗
The zealz.fun test lab sidebar now pins the Zcash ecosystem tokens from mainnet ($ZEAL, $ANONZEAL, zZEC). Each opens a view-only page with live mainnet price, chart, buys vs sells and recent trades, clearly marked not tradeable on testnet, with links to DexScreener and zZEC redemption.See $ZEAL on the test lab ↗
The zealz.fun test lab launch form is now one page: fund your launch, name and icon, launch style (instant or 10-minute batch) and the fee split (holder rewards, ZEAL buybacks, creator share) front and centre, then review and launch, with a live preview alongside. Same validation, drafts and launch transactions. Test tokens only.Try a test launch ↗
Opened the V2 zealz.fun test lab to everyone: no password on testnet.zealz.fun. New desk with a top-10 rail, All tokens, Watchlist and Leaderboard in place; feed, zonks, P/L leaderboard, profiles, Burn Board, portfolio value and zZEC earned; an app-style phone layout and a new Connect wallet sheet. Test tokens only; mainnet terminal stays password-gated and mainnet trading is not live.Open the test lab ↗
The mainnet preview is now the full zealz.fun terminal on Robinhood Chain mainnet (password-gated): $ZEAL, $ANONZEAL and zZEC with real prices, our own charts, a trades feed, leaderboard and profiles built from a new mainnet swap indexer. No simulated traders on mainnet. Trading and launching on zealz.fun mainnet stay off until the audit.
Raised live automatic wrap to 0.001–5 ZEC per payment, matching V2 redeem. The AWS worker limit and the deposit sweep signer were installed together, with backups and two successful wrap runs; the signer still sends only to the published reserve. First reserve-direct V2 redeem proven the same day: request 3 paid 0.01 ZEC from t1Ujk… with change back to the reserve, reported and verified on chain.Wrap limits ↗
Returned leftover isolated V2 float ZEC to the published reserve (0.9193 ZEC to t1Ujk…, 0.0002 ZEC fee). Do not retry that send. Live V2 automatic payouts stay on the reserve signer. The float wallet remains in place empty except dust. Public site copy is updated in source; it is live on zealtoken.com only after an explicit publish.float return ↗
Started a read-only mainnet preview of zealz.fun behind the site password. It lists the Zcash ecosystem projects ($ZEAL first, then $ANONZEAL and zZEC) with live DexScreener prices and charts, and a Burn Board with the Furnace’s real ZEAL buybacks and burns linked to each transaction. Launching and trading on mainnet are not live, and the password no longer turns them on.
On the test lab you can now paste any Robinhood Chain testnet token address and trade it if it has a test zZEC or ETH pool. Trades go through the rebate router, so half of the 0.75% fee comes back to you in test zZEC. Outside tokens carry an unverified-project warning, and a Zcash ecosystem / All projects toggle sits in the rail. The rail also ranks by market cap, rewards paid or holders over 1H, 24H or 7D. Everyone now has a display name, new wallets pick one when they first connect, profiles take a cover photo, and clicking zZEC earned opens withdraw-to-shielded and sell options. Test tokens only.
Turned on live V2 automatic payouts from the published reserve. The new payer is running on the worker; leftover isolated-float ZEC has not been moved yet (waiting for one proven reserve pay). No float send in this step.Redemption limits ↗
The test lab now has its own identity and a privacy lane. Private profiles hide your trades, P/L and earnings from other people on zealz.fun (transactions stay public on chain); shielded launches carry a Private badge; and your zZEC earned card has a Withdraw to shielded ZEC button. New words and layout: your Herd, the Stampede, and a Burn Board pairing live mainnet ZEAL burns with zZEC paid to traders, plus a strip across the desk led by your P/L. The leaderboard now ranks by P/L. Also fixed a signing bug that stopped profile saves, zonks and follows from going through. Test assets only.Test lab status ↗
zealz.fun now has a live bottom bar on every page with the mainnet zZEC and ZEAL prices and how much ZEAL the Furnace has bought back and burned in the last 24 hours and all time, read from the Furnace contracts and their burn events. On the test lab, wallet messages became small pop-ups under your wallet, profiles show a plain P/L (sells minus buys plus what your remaining tokens are worth, capped at what their pools can pay), and theses are now called Zonks.zealz.fun ↗
Deployed the zealz rebate router on Robinhood Chain testnet. Swaps through it pay 0.75% on the zZEC or ETH leg: 0.375% goes to the platform treasury and 0.375% goes straight back to the trader as zZEC in the same transaction. No owner, no fee changes, no withdrawals. A live 0.001 test zZEC swap confirmed the split on chain, and rebates now count toward zZEC earned. The test-lab trade ticket moves onto it next. Test assets only.Router on explorer ↗
zZEC earned is now the headline number on the passworded test lab: a gold chip next to your wallet, a zZEC earned stat and card on every profile, and an earned column plus Top earners ranking on the leaderboard. Every figure is summed from on-chain zZEC payouts to holders of zealz launches (975 payouts to 25 wallets indexed so far). Also built and tested, not deployed: a testnet swap router that charges 0.75% and returns half to the trader as zZEC in the same transaction, with no admin controls. Test assets only.Test lab status ↗
Hardened reserve-direct V2 settlement so a matching t1 output is not enough: coins must have come from t1Ujk…, change must return there, shielded value cannot invent the pay, the same native txid cannot settle two requests, and an all-zero txid is refused. Tested in source; not live; no native send.Security and trust ↗
Simulated traders are live on the test lab, and the demand bot is funded again and now guarantees every listed test token trades at least once an hour. Also: the header reads Testnet, profile photos no longer clip under the banner, and the token list’s Buy pill opens the trade pop-up, which now shows your position and transactions under the ticket. Deployed to the operator preview; test assets only.Test lab status ↗
Source V2 automatic payouts now spend the published reserve with a locked signer: only transparent t1Ujk… inputs, change back there, destination the committed holder t1, 0.01–5 ZEC and 5.1 ZEC per rolling day. Isolated V2 float top-up is retired once that gate is installed. The switch was turned on for live AWS on Sep 16; no reserve-direct payout has been made yet, so it is live but unproven. Remaining float ZEC has not been moved. No native send.Redemption limits ↗
Matched automatic wrap and V2 redeem at 5 ZEC in source: wrap 0.001–5 per payment, redeem 0.01–5 per request and 5.1 ZEC per rolling day. Isolated V2 float is still about 1 ZEC, so this is not live until that float is funded and the wrap/payout workers are installed. No native send. V1 auto-redeem stays 0.5 ZEC.Redemption limits ↗
Built twelve labelled simulated trader personas for the test lab: each has its own testnet wallet, profile and style, trades through the public test router and sometimes posts a thesis written only from indexed numbers. Every one shows a BOT badge. Deployed and registered; trading starts once their test-ETH top-up key is configured (the existing demand bot has been paused for low test gas since September 12). Test assets only.Test lab status ↗
Test lab: reloading no longer disconnects your wallet — the lab silently re-reads the wallet you last used (no prompt) and reconnects only if it still authorises the site on Robinhood Chain Testnet; Disconnect forgets it. Brief “updates delayed” flashes are gone: the market API was healthy, so the warning now appears only if a problem lasts 20 seconds. Your positions now sit in the right rail on Feed, Board and Profile, and the token list ends in a simple View all row. Deployed to the operator preview.Test lab status ↗
Corrected the automatic V2 redemption cap. The site, app and intake allowed 0.01–0.5 ZEC, but the live payout authorizer and native handoff still enforced 0.05 ZEC, so larger requests would have waited in escrow unpaid (none were made). Both now enforce 0.5 ZEC per request with the unchanged 0.51 ZEC daily budget and 0.02 ZEC float floor; readiness still checks the float first. Deployed to the payout host with backups and verified. The partner API now covers redemption end to end: prepare the escrow request, read its receipt and status, and register the holder-signed destination. Holders sign everything; the API holds no keys.Redemption limits ↗
Test-lab polish: the top search bar is one clean field with proper spacing, and the token stats row was rebuilt as seven even cells (market cap, price, 24H change, 24H volume, liquidity, holders, top 10) with quiet labels, one value style and explanations on hover. Tokens with no 24-hour history show a dash instead of “New”. Deployed to the operator preview.Test lab status ↗
FOMO-style trade pop-up on the passworded test lab: on desktop, tokens clicked from the feed, leaderboard or a profile open over the page with the chart and trade markers, market cap and 24H change, About and Theses, and either the trade ticket or the clicked trader’s position with PnL, average entry and transactions. Quotes refresh automatically and Buy shows “Fetching quote…” until one is ready, using the same wallet-confirmed trade path. Also fixed light mode (no dark page bleeding through), restored the Launch token button in the desk header, and made a token icon required for every new launch. Deployed to the operator preview; test assets only.Test lab status ↗
Moved Robinhood Chain reads to a dedicated Alchemy endpoint. zealtoken.com, the partner API, zealz.fun and the AWS operator worker try it first and fall back to the public node for reads; transaction broadcasts never fall back. The API key stays server-side. Deployed and verified: site relay reads, including full-history log queries, report the dedicated upstream, and the wrap worker ran 10 of 10 passes without the read errors that previously failed about one pass in eight. The keeper and V2 destination-intake daemons were restarted onto it and verified running.RPC setup ↗
Every test token now has an icon: tokens without a creator logo show one of 26 objects from the zealz.fun herd illustration (Z balloon, sailboats, the sunglasses bull, the ZEAL coin, van, coffee bar…), assigned by token address, replacing two-letter initials across the rail, feed, profiles and token page. Creator logos and designed icons are untouched. The caption above the top-bar search is gone (kept for screen readers). Deployed to the operator preview.Test lab status ↗
Test-lab profiles look inhabited: every wallet without an uploaded photo now shows a zebra portrait and a profile cover cropped from the zealz.fun herd illustration (50 characters, 14 scenes), assigned by wallet hash so the same wallet gets the same art in the feed, leaderboard, rail, hover cards and profile. Uploaded photos win; the art is a default, not an identity claim. Built, verified in the browser, deployed to the operator preview.Test lab status ↗
Social desk v2 behind the test-lab password, built on FOMO’s structure: trader profiles now span every listed market — all indexed swaps with implied market caps, positions from the holder ledger with cost-basis PnL, closed and top trades with average entry and exit, a 24H/7D/30D/ALL net-flow line, followers and following, first trade, average hold and 24h rank, plus shareable ?u=handle links. The leaderboard ranks indexed volume across all markets with BOT labels for simulation wallets, Your rank and a New traders tab. The feed is one-line rows of trades, theses, new listings and first-time traders with Copy buy/sell, filters and a Show-new-activity pill; hover cards and a Top-traders rail round it out. Every number is indexed buy/sell flow at the labelled simulated-USD reference, never marked-to-market. Verified against the live index at desktop and phone widths; deployed to the operator preview. The top testnet warning bar is gone at operator request; the footer disclaimer and TEST LAB badge remain.Test lab status ↗
Converted the ops-funded reserve-sink balance: 0.2969 ETH to 0.53148561 confirmed native ZEC. Also swept a dust leftover from the liquidity sink into that purchase. Do not retry. No mint. Keeper untouched.Robinhood bridge tx ↗
Paused protocol-LP adds from Foundry sinks so wrap capacity comes first. Sent leftover liquidity-sink ETH into the reserve sink, then converted 0.1678 ETH to 0.29786767 confirmed native ZEC. Do not retry. Keeper untouched.Robinhood bridge tx ↗
Converted 0.10 ETH from the reserve sink through Relay and 1Click into 0.18993529 confirmed native ZEC in the published reserve, to restore wrap fee capacity after the LP mint used the spare buffer. Do not retry. No attestation or mint in this step. The wrap worker still has to count the confirmed UTXO before deposit instructions reopen.Robinhood bridge tx ↗
New wrap deposits are on hold. At 16:30 UTC the LP-from-sinks run minted 0.47975049 zZEC into protocol LP, using all but 1 zatoshi of spare backing. That left the 0.00314001 ZEC of leftover wrap holds and the consolidation-fee buffer uncovered, so the worker correctly closed deposit instructions. Existing deposits are unaffected. The LP planner now always leaves 0.005 ZEC of headroom unminted. Update: 0.19000529 native ZEC was added to the published reserve (live 12.90974272 ZEC against 12.71973742 ZEC liability), fee capacity returned and deposit instructions reopened by 18:08 UTC the same day.LP mint ↗
Fixed deposits flickering to on hold. About one wrap-worker pass in eight failed on a brief node read error before touching its payment journal, and each one published a closed status for roughly 35 seconds. Such passes now leave the last status in place; it still expires after two minutes, so real outages close the desk as before. Failures now log a safe reason. Deployed to the AWS worker and observed staying open through a failed pass. Also: phone tab labels no longer truncate, Switch account explains how to change accounts, the site RPC relay briefly reuses recent view reads when the public node rate-limits, and the browser test suite was updated to the live V2 app.Wrap availability ↗
Built and tested a public, read-only partner API for zZEC wrapping, so exchanges and wallets can offer it in their own interface. It returns availability with named blockers, the one route transaction the receiving wallet signs, the permanent deposit address only after the same chain and worker checks the ZEAL app runs, and per-deposit progress. No keys, no signing, no deposits handled. Deployed September 16 to zealtoken.com/api/v1; wrapping stays operator-custodied.Partner API docs ↗
Added protocol-owned r4 liquidity from both Foundry sinks into #2646448: minted 0.47975049 V2 zZEC, then increased by about 0.264 ETH and 0.500 zZEC. Keeper and ops sink untouched. No extra reserve conversion. Do not retry these receipts.LP increase receipt ↗
Test lab intro banner and herd video are gone — the desk opens straight into the terminal, dark by default again (light stays available in the header).Test lab status ↗
Passworded desk reworked to the FOMO terminal layout: thin top bar with universal search, cash and avatar; left rail nav pills and sparkline token rows with hover quick-Buy; compact token metrics (market cap, price, 24H change, volume, liquidity, holders, top-10); chart trade markers with my-swaps/friends/min-size overlay filters; holders with average entry and PnL; right column with the Buy/Sell ticket, token about with buys/sells bars, and your positions with cost-basis PnL. Test assets only; visitors still see Upgrading to V2.Test lab status ↗
testnet.zealz.fun is publicly closed for a V2 desk upgrade. Visitors see Upgrading to V2. The FOMO-style desk is an operator preview behind the same password as the mainnet pad. Interface only; test tokens have no cash value.Test lab status ↗
CloudWatch ProcessAlarm no longer sends Gmail. Routine operator jobs (RPC, tap-pull, website, keeper ticks) keep the Healthy metric at 1 so that generic 15-minute alarm does not fire. Peg defense, wrap review and a missing health heartbeat still can. Host status-check still emails. Detailed operator mail is unchanged. Deployed to the AWS worker.monitoring status ↗
Increased protocol-owned full-range position #2646448 by 0.10045 ETH and 0.21898266 zZEC (PositionManager, not a new NFT). Do not retry.LP increase receipt ↗
Minted 0.2467027 V2 zZEC to the LP owner after a 0.114 ETH reserve-sink conversion (0.2467027 native ZEC) and attest refresh. Do not retry the mint or that sweep. Position #2646448 was not increased in this step.mint receipt ↗
Converted 0.223 ETH from the reserve sink through Relay and 1Click into 0.48426765 confirmed native ZEC in the published reserve. Do not retry. Attestation, mint and the #2646448 increase were not part of this purchase.Robinhood bridge tx ↗
Operator mail: CloudWatch process alarm now needs 15 straight minutes of Healthy=0 (was 3). Routine job failures including tap-pull wait 15 minutes before that metric. Peg defense, funding, wrap review and unexpected roles still email immediately. A Robinhood RPC 403 is a retry, not a crashed keeper; do not re-run burns that already have a hash.monitoring status ↗
zealz.fun sales calculator now opens on Balanced (1% hook, 0.25% each to holders, buybacks, creator and platform). Platform is slate on the fee bar so it does not look like a gap. Launch forms still start at the 0.75% minimum. Public mainnet launching stays closed.zealz.fun ↗
zealz.fun fee picker now uses a color bar and a written legend: black buyback, ZEAL green holders, gold creator, white platform. Thin slices no longer hide their names. Public mainnet launching stays closed.zealz.fun ↗
zealz.fun fee sliders stay movable on the 5% Holder rewards preset. Raising buyback or creator takes from holders down to the 0.25% floor instead of locking the track. Raising holders at 5% takes from buyback the same way. Public mainnet launching stays closed.zealz.fun ↗
Public testnet simulation now attempts a varied buy or sell on up to 48 eligible markets every minute instead of 14 markets every five minutes. New and quiet markets still go first. Immediate buy-then-sell in the same run stays off. Test assets and labelled simulation wallets only; low test gas still pauses trading to protect settlement.Trade on testnet ↗
zealz.fun sales calculator now opens on Holder rewards (5% hook, 4.5% to holders, 0% creator) instead of the 0.75% minimum. The featured payout is holder zZEC at the chosen daily volume. Real launch forms still start at the 0.75% minimum. Public mainnet launching stays closed.zealz.fun ↗
zealz.fun public homepage is a sales page: factory feed removed, labelled sample preview restored. Two early factory tokens stay omitted from the site and remain on chain. Public launching stays closed.zealz.fun ↗
Paid Dexscreener token info is live for V2 zZEC (0x1955…1A25): coin icon, wrap 1:1 banner, wrap desk, docs, testnet.zealz.fun, zealz.fun, X and Telegram. Use the 0.50%/60 ETH pool chart. Ignore the thin leftover 0.05% v4 book and the ~$200 v3 WETH pair. Dexscreener listing is not an audit, a peg guarantee or an LP lock.zZEC on Dexscreener ↗
testnet.zealz.fun ticket size labels now say USD, not Simulated USD. The trade still settles in test zZEC; faucet Test USD stays in Advanced.Trade on testnet ↗
