c00k Exchangec00kExchange
Checking…

06 · Proof

What has been checked,
and what has not.

Every result below can be reproduced from the repository with the command named beside it. The second half of this page is the list of things nobody has verified, and it includes the one that matters most. A project that only publishes its passing tests has published an advertisement.

Read the dates. This project ran on another chain before Arc, and the conformance runs below were measured there, against that chain’s pools, before the move. The first four below were taken again on Arc on 28 September 2026 and are marked so. The rest are measurements of a specific chain at a specific block somewhere else, and should be read as what the software did there.

Measured on Arc, 28 September 2026

1 / 12

npm run venues

Which venues are routed at all

Every concentrated liquidity venue on Arc, swapped by this engine and by its own pool code through a probe inside an eth_call, at three different blocks. One disagreement, or a callback the router cannot answer, and the venue is not routed.

Re-run on 8 October 2026: one venue of twelve was exact at every sample, 72 of 72 across its busiest pools, and it holds 1,159 pools. One disagreed by up to 357 parts per million, three call back functions the router does not implement, and seven had nothing to probe. Uniswap v4 and constant product pools are not part of this check.

8 / 8

npm run testroutes

The router contract executing against Arc

Each case is quoted, encoded into calldata, and executed against Arc pool state at the block it was quoted for. It passes only when the contract delivers exactly what the quote promised.

Eight cases re-run on 8 October 2026, every one exact to the wei, among them buying and selling $c00k through its Argus pool, whose hook takes the launch taxes and is priced by asking the chain rather than by a curve, and a 25,000 USDC order split across two legs. The hop kinds reached were concentrated liquidity and Uniswap v4.

14 / 14

npm run fairtest

Proof of fair, a round end to end on Arc

The contract deployed inside one eth_call against the live router: a 5 USDC round committed, a burn without a route refused inside the day of grace, the fee routed into $c00k, the burn routed into the target, the bounty paid, a second execution refused, a batch over the pot refused, and the pot paid out in batches.

Measured before ProofOfFair went on the chain and re-run on 8 October 2026, 14 of 14, with the burn routed into EURC. It is now deployed on Arc at 0xe82eb68e4eba49c26ad26d2f5a049b48115a86e3 in block 23,160,262, with the $c00k dev wallet as its treasury, and the engine checks on every start that the code there matches this compile byte for byte.

11 / 11

npm run transittest

The rules of a window, against Arc

The transit contract deployed inside one eth_call with two tokens of its own, then settled and refused: crossing orders with no route, the same orders twice, a fill under a maker’s floor, an unsigned order, a route that pays somewhere else.

Measured before CookTransit went on the chain and re-run on 8 October 2026, 11 of 11. It is live now, and the Batch page reads its counters from it.

25 / 25

npm run lockertest

The pantry’s locker, against a real position

CookLocker placed on Arc with a state override and handed a real Uniswap v4 position by its real owner, across simulated blocks with the clock moved forward: locked, its fees collected, a stranger refused at every door, shortened and refused, extended, withdrawn only after its time, locked forever and still refused a hundred years on, and handed to a new owner.

Run again by the deploy script before anything was sent, on 28 September 2026. It could not be re-run on 8 October: it needs eth_simulateV1, and none of the Arc endpoints this project uses answers it today. CookLocker is deployed on Arc at 0xd8e3ff27a3c132a1ddb99fc8743f2f12064930c6 in block 23,164,814, and the engine checks on every start that the code there matches this compile byte for byte.

Measured on the previous chain

144 / 144

npm run verify

Concentrated liquidity maths against the chain

Six Uniswap v3 pools, twenty four amounts each, quoted by this engine and by Uniswap’s own QuoterV2 at the same pinned block. A quote counts only when the two agree on every digit.

120 of the 144 crossed at least one initialised tick, and the deepest crossed six. Ticks are where the arithmetic gets hard, so a suite that never crosses one has proved almost nothing.

12 / 12

npm run verifyv4

Uniswap v4 swaps replayed out of their own logs

Twelve real swaps that already happened, replayed against the pool state at the block before each one, and compared against the amounts the chain recorded.

Every sample is counted, including the ones the quoter refuses to answer. An earlier version silently dropped those and reported nine of ten with nothing accounting for the tenth.

7 / 7

npm run testroutes

The router contract executing against live state

Each case is quoted, encoded into calldata, and executed against real pool state at the block it was quoted for. It passes only when the contract delivers exactly what the quote promised.

No deployment and no private key. The contract’s runtime bytecode is recovered by running its creation code inside an eth_call, then injected at an address with a state override.

What the tests found

The first time the contract executed a route it came up 5.5 parts per million short of the quote. Uniswap v4 charges its protocol fee on top of the liquidity provider fee rather than out of it, and the engine had been reading only lpFee.

