Monitor Runtime
Threat Model
- Score forgery
An attestation is only valid if the digest recomputes to the same struct the signer approved.
- Replay
Each attestation carries a nonce, and an anchored motion hash cannot be anchored twice.
- Signature malleability
Signatures in the upper half of the curve order are rejected outright.
- Signer capture
Quorum is enforced on chain, and veRONET locking is planned to raise the cost of assembling one.
Signer Liveness
| Signer | Role | Status | Latency |
|---|---|---|---|
| validator-00 | Primary attestor | Online | 42 ms |
| validator-01 | Primary attestor | Online | 67 ms |
| validator-02 | Secondary attestor | Online | 95 ms |
| validator-03 | Standby | Syncing | — |
3
Signers Online
2 of 3
Quorum Policy
41 ms
Median Drift
0
Failed Anchors
Testnet trust assumptions
The signer set shown above runs on testnet and is operated by the core team during this phase. Decentralization of the attestation set, and the veRONET locking that secures it, are planned work rather than live guarantees.