testnet.zealz.fun sells now use the same compact zZEC / USD size toggle as buys. The ticket converts that value to an estimated token amount at spot; preview still shows tokens sold and test zZEC received.Trade on testnet ↗
testnet.zealz.fun buys now have a compact zZEC / USD size toggle. USD is Simulated USD, not faucet Test USD. ETH and Test USD remain under Advanced.Trade on testnet ↗
testnet.zealz.fun Buy/Sell now says the quote asset is test zZEC, with ETH and Test USD in Advanced. No extra payment controls on the simple ticket.Trade on testnet ↗
testnet.zealz.fun charts now default to All indexed history instead of 24 hours. Line, FDV and Auto interval are unchanged. 24H remains a range option.Trade on testnet ↗
Add liquidity now has a zZEC-only Kyber path as well as ETH-only. Same live 0.50%/60 pool: Kyber swaps part of the starting asset for the other and you sign the deposit there. Preview 0.01–1 zZEC; keep ETH for gas. Quotes only on zealtoken.com; no in-app zap transaction.Add liquidity ↗
Visitor feedback on testnet.zealz.fun: clicking another trending token no longer jumps the page to the top. The buy/sell ticket is a simple amount plus quote; Simulated USD, auto-quotes, fees, limits and routed buys sit under Advanced. Sells are sized in tokens, with test zZEC received in smaller text. Test assets have no cash value.Trade on testnet ↗
Closed public mainnet launching on zealz.fun. The site no longer sends launch transactions to ZealzFactoryEth (0x3178…57D5). Launch on testnet.zealz.fun. The factory remains deployed and permissionless, so a wallet can still call it directly. Tokens already created there can still appear in the directory. Charts and prices stay thin until a full indexer exists.Launch on testnet ↗
Public docs, README and handoff now match live r4 wrap, redeem and the 0.50%/0.25% pool. Independent audit, independent signing, a project LP lock and WalletConnect pairing stay not-activated. zealz.fun lists factory launches instead of sample tokens; charts and prices on those cards are still thin until a full indexer exists.Overview ↗
Add liquidity now keeps only an in-flight PositionManager deposit as the current receipt. Approvals are not listed as deposits. A confirmed or reverted add moves to Recent in this browser, returns the wizard to step 1, and clears the leftover Max amount so review cannot show a fake shortfall or a leftover simulation revert.Add liquidity ↗
Increased protocol-owned full-range position #2646448 on the live r4 0.50%/60 pool by about 1.46 zZEC and 0.65 ETH (PositionManager increase, not a new NFT). Independent reads show the NFT still in the LP owner wallet and pool depth about 2.90 ETH / 6.52 zZEC. A review-screen NOT_MINTED after that receipt was a follow-up read, not a reverted deposit. Do not retry.LP increase receipt ↗
Finished Add liquidity deposits stay in a browser history list under My positions. Only a pending transaction holds the review step; a confirmed receipt no longer traps the form there.Add liquidity ↗
Pinned the V2 direct-mint command to live r4 so the leftover V1 address in operator env cannot be treated as paused r4. No mint was sent by this tooling fix.V2 mint command ↗
V2 reserve-attestation refresh now restates the on-chain paid-out debit from fulfilled V2 payouts instead of refusing a nonzero accumulator. Empty-create still requires a zero debit. This is an operator-tooling change, not a mint or LP add.V2 attestation refresh ↗
Installed live automatic V2 payouts at 0.01–0.5 ZEC (0.5 ZEC per rolling day, 0.02 ZEC floor) after the 0.50 ZEC desk top-up confirmed (txid ff1409d4…84ad) and its isolated shield became spendable (txid b70b4f9b…a42bb). Isolated-float spendable was 0.91955 ZEC. Do not retry either native send.desk-top-up shield ↗
Returned 0.08 ZEC from the isolated V2 float to the published reserve (txid 5881e99f…5104, orchard deshield, 0.00015 ZEC fee). After three native confirmations, wrap reports fee capacity and is accepting again (reserve live 10.09932055 ZEC, liability 10.08857255 ZEC, leftover wrap holds 0.00314001 ZEC, margin 0.00760799 ZEC). Do not retry that send. Isolated float top-ups still do not count toward wrap fees.reserve return ↗
Public wrap no longer fail-closes deposits when reimbursement holds the issuance lock: wrap skips that pass and reimbursement skips when the wrap checkpoint is busy.wrapping status ↗
Silenced expected V1 mint-paused and leftover V1 minter-proposal alert mail, pointed keeper inventory alerts at live V2 zZEC, stopped the hourly V1 LP reinvest job that was reverting, and rearmed an interrupted wrap checkpoint so public wrapping can run again.monitoring status ↗
Removed V1/V2 wording from Wrap, Redeem, Add liquidity and the workspace intro. Those tabs just say zZEC. Leftover holders still reach Move to V2 and the original desk on the V1 dashboard tab.Zcash workspace ↗
Confirmed the 0.4103 ZEC isolated V2 float top-up (txid 874623c2…27f5, 17 native confirmations), submitted the internal shield (txid 5f4b6c26…9bd7, 0.00015 ZEC fee; mined, confirmations still accumulating), and installed live automatic V2 payouts at 0.01–0.1 ZEC (0.25 ZEC per rolling day, 0.02 ZEC floor). Do not retry either native send.V2 float shield ↗
Listed the live V2 zZEC contract (0x1955…1A25) next to $ZEAL in the homepage hero, with copy and explorer. The footer already had both. Existing V1 remains on the V1 dashboard.V2 zZEC contract ↗
Returned the Wrap through V1 dashboard actions to a compact centered segmented control (sage track, white selected slice). The header CTA stays Connect wallet; switching to Robinhood Chain still happens during connect.Zcash workspace ↗
Sized the Wrap through V1 dashboard workspace actions as separate buttons instead of a full-width bar. The header CTA stays Connect wallet; switching to Robinhood Chain still happens during connect.Zcash workspace ↗
Renamed the V1 leftover app tab to V1 dashboard. Wrap, Redeem and Add liquidity still sit on V2. #migrate and #v1 open the same V1 dashboard. Automatic V2 payouts remain 0.01–0.05 ZEC.V1 dashboard ↗
Submitted a 0.4103 ZEC reserve transfer to the isolated V2 payout float (txid 874623c2…27f5, 0.00010 ZEC fee) after installing a Linux-only top-up signer. Ten confirmations, shielding, and the 0.1 worker bounds are still pending. Automatic V2 payouts remain 0.01–0.05 ZEC.V2 float top-up ↗
Prepared a dedicated reserve top-up toward a 0.5 ZEC isolated V2 float and raised automatic payout source bounds to 0.01–0.1 ZEC per request (0.25 ZEC per rolling day, 0.02 ZEC floor). Live production worker still pays 0.01–0.05 ZEC until the top-up is confirmed, shielded, and the worker binaries are installed. Public site copy is not live until a production deploy.Redeeming zZEC ↗
Restyled the V2 redeem desk to match the V1 desk (stepper, amount/address fields, status cards) and moved Move to V2 plus the original V1 desk onto a V1 dashboard tab. Redeem is V2 only. #migrate and #v1 open that tab. Automatic V2 payouts remain 0.01–0.05 ZEC; V1 auto remains 0.5 ZEC per request and per rolling day.Redeem zZEC ↗
Opened production V2 native ZEC payouts on live r4. The isolated payout worker is active behind V2_PAYOUT_ACTIVE and V2_INTAKE_ACTIVE: native handoff socket, signed destination intake, reporter/verifier queue timers, and HTTPS registration (empty POST returns 400, not 503). Automatic V2 payouts are 0.01–0.05 ZEC from the 0.09985 ZEC shielded float, keeping a 0.02 ZEC floor. The Linux QA copy stayed stopped. Settlement on r4 was already unpaused; r3/r2/canary minting stayed paused.Redeeming zZEC ↗
V2 native redeem on mainnet r4 stays closed. Opening it now waits on the production payout worker and an explicit owner unpause, not a testnet calendar. Testnet r5 already paid through the QA worker; timed reclaim is covered by local tests. This update does not unpause mainnet V2 payouts.Redeeming zZEC ↗
Cancelled unpaid r5 request 6 so 0.01 test zZEC returned immediately instead of sitting until the seven-day reclaim clock. Timed Open reclaim remains covered by local contract tests and is not a mainnet gate. Mainnet V2 native payouts stay closed.r5 request 6 cancelled ↗
Rehearsed V2 native payouts on testnet r5 through the Linux QA worker: request 5 committed, paid 0.01 test ZEC once, reported, repeat-report refused, then confirmed and burned. An unpaid Open request 6 was created in the same session. Mainnet V2 native payouts stay closed.r5 request 5 confirmed ↗
Paused new requests on leftover V1 WrapDesk 0xb53E…E118 so that desk cannot take new wrap deposits. Public wrapping still mints r4 V2. Site Furnace copy and security addresses now lead with r4 0x0580…; the ledger still sums leftover V1 Furnace burns. V1 minting stays paused; the V1 redemption desk stays open. V2 native ZEC payouts remain closed.V1 WrapDesk paused ↗
Pointed zealz.fun launch signing at ZealzFactoryEth (0x3178…57D5) on r4 V2. Creators can pay the 0.005 zZEC fee in ETH via launchWithEth (0.02 ETH cap, leftover refunded) or approve V2 zZEC. The homepage directory remains labelled sample data; LIVE stays false. testnet.zealz.fun is unchanged. No mainnet canary launch was broadcast. V2 native ZEC payouts remain closed.Launch on zealz.fun ↗
Cut public wrapping over to live r4 V2. The AWS unique-address worker mints V2, V1 minting is paused so new wraps cannot create V1, and the wrap form checks the V2 minter plus both pause flags. Existing V1 still migrates 1:1 or redeems on the V1 desk. V2 native ZEC payouts remain closed.V1 minting paused ↗
Migrated the peg keeper’s 2.8569634 V1 zZEC to V2 in wallet 0x19ce…9738 (approve then migrate). Inventory is now 0 V1, 3.54217293 V2 and 0.566 ETH. No ETH moved from the native reserve, Foundry 6812/f8D7 sinks or ops 2598. MAX_TRADE_ETH stays 0.1. At current ZEC/ETH the mix is ETH-low versus the 35–65% band; peg sells can use the new V2. V2 native ZEC payouts remain closed.Keeper V1→V2 migrate ↗
Deployed ZealzFactoryEth on Robinhood Chain mainnet at 0x3178…57D5 with balanced launch hook 0x4269…a0cC (0x20CC flags; 0.75% min total, 0.25% platform / burn / holders) and locker 0x04De…5D6F. The factory is bound to V2 r4 zZEC and V2 Furnace. launchWithEth buys the 0.005 zZEC fee on the pinned 0.50%/60 ETH pool and refunds leftover ETH; that hop does not mint zZEC. Production zealz.fun is not pointed at this factory. The public test lab still uses test zZEC.ZealzFactoryEth ↗
Pointed the AWS peg keeper at the live V2 r4 ETH/zZEC pool (0.50% LP, 0.25% hook). Wrap and redeem stay on V1. No ETH was moved from the Foundry reserve or liquidity sinks in this step. V2 native ZEC payouts remain closed.Market and keeper ↗
Operator email now fires on every new V1 desk redemption request, including ones the automatic payer already completed, and when the V1 zingo float spendable shielded balance is below 0.50 ZEC. That float is t1cS6w…, not the reserve and not the closed V2 float. V2 native ZEC payouts remain closed.Operations runbook ↗
Unpaused ignition on the V2 r4 Furnace and pointed the AWS burner at both hooked books. The job now checks hourly and ignites a Furnace only when a dry-run would buy back at least 250 ZEAL. V1 stays on that cadence while it still trades. Hook fees still accrue if a check skips. V2 native ZEC payouts remain closed.V2 Furnace ignition unpaused ↗
Added ZealzFactoryEth.launchWithEth in source: the 0.005 zZEC launch fee can be paid in ETH by buying V2 zZEC from the hardcoded r4 pool (0.50% LP, 0.25% Furnace hook), with leftover ETH and extra zZEC refunded to the creator. This does not mint zZEC or wrap ZEC. Unit tests cover the r4-only gate. The factory is not deployed; production zealz.fun is not released; the public test lab still charges test zZEC.Launchpad design ↗
Raised the V1 automatic redemption rolling 24-hour desk cap from 0.25 ZEC to 0.5 ZEC so it matches the 0.5 ZEC per-request limit. Reserve reimbursement may refill the hot float up to 0.5 ZEC per day, still in 0.1 ZEC transfers from unencumbered surplus. Larger redemptions still need operator coordination. No reserve transfer was sent with this policy change.Redeem zZEC ↗
Reopened public wrapping as V1 wrap then Move to V2. V1 minting was unpaused, the AWS unique-address worker is accepting, and the wrap form reads the V1 minter and minting-pause flags. New wraps mint V1 zZEC; the live market and liquidity desk still need V2. Direct V2 wrapping is not offered. V2 native ZEC payouts remain closed.V1 minting unpaused ↗
Reordered the shared app tabs to Wrap ZEC, Redeem zZEC, Add liquidity, then Move to V2. Existing #wrap, #redeem, #liquidity and #migrate links still open the same desks. Wrap minting and V2 native ZEC payouts remain closed.Open the app ↗
Merged operator V2 LP position #2647751 into the larger full-range NFT #2646448 and burned the emptied token. Liquidity was moved inside the 0.50%/60 pool, not added from reserve. Wrap minting and V2 native ZEC payouts remain closed.Merged V2 LP NFTs ↗
The public two-asset V2 desk adds to an existing full-range NFT in the connected wallet when one is present, and mints only on a first deposit. Kyber still mints its own position. Wrap minting and V2 native ZEC payouts remain closed.Add V2 liquidity ↗
Direct V2 liquidity deposits can be sized from ETH or from zZEC. Connected wallets get an all-my-zZEC control that leaves 0.5% headroom for the mint maximum. Wrap minting and V2 native ZEC payouts remain closed.Add V2 liquidity ↗
Reopened the ETH-only Kyber liquidity preview on the live V2 0.50%/60 r4 pool. The quote and Continue to Kyber link target that pool’s V2 zZEC, not V1. Direct zZEC + ETH deposits remain available. Wrap minting and V2 native ZEC payouts remain closed.Add V2 liquidity ↗
Moved three 0.05%/10 V2 LP positions (#2592442, #2592853, #2597700) into the 0.50%/60 r4 pool as full-range position #2646448, with 0.50% to LPs and 0.25% hook to ZEAL buyback and burn. The 0.05% pool now has zero liquidity. Wrap minting and V2 native ZEC payouts remain closed.New 0.50% LP position ↗
Retargeted in-app V2 liquidity deposits to the intended r4 pool: 0.50% LP fee, tick spacing 60, and 0.25% ZealBurnHook to ZEAL buyback and burn (0.75% headline). That pool is initialized and empty of LP; an earlier 0.05%/10 position is a different pool key. Wrap minting and V2 native ZEC payouts remain closed.Add V2 liquidity ↗
Reopened in-app V2 liquidity deposits on the live r4 zZEC/ETH pool (0.05% LP fee, tick spacing 10, hook 0x3388…0044). The desk now mints into that pool instead of the old 0.30%/60 key. Wrap minting and V2 native ZEC payouts remain closed. The ETH-only Kyber preview still quotes V1 and is not offered.Add V2 liquidity ↗
Fixed Move to V2 contract reads to use the latest block instead of a pinned block number. Wallet and public RPCs that reject historic block tags were returning “unsupported block number” and blocking balance loads and migrate submits.Move V1 to V2 ↗
Restyled Move to V2 to match Wrap and Redeem and removed the Migrate LP tab. Token migration is still one wallet flow: exact V1 approval, then migrate 1:1. A Uniswap LP position cannot be moved in one click; withdraw on Uniswap first. V2 native ZEC payouts remain closed; the V1 desk still pays only V1 tokens.Move V1 to V2 ↗
Opened the public Move to V2 app action. Holders migrate V1 zZEC to r4 1:1 with one button: an exact V1 approval, then the migrate transaction is submitted automatically. There is no protocol fee, only Robinhood Chain gas. Migration permanently locks V1 in the V2 contract. V2 native ZEC payouts remain closed; the V1 redemption desk still pays only V1 tokens.Move V1 to V2 ↗
Prepared a fail-closed owner activation command that checks fresh r4 attestation and paused-empty state before unpausing and minting only the reviewed 0.25 zZEC LP inventory. It has not been executed; liquidity remains unfunded.V2 activation preparation ↗
Added a fail-closed mainnet r4 attestation command. It rebuilds reserve and liability inputs, checks the paused empty deployment and V1 binding, simulates the exact call and uses the existing signer lock. Typecheck passed; no attestation was broadcast.V2 attestation preparation ↗
Chained the website proxy, HTTPS handler and signed intake locally: first registration and replay succeeded without leaking destinations, and closed/forged/untrusted paths failed closed. Public HTTPS remains 503. Journaled testnet request 4 still cannot pay twice; the native 0.01 test ZEC output still proves independently. Staged pinned V2 profile modules on AWS with matching hashes, restarted closed intake only, and left payout gates off. Prepared an unsigned 0.25 zZEC plus 0.1124 ETH LP seed for review. Mainnet r4 stays paused with zero supply.V2 integration and recovery ↗
Prepared a real testnet signed-intake and durable-queue payout rehearsal using an explicit testnet profile. Mainnet authorization text remains unchanged; testnet signatures and journals are rejected by the default mainnet path. Ops checks passed with 192 tests and two opt-in skips, plus 27 site tests. The real testnet rehearsal subsequently passed signed intake, restart replay, one commitment, one native 0.01 test ZEC payout and separate verifier completion with zero escrow. Public HTTPS/browser integration remains outstanding; mainnet V2 stays paused.V2 network isolation checks ↗
Shielded the initial V2 payout float with the approved 0.00015 ZEC fee; the wallet reports 0.09985 ZEC confirmed shielded funds and a fresh encrypted backup completed. Deployed the HTTPS intake transport and verified its connection to the closed private worker. Forwarding remains disabled. Website integration, full real-testnet settlement rehearsal, fresh backing checks and reviewed liquidity funding remain before activation.V2 release progress ↗
Prepared an AWS-managed HTTPS intake handler to avoid a custom DNS dependency. Three focused tests passed. Closed CloudFormation deployment is prepared and AWS template validation passed. Private VPC listener/security-group setup and deployment remain pending; public intake stays closed.V2 managed HTTPS preparation ↗
Built a closed-by-default same-origin V2 intake proxy with bounded payloads, restricted origins, no redirects and sanitized registration responses. Four focused tests and the standalone API typecheck passed. Site verification now includes this endpoint typecheck. HTTPS worker configuration and deployment remain outstanding; public intake is closed.V2 intake transport preparation ↗
Added per-wallet browser locks shared by V2 request and recovery actions. A two-tab rehearsal confirmed that an occupied lock sends nothing and the normal request flow resumes after release. This protects same-origin tabs only. Production remains disabled.V2 browser concurrency ↗
Wired the local V2 request form to wallet submission and receipt confirmation without storing raw payout addresses. Matching receipt events open the exact registration record. 23 unit tests and three targeted browser checks passed, including isolated enabled submission, receipt recovery and registration navigation. Real-chain integration remains outstanding and the source release flag stays disabled.V2 request form ↗
Built local V2 request preparation with mainnet destination checksum validation, browser-side hashing, balance checks and the initial 0.01–0.05 zZEC payout range. Request IDs are bound to receipt events. Form integration remains unfinished and release stays disabled.V2 request preparation ↗
Built local V2 holder recovery controls for Open requests, with fresh contract checks, simulation and pending/uncertain wallet-response holds. Two mocked-wallet browser checks passed, including no-send status checking and wallet-change handling. Committed payouts do not expose cancellation or timed reclaim. Not published; new request creation remains unfinished.V2 holder recovery controls ↗