Undercharging the fee means overquoting the trader, which is the direction that makes a real swap revert on its own minimum and charge gas for nothing. Five parts per million is far too small to notice by eye. It is the reason the standard here is exact agreement rather than close agreement.

The contract, and what it deliberately lacks

  • No arbitrary call surface. A router that forwards a target and calldata is a machine for draining every allowance ever granted to it.
  • No owner, no pause, no upgrade path and no rescue function.
  • Every amount is measured from balances rather than taken from what a pool reports, so a token that charges a fee on transfer is priced by what actually arrived.
  • Slippage is checked once, against the total delivered, not leg by leg.

On the chain

Two things a reader can check without trusting this site, both of them on an explorer this project does not run.

Source
Published and confirmed an exact match. The explorer compiled the source itself and reproduced the bytecode at that address, and it recovered the two constructor arguments from the deployment rather than being told them.
Keeper
0x98cac438cea984a637f02387658963891ce9980cThe contract that holds a scheduled swap until its window opens and lets anyone run it through the router for a bounty. It has no owner, no pause and no upgrade path, and the only contract it calls on its own is the router above. Its source is published on the explorer and confirmed an exact match, with the router recovered as its one constructor argument. Before it was deployed it was run end to end inside a single call against live pools: an order placed, a lowered minimum refused, an unopened window refused, the real route executed, a second run refused, a cancel refunded in full. The engine checks its bytecode on every start the same way it checks the router.
Proof of fair
0xe82eb68e4eba49c26ad26d2f5a049b48115a86e3The pool a dev hands tokens to at a moment they name, with no way back. At that moment it buys a tenth into $c00k for the $c00k dev wallet, buys the dev’s burn share into the token they chose for the dead address, and the publisher pushes the rest to the largest holders. It has no owner, no pause, no upgrade path and no withdraw, and the only contract it calls on its own is the router above. Four things are fixed in it forever, the router, $c00k, the fee wallet and the publisher, and the engine rebuilds its bytecode from those four on every start and refuses anything that does not match. Before it was deployed it was run end to end inside a single call against live pools: a native round committed, a burn without a route refused inside the day of grace, the real fee and burn routes executed to the treasury and the dead address, a second execution refused, a batch over the pot refused, two batches paid and the remainder burned. Fourteen checks, fourteen passes, reproducible with npm run fairtest. The one thing it trusts is the publisher’s list of holders, whose hash it writes with the last batch and which npm run fair-list recomputes from the chain.
Checked here
The engine reads the code at that address every time it starts and compares it byte for byte with what this repository compiles, immutables included. It refuses to build a swap against anything that does not match, so a swapped address stops the terminal rather than being served quietly.

Not measured

It is on the chain, and nobody outside this project has read it

The router is deployed at 0xe8b393641b2647e294374b6a06f4424e6d0f9593. The engine checks on every start that the code there is byte for byte what this repository compiles to, and refuses to build a swap if it is not. The source has not been published on an explorer yet. That establishes what the code is. It does not establish that the code is right. It takes custody of a trader’s tokens for the length of a swap, which makes it the most dangerous code in the project, and the only people who have read it are the people who wrote it. The keeper, which holds a scheduled swap for as long as its placer chooses, and proof of fair, which holds a dev’s commitment until the moment they named, were written by the same people and have been read by nobody else either.

A pass is a measurement, not a guarantee

These suites run against the liquidity that exists on the day they run. A route shape nothing currently prices will not appear in a run, and the suite reports which of the five hop kinds it actually reached rather than assuming it covered them all.

Two tokens here are not what their names suggest

WETH on this chain is not the canonical immutable WETH9. It is an upgradeable proxy, and so is USDC. Both answer the EIP-1967 implementation slot with a live address. Treating the wrapper as one for one and unbounded is true of the code deployed today and is a statement about whoever controls that proxy.

A comparison at one moment measures nothing

The advantage over a single pool ran from zero to about fifteen basis points in the runs recorded here. Hours earlier the same ladder showed four times that. Nothing in the router changed between them, liquidity moved. Any figure quoted from this project carries the block it came from.

Exact output overshoots, on purpose

Asking for an exact amount out is answered by searching for the smallest input that clears it, so the result usually delivers a few parts per million more than asked. That is the safe direction to miss in, and it is reported rather than trimmed away.

The copilot

The assistant beside the ticket reads the engine through tools and cannot state a figure it did not fetch, and it cannot sign: every swap it stages ends at the wallet prompt. What has not been measured is how often it misreads a request. There is no eval set for it yet, and until there is, treat what it says as a reading of the panel, not a substitute for it.

There is no audit badge on this site because there has been no audit. There are no partner logos because there are no partners, and no listing claims because nothing is listed. Every name that appears here is either a contract this project reads or a piece of software it runs.