- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
Paid crypto market-intelligence API for autonomous agents: crypto signals, whale/CEX/bridge flow alerts, calibrated price ranges, risk state, preflight checks, decision journals, and outcome audits via x402.
- Implementation fingerprint
- custom 35% confidence
- Fingerprint evidence
- valid 402 Payment challenge observed without implementation-specific marker
- First seen
- Aug 26, 2026, 12:17 PM UTC
- Last seen
- Oct 9, 2026, 6:22 PM UTC
- Origin
- https://crypto.forgemesh.io
- Tags
- None advertised
Payment surface
14 MPP endpoints
This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.
- Recipient
- 0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
- Chain
- 8453
- Unit type
- not observed
- Session · description
- Returns a verdict, realized pnl_pct, and direction_correct flag for any prior decision_id — the accountability check that closes the loop on
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
- Chain
- 8453
- Unit type
- not observed
- Session · description
- Returns a full decision journal entry — directional_bias, calibrated_confidence, anomaly_score, and agreement_score — plus a decision_id, co
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
- Chain
- 8453
- Unit type
- not observed
- Session · description
- Returns a conformally-calibrated range_80 price interval (~80% empirical coverage) plus current_price and upside_probability for BTC, ETH, S
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
- Chain
- 8453
- Unit type
- not observed
- Session · description
- Returns a perpetual-futures decision package for BTC, ETH, SOL, XRP, or ADA: direction LONG / SHORT / FLAT from the Kronos signal, stop-loss
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
- Chain
- 8453
- Unit type
- not observed
- Session · description
- Returns live perpetual-futures funding rates, mark and index price, open interest, and 24h volume for BTC, ETH, SOL, XRP, and ADA from Krake
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
- Chain
- 8453
- Unit type
- not observed
- Session · description
- Answers 'will this leveraged perp position survive the calibrated range?' for a side, entry, and leverage you specify: liquidation price and
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
- Chain
- 8453
- Unit type
- not observed
- Session · description
- Returns up to 168 hours of historical signal snapshots with timestamps and per-symbol scores — use it to backtest, chart signal drift, or bu
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
- Chain
- 8453
- Unit type
- not observed
- Session · description
- Returns a go/no-go allowed flag with market_state, cooldown status, and warnings for one symbol — call it before /kronos/decision to skip a
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
- Chain
- 8453
- Unit type
- not observed
- Session · description
- Returns current market risk state, per-symbol signal streaks, and active cooldown timers — use it as a pre-trade risk gate before acting on
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
- Chain
- 8453
- Unit type
- not observed
- Session · description
- Returns latest per-symbol signal scores and a ranked top_k list across crypto and supported stock symbols — pair with /kronos/risk and /kron
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
- Chain
- 8453
- Unit type
- not observed
- Session · description
- Returns current signal scores for BTC, ETH, SOL, XRP, and ADA plus a ranked top_k list, regime, and data freshness — use it as a lightweight
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x93A1F57D2e0DBE4cc882b5DbAEbe7F0F16443338
- Chain
- 8453
- Unit type
- not observed
- Session · description
- Returns whale, CEX, bridge, and stablecoin flow alerts for a chosen chain and lookback window, each with direction, venue, and USD value — u
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
Probe coverage
53 harmless observations
These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.
GET https://crypto.forgemesh.io/.well-known/api-catalog
HTTP 404162 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:22 PM UTCGET https://crypto.forgemesh.io/api/kronos/preflight
HTTP 4021,178 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:21 PM UTCGET https://crypto.forgemesh.io/api/kronos/history
HTTP 4021,256 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:21 PM UTCGET https://crypto.forgemesh.io/
HTTP 20035,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:20 PM UTCGET https://crypto.forgemesh.io/api/kronos/forecast
HTTP 4021,355 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:20 PM UTCGET https://crypto.forgemesh.io/api/kronos/risk
HTTP 4021,413 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:20 PM UTCGET https://crypto.forgemesh.io/api/kronos/signals
HTTP 4021,261 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:20 PM UTCGET https://crypto.forgemesh.io/api/signals
HTTP 4021,543 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:26 PM UTCGET https://crypto.forgemesh.io/api/kronos/futures/decision
HTTP 4021,806 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:24 PM UTCGET https://crypto.forgemesh.io/api/whale
HTTP 4021,330 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:23 PM UTCGET https://crypto.forgemesh.io/api/kronos/futures/funding
HTTP 4021,549 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:23 PM UTCGET https://crypto.forgemesh.io/api/kronos/futures/risk
HTTP 4021,525 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:23 PM UTCGET https://crypto.forgemesh.io/openapi.json
HTTP 20034,187 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:18 AM UTCGET https://crypto.forgemesh.io/api/kronos/audit
HTTP 4021,373 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:18 AM UTCGET https://crypto.forgemesh.io/api/kronos/decision
HTTP 4021,630 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 1, 2026, 12:24 AM UTCGET https://crypto.forgemesh.io/.well-known/api-catalog
HTTP 404162 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:22 PM UTCGET https://crypto.forgemesh.io/api/kronos/preflight
HTTP 4021,178 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:21 PM UTCGET https://crypto.forgemesh.io/api/kronos/history
HTTP 4021,256 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:21 PM UTCGET https://crypto.forgemesh.io/api/kronos/forecast
HTTP 4021,355 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:21 PM UTCGET https://crypto.forgemesh.io/
HTTP 20035,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:21 PM UTCGET https://crypto.forgemesh.io/api/kronos/risk
HTTP 4021,413 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:21 PM UTCGET https://crypto.forgemesh.io/api/kronos/signals
HTTP 4021,261 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:20 PM UTCGET https://crypto.forgemesh.io/api/whale
HTTP 4021,330 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:20 PM UTCGET https://crypto.forgemesh.io/api/signals
HTTP 4021,544 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:20 PM UTCGET https://crypto.forgemesh.io/api/kronos/futures/decision
HTTP 4021,806 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 12:24 PM UTCGET https://crypto.forgemesh.io/api/kronos/futures/funding
HTTP 4021,549 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 12:23 PM UTCGET https://crypto.forgemesh.io/api/kronos/futures/risk
HTTP 4021,525 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 12:22 PM UTCGET https://crypto.forgemesh.io/openapi.json
HTTP 20034,187 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 12:18 PM UTCGET https://crypto.forgemesh.io/api/kronos/audit
HTTP 4021,373 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 12:18 PM UTCGET https://crypto.forgemesh.io/api/kronos/decision
HTTP 4021,626 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 6:23 PM UTCGET https://crypto.forgemesh.io/api/kronos/preflight