Aligned the AWS snapshot file limit with the 16 MB intake/queue limit; nine local and worker tests passed. Completed a fresh encrypted backup after queue initialization. A separate encrypted snapshot restored in a network-disabled temporary directory matched the full coordinator state, including intake and queue. Live issuance locks were respected. Payout gates remain closed; no funds moved.V2 queue backup rehearsal ↗
Staged the integrated V2 queue bundle on AWS; both systemd definitions validated. Initialized private empty journals at block 61,564,841 after paused/zero-history checks. Repeat initialization was refused. Queue services remain inactive and payout/intake gates closed; no funds moved.V2 queue staged ↗
Rechecked AWS: payout/intake gates closed, reporter/verifier inactive, float still unshielded. Prepared an exclusive-create queue initializer restricted to paused, empty r4 with no redemption history. Typechecked locally; worker initialization not yet executed.V2 initialization preparation ↗
Added preflight checks for both V2 settlement roles before commitment and native payout: minimum 0.001 ETH each and no unresolved shared-wallet transaction. Four focused tests passed. These checks do not guarantee future verifier availability; production rollout remains pending.V2 settlement readiness ↗
Passed durable queue dispatch against a disposable local V2 EVM deployment: one commitment, reporter settlement, separate verifier confirmation and zero escrow. Repeated dispatch did not recommit or repeat the modeled native payment. Real Zcash transport and production service rehearsal remain outstanding.V2 EVM queue rehearsal ↗
Passed three combined local queue rehearsals using real holder signatures and durable storage: normal reporter/verifier completion, lost commitment response and interrupted reporter handoff. Chain and native-payment calls were simulated; live-chain rehearsal remains required. V2 remains paused.V2 local queue rehearsal ↗
Wired the local V2 queue-worker entry point to signed intake, durable storage and the payout runner. Reporter and verifier modes retain separate credentials and verifier commitment is forbidden. Service definitions are prepared, not installed or enabled; combined rehearsal remains outstanding.V2 worker integration ↗
Connected signed V2 intake to durable queue admission locally. Holder signatures are rechecked, accepted registrations survive processing delays, and replay preserves existing commitment history. Nine focused intake/storage tests passed. Production dispatch service and full rehearsal remain pending; no payout activation.V2 authenticated queue ↗
Added durable V2 queue storage that refuses missing history, changed request identities, replaced commitment hashes and backwards state transitions. Local storage and recovery tests passed. Production queue initialization and worker integration remain pending; V2 stays paused.V2 queue recovery ↗
Built local V2 dispatch orchestration that releases the queue lock before payout execution, prevents verifier-created commitments and holds uncertain requests. Five focused tests and ops typechecking passed. Durable storage and service wiring remain unfinished; production payouts stay closed.V2 dispatch preparation ↗
Enabled read-only V2 wallet-health refresh on AWS. The isolated wallet account observes balances and a separate publisher exposes validated readiness fields. The service passed; the float remains unshielded and payout gates remain closed. No funds moved.V2 wallet monitoring ↗
Connected V2 native-readiness checks for wallet balance, backup freshness, unresolved payments and handoff availability. The AWS read-only observation correctly reports no shielded spendable balance and disabled payouts. V2 remains paused; no funds moved.V2 readiness preflight ↗
Staged V2 signed destination intake on the AWS worker with its release gate closed; real HTTP rehearsal returned 503. Added commitment queue recovery tests preventing blind transaction retries. 165 ops tests passed with two opt-in skips, including canonical commitment checks. The signing adapter is local and unexercised on mainnet. Public intake and payouts remain disabled.V2 worker staging ↗
Built V2 destination registration that verifies holder signatures, native address checksums and the on-chain request. Duplicate registrations do not replace destinations. 155 ops tests passed with two opt-in skips, 19 site unit tests and two V2 browser checks passed, including the shared signature format; typecheck passed. Public intake is not deployed and V2 remains paused.V2 intake preparation ↗
Built a V2 redemption-status lookup using effective on-chain status and reclaim deadlines at one block. Open cancellation and disputed recovery are explained separately. Fifteen site unit tests and the targeted browser check passed. Intake remains closed; no activation.V2 redemption status ↗
Built a separate V2 migration interface with distinct V1/V2 balances, exact approvals, fresh wallet checks and pending-transaction recovery. Release flag remains closed. V1 routes are unchanged; this is local preparation, not an activated migration.V2 migration preparation ↗
Confirmed the approved initial V2 float transfer with 12 native confirmations. Reconciled reserve is 9.00708328 ZEC, excluding the float; protected liabilities and V1 supply leave 2.58737072 ZEC headroom. Fresh attestation simulated but not sent. V2 remains paused.V2 reserve reconciliation ↗
Prepared internal shielding of the initial V2 payout float for a 0.00015 ZEC fee. Four failure-path tests passed locally and on AWS; live unsigned preview passed. No shielding transaction or V2 activation was sent.V2 payout preparation ↗
Added the initial V2 float transaction journal to encrypted recovery backups. Seven snapshot tests passed locally and on AWS; network-isolated restore matched the submitted funding record. V2 remains paused; native confirmations and reconciliation are pending.V2 funding recovery ↗
Submitted the owner-approved 0.10 ZEC transfer to the isolated V2 payout wallet with exactly 0.00010 ZEC network fee and reserve change. Linux signer tests and a live unsigned preview passed. The approval gate was removed after submission. Ten native confirmations and fresh reserve reconciliation remain required; V2 is paused and no LP funding occurred.Initial V2 payout float submission ↗
Prepared an unsigned 0.10 ZEC reserve-to-V2-payout-wallet proposal after fresh protected-deposit and pending-transfer checks. A separate fixed-destination offline signer passed seven synthetic-key tests locally; it is not installed or used in production. The proposed 0.00010 ZEC network fee and reserve change are explicit; the payout float will not count as reserve backing. No native transaction signed or sent and V2 remains paused.V2 payout funding preparation ↗
Added a local burner preflight that rejects token, pool and hook settings inconsistent with the selected Furnace, preventing mixed V1/V2 configuration during migration. Thirteen checks and a read-only new-market binding check passed, along with ops typechecking. Production burner configuration remains unchanged; V2 is paused and unfunded.Burner migration checks ↗
Added and ran repeatable read-only checks matching the new hook and Furnace deployment transactions to compiled creation bytecode and constructor arguments, with runtime instruction and role checks. Prepared explorer source packs and corrected deployment policy to deployed, paused and unfunded. Explorer source publication remains pending. No activation or funding.V2 market verification status ↗
The owner deployed the empty r4 market and replacement Furnace. All five transactions succeeded. Independent on-chain reads confirmed the 0.50% LP fee, 0.25% hook fee, correct Furnace destination and retained burner policy. V2 minting and Furnace ignition remain paused, supply and escrow are zero, and no liquidity was funded. Source verification and production funding, integration and activation checks remain before public launch.Deployed empty V2 Furnace ↗
Prepared the owner-signed empty V2 market deployment with nonce journals and gas caps. Exact-r4 deployment and market trading/burning/LP exit passed on local forks. Production reporter/verifier credential checks passed without signing; real 0.01 test-ZEC Linux native payout and separate verifier settlement passed, with one payment and zero escrow. Mainnet r4 remains paused; no production funds moved.V2 market preparation ↗
Confirmed exact-match mainnet r4 source verification and fresh runtime/pause checks. Reconciled reserve observations with 0.00314001 ZEC protected for user wrapping deposits, leaving observed backing headroom of 2.68747072 ZEC. Full service rehearsal and the V2 market remain unfinished. No funds moved or activation; documentation local.Verified r4 source ↗
Read-only V1 accounting verified the 0.002 ZEC reserve reimbursement and found zero remaining desk reimbursement liability at block 61,467,680. This does not clear unrelated obligations or V2 activation. No funds moved; documentation local, not published.Reimbursement reconciliation ↗
Staged V2 reporter/verifier runners and combined native/EVM recovery backups on AWS. Both runners rejected the closed gate; a real encrypted backup restored offline with wallet and shared transaction records intact. Payout services remain inactive. Linux native proof passed against the confirmed reserve purchase; full service rehearsal remains outstanding. No mainnet funds moved; docs local, not published.V2 runner and recovery ↗
Staged a restricted V2 native wallet handoff on AWS. The native service independently checks the committed request and derives the amount; Linux peer checks and closed-gate wallet integrity passed. The service remains inactive, with full service rehearsal and coordinated recovery still required. No mainnet funds moved. Docs updated locally, not published.Native handoff preparation ↗
Built shared V1/V2 EVM transaction journaling for V2 settlement, with native-payment preflight and persisted signed hashes. Lost-response failure injection and separately signed local settlement passed; 115 ops tests passed. A new real 0.01 test-ZEC payout completed across both public testnets with separate verification, no repeat send and zero escrow. AWS production handoff remains unfinished. Mainnet r4 remains paused; docs local, not published.V2 settlement preparation ↗
Staged a separate V2 payout wallet on AWS and verified encrypted backup restoration offline. Hourly encrypted backups and failure monitoring are enabled. Nineteen native checks and five backup tests passed on AWS; a gated send changed no wallet or journal. Production payouts and r4 activation remain disabled. Docs updated locally, pending publication.V2 wallet preparation ↗
Hardened the testnet native payout driver with durable wallet reservations, a fee-inclusive daily cap, a retained balance floor and wallet-wide uncertain-send holds. Sixteen Python tests passed; two pre-signing balance-parser timeouts were reconciled and corrected, and the clean local-EVM/real-native-testnet payout completed with separate verification and zero escrow. No production sending or V2 activation. Documentation remains local.Payout readiness ↗
Activated automatic Tap v2 claims on AWS. The worker checks credited ETH about every minute, applies minimum-credit and gas limits, and forwards through the fixed 60/25/15 Foundry split. First automated pull confirmed 0.0631411 ETH distributed. It does not invoke Pons conversion, buy ZEC, fund LP or activate V2. Documentation pending publication.First automatic Tap claim ↗
Built a local mainnet payout verifier covering exact outputs, actual fees, inclusion and ten confirmations across two regional endpoints. Read-only verification found 2.68407759 ZEC delivered by the recorded reserve purchase, 0.00007 above the service report. Production sending remains disabled; no attestation, mint or activation. Documentation pending publication.Native receipt reconciliation ↗
Owner assigned the separate r4 guardian. Independent runtime, role and pause checks passed at block 61,397,159; V2 remains paused with zero supply and escrow. No mint, migration or liquidity funding. Production payout and market gates remain open. Documentation updated locally, pending publication.Guardian assignment receipt ↗
Prepared an owner-signed r4 guardian assignment command with pinned-runtime and paused-state checks, a gas cap and durable pre-broadcast transaction identity. Dry run passed; owner signature remains pending. Separate phone-wallet seed confirmed, but no automated payout connection or activation. Local preparation; not published.V2 guardian preparation ↗
Built local combined V1/r4 reserve reconciliation with conservative refusal cases and prepared an unsigned guardian assignment. Fresh r4 runtime/pause verification passed; no role assignment, attestation, mint, migration or liquidity funding sent. Production payout binding, independent custody and market readiness remain gates. Documentation pending publication.V2 preparation safeguards ↗
Completed a 1.2 ETH reserve purchase through Relay and NEAR 1Click, delivering 2.68400759 native ZEC with confirmation recorded. No attestation, mint or V2 activation performed by this purchase. Reworked the ledger to lead with distributed fees and cumulative 60/25/15 funding allocations; pending fees remain secondary and old escrow history stays documented.Reserve purchase and fee accounting ↗
Added a terminal-only encrypted reserve-key import command and 1.2 ETH per-purchase/rolling-day limits. Incomplete history blocks a new purchase; journals are flushed before broadcast. Local tests passed. No key imported, funds spent or unattended service enabled.Reserve conversion limits ↗
Hardened the local ETH-to-native-ZEC conversion script: replaced percentage gas holdback with a bounded allowance, recorded transaction hashes before broadcast and required native reserve confirmations before completion. Quote ranking has unit coverage; multi-provider execution and unattended signing remain unfinished. No purchase or deployment.Reserve automation preparation ↗
Prepared a 1.2 ETH reserve-purchase quote to the existing native ZEC reserve while retaining the separate liquidity allocation. No purchase was signed or executed. The Foundry remains 60/25/15; V2 remains paused and unfunded.Reserve purchase preparation ↗
Created mainnet zZEC V2 r4 paused at 0x1955…3A25. Independent verification matched the complete reviewed 18,693-byte runtime and confirmed zero supply, zero escrow, matching roles and paused mint/migration paths. Older deployments remain paused. Guardian remains owner; custody, production payout, reconciliation and new-market gates remain. No activation or liquidity funding.Paused r4 deployment ↗
Connected the testnet native driver to the ops transport and independently decoded the real payout fee. A combined local-EVM/native-testnet exercise retained unresolved intent after a path-alias mismatch without sending again; recovery verification completed and the separate verifier settled the same payment without another native send. A clean local-EVM/real-native-testnet run also passed. Paused r4 create dry run passed. The proposed cofounder address matches recovery, not guardian; custody remains unconfirmed. No mainnet deployment, activation or funding.Native adapter and custody gates ↗
Built a testnet-only native payout driver with fee inspection before signing, durable transaction evidence before broadcast and an exclusive rehearsal-wallet lock. Nine driver tests pass. Isolated testnet faucet funding was received and a real 0.01 test ZEC driver payment broadcast after checking its fee. Confirmation and the full settlement rehearsal remain pending. Mainnet use is disabled in the driver. No reserve spend, deployment or activation.Native payout release gates ↗
Rehearsed a separate V2 Furnace/hook/pool against real v4 infrastructure on a local fork: buys, sells, slippage rejection, fee-to-ZEAL burn, fee collection and LP withdrawal passed. Built a durable-intent V2 payout coordinator and EVM adapter with separate-role local-node testing. Native payments in that adapter test were modeled; production wallet integration remains gated. Refreshed reserve observations without moving funds. No mainnet activation or funding.V2 rehearsal and payout gates ↗
Expanded local zZEC V2 readiness testing with exact runtime matching, pause-specific deployment checks, native reserve fault scenarios and actual V1 migration on a local mainnet fork at block 61,317,395. The fork preserves combined liabilities and rejects repeated settlement; its native references are synthetic. Current Solidity is unchanged. Mainnet r4 creation, custody confirmation, production payout integration and the new market remain activation gates. No funds moved and V1 remains public.V2 readiness and remaining gates ↗
Pons converted accumulated ZEAL-denominated fees and credited 4.618428039464363737 ETH to Tap v2. A permissionless pull confirmed at mainnet block 61,307,962 and routed the complete new credit through the immutable Foundry split: 2.771056823678618243 ETH reserve, 1.154607009866090934 ETH liquidity, and 0.692764205919654560 ETH operations. Tap escrow is cleared. The earlier 15.584690486596283445 ETH legacy Foundry credit remains stranded. This event is not a ZEAL buyback.Pons fee pull ↗
Deployed and exercised testnet ETH/Test USD routes, atomic instant launch-and-buy, and full-fill limit buys/sells. Verified real testnet receipts after contract and fork checks. Existing TP/SL orders and balanced fees remain intact. Published on the public testnet app; faucet Test USD is not USDC. No production reserve or Tap changes.Trading upgrade evidence ↗
Stood up current-source zZEC V2 on Robinhood Chain testnet at 0x0087aaFfDa2A683156b10b91E8a539d956Fcd636 (r5, runtime 18,693 bytes), including the Opus M1 bound so a dust report can debit at most amount plus twice that amount. After commitPayout, the desk sent 0.01 real test ZEC (txid 15ac90138dadbf492ffb9b494902843af06369d6fb53301369e22f3fe25e8d2d, 10,000-zat fee, three confirmations), then reportPayout and confirmPayout fulfilled request 1. Testnet r4 remains the older synthetic-txid exercise and was not overwritten. Mainnet r3 at 0x5593…917B is pre-M1 bytecode, stays minting-paused with supply 0, and was not unpaused. V1 remains the public token. This proves the commit-then-broadcast desk path on current source. It is not activation. Owner, guardian and recovery are still the same person on mainnet. A bridge-security review and honest custody remain required before any mainnet unpause.Testnet r5 native payout ↗
Built a testnet visitor-feedback follow-up locally: confirmed launches navigate to their market, My launches filters by connected creator before pagination, banner visibility persists, and optional automatic quotes retain minimum output, expiry and wallet confirmations. Verified sample testnet position 3760 is locked and has compounded liquidity; clarified that the 0.3% LP fee is collected and reinvested by a transaction, not automatically on each swap. Added optional first-buy preparation with separate wallet confirmation and recovery after reload. Twelve Chrome/WebKit checks passed. Isolated preview deployed, but its database environment is unconfigured; public testnet not promoted. No fee parameters or production contracts changed.Read the feedback follow-up ↗
A fourth independent post-r3 review still refused unpause and reproduced a dust-report path: one report can debit amount plus twice the stamped fee cap, so 1 zatoshi of escrow can take 0.1 ZEC of headroom at the fee ceiling. That is not a steal and attest clears it. The desk must not pay dust. A tighter bound belongs in any activation create; this is not a reason to write r4 today. A 1-zatoshi gift can front-run one pending dust-exit amount; the holder can still redeem the new full balance. r3 stays paused.Read the review follow-up ↗
A third independent post-r3 review of the current zZEC V2 source also found no unprivileged theft path, no skipped commit, no in-flight clock move, and no settle-only mint headroom. Unpause is still refused on custody and the EVM-cannot-see-Zcash limit. One more review is still running. r3 stays paused.Read the review follow-up ↗
A second independent post-r3 review of the current zZEC V2 source also found no unprivileged theft path and no reason to write new bytecode. It named the pause-cap composition now written in the docs: each halt stage saturates at seven days on its own, so stacked halts can defer a claimed path to Disputed by about twenty-eight days, while unreported Open escrow still exits within fourteen. A plain transfer into the contract freezes tokens and does not change totalEscrowed. Unpause is still refused: owner, guardian and recovery are the same person, and no native Zcash payout has been proven on this bytecode. Two more reviews are still running. r3 stays paused.Read the review follow-up ↗
Expanded local testing of the current zZEC V2 source after the paused r3 create. Added 13 adversarial cases (commit kills cancel and reclaim, stamped clocks, settle does not open mint room, halt still lets holders request and cancel). Fuzz now runs 12 seeds and includes settleExternalLiability. Mutation harness killed 40 of 40 guards. A first independent post-r3 review of hash 6dbe4718… found no new bytecode defect and still refused unpause: payment validity is externally trusted, and owner, guardian and recovery remain the same person. Three more independent reviews are still running. r3 stays paused. V1 remains the public token.Read the test follow-up ↗
Created the current-source zZEC V2 on Robinhood Chain mainnet at 0x5593aD53e67674fBFFB604b5448D753c3057917B. Runtime is 18,677 bytes, larger than r2's 18,232. Constructor binds live V1, reserve t1Ujk…nJTw, and recovery 0x8338…e80f. Minting is paused, supply is 0, settlement is unpaused, commit window max is one day. Live views match the manifest. migrate and mint revert. r2 at 0xb633…4B2E and the old canary at 0xC7e7…D043 stay paused and empty. V1 minting stays paused and remains the public token. This is not activation. Unpausing would let every V1 holder migrate. Recovery and owner are the same person. No attestation, hook, pool, or public migration UI.Mainnet r3 create ↗
A second contrary review of the current zZEC V2 source also found no unprivileged theft path and no bytecode reason to block a paused create. It named two accepted reporter-key limits now written in the docs: commit can freeze every Open request into Disputed at zero cost, and an unpaid Disputed request can be late-reported forever for one extra delay plus a debit. A burn proposal with no recorded payout now reverts immediately. Mainnet r2 and testnet r4 do not include this source. Do not unpause r2. This is not a new mainnet create.Read the review follow-up ↗
A contrary review of the current zZEC V2 source found no unprivileged theft path and no reason to block a paused create. It found one Low: commitWindow was readable live up to two days, so an owner raise plus a last-second commit could put confirmDeadline about a day past the advertised seven-day figure. Source now caps the commit window at one day. Local tests cover the old stretch. Mainnet r2 and testnet r4 do not include this. Do not unpause r2. A second review is still running. This is not a new mainnet create.Read the review follow-up ↗
Made the zZEC V2 payout path match the intended desk rule: reportPayout now rejects Open, so the reporter must commit on Robinhood Chain before the EVM will accept a txid. Also added settleExternalLiability so an attestor can close a paid external IOU without quietly lowering the figure in attest; the settled amount hits the paid-out debit and the next attest must match it. Local tests cover both. Mainnet r2 and testnet r4 do not include this. Do not unpause r2. Paying ZEC before commit is still an ops fault the EVM cannot see.Read the settlement status ↗
Kept fixing zZEC V2 source after the contrary reviews. A later fee-cap cut can no longer force an under-debited report; a second resolve proposal cannot reset the seven-day delay; attest rejects a huge expected V1 supply and cannot lower a carried external liability; confirm and commit windows must still fit inside the Open cutoff; and a reported request no longer advertises a reclaim date. Local tests cover those paths. Mainnet r2 and testnet r4 do not include them. Do not unpause r2. Owner, guardian and recovery are still the same person. No native Zcash payout has been proven on this bytecode.Read the review follow-up ↗
A second contrary review agreed there is no unprivileged theft path and still refused activation while one person holds owner, guardian and recovery. It confirmed the late-report/queued-return hole and found another: a legal commit near the Open cutoff made an honest payout unreportable until Disputed. Source now lets a committed request report until its commit deadline, and the verifier can still confirm. Three source fixes are local-tested only. Mainnet r2 and testnet r4 do not include them. Do not unpause r2.Read the review follow-up ↗
A contrary review of the current zZEC V2 source found no critical bytecode bug and refused activation while owner, guardian and recovery are the same person. It also found a real hole: a late payout report did not cancel a queued return, so a holder who already received ZEC could still get zZEC back. Source now deletes that proposal on report and seeds the V1 supply at construction so a burn between create and first attest cannot vanish. Those two fixes are local tests only. Mainnet r2 at 0xb633…4B2E and testnet r4 do not include them. Do not unpause r2 onto the older copy.Read the review follow-up ↗
Created the recovery-bytecode zZEC V2 on Robinhood Chain mainnet at 0xb6338e8DFa16CD18f682C6737a58DCc9773E4B2E. Runtime is 18,232 bytes, matching testnet r4. Constructor binds live V1, reserve t1Ujk…nJTw, and recovery 0x8338…e80f. Minting is paused, supply is 0, settlement is unpaused. Live views match the manifest. migrate and mint revert. The old canary at 0xC7e7…D043 stays paused and empty. V1 minting stays paused and its reserve still covers supply. This is not activation. Unpausing would let every V1 holder migrate. Recovery and owner are the same person. No attestation, hook, pool, or public migration UI.Mainnet r2 create ↗
Deployed the recovery-bytecode zZEC V2 to Robinhood Chain testnet at 0x02F214a77d5ce5162276b9e662Cd00d23588811B (r4, runtime 18,232 bytes) with a distinct recovery role. Minting was unpaused on testnet only, 0.01 migrated, then 47 live EVM cases passed: holder cancel returned escrow, commit blocked cancel and reclaim, commit-then-synthetic-report-then-confirm burned, report-from-Open still worked, settlement halt blocked commit and report, and stranger recovery calls reverted. Request 4 is left Committed (dispute clock 2026-09-13 03:16 UTC). Request 5 is left Open for the seven-day reclaim (2026-09-19 03:16 UTC). Report/confirm used labeled synthetic txids — no native test ZEC moved. Older testnet instances including 0xb393…67c3 are superseded. The mainnet canary at 0xC7e7…D043 is still the older 17,100-byte bytecode, stays minting-paused with zero supply, and was not unpaused. V1 remains the public zZEC. Public docs in this repo are updated; zealtoken.com does not change until publish.Testnet r4 contract ↗
Built the custom optimistic zZEC V2 settlement in source: reporter commit before broadcast, Disputed instead of reclaim after a claimed pay, delayed recovery burn or return, and a reusable halt that no longer dies after seven lifetime days. Local tests cover the existing suite plus recovery paths and a separate native-reserve model, including the Codex H1/H2 cases. This is not deployed and not activated. The mainnet canary at 0xC7e7…D043 is older bytecode and stays minting-paused with zero supply. A replacement create still needs a distinct recovery key and a review of this source before anyone treats it as live.Read the settlement status ↗
Expanded the zZEC V2 settlement design after a second review pass, still without writing replacement bytecode. The proposal is a small custom optimistic settlement: the reporter commits on the EVM before broadcasting Zcash, a missed confirm or a commit with no report becomes Disputed rather than reclaim, and recovery plus owner resolve burn or return after a seven-day public delay. A reusable halt replaces the lifetime seven-day pause fuse; Open escrow still cannot be pause-trapped past a per-request cap. The writeup names what this model cannot guarantee — including that distinct role addresses are not independent custody, that a timeout does not prove a payment failed, and that paying an Open request is an ops fault the contract cannot see. UMA, HTLCs and a Zcash light client are compared and rejected for this replacement. The canary at 0xC7e7…D043 stays minting-paused with zero supply. A bridge-security specialist review is required before any production activation.Read the settlement design ↗
Wrote the complete proposed zZEC V2 redemption and recovery rules before any further contract work. After a payout is reported, a missed verifier deadline would move the request to Disputed instead of unlocking reclaim; an independent recovery proposer and the owner would then choose burn or return after a seven-day public delay, with the guardian able to cancel. A reusable emergency halt would replace the lifetime seven-day settlement-pause fuse. The written tradeoffs include false-report burns, return after a real pay, and Disputed escrow that can sit forever if recovery signers are unavailable. This is design only: the mainnet canary at 0xC7e7…D043 stays minting-paused with zero supply, V1 remains the public token, and no replacement bytecode is written or deployed until those tradeoffs are accepted.Read the proposed recovery rules ↗
Executed the Pons creator-fee recipient change to ZealTapV2. The hook creator is now 0x9F5b…bB47. The queued proposal is cleared. A dry-run of tap.sweep(0, 0) still reverts while the hook holds about 3.37 ETH plus 9.66 million ZEAL that need Pons conversion; tap.pull() reverts NothingToPull because Tap escrow is still 0. The 15.58 ETH credited under the Foundry remains stranded. This activates the route for later sweeps. It does not move the old escrow or add liquidity.Pons recipient execute ↗
Deployed a paused zZEC V2 canary on Robinhood Chain mainnet at 0xC7e7b61E1b470A5f9f23063bfE52CDCe54AAD043. Runtime is 17,100 bytes, the same size as the current testnet rehearsal. Constructor binds the live V1 token and the public reserve t1Ujk…nJTw. Minting is paused, supply is 0, settlement is unpaused, and the confirm window is 3 days. This is not activation: migrate and mint revert until a separate owner unpause, which would let any V1 holder move in. The 0.50%/0.25% hook and pool are not deployed. V1 remains the public zZEC and its minting pause is unchanged.Mainnet canary deploy ↗
Exercised the current-bytecode testnet V2 at 0xb3935146AEec199AeCB7cb88925Df1eae59c67c3 through the live EVM paths: raising confirmWindow left an in-flight cutoff in place and the later report still used the stamped 3-day window; settlement pause blocked report; synthetic report then confirm burned 0.01 escrow and debited 1,010,000 zats; a 0.004 dust mint redeemed as a full-balance escape; minting pause blocked mint and migrate; role and reserve proposals reverted if committed early and were cancelled; attestation age and redemption limits were changed and restored. 57 cases passed. Report/confirm used a labeled synthetic txid — no native test ZEC moved. Request 3 (0.01) is open for the seven-day reclaim (2026-09-19 00:39 UTC). The 0.50%/0.25% market hook is still not deployed. Mainnet V2 does not exist.Synthetic report on r3 ↗
Deployed the current zZEC V2 bytecode to Robinhood Chain testnet at 0xb3935146AEec199AeCB7cb88925Df1eae59c67c3 and verified the source. Runtime is 17,100 bytes and confirmWindow() reads 3 days. Minting was unpaused, the attestor posted 28,415,000 zats of test reserve plus 1,000,000 zats of external liability for leftover escrow on the two older instances, 0.01 test zZEC migrated 1:1, and the full 0.01 sits in request #1 without reducing supply. requestRedeem(0) and immediate reclaim revert. Native payout, report, confirm and the seven-day reclaim are not done; reclaim opens 2026-09-19 00:33:17 UTC and the payout size is 0.01 test ZEC, matching the constructor dust floor. Older instances 0x5f48…4690 and 0x6C35…27ba are superseded. The 0.50% LP / 0.25% Furnace market is still not on chain. Mainnet V2 does not exist.Verified r3 testnet contract ↗
Closed two sibling-site defects on the zZEC V2 review branch and locked the replacement-market fee policy at 0.50% to liquidity providers plus 0.25% to the Furnace for ZEAL buybacks and burns (0.75% headline). reportPayout now reconstructs the confirm window stamped at request time, so setConfirmWindow cannot push an in-flight reclaim past the advertised seven days. requestRedeem now rejects a zero amount, matching mint and migrate, so a zero-balance caller cannot open empty redemptions. Both cases have guard tests and mutation anchors. Stale 0.20% Furnace copy in the design doc, architecture note, README and operator handoff was aligned to the committed 50/25/75 policy file. This is source only: mainnet V2, its hook and its pool are not deployed, today’s live market remains 0.30% LP plus 0.70% Furnace, and a human auditor has not reviewed the current bytecode.Review the V2 market policy ↗
Raised the predeployment zZEC V2 Furnace share from 0.20% to 0.25%, giving a policy of 0.50% to liquidity providers plus 0.25% to the Furnace for a 0.75% headline trading fee. Liquidity providers keep the same 0.50% rate, which is 67% more per dollar of eligible volume than the current pool’s 0.30%, while every trade now contributes more to ZEAL buybacks and burns. The total trader hurdle remains below the current market’s 1.00%. The machine-checked policy file and the hook unit test were both updated and now fail if these values drift; the hook test asserts 250 zats taken from a 100,000 output leg. Wrapping and redemption still add no protocol fee and the immutable Foundry split is unchanged at 60% reserve, 25% liquidity and 15% operations. This is predeployment policy only: the V2 token, its new hook and its replacement pool are not deployed or activated, and today’s market fee is unchanged. A higher total fee can reduce the trading and arbitrage volume it is charged on, so the effect on Furnace revenue is not simply proportional.Review the V2 market policy ↗
Completed an independent review of the escrow-first zZEC V2 source and repaired every finding in code. The review examined commit 065d7ab and returned 29 findings — 2 critical, 3 high, 6 medium, 12 low and 6 informational — with 21 supported by executed proof-of-concept tests, and a verdict of do not deploy. The first critical defect was that confirming a payout burned redemption escrow without recording that native ZEC had left the reserve, so each fulfilled redemption reopened issuance headroom equal to the payout until the next attestation while the coverage view still read 100%; reproduced at the dated mainnet figures, one ordinary redemption turned 453,314 zats of designed capacity into 100,453,314. The second was that the constructor accepted a zero legacy-token address, permanently deleting the legacy liability term in an immutable field. The contract now debits usable reserve when a payout is reported, separates the verifier deadline from the holder reclaim unlock so a real payout that misses confirmation is no longer unrecoverable, adds a settlement pause and an independent guardian that can only pause, binds each report and confirmation to its request in calldata, requires attestations to state the legacy supply they read and to carry unreconciled legacy falls forward as external liability, replaces a strict legacy-supply equality that any holder could use to halt issuance with a conservative floor, disables ownership renunciation, expires stale role proposals and is born paused. The contract suite is 172 passing with a named regression test for every finding. This is source only and it is an independent review, not an audit: nothing is deployed, the testnet instance still runs the reviewed pre-fix code, and the completed rehearsal and pending seven-day reclaim now describe superseded code and must be repeated on a redeployed testnet instance. Mainnet V2 does not exist and mainnet minting remains paused.Read the review outcome ↗
Revised the predeployment zZEC V2 market policy after reviewing the need for deeper external liquidity. The replacement pool now specifies 0.50% for liquidity providers plus 0.20% to the Furnace, for a 0.70% headline trading fee. That raises the LP rate by 67% per dollar of eligible volume compared with the current pool while keeping the total below its existing 1.00% fee and preserving a ZEAL buyback-and-burn contribution on every trade. The machine-checked policy and hook test now require the 0.50% pool tier. This does not guarantee provider earnings, deploy a pool or change today’s market; actual returns still depend on volume, active range, position share and price movement.Review the revised V2 market policy ↗
Fixed the reviewed predeployment fee policy for the future zZEC V2 / native ETH market at 0.30% to liquidity providers plus 0.20% to the Furnace, reducing the headline trading fee from the current market’s 1.00% to 0.50% while keeping ZEAL buybacks and burns in every trade. Wrapping and redemption add no protocol fee; actual disclosed Zcash network fees can still apply to native payouts. The existing immutable Foundry split remains 60% reserve, 25% protocol-owned liquidity and 15% operations. A machine-checked policy file and hook unit test now prevent those values from drifting unnoticed. This is built and tested deployment policy only: zZEC V2, its new hook and its replacement mainnet pool are not deployed or activated, and the current market fee is unchanged.Review the V2 market fee policy ↗
Built a repository assurance layer so deployment and security claims can be checked without relying on marketing copy. The root status matrix now separates production, public testnet, tested and pending systems. New architecture, threat-model, security-policy, evidence, contribution and release documents state cross-chain trust, legacy redemption risk, privacy limits and missing evidence. CI now includes site unit checks, the complete contract suite, operator tests and a Chromium interface smoke suite. Separate read-only automation verifies production chain identity, deployed bytecode, Furnace and hook wiring, RedemptionDesk wiring, zZEC recorded coverage and completed Furnace burns every day; a weekly local fork exercises the launchpad lifecycle against public Robinhood Chain state. A new model-based zZEC V2 test checks supply, escrow and liability conservation through repeated fulfilled and reclaimed redemptions. Generated Python caches are removed from source control and dependency update review is configured. During the review, public chain reads confirmed the Furnace at 10 burns and 208,393.993067538169230611 ZEAL removed, while legacy zZEC issuance remains paused. This release changes repository checks and documentation only; it deploys no contract and moves no funds.Review the assurance model ↗
Released batched shielded withdrawal execution for the public test lab. After three confirmations of each fixed 0.005 test-zZEC lock, the worker selects the oldest requests and groups up to eight equal Orchard payouts into one FullPrivacy Zcash transaction. A batch starts with two ready requests; a lone request has a 30-minute maximum batching wait. The complete request set, destinations, amounts and encrypted memos are bound to one PCZT. Prepared, proven, signed and extracted artifacts are persisted before broadcast, the existing 10,000-zat native fee cap is enforced and unresolved bytes are recovered instead of replaced. Every request shares the batch transaction ID, while every EVM lock and native output is independently rechecked. The interface reports batch size or remaining wait. Niney-four shielded backend checks, 16 Chrome and Safari client checks, ops typechecking and the production build passed. The live worker had no pending withdrawals at activation, so a real multi-recipient public-testnet payout remains to be observed. ZEAL can still associate each private destination with its request, EVM activity remains public and production zZEC redemption is unchanged.Try batched shielded withdrawals ↗
Deployed a source-verified testnet contract for noncustodial take-profit and stop-loss sell orders on current-generation zealz.fun markets. Users approve and commit an amount while keeping tokens in their own wallet until a live full-order quote reaches the recorded trigger. Execution enforces a separate minimum output and sends all test zZEC directly to the owner; executors receive no fee and cannot change the recipient. Owners can cancel before execution and elapsed orders can be expired. The existing minute worker scans a bounded rotating set under its signer lock, statically verifies executable orders and records each hash before waiting. A final public smoke test created an order without transferring tokens, cancelled it and revoked the remaining allowance. Seven focused contract tests and six Chrome and Safari worker or responsive interface checks passed. Execution remains best effort, original-generation markets are excluded and no production order system is released.Verified TP / SL testnet contract ↗
Deployed the escrow-first zZEC V2 contract to Robinhood Chain testnet with verified source and four distinct operating-role accounts. The rehearsal used a dedicated 0.02 synthetic legacy test token, migrated 0.01 test zZEC 1:1 and kept a destination-bound 0.005 redemption in escrow and total supply while the native payment was pending. After three Zcash testnet confirmations, the payout reporter recorded the native transaction, the attestor recorded the reserve decrease from 28,925,000 to 28,415,000 zats, and a separate verifier burned the 500,000-zat escrow. The decrease reconciles to the payout plus a capped 10,000-zat network fee. One setup-only request remains escrowed for the seven-day reclaim exercise. All 138 contract tests and 80 shielded operations checks pass. A read-only mainnet snapshot at block 60,259,482 reconciled 6.42310569 ZEC, 6.41657255 legacy zZEC and a 0.002 ZEC external redemption liability, leaving 0.00453314 ZEC of unused capacity. This is testnet evidence; independent review, timed reclaim, a fresh production reconciliation, mainnet deployment and liquidity migration remain incomplete. Mainnet minting remains paused.Verified V2 testnet contract ↗
Paused minting on the existing zZEC contract while the wrapper upgrade is prepared. The public wrap interface now shows a short upgrade state and cannot create or display new deposit instructions. Existing zZEC remains transferable and redemption remains available. The pause was confirmed on Robinhood Chain at block 60,252,004.Mint pause transaction ↗
Built and locally tested the zZEC V2 contract to remove the original direct burn-before-payment redemption path. Redemption requests now remain in contract escrow and in total supply until a payout reporter records a native Zcash transaction and a separate verifier confirms it. Ignored requests can be reclaimed after seven days; reported but unverified requests can be reclaimed after one day. Zcash transaction IDs cannot be reused. V2 checkpoints active legacy supply, counts explicit external liabilities against reserve backing and blocks normal minting after an unreconciled legacy supply change. Atomic migration permanently locks legacy zZEC and issues the same amount of V2 without reducing aggregate backing liability. The emergency pause covers normal issuance and migration, and attestation values are bounded by the Zcash monetary limit. Eleven focused adversarial contract checks passed within the 138-test passing contract suite. The contract is not deployed or activated. Independent review, public testnet exercises, separate signer control and exact reserve reconciliation remain deployment gates.V2 redemption design ↗
Added shielded creator payouts to the public test lab. The service derives eligibility from finalized creator-fee events for markets launched by the requesting wallet, excludes creator-self trades and known simulation or operator wallets, limits the beta to one completed payout per creator wallet and rejects faucet balances as proof of earnings. A creator signs a separate destination-bound intent and permanently locks exactly 0.005 test zZEC before the worker can pay 0.005 test ZEC to an Orchard address. Native payments use a separately funded, capped testnet incentive account that is excluded from zZEC reserve backing. The current factory, hook, deployed code hashes, chain genesis and event range are pinned. A confirmed independent-wallet trade earned 0.006 test zZEC from a 0.5% creator split. The first complete proof locked 0.005 test zZEC and paid 0.005 test ZEC after three confirmations. The incentive account retained 990,000 confirmed zats. All 80 shielded backend checks, 12 Chrome and Safari client checks, ops typechecking and both production builds passed. Production creator payouts remain disabled.Verified creator payout ↗
Completed the first shielded test ZEC withdrawal across both public testnets and released the public interface. Only test zZEC credited through verified reusable shielded account funding is eligible; freely issued faucet tokens and launch-purpose credits cannot claim native test ZEC. A wallet signs an Orchard-destination hash, permanently locks exactly 0.005 test zZEC in the fixed testnet contract and waits for three Robinhood Chain confirmations. The worker then verifies the exact lock, reserve coverage and a capped native fee before paying exactly 0.005 test ZEC to the shielded address. The end-to-end trial verified a fresh deposit, reserve consolidation, test credit, EVM lock and three-confirmation native payout. The reserve retained 29,435,000 confirmed zats against 9,990,000 zats of remaining verified test-credit liability. The live run found and fixed missing PCZT read permissions and spent-note fallback context before release; the saved payout bytes were matched, proven absent from the node mempool and broadcast once without creating a replacement plan. The contract tests, all 76 shielded backend checks, ten Chrome and Safari client checks, ops typechecking and both production builds passed. Production ZEC and production zZEC redemption remain disabled.Verified withdrawal lock ↗
Completed the AWS rollout of planned-change alert routing after finding that the worker still had the previous health runner. The exact reviewed Pons recipient proposal is now tracked as scheduled maintenance and the exact reviewed zZEC minter proposal as ready for review; neither was activated. Unknown addresses or schedules remain urgent. The ordinary cloud alert channel recovered, the LP reinvestment service is healthy and its hourly timer remains active. A prior 403 run had already succeeded on retry and moved no funds because the estimated transaction cost exceeded its 2% limit. This monitoring change did not alter roles, signing, custody, transaction limits or balances.monitoring status ↗
Added reusable shielded account funding to the public test lab. A connected wallet signs a dedicated account intent, sends exactly 0.005 test ZEC to a unique Orchard-only route and receives 0.005 test zZEC after three confirmations, reserve settlement and the existing backing-gated credit. The balance can then fund normal Robinhood Chain testnet launches and trades. Launch and account intents use separate signed purposes and status authorizations. Recovered Zallet scanning from an older invalid-UTF-8 settlement memo by discovering unspent routes and reverifying known deposits individually. The live worker returned idle, all 73 shielded checks and both builds passed, and the test credit lab was replenished to 1 test zZEC from its public faucet allowance. ZEAL can see the deposit-to-wallet mapping, EVM activity remains public, and production ZEC remains disabled.Try shielded account funding ↗
Published a shareable proof page for the first shielded Zcash funded launch. It connects the shielded Zcash deposit and reserve settlement with the Robinhood Chain test-zZEC credit, token launch and locked liquidity position in one plain-language receipt. Each step links to its public explorer evidence. The page states that Zcash hides the sender and shielded amount, so the receiver verifies that private match; the credit contract remains operator controlled, Robinhood Chain activity is public and production remains disabled. The SHLD market links back to the receipt. Four focused browser and data checks, including phone overflow, passed with the production build.View shielded launch proof ↗
Added persistent test-asset access throughout the launchpad. Connected users can get test zZEC from the overview, launch checklist and buy ticket instead of hunting for the claim action. Test ETH has a separate faucet link, and the interface explains that test zZEC funds launches and trades while test ETH pays Robinhood Chain testnet network fees. The existing 100 test-zZEC hourly contract limit, wallet approval and gas checks remain unchanged. The production build and focused wallet-onboarding browser checks passed. This affects free public-testnet assets only.Get test assets ↗
Completed the first end-to-end shielded test ZEC funded token launch across both public testnets. A faucet sent 0.1 TAZ to an isolated funding account; after its network fee, 9,990,000 zats reached the creator-bound route and received three canonical confirmations. A persisted PCZT moved 9,980,000 zats into the dedicated reserve, the backing-gated credit contract issued exactly 9,990,000 test zZEC to the same retained creator, and that creator approved and launched Shielded Zebra through the balanced-fee factory. The final runner verified the Zcash settlement, Robinhood testnet credit and launch receipts, exact factory registry values, zero launched-token balances at the creator and factory, and locked position 3923. Zallet rejected listing the raw binary settlement memo after mining; execution stopped before credit, then resumed through a pinned recovery that excludes only the verified outgoing consolidation block. Future runner memos are valid text bytes. The 139-test ops suite and typecheck passed. Production and mainnet ZEC remain disabled.Verified shielded launch ↗
Replenished the public testnet settlement worker with 0.0007 test ETH after its balance crossed the 0.002 refill threshold. Chain 46630, the fixed sender and recipient, matching latest and pending sender nonces, the sender retention floor and the final receipt were verified. The worker finished with 0.00247047898 test ETH; the project test deployment wallet retained 0.00104637167 test ETH. An initial signed transaction was rejected by the RPC before admission because its gas limit was below the chain intrinsic requirement; that hash was checked as absent, recorded as rejected and replaced once with an estimated-gas transaction. No production or reserve funds were used.Testnet refill receipt ↗
Released shielded test ZEC launch funding as a public testnet beta. A creator signs the exact token draft, receives a unique Orchard-only Zcash testnet address and sends exactly 0.005 test ZEC. The receiver requires three canonical confirmations; an automatic local operator consolidates the complete deposit into the dedicated test reserve and credits the same creator through the pre-funded Robinhood Chain testnet credit contract before the normal creator-signed launch can proceed. The public receiver is rate limited, origin restricted and exposed through an encrypted tunnel; its wallet RPC remains loopback-only with a read allowlist. The interface invalidates routes when the wallet or draft changes and never accepts mainnet ZEC. Production deposits remain disabled. The deployed receiver health check, a signed public route creation, six focused browser checks, all 72 shielded backend checks, ops typechecking and the production build passed. No public user deposit or public shielded launch has completed yet.Try shielded testnet funding ↗
Consolidated the verified 0.1 TAZ shielded deposit into a dedicated public-testnet reserve and separately funded its network-fee shortfall. Deployed and pre-funded an operator-trusted test-credit lab on Robinhood Chain testnet with pinned network, code, token and receipt checks. Verified its live bindings, funded the retained creator with test gas and prepared restart-safe settlement, credit and launch runners. Exact RPC-origin and route-binding checks bring the ops suite to 139 passing tests. The final runner pins factory, locker and position-manager code, verifies the exact launch parameters, empty creator/factory token balances and locked position, then writes a public receipt manifest only after all native and EVM evidence rebinds. A live preflight passed every chain and contract binding before stopping at the missing-credit gate without signing. The creator deposit is waiting on the faucet cooldown, so no credit or launch has executed and public deposits remain disabled.Shielded testnet settlement ↗
Extended shielded transaction planning and reserve reads to explicitly pinned public testnet. Upgraded an isolated wallet copy to support fee inspection and verified an encrypted recovery backup. All 70 backend checks passed. New-account scanning still blocks live consolidation; no payment, credit or launch was executed and public access remains disabled.Shielded settlement preparation ↗
Built a read-only shielded-launch handoff validator for the original intent, exact draft, confirmed deposit and fresh creator signature. All 67 backend tests passed. Credit integration remains unfinished; the first receiving-only test signer cannot sign a launch. Public activation remains disabled.Shielded launch progress ↗
Verified a faucet-funded 0.1 TAZ shielded deposit against a locally signed funding intent on public Zcash testnet. Our wallet and node checked the exact Ironwood output and at least three canonical confirmations. Receiving passed; credit, consolidation, mobile-wallet signing and launch execution were not performed. Public funding remains disabled.Testnet deposit receipt ↗
Prepared an isolated shielded-launch public-testnet receiver account after the Zcash testnet node reached its tip. All 66 backend checks and the operator typecheck passed. Wallet account scanning and a public-testnet deposit are not yet verified. No public funding or launch activation.Shielded launch status ↗
Published a horizontal trending-rail update with slow movement, side arrows, a pause control and a fixed sort heading. Interaction pauses movement and reduced-motion settings disable autoplay. Existing market data is unchanged. Production build passed and the update is deployed to the public test lab.Trending navigation ↗
Activated keeper peg-priority trading on the AWS operator. Corrective buys and sells may now cross the preferred 35–65% inventory mix while the 0.1 ETH per-pass cap, fair-value output floor, fresh quote and balance checks, gas allowance and three-trade absolute reserves remain enforced. The live trigger is 1% and target 0.2%. A blocked correction or keeper outage during an out-of-band state now creates an immediate, prominent email alert with the last observed gap and public inventory. Seventy-four operator tests and six alert-policy tests passed. The pool was already within the band at activation, so no unnecessary transaction was sent.keeper safeguards ↗
Expanded the public testnet volume selector from three periods to six: 5 minutes, 1 hour, 4 hours, 24 hours, 7 days and all indexed history. Each selection recalculates total volume, buy and sell counts, side volume and unique addresses from confirmed swaps. The six controls share one compact row on phones. Production builds passed; market history and transaction behavior are unchanged.Inspect testnet volume ↗
Fixed a test-lab onboarding lockout where a zero or delayed public test-ETH reading could hide the test-zZEC claim even when the connected wallet was already funded. Balance checks now compare the public endpoint with the selected wallet, refresh when the page regains focus and keep a direct claim path plus manual recheck available when the wallet shows funds. The wallet still estimates gas and the faucet contract still enforces its hourly claim limit. Deployed to the public test lab after production build validation; this changes testnet setup only.Open testnet setup ↗
Built a distinct WalletConnect path for the test lab so compatible phone wallets can pair by QR instead of being mistaken for MetaMask Connect. The chooser keeps individually detected browser extensions, labels the MetaMask-only fallback accurately, validates Robinhood Chain Testnet transaction permission and supports pairing cancellation. Production activation is pending a public Reown project ID and live-wallet verification; the option remains hidden until configured.Wallet connection status ↗
Expanded the testnet activity scheduler so every public launch can build useful chart history. Each eligible five-minute run now prioritizes launches with no confirmed trades, then the least-recently traded markets, and fills up to 14 valid slots after excluding fixtures and unsettled openings. Market trades receive the worker time budget before holder-reward maintenance. Production run 281 confirmed all 14 slots across both contract generations with nine buys, five sells and 13 distinct test-zZEC volumes. Immediate paired round trips remain disabled. Scheduler and reward checks plus the production build passed; activity remains labelled simulation and uses test assets only.Verified simulation trade ↗
Changed ordinary phone entry to open the official current-generation Test ZEAL market after verified market data loads, giving mobile visitors an immediate chart and trade context. Exact shared-token links still win, and visitors can change markets normally. Desktop restoration and volume-leading fallback behavior are unchanged. This is a selection default only; contracts, prices and trading behavior are unchanged.Open the mobile testnet ↗
Reworked public testnet chart semantics around the confirmed post-trade Uniswap pool spot price. Charts now open on 24 hours, separate range from interval so 1m means one-minute OHLC buckets across the selected history, and use every confirmed swap for close-price lines, candles and volume. Quiet ranges retain a flat current-price reference with an explicit no-trades note. Deployed a rotating simulator plan that includes original and current markets, varies trade direction and size, and avoids immediate paired round trips. Forty-four targeted Chrome and Safari checks plus the production build passed. On-chain worker run 275 then recorded fresh confirmed trades in both contract generations; activity remains labelled simulation and uses test assets only.Verified legacy-market simulation ↗
Replaced the public testnet’s horizontally swiped phone directory with stacked market cards. Token identity, 24-hour price line, volume, pool zZEC, FDV, latest activity and the market action now read in one vertical flow; desktop keeps the full comparison table. Zero-result searches remove empty headers and pagination and show a single clear state. Ten Chrome and Safari checks passed with no horizontal overflow. Market data and trading behavior are unchanged.Browse mobile markets ↗
Reflowed the public testnet workspace before reduced desktop widths could squeeze the selected-market chart. From 701 to 1380 pixels, Trending tokens is a horizontal rail above the market and trade ticket; the ticket stacks below at 820 pixels and narrower, while wide desktops retain the three-column layout. Ten Chrome and Safari responsive checks passed from 390 to 2560 pixels with no horizontal overflow. Market data, rankings, charts and transaction behavior are unchanged.Open the responsive testnet ↗
Unified testnet discovery around the main Find a token or project field. One query now filters quick results, the market rail and the All tokens directory by name, ticker or contract address. Removed the duplicate sidebar and directory search boxes while retaining their sort controls, token cards, keyboard results and explicit unavailable states. No market data, wallet or transaction behavior changed.Search testnet markets ↗
Renamed testnet Favorites to Watchlist and moved it into the primary market navigation beside Explore & trade and All tokens. The saved count and active state remain visible without consuming a separate toolbar row. The market star now says Add to watchlist or Remove from watchlist, while existing browser-saved tokens remain intact. No wallet, contract or trading behavior changed.Open the Watchlist ↗
Restored line view as the selected-market default after live visual review, while retaining the corrected representative-price series, adaptive intervals, precise axes and volume pane. The plot now inherits the page theme and reaches the market-card edges without a nested frame. Compact market charts label exact zero movement as Flat, show tiny nonzero moves with a less-than value instead of +0.0% or -0.0%, and use a neutral straight line when there are no 24-hour trades. Volume remains independent from net price change and every indexed swap still counts.Read clearer testnet charts ↗
Rebuilt the selected-market testnet chart around adaptive OHLC candles and volume on a dedicated dark exchange-style surface in both page themes. Candles now open by default and line view uses the same readable buckets. Rapid confirmed executions are grouped into representative prices so the mechanical buy/sell spread does not appear as repeated spikes, while every indexed fill and its volume remain counted in chart totals, volume analysis and activity. Added dotted grids, UTC axes and a current-price guide. Contracts, trades and transaction behavior are unchanged.Read live market charts ↗
Corrected dense red and green combs in compact testnet price charts. Confirmed executions no more than 30 seconds apart now form one arithmetic-average point over a maximum 60-second cluster, preventing rapid paired buy/sell spreads from masquerading as repeated market swings. Broader price movement, indexed trade counts and volume remain unchanged, and no trades or prices are invented.Cleaner market trends ↗
Refined testnet market entry by screen size. Desktop restores the last valid market selected in that browser or opens the current first market by 24-hour volume; phones begin with no market selected unless a shared token link was opened. Invalid remembered markets fall back safely after fresh directory data arrives. ZEAL stays prominent in navigation without displacing community momentum.market entry ↗
Made newly active testnet markets draw their mini charts immediately from up to 48 recent confirmed execution timestamps instead of waiting for activity to cross 30-minute buckets. Multiple swaps in one second resolve to the final confirmed execution. A single execution draws a flat line without claiming direction, and markets with no 24-hour execution say so. Existing indexed simulated-bot volume remains labelled and no price movement is invented.See live test markets ↗
Replaced the redundant Trading line in testnet market cards with compact 24-hour price sparklines and red or green direction. The existing 24-hour volume remains directly below, while batch-opening and settlement states keep explicit labels. Lines use indexed execution history and show a building state when there is not enough history; no price movement is invented.Scan live markets ↗
Made holder rewards an explicit slider in the shared launch fee controls. Moving it now changes the total hook fee automatically while preserving the chosen buyback and creator shares and the fixed platform allocation. The control enforces the deployed 0.75% to 5% total range and 0.25% holder and buyback minimums. The permanent split remains visible in launch review. This changes fee selection in the interface, not the deployed contract rules.Set holder rewards ↗
Added a Holders view to every public testnet token page. It ranks the complete confirmed positive-balance ledger, supports largest-first and smallest-first sorting, shows token balances and total-supply shares, and links each address to the explorer. Pool inventory, simulation wallets and known launchpad contracts remain visible with explicit labels. The eligible-holder summary continues to apply the reward exclusions. Holder data is read only and fails visibly while its index is incomplete.Explore token holders ↗
Restored original-generation testnet markets and cumulative test ZEAL burns to the public application after the balanced-fee contract generation changed the index start. The directory, search, charts and holder ledger now identify each market by its factory and launch index across both generations; new launches still use the balanced fee contracts. On-chain reads confirmed 25 original markets, 9 current markets and 195,137,591.886852565 test ZEAL burned in the original furnace. Known internal QA fixtures remain hidden. The chain never deleted the tokens or reversed the burns; derived database history was rebuilt from the earliest deployment block.Restored testnet history ↗
Removed the public sample-token visibility control and kept QA fixtures excluded from the market rail, project search and full token directory. Visitors now see launched community markets only. Direct links used for internal verification remain available, and market, fee and transaction behavior are unchanged.Hidden test fixtures ↗
Removed the selected market’s redundant Chart / Activity switch. Each market now presents its chart followed directly by indexed volume, recent trades and trader rankings, so visitors do not need to reveal the activity view first. The internal Activity / Top traders control and five-row initial limit remain. Market data and transaction behavior are unchanged.Visible market activity ↗
Made the selected testnet market summary respond to its own card width. Reduced-width desktop layouts move valuation and price above volume, liquidity and holders before long small-token prices can collide with neighboring values; wider cards retain the compact five-column row. Verified the rendered values at 1024, 1136, 1280 and 1440 pixels. Market data, pricing and transaction behavior are unchanged.Responsive market summary ↗
Added test zZEC and simulated-USD sizing to the public testnet trade ticket. Buys convert the chosen display value to an exact test-zZEC input. Sells use the current pool price to derive the exact token input and clearly identify the entered value as approximate; Preview still supplies the actual estimated receipt, minimum received, fees and price impact before any wallet request. Conversion and invalid-input tests passed with phone and desktop layout checks. Contracts and fee rules are unchanged.Trade value controls ↗
Simplified the selected-market Favorite action to a compact star. Unsaved markets show an outline; saved markets use a filled lime state with explicit accessible labels and pressed state. Browser storage and the Favorites filter are unchanged. Verified persistence, removal and phone sizing; no wallet or transaction behavior changed.Testnet Favorites ↗
Refined the public testnet mobile entry. The theme control now stays in the header’s top-right corner, the no-real-funds notice remains on one line at phone widths, and ordinary visits begin without silently selecting a token. Shared token links still open their exact market, while search, the market rail and the directory provide explicit selection. Verified at phone and desktop widths with both themes; no contracts, fees or transaction behavior changed.Mobile testnet entry ↗
Deployed and activated the balanced fee generation on public testnet for new launches. The hook reserves at least 0.25% each for holder rewards, ZEAL buybacks and the platform, with a 0.75% minimum hook fee and a separate 0.3% LP fee. Local boundary and accounting tests passed, followed by a public testnet launch, buy, sell, fee flush and holder payout. The original testnet contracts remain on chain; production launchpad contracts and the production ETH/zZEC pool are unchanged.Verified testnet launch ↗
Replaced the testnet market’s generic copy-link control with Share on X. It opens an editable post containing the selected token name, ticker and exact market link. A server-rendered social route exposes the immutable uploaded token image to X and redirects visitors to the selected market; launches without an image use the ZEAL fallback. Production build and live route checks passed. No post is published without the user confirming it on X.Share a testnet market ↗
Made the testnet market board visibly live with indexed 24-hour price sparklines, buy and sell counts and observed rank movement. The top three cards rerank from actual indexed volume every 30 seconds; rows only animate when an observed refresh changes position. Delayed history remains unavailable instead of inventing activity. Twenty focused database and Chrome/Safari-engine checks passed, followed by a production visual and console review. No contracts, fees or transaction behavior changed.Live market board ↗
Refined the testnet token directory into a compact market board with FDV, price, indexed 24-hour volume, swap counts, last-trade times, result-page activity highlights and direct market actions. Search, sorting and pagination remain available, with expandable wallet setup and data definitions. Simulated values and bot activity stay explicit; delayed indexing does not invent activity. Verified with desktop and phone browser checks plus database cutoff and delayed-data tests; released on the public testnet.Market discovery ↗
Added a prominent testnet project search above the market tabs. Name, ticker and contract-address results open the selected market, including on phones; keyboard controls, clear, no-match and unavailable states are supported. Search spans all indexed launches and sample tokens independently of Favorites.Search the testnet ↗
Testnet market summaries combine Market cap / FDV when the indexed supplies match, or show estimated circulating market cap beneath FDV when they differ. Reconciled transfer balances exclude identified burn and undistributed contract balances while retaining pool inventory. Expandable methodology and unavailable-data states keep the estimate explicit; simulated USD labels remain.Market valuation methodology ↗
Liquidity desk now surfaces wallet-owned positions and Uniswap collection/removal paths, reserve and contract verification, custody limits and saved position receipts. Direct approvals are capped at the deposit maximum, with a 20-minute PositionManager permission and pre-submit simulation. Local fork tests verified minting, collection and full removal with bounded approvals; no real funds moved. Independent audit, project LP lock and independent signing remain pending.Liquidity controls and limits ↗
Testnet intro and herd video now start visible on every visit. A left-aligned button below the video hides or restores them for that visit only; saved markets no longer automatically skip the homepage intro. Explicit market and launch links retain direct navigation.Open testnet ↗
Expanded the testnet workspace with responsive side gutters and more chart and trading space on wide screens. Made light mode the default while preserving saved theme choices, tightened token controls, enlarged the trade amount and consolidated connection setup. Passed 22 Chrome and Safari checks covering themes, card alignment and widths from 320 to 2560px. No financial behavior changed.wider testnet workspace ↗
Aligned mobile chart, rewards and trading cards to the same available width. Made automatic wallet payouts the primary rewards message and moved optional manual claiming into Payout help. Existing claim safeguards and automatic payout behavior are unchanged.mobile markets and payouts ↗
Refined the website, app, launchpad preview and testnet after a 20-finding interface review. Added a three-step launch review and direct wallet recovery; compacted setup, market statistics and quote help; corrected sample links and liquidity wording; fixed narrow layouts and step focus; retained USD context in liquidity review; added chart data tables and returning-market navigation. Updated the relevant docs. Browser and provider checks cover these flows; physical-phone wallet handoff and a full accessibility audit remain separate checks. No contracts or financial permissions changed.interface improvements ↗
Published screen-aware video selection for the shared launchpad homepage and testnet. Wide and Retina displays can use the existing 2288-pixel web encode instead of stretching the 1280-pixel version. Smaller displays keep lighter files; visibility, reduced-motion and data-saving behavior are preserved.video quality ↗
Published a public security and verification page with official domains, current contract explorer links, wallet-prompt checks, trust boundaries and reporting guidance. Added enforced browser policies across the website, app, docs, launchpad and testnet to block framing, restrict scripts and disable unused browser permissions. Updated the optional WalletConnect dependency tree to replace the reported vulnerable HTTP client. Production builds and dependency audits passed; these controls are not a third-party contract audit.security and verification ↗
Hardened testnet wallet connections after a Rabby report: corrected legacy wallet labeling, avoided redundant network-switch requests and removed a second account-permission path. Added popup recovery guidance and provider regression tests. The exact visitor extension issue remains unconfirmed; no contract or signing authority changed.wallet recovery ↗
Deployed compact testnet market panels, same-block price-impact-plus-fees review with acknowledgment at 5%, history prefetch and smaller desktop/phone videos. Passed 74 browser and 32 data checks, plus focused narrow-screen and wallet SDK checks. Verified a fresh testnet faucet claim, instant launch, buy, sell, automatic batch settlement and allocation claim. Settlement confirmed 171 seconds after expiry; physical-phone handoff remains pending. QA uses test ETH only; no production contracts or reserves changed.testnet review ↗
Improved testnet quote recovery and market navigation. Quote reads time out after 20 seconds with input preserved and late replies ignored; shared token links and discovery selections move to the market card. Normal entry and background refresh retain their position. Existing slippage and transaction safeguards are unchanged.testnet usability ↗
Deployed separate maintenance notifications for the reviewed Pons recipient and zZEC minter proposals. Scheduled, ready and expired states are distinguished; unchanged proposals no longer repeat as urgent alerts or affect service health. Unexpected changes and operational failures retain normal alerts. No on-chain roles changed.monitoring ↗
Completed the timelocked burner handoff to the dedicated AWS igniter. Daily checks now run at 19:00 UTC; the first cloud run succeeded and skipped because no fees were available. Retired the laptop burn job and obsolete laptop heartbeat alarm. Pons recipient and minter proposals were not changed.burner activation ↗
Standardized typography across the website, wallet app, docs, launchpad and testnet. Consolidated near-identical sizes into shared roles, aligned interface fonts and made small labels more readable. The homepage retains its content and sections; this pass improves hierarchy rather than removing detail.readability ↗
Extended the testnet worker to pay accrued test zZEC directly to indexed eligible wallets, rather than only simulation wallets. Bounded market/wallet rotation includes former holders with unpaid rewards, preserves settlement gas and retains optional manual claiming. No holder login or transaction is required; timing depends on worker, index and network availability.automatic testnet rewards ↗
Unified wrapping, liquidity and redemption around three guided stages. Payment instructions give way to tracking, explanations collapse, and direct redemption/liquidity transaction hashes survive reloads to prevent repeat submission while pending. Confirmation and payout remain distinct; existing financial limits are unchanged.guided app ↗
Fixed an indefinite background wallet check in the shared app and homepage. Unanswered account/network reads now time out after eight seconds and restore connection controls with recovery guidance. Repeated focus events share the pending check; outdated responses cannot restore an old session.wallet recovery ↗
Added a three-step liquidity flow to the shared homepage/app workspace: choose assets, prepare, then review and add. Completed steps can be edited, direct amounts survive session reloads, and native-ZEC and Kyber routes show their distinct next actions. Wallet and balance checks remain required; no deposit is submitted automatically.guided liquidity ↗
Added secondary USD reference values to the sweep estimate, fee totals, old escrow, projected allocations, ETH breakdown and buyback inputs. Buyback inputs are current reference valuations, not historical cost, and overlap rather than add together. One timestamped Coinbase ETH reference is used throughout; delayed prices are labeled and expired estimates omitted. ETH remains primary and unconverted ZEAL stays excluded.fee valuations ↗
Unified the homepage and app around one Wrap, Add liquidity and Redeem panel with shared wallet controls. Replaced oversized starting-asset cards with a compact selector, showing only the relevant path and identifying Kyber as external execution. Moved detailed liquidity explanations below the form. Existing action links select the matching tab.shared workspace ↗
Added the zZEC/ETH active-liquidity estimate to the live ledger, with both asset amounts, an optional USD reference and direct Wrap Zcash and Add liquidity app links. The display distinguishes active pool depth from reserve backing and projected fee allocations; no financial permissions changed.liquidity summary ↗
Replenished the testnet worker with 0.003 project test ETH and 0.01 faucet test ETH after a low-gas stoppage. Transactions resumed. Deployed a tested 0.001 test-ETH buffer for settlement, checked before each optional simulation send. Configured six-hour gas checks and bounded refills from available project test funds. Real reserves and mainnet funds were untouched.test gas funding ↗
Added secondary USD estimates beneath the reserve and outstanding-supply balances. Both use the same Coinbase ZEC price with a visible source and check time. The zZEC figure is a 1 ZEC reference valuation, not its pool price. Delayed prices are labeled and expired estimates are hidden without affecting balance reads.reserve USD estimates ↗
Removed the standalone Pons recipient-change section from the homepage. Its compact status and eligibility remain with the fee estimate in the live ledger, and existing shared recipient links open that ledger area. Updated the fee-route guide and incident links to match.live ledger ↗
Clarified the ledger headline as an ETH-only estimate after the Pons split and simplified the secondary label to Old escrow. Unconverted ZEAL fees remain separate. Reconciled the display against a fresh on-chain read; the earlier gross-pending figure is not directly comparable with the net estimate. Fee accounting and routing are unchanged.understanding the sweep estimate ↗
Published a clearer public ledger with estimated pending creator ETH as the headline, the Foundry allocation beneath it, and separate reserve and burn sections. Corrected the previous gross/net fee mix, separated old stuck escrow credit and unconverted ZEAL, and added shared fee reads and missing-data states. Seven accounting, timelock and shared-reader checks passed, along with the production build and desktop/mobile layout verification. No funds or contract permissions changed.fee-sweep accounting ↗
Deployed the testnet experience-review improvements: saved launch drafts, MetaMask phone/QR connection, guided setup, a mobile Trade shortcut, clearer quiet charts and quote minimums, and saved/replacement receipt recovery. Added incremental holder accounting and paginated discovery using shared 24-hour pool volume, with opt-in sanitized bug diagnostics. 32 targeted checks and 57 read-only quotes across 19 markets passed; desktop/mobile layout, QR display and cancellation verified. Holder backfill reconciled all 19 markets. No mainnet contracts or signing permissions changed.experience review improvements ↗
Deployed a correction for recurring testnet update warnings after 28 targeted Chrome/Safari-engine checks and staged phone/desktop recovery checks. Brief market-refresh failures retain usable readings only within their original two-minute window and retry after roughly 5–30 seconds. Expired data still pauses actions. Recovery preserves launch drafts, and diagnostics distinguish delayed snapshots from fresh results.market refresh recovery ↗
Upgraded testnet loading and recovery: earlier shared data reads, smaller route bundles, reusable cached assets and retained prior-release files. Fixed a reproduced Safari preload-cache failure and added bounded startup recovery that leaves open wallet sessions and launch drafts alone. Reduced the silent video from 49.9 MB to 11.8 MB at the same resolution and frame rate. Added bounded RPC retries, successful-read coalescing and history cancellation/recovery. Passed 256 distinct browser/data checks, 33 read-only quote cases and a 60-request cache sample without failures; these do not establish sustained capacity.speed and reliability release ↗
Completed 198 browser/data checks and 13 contract/fork checks, plus real public-testnet faucet, launch, buy, sell, reward and batch-claim transactions. The scheduled worker settled the QA batch 79 seconds after expiry without a manual settlement transaction. Verified 75 read-only quote cases and locker ownership for all 16 positions at the snapshot. A bounded 30-request read sample had no failures; this is not a capacity guarantee or independent security audit. Deployed wallet/receipt/quote fixes and clearer simulated-dollar chart labels.automatic testnet settlement ↗
Found and corrected a testnet onboarding blocker: zero claimable token rewards could fail the entire wallet-balance check and disable the faucet and launch actions. Explicit empty-reward responses now return zero; unexpected reverts and RPC failures still fail closed. Added fresh-wallet browser regression coverage, receipt-based selection after a launch, immediate balance refresh after confirmations, and visible quote expiry. Unknown token links no longer display a different tradable market.testnet wallet correction ↗
Passed nine local mainnet-fork buy and sell checks across two accounts and three trade sizes. Corrected reserve-cap, redemption and key-independence disclosures. Identified that locking project LP NFT 1909208 would interrupt its existing fee-reinvestment helper. No funds moved, no LP lock or new custody control activated, and no third-party audit claimed.safety review and limitations ↗
Made the Pons recipient tracker directly shareable at #fee-route in its own visible section. It shows exact UTC eligibility and expiry, distinguishes proposal from confirmed recipient activation, and reports delayed reads. The countdown is an execution eligibility time, not an automatic fee payout.recipient status ↗
Made the Kyber deposit step explicit after an ETH-only preview: a prominent Continue to deposit on Kyber button now sits under the estimate, with the entered amount and wallet, network and range steps. Preview does not deposit funds; approval still happens on Kyber.liquidity deposit flow ↗
Added an ETH-only Kyber cost preview and exact-pool handoff to the liquidity desk, preserving direct two-asset deposits. Validated a 0.01 ETH route on an isolated mainnet fork: 0.5% tolerance reverted, while 1% minted a position to the intended recipient and permitted withdrawal of both assets. Users choose their tolerance and approve on Kyber. No real funds moved, no second pool opened and no paid LP incentives activated.Kyber entry and validation ↗
Added a detected-wallet chooser and guided Robinhood testnet setup. Network add/switch requests require wallet approval; the selected provider stays attached to signing. Launch forms now explain connection, test ETH gas and test zZEC funding without clearing the draft. Browser checks cover network setup, cancellation and mobile help; no token transactions were submitted.testnet wallet setup ↗
Activated keeper inventory controls on the cloud operator with a 35–65% ETH reference-value band, three-trade working buffers, fresh pre-send balance and gas checks, and operator status reporting. Peg trades remain the only trigger. All 74 operator tests passed. Treasury top-up proposals are tested; funding transfers and external conversions remain disabled pending a designated treasury and budget.keeper inventory policy ↗
Replaced the full-width community video on zealz.fun and the public test lab with the latest supplied coastal herd animation (third video revision). Preserved the original 2288 × 912 resolution without recompressing the source video, removed audio and refreshed the full-resolution reduced-motion poster with versioned assets.updated launchpad homepage ↗
Added a guided liquidity page with starting paths for zZEC plus ETH, native ZEC and ETH, a two-asset deposit summary and a clear explanation of pool liquidity versus native ZEC reserve backing. Uses the existing full-range deposit flow; reserve donations and additional incentive rewards are not activated.liquidity guide ↗
Added automatic testnet batch settlement checks every minute, ahead of optional simulation trades. Shared signer locking, pending-transaction checks and contract rechecks prevent overlapping sends. Expired and empty batches are eligible; failed pools retry later, with manual settlement retained. Verified CAT’s settlement by the scheduled bot and four focused tests.CAT settlement receipt ↗
Added shared market and holder snapshots, visibility-aware polling with backoff, unchanged-history reuse and per-token delay handling. Wallet reads stay private and selected-token only. Added saved tokens, shareable market links, clearer faucet and signing states, plus aggregate health diagnostics. Transaction checks still use current network reads. Desktop/mobile and wallet-cancellation checks passed; a 60-request live read sample had no failures at up to 10 concurrent requests.improved test lab ↗
Reduced sequential testnet market waits with a bounded three-token scan and stopped obsolete scans from scheduling more reads. Delayed refreshes now show the last successful check time while retaining prior data and pausing actions until recovery.testnet recovery ↗
Added Open testnet beside See the mechanism on the zealz.fun homepage, plus the silent community video spanning the full page beneath the introduction. The video shares offscreen playback suspension and reduced-motion support with the test lab.homepage ↗
Simplified the testnet header with Explore, Docs and a More menu for Feedback and Explorer. Wallet controls stay visible and Launch token is the single lime navigation action, opening the form within the app.test lab ↗
Set zealz.fun to open in light mode and the test lab in dark mode. Explicit visitor choices remain remembered, with matching initial-page and application defaults.zealz.fun ↗
Separated token launching from the testnet browsing tabs. Explore and All tokens remain grouped; a prominent launch action sits to the right on desktop and full-width above them on phones. Refresh status now has its own quieter row.testnet navigation ↗
Changed zealz.fun and the test lab to default to dark mode while preserving each visitor’s explicit theme preference. Initial HTML and the application use the same default to prevent a light flash during loading.test lab ↗
Added testnet feedback with optional reply contact, persistent submission storage, spam limits and queued email notifications. Delivery uses a narrowly scoped AWS role with short-lived credentials; temporary delivery failures are retried. No wallet connection is required.send feedback ↗
Added the community video beneath the testnet introduction, spanning the full viewport without side margins or visible controls. Compressed the clip and removed its audio track. Added inline looping, reduced-motion poster mode and offscreen playback suspension.test lab ↗
Made simulated USD the automatic testnet market display, removing the currency toggle and editable rate. Stats, charts and volume use one fixed ZEC/USD reference with a source note. Wallet balances and trading stay in test zZEC; test assets have no cash value.simulated USD display ↗
Deployed testnet read optimizations: session caching for fixed token details, an explicit startup chain check instead of redundant per-batch checks, and a five-second shared edge cache for first chart-history pages. Wallet network checks and live balance, quote and transaction reads remain active. Browser checks cover cache retry, launch controls and market values; this is not a high-concurrency capacity certification.testnet read efficiency ↗
Repaired documentation tables so contract names keep a readable column width and wide tables scroll inside the article. Reorganized the launchpad guide around current public-testnet features, indexed history, rewards and liquidity limits, with shielded funding and the opening-fee experiment clearly separated as local work.launchpad guide ↗
Built a local instant-launch opening-fee experiment: 20% declining to zero over 30 seconds, with no address exemptions. Extra fees are assigned to the same locked pool position and explicitly remain queued until the token ratio permits compounding. Verified the fee-to-position lifecycle on a real testnet fork and checked the browser disclosure. Not deployed or enabled on public testnet or production.opening fee experiment ↗
Deployed a persistent testnet pool-swap index with resumable backfill, duplicate protection and reorg recovery. Independently reconciled 103 swaps across 11 markets through block 115774077. Charts and volume now use indexed pool history with explicit checkpoint coverage. Twenty-two checks passed, and consecutive scheduled updates were observed.persistent history ↗
Renamed chart and volume history selectors to All available. Documented that the current frontend query is bounded and is not a complete lifetime trading index.history labels ↗
Added an optional Simulated USD market display with a visible, editable illustrative reference rate. FDV, price, sampled volume and estimated liquidity use the same conversion. Native units remain the default and transaction amounts are unchanged.simulated USD ↗
Restored line view as the default testnet chart and clarified the Buybacks fee card as Buyback and burn test ZEAL. Candlestick view remains selectable.chart and fee copy ↗
Refined the testnet trading chart with default candlesticks, compact timeframes, green/orange candles, a subtle dotted background and a shallow volume pane. Preserved real trade timing, sparse-history disclosures and explicit testnet units.chart design ↗
Deployed a testnet market summary with FDV, price, sampled volume, estimated liquidity and supply-reconciled holder counts. Charts switch between FDV and price. Test zZEC units and sampled-history limits remain explicit. Six desktop/mobile data and browser checks passed in Chrome and Safari.market summary ↗
Deployed expanded testnet simulation on a five-minute schedule, with a rolling on-chain cooldown, bounded runs and low-test-gas checks. Verified 24 new test swaps, including a buy and sell in all six visible trading markets. Activity remains labelled as simulation; chart history comes from confirmed testnet transactions.testnet activity ↗
Deployed corrections to testnet chart time spacing, second-level labels and oversized volume bars. Sparse trading history now has a compact layout and explicit counts. Nine browser/data checks passed across Chrome and Safari. No prices or trades are invented to fill gaps.testnet charts ↗
Deployed bounded waiting for the reserve reimbursement job while wrapping holds the shared execution lock or finishes its verified checkpoint. Added safe failure-stage diagnostics. Twelve targeted checks passed; backing protections, transfer limits and persistent-failure alerts remain unchanged.operator reliability ↗
Added pre-signing native fee checks and saved-transaction refund recovery in the isolated shielded lab. Verified full 0.01-ZEC payments and recovery after an accepted response was lost and the wallet restarted. Bound local reserves to one authoritative ledger. Sixty-six backend checks passed. Public-testnet and mobile-wallet verification remain pending; nothing released.
Verified a fresh signed shielded deposit through reserve settlement, full test credit and creator-signed launch on isolated local chains. Failed launch funds remained available for retry; trading and reward claims passed. Added a non-spending operator recovery command. Fifty-seven backend checks passed. Public-testnet and real-wallet verification remain pending; nothing released.
Added fresh receipt-based local refund accounting and a reconciliation method for lost wallet operation responses. Verified the existing 0.01-ZEC refund after wallet/node restart without another payment. Fifty-three backend checks passed. Public-testnet integration and operator recovery UI remain unfinished; nothing released.
Verified a 0.01-ZEC native shielded refund on the isolated local chain with three confirmations. Durable submission tracking prevents blind resend after a lost wallet response; exact payout receipts are checked after restart. Forty-nine backend checks passed. Refund accounting and public-testnet launch integration remain unfinished; nothing released.
Added creator-signed local refund reservations for expired shielded funding intents. Signatures bind the return address, full amount and deposits; the ledger prevents credit/refund overlap and retains liabilities. Forty-four backend checks passed. Native refund payments and public-testnet launch integration remain unfinished; nothing released.
Verified local reserve-backed test-credit execution and restart recovery after an accepted transaction lost its response. Full credit stayed backed and repeated execution did not pay twice. Added durable signed-transaction recovery and retained confirmed liabilities. Thirty-seven backend checks passed. Local and unreleased; public-testnet launch integration and refunds remain unfinished.
Verified a real isolated shielded consolidation and added durable full-amount credit preparation with settlement/note replay checks. Twenty-eight backend checks passed. Live backing integration and credit execution remain unfinished; the feature stays local and unreleased.
Prepared the separate public-testnet wallet and an undeployed test-credit contract. Three local EVM tests cover one-time credits, duplicate rejection, permissions and failed-transfer retry. Credits use pre-funded test tokens and require operator-verified settlement. Testnet sync and full settlement integration remain in progress; nothing released.
Connected the unreleased HTTP service to Zallet. Verified address creation, retries, signed status and restart recovery. Added persistent network/account binding and genesis-bound signatures. Twenty-one backend tests passed. Public-testnet sync has started; deposits, reserve credit and launches remain unavailable.
Verified a real 0.01 ZEC shielded transfer on an isolated Z3 local test chain, with three confirmations and wallet-restart detection. Added a Zallet adapter with genesis pinning, wallet-sync checks and Ironwood note handling. Nineeen receiver tests passed. Public-testnet verification, service integration and reserve credit remain unfinished; nothing released.
Extended the unreleased shielded lab with creator-signed draft intents, authenticated status checks and safe retries. Wallet or draft changes discard stale responses. Added client binding tests and account-wide Orchard note isolation. Address display, reserve credit and launch execution remain disabled pending real-wallet verification.
Staged the Orchard-only shielded launch foundation: signed funding intents, dedicated testnet receiving addresses and durable note/reorg checks. Ten automated receiver tests passed. No live wallet integration, reserve credit or launch execution is enabled; production excludes the option.
Fixed the testnet line chart viewport: available trades stay fitted across the plotting area on refresh and resize. Removed accidental line-view panning and zooming; candles retain manual navigation. Verified desktop-to-phone resizing in Chrome and Safari.
Added a top-right Launch a token button to the test lab header, opening the existing launch form. Verified desktop and phone navigation; wallet requirements for submitting a launch are unchanged.
Simplified the test lab footer by removing the repeated bold deposit/reserve sentence. Verified the build; testnet labeling and functionality details remain visible.
Launched ORBIT, PRISM and EMBER as distinct testnet showcase tokens with original vector logos. Repeated UILAB interface fixtures are hidden from browsing by default and remain available through Show test fixtures. Contracts and histories remain intact. Verified directory counts, fixture toggle and mobile layouts.Meet the new test tokens ↗
Simplified the test token directory: removed the volume column and renamed the sort labels to Trending and Pool zZEC. Added a plain-language explanation of pool funds. Build and directory rendering verified.Browse tokens ↗
Test launchpad chart redesign: a price-first headline, gradient line view by default, rounded time controls and a clearer plotting surface in both themes. Candles and volume remain available. Uses confirmed test executions with explicit sample limits. Verified chart modes, theme switching and phone layouts in Chrome and Safari.View the chart ↗
zealz.fun now defaults to light mode across the preview and test lab. Dark mode is an explicit remembered choice, with brighter labels, stronger controls and clearer card separation. Verified theme persistence, dark-device defaults, shared text contrast and phone layouts in Chrome and Safari.Explore the test lab ↗
Test launchpad loading: replaced the empty startup screen with a responsive market skeleton, delayed-network message and retry state. Fixed overlapping polling that could continually discard slow reads. Added bounded startup checks and verified delayed reads plus failure/retry recovery in Chrome and Safari.Open the test lab ↗
Test launchpad: added a receipt-linked activity table, direction/size/time filters and volume-ranked traders beneath each token chart. Simulation activity stays labeled; loading and delayed updates remain explicit. Desktop and phone browser checks cover filters, wallet aggregation and contained table scrolling.Explore the testnet ↗
Refined the test market view with statistics above price, a separate volume pane and buy-versus-sell totals, counts and wallet activity. Added 5-minute and loaded-history filters with sample limits disclosed. Removed the confusing candle slider; chart interaction now reveals trade details directly.Explore price and volume ↗
Polished the testnet trade panel with token branding, tighter controls and an expanded-by-default visual fee breakdown. Holder rewards, test buybacks, creator and platform allocations read the selected market’s settings, with LP fees shown separately. Disconnected users can now connect directly from the trade panel.See the trade panel ↗
Replaced the test launchpad’s outline sample icons with original circular token logos: distinctive geometric marks, high contrast and a restrained metallic palette. The sidebar, directory and token pages share the new identities; creator-uploaded images remain intact.See the token identities ↗
Added a searchable test-token directory and a full-height discovery rail with observed-volume, newest and locked-zZEC sorting. Replaced the basic chart with TradingView Lightweight Charts for pan, zoom, crosshairs and clearer axes. Rankings disclose their sampled history and simulation bots; sparse charts explain their limited fills.Browse test tokens ↗
Refined the test launchpad around token discovery and trading: searchable markets, a compact introduction, available balances, quick trade amounts and token-specific activity. Fee breakdowns and advanced fee-cycle tools expand on demand; real testnet receipts and simulated-demand labels stay visible.Explore the refined test lab ↗
Test markets now show token icons and cleaner sidebar names. Live charts read each token’s confirmed fills, with candles, volume, OHLC, time and price axes, line mode and receipt links. Charts refresh every 15 seconds; sparse history and simulated activity are labeled rather than filled with invented prices.View test market charts ↗
Full testnet launch form connected: token image, description and social links persist on the test token; opening choices, fee presets and custom sliders submit the actual contract settings. A live token-card preview matches the launchpad mockups. Images are compressed and stored with immutable metadata, increasing test gas.Create a test launch ↗
Testnet wallet setup now preserves unknown-network errors so compatible wallets can offer to add Robinhood Chain Testnet, verifies the active chain before connecting, and explains Phantom testnet-mode refusals and its documented network limitation.Testnet wallet setup ↗
The launchpad test lab now shares the zealz.fun preview design: zebra branding, bold typography, light and dark themes, animated engraving background and responsive trading panels. Charts still show actual testnet fills, with simulated activity labeled. The dedicated testnet.zealz.fun address is available over HTTPS.Explore the test lab ↗
Separate zealz.fun test lab on Robinhood Chain Testnet: faucet test zZEC, instant and batch launches, test buys and sells, holder rewards, locked-fee compounding and fee-funded test ZEAL burns. Sample markets use actual testnet receipts; simulated bot activity is labeled. The test buyback harness is separate from production ETH routing and reserves.Try the test lab ↗
WalletConnect integration built with one selected provider across all three app desks, a pairing QR, cancellation, session restoration and disconnect. Automated checks use mock wallets; public pairing is pending Reown project configuration and real-wallet compatibility verification. Existing browser-wallet connections remain available.WalletConnect rollout ↗
App usability pass: shorter desk headers with transfer directions, sticky action tabs, clearer wallet setup help and a manual overview refresh. Redemption history distinguishes loading from empty; liquidity explains balance/data blocks before submission. Read batches stay within relay limits as histories grow, and loading failures have a reload screen instead of an empty page. Keyboard, mobile and Safari-engine checks cover the revised flows.App experience ↗
Completed wraps now use a compact, dismissible receipt message instead of a permanent full-size success card. The form resets to Ready to send ZEC when available; deposit history and pending-payment progress remain intact.Wrap receipts ↗
One header wallet connection now serves wrapping, redemption, liquidity and the overview. Added an account chooser and persistent session disconnect, cleared desk state on wallet/network changes, and checked the active account again before signing. Browser coverage includes connect-once, switching, disconnect/reload and rejected network changes.Shared app connection ↗
Connected-wallet overview added to the app: persistent balances, zZEC/ETH positions, uncollected fees and recent wrap/redemption activity across all tabs. Live read-only figures checked; account changes, delayed updates and mobile layouts covered by browser tests. No signature is required to view it.Your overview ↗
Mobile usability review: constrained docs and build-log content, larger touch controls, clearer wallet-browser guidance and a mobile menu for the zealz.fun preview. Chrome and Safari-engine checks cover responsive layouts and deposit/QR recovery states; physical mobile-wallet signing remains a separate device check.Mobile usage ↗
zZEC traded up to twenty-one times par overnight. Nothing malfunctioned: a peg needs two arbitrage legs and only redemption was live, so supply was fixed and nobody could add more until the wrapper opened. Coverage never fell below 1.incidents ↗
Peg defended with our own capital. ZEC added to the reserve, minted 1:1 against it, and sold back into the market by the keeper until the price returned to par. zZEC back to 0.484 ETH against a fair value of 0.485.
Reserve more than tripled overnight, from 0.99 to 3.39 ZEC, coverage 1.0018. Every zZEC still backed one for one.reserve ↗
Largest burn to date. 69,377 $ZEAL bought back and burned from that volume alone, nearly seven times everything burned before it, on a fee split nobody can switch off.furnace ↗
ZEAL homepage reorganized around the broader Zcash ecosystem. Buy $ZEAL remains primary; direct liquidity and zealz.fun preview links sit beside it. A launchpad overview explains benefits for ZEAL, zZEC, creators and traders, with preview status explicit.launchpad overview ↗
Liquidity deposits can be previewed before connecting a wallet. Fee explanations and Uniswap position-management links added; misleading estimated historical earnings and price-impact figures removed. Exact decimal input validation and Permit2 allowance-expiry handling improved. This does not add ETH-only deposits or a public compounding program.liquidity desk ↗
Roadmap expanded to cover community, wrapped Zcash, liquidity, zealz.fun and custody. FAQ expanded from four to sixteen questions with topic filters and supporting links. Desktop and mobile layouts, navigation and FAQ interactions checked; production builds passed.roadmap and documentation ↗
Launchpad overview now explains its central role in the ecosystem: creators launch against zZEC, trading gives the wrapper more uses, and fees support ZEAL buybacks and burns. Added a three-step flow and explained why zZEC/ETH depth matters to the planned ETH-buying route. Launchpad documentation updated; development status remains explicit.ecosystem connection ↗
Wrapping readiness checked against on-chain roles and AWS services. Timelock eligibility does not mean activation: the minter change is uncommitted and the wrapping worker is not installed. Public wrapping remains pending. Added local operator regression checks and a deployed-contract fork test; no real deposit-to-mint test has been completed.wrapping readiness ↗
Wrap deposit accounting protections deployed to AWS: pending, duplicate and cancelled-request payments stay reserved from other minting and reserve spending. Wrapping worker installed behind a disabled activation gate. Added confirmation recovery, older request history and cancellation warnings to the website. Owner activation and a real deposit-to-mint test remain outstanding; public wrapping is still closed.readiness and remaining limits ↗
Launchpad overview now includes a clickable token-page preview beside the introduction. Based on zealz.fun’s Zebra Foundry sample, it shows the chart, locked liquidity and ZEAL-burn presentation with sample status explicit. Responsive layout stacks the preview below the introduction on mobile.see the preview ↗
WrapDesk minter activation confirmed on-chain. AWS wrapping worker and timer enabled; the first no-deposit pass completed successfully. The public form remains gated until a real minimum-size deposit-to-mint test is reconciled.activation transaction ↗
Fixed overlapping heading and fee description in the zealz.fun token preview’s “Where every trade goes” section. The explanation now sits below the heading, left-aligned, with room to wrap on smaller screens.token preview ↗
Wrapping redesign started after an exact-amount test mismatch. Public wrapping stays closed; the legacy matcher is paused and the claimed test output is reserved for reconciliation. Built and locally tested a replacement contract with permanent recipient-bound deposit addresses and one-time credit per Zcash output. Dedicated custody, cloud integration and a new minter migration remain.unique-address migration ↗
Unique-address WrapDeskV2 deployed fully paused. Deployment bytecode and custody configuration checked; the dedicated deposit wallet is prepared locally. Public wrapping remains closed while cloud integration, off-device backup verification, the minter timelock and end-to-end tests are completed. Minter proposal tooling now guards the network, deployed code and existing proposals.paused deployment ↗
Temporary wrapping path under development through the existing minter, avoiding a new role delay for that path. Prepared secure cloud custody upload, a reserve-only deposit signer and initial receipt checks; 8 signer tests and 61 operator tests pass. Public wrapping remains closed until integration and real end-to-end verification pass.temporary path status ↗
Deposit custody staged in AWS with a restore-tested off-device encrypted backup. An isolated cloud wallet check passed; the reserve-only Linux signer passed 8 tests and is installed. No deposit worker is activated. Accounting, restart recovery, the user flow and a real deposit-to-mint test remain opening requirements.custody and launch status ↗
V2 minter proposal confirmed, eligible September 9 at 20:16:37 UTC. Deployed a worker restricted to the owner’s test route, assigned its deposit address and verified idle/reserve checks. Added durable pre-broadcast records and consolidation accounting safeguards. Public wrapping stays closed pending the funded end-to-end test and release checks.upgrade proposal ↗
A test transfer sent to the legacy reserve was held separately for reconciliation, without minting or crediting the unique-address route. Added clearer destination checks and recovery guidance. The funded unique-address test remains pending.deposit destination guidance ↗
First funded unique-address wrapping test completed: 0.00207 ZEC credited as 0.00207 zZEC through the existing minter. Verified confirmed reserve consolidation, project-paid network fee, exact mint receipt, protected backing and a fresh worker run with no duplicate mint. Public wrapping stays closed while automation, the user flow and broader recovery checks are completed.verified test mint ↗
Automatic dedicated-address worker deployed in AWS with off-device checkpoint recovery, fresh status reporting and alerts. Published the wallet request, deposit-address and receipt UI; verified stale-status and account-switch safeguards and mobile layout. Public requests remain gated by the final owner opening transaction. V2 credits stay paused.public wrapping flow and safeguards ↗
Added a wallet-opening help popup with the selected ZEC amount, copyable deposit address and manual sending instructions. It explains what to do when a browser cannot open a Zcash wallet without falsely claiming to detect installed apps. Wallet changes or unavailable deposit status close the popup.wallet-opening help ↗
Wrapping now shows a prominent payment-progress card, advances from sending to receiving, and announces status changes in-page. Confirmed mints display their receipt; pending deposits take priority over older completed tests. Recorded history stays visible during temporary status outages, while new sending instructions remain gated. Updated wrapping guidance.deposit progress ↗
Wallet reconnection now shows an explicit loading state until address and deposit-history checks finish. Empty-history messages require fresh, matching account data; failed or incomplete checks show an automatic retry message and manual retry button instead of implying deposits are missing.reconnection loading states ↗
Reduced routine keeper funding notifications: warning threshold is now below 0.2 ETH, while the separate 1 ETH-plus-gas refill preservation rule remains unchanged. The exact planned V2 minter proposal stays quiet until eligibility; unexpected changes, low gas, backing, payout and service failures still alert.funding notifications ↗
Homepage simplified: liquidity moves earlier, wrapping and redemption share a tabbed desk, and calculators, diagrams and the full build archive expand on demand. The ecosystem overview includes zealz.fun and its planned zZEC markets and ZEAL fee benefits, clearly labeled in development. Header links and dropdowns now share consistent sizing, spacing and readable solid backgrounds. The footer lists both token contracts with separate copy and explorer controls in compact rows. Hero action buttons and the contract-address bar use opaque backgrounds for readability over the animation. Transaction behavior and payout limits are unchanged.Using the homepage ↗
Fixed automatic reserve reimbursement’s access to the public wrapping checkpoint while keeping credentials private. Added the reimbursement service to cloud health alerts; prior confirmed transfers remain credited, with existing backing protections and transfer limits unchanged.reimbursement monitoring ↗
Reduced alert flapping: routine cloud service failures now require five minutes of persistence, with five minutes of stable recovery before a recovery email. Funding and safety alerts remain immediate; transaction safeguards and six-hour reminders are unchanged.alert timing ↗
Public backing, contract verification and the story behind ZEAL now open by default on the homepage. Each section remains collapsible, so visitors can inspect the system immediately and choose how much detail to keep visible.homepage guide ↗
Homepage copy now explains wrapping, redemption, liquidity providers, the Foundry and the Furnace in plain language. Clarified the launchpad’s planned role and what public verification can show, while preserving fee, custody and loss disclosures. Updated the overview with a short terminology guide.understand the ecosystem ↗
Brought planned zealz.fun holder rewards into the homepage introduction: participating token holders can accrue wrapped Zcash from trading fees without staking, alongside ZEAL buybacks and burns. Clarified that holder allocations can be zero and rewards depend on trading activity; launchpad development status remains explicit.holder rewards and fee splits ↗
Added a dedicated ZEAL app with persistent Wrap, Redeem and Liquidity tabs. Verified deposit addresses stay visible during refreshes and progress updates; fresh checks still gate sending, copying and a new locally generated Zcash address QR. Browser checks cover outages, recovery, wallet changes, progress, QR decoding and mobile layout. The app is live at app.zealtoken.com, with /app retained as an alternate entry point.open ZEAL app ↗
Redemption opens. First redemption paid end to end: zZEC escrowed, native ZEC sent, the Zcash transaction recorded on chain, and only then the escrow burned.source ↗
Automatic payer live. Redemptions are paid from a hot float within minutes, capped per request and per day, and every payout is journalled before anything is burned. No human in the loop for ordinary amounts.
The Herd. A liquidity desk on this page: leaderboard, tiers, and a way to add zZEC depth without leaving the site.the herd ↗
Docs. Seventeen chapters covering every process, every address, and every risk we know about.docs ↗
zealz.fun launchpad contracts pass a full lifecycle against a fork of this chain: capital-free launch, batch and instant openings, zZEC dividends to holders, compounding locks, and buying with ETH. Built, not deployed.design ↗
Adversarial review round. Sixteen independent reviews of the contracts, the operator and the site produced 139 findings. Nine launchpad design issues were fixed the same night, before anything was deployed.what was fixed ↗
Peg keeper live. A dedicated wallet with zZEC and ETH inventory checks the pool every minute and trades it back to the ZEC price outside a 1.5% band. First automated trade: a 5.7% premium closed to 0.6%.tx ↗
The burn hook. A Uniswap v4 hook on the zZEC market takes 0.7% of every swap and hands it to the Furnace, whoever provides the liquidity. Proven on a fork of the live chain, then deployed.hook ↗
The zZEC market moves to the hooked pool: 0.3% to liquidity providers, 0.7% to the burn. Same 1% for traders, every trade now burns $ZEAL.tx ↗
Redemption desk deployed. Escrow zZEC with a transparent Zcash address; the operator pays native ZEC and records the Zcash transaction on chain before anything burns. If a payout ever failed, you reclaim it yourself. Nobody can stop that.desk ↗
Redeem form on this page. Connect a wallet, approve, request, watch your own queue. Phase 03 is open.redeem ↗
WrapDesk deployed and verified: send ZEC to the reserve, receive zZEC 1:1. Each request carries a unique deposit tag so payments match without trusting anyone to say which is which. Every mint passes through the desk with its reason.desk ↗
zZEC minter rotation proposed to the WrapDesk. The wrapper enforces a 48-hour timelock on role changes, so activation becomes eligible on Sep 07 at 19:16 UTC. The public wrap opening is scheduled for 23:16 UTC, after activation.tx ↗
Live ZEC balance on the ledger, read from a Zcash node next to the attested number. Check either against the explorer.
The Furnace rebuilt for Uniswap v4: zZEC fees → ETH → $ZEAL → burn, LP fees collectable by anyone, liquidity itself untouchable. 9 new tests, 83 total.source ↗
First attestation posted by the attestor key, on a 6-hour schedule from here. Reserve 0, supply 0, coverage honest.tx ↗
Adversarial review pass over every contract, the operator, and the site. One real hole in the unreleased Furnace, plus operator and copy fixes. All closed. 84 tests.
First ZEC in the reserve, bought with ETH over NEAR Intents and attested on-chain a minute later. Both tiles agree.tx ↗
First mint: 0.11833344 zZEC against 0.11833344 ZEC. Coverage exactly 1.00.tx ↗
The zZEC/ETH market opens on Uniswap v4, initialized and seeded in one transaction. The first wrapped Zcash on Robinhood Chain is tradable.tx ↗
The Furnace deploys, verified, with an instant pause, owner-set hook data, and timelocked pool rotation added from an outside reader’s review the same day. Loop two is on chain.source ↗
First burn. zZEC trading fees collected, swapped to $ZEAL through the Furnace, and sent to the burn address. 571.8 $ZEAL gone. Loop two turns.tx ↗
Reserve grows to 0.4263 ZEC, attested and minted the same evening. Second liquidity position: pool depth 3.6x, coverage still exactly 1.00.tx ↗
$ZEAL live on pons.family. Graduated in under an hour.Pons ↗
ZealFoundry deployed. 60/25/15 split, no owner, no admin. Source verified.source ↗
ZealTap deployed and verified. Pons V2 pays only a caller, so the Tap claims and hands everything to the Foundry.source ↗
ZealTapV2 deployed and verified. It can sweep its own pool and migrate itself, so fee routing never depends on anyone else again. Still one exit: the Foundry.source ↗
zZEC contract written and tested, CI on every push.ZZEC.sol ↗
Reserve operator built: attest, mint, redemption watcher, ETH → ZEC sweep over Relay and NEAR Intents.ops/ ↗
Everything public: contracts, tests, operator, site.github ↗
Reserve address published. A transparent Zcash address anyone can watch, balance zero until the first conversion lands.zcash ↗
zZEC deployed and verified. Supply zero. It cannot mint until the reserve is attested, and it can never stop redemptions.source ↗
nextPons routes $ZEAL fees to the Tap, and loop one turns too.

Questions

Ask the
hard ones.

Clear answers about the tokens, your funds, trading fees and what we’re building next.

  • ZEC is native Zcash. zZEC is the reserve-backed token representing ZEC on Robinhood Chain. $ZEAL is the ecosystem’s community token. Buying $ZEAL, holding zZEC and providing liquidity are different activities with different risks.

    Compare ways to participate →

Put Zcash
on the chain.

Join the ZEAL community on zealz.fun: trade the Zcash ecosystem, wrap ZEC and follow every burn.