HTTP 4021,178 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 12:24 PM UTCGET https://crypto.forgemesh.io/.well-known/api-catalog
HTTP 404162 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 12:24 PM UTCGET https://crypto.forgemesh.io/api/kronos/history
HTTP 4021,256 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 12:23 PM UTCGET https://crypto.forgemesh.io/api/kronos/forecast
HTTP 4021,355 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 12:23 PM UTCGET https://crypto.forgemesh.io/api/kronos/risk
HTTP 4021,413 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 12:23 PM UTCGET https://crypto.forgemesh.io/
HTTP 20034,069 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 12:23 PM UTCGET https://crypto.forgemesh.io/api/kronos/signals
HTTP 4021,259 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 12:22 PM UTCGET https://crypto.forgemesh.io/api/whale
HTTP 4021,330 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 12:22 PM UTCGET https://crypto.forgemesh.io/api/signals
HTTP 4021,542 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 12:22 PM UTCGET https://crypto.forgemesh.io/openapi.json
HTTP 20025,413 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 6:22 AM UTCGET https://crypto.forgemesh.io/api/kronos/audit
HTTP 4021,373 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 21, 2026, 6:20 AM UTCGET https://crypto.forgemesh.io/api/kronos/decision
HTTP 53017 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 12:25 PM UTCGET https://crypto.forgemesh.io/api/kronos/preflight
HTTP 53017 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 12:23 PM UTCGET https://crypto.forgemesh.io/.well-known/api-catalog
HTTP 53017 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 12:22 PM UTCGET https://crypto.forgemesh.io/api/kronos/history
HTTP 53017 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 12:22 PM UTCGET https://crypto.forgemesh.io/api/kronos/forecast
HTTP 53017 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 12:21 PM UTCGET https://crypto.forgemesh.io/api/kronos/risk
HTTP 53017 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 12:21 PM UTCGET https://crypto.forgemesh.io/
HTTP 53017 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 12:21 PM UTCGET https://crypto.forgemesh.io/api/kronos/signals
HTTP 53017 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 12:21 PM UTCGET https://crypto.forgemesh.io/api/whale
HTTP 53017 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 12, 2026, 12:20 PM UTCEvidence model
Security properties
Every result names its evidence state. Unknown and not tested never mean secure.
api_catalog_parse
ObservedNo RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links were withdrawn
Basis: RFC 9727 discovery response · Oct 9, 2026, 6:22 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:22 PM UTCbounded_response
Tested — pass162 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:22 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:22 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:22 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:22 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTCbounded_response
Tested — pass1178 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCeconomic_exposure_metadata
Unknown[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTCbounded_response
Tested — pass1256 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCeconomic_exposure_metadata
Unknown[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:20 PM UTCbounded_response
Tested — pass35038 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:20 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:20 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:20 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:20 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:20 PM UTCbounded_response
Tested — pass1355 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:20 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTCeconomic_exposure_metadata
Unknown[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:20 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:20 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:20 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:20 PM UTCbounded_response
Tested — pass1413 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:20 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTCeconomic_exposure_metadata
Unknown[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:20 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:20 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:20 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:20 PM UTCbounded_response
Tested — pass1261 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:20 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTCeconomic_exposure_metadata
Unknown[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:20 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:20 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:20 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:26 PM UTCbounded_response
Tested — pass1543 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:26 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTCeconomic_exposure_metadata
Unknown[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 12:26 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:26 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:26 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:24 PM UTCbounded_response
Tested — pass1806 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:24 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:24 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:24 PM UTCeconomic_exposure_metadata
Unknown[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 12:24 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:24 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:24 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:24 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:24 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTCbounded_response
Tested — pass1330 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCeconomic_exposure_metadata
Unknown[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTCbounded_response
Tested — pass1549 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCeconomic_exposure_metadata
Unknown[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTCbounded_response
Tested — pass1525 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCeconomic_exposure_metadata
Unknown[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTCopenapi_parse
Tested — pass14 payment offer(s) accepted
Basis: harmless discovery response · Oct 9, 2026, 6:18 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:18 AM UTCbounded_response
Tested — pass1373 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:18 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:18 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:18 AM UTCeconomic_exposure_metadata
Unknown[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:18 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:18 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:18 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:18 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:18 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 1, 2026, 12:24 AM UTCbounded_response
Tested — pass1630 bytes within scanner limit
Basis: harmless scanner · Oct 1, 2026, 12:24 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 1, 2026, 12:24 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 1, 2026, 12:24 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 1, 2026, 12:24 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 12:24 AM UTCeconomic_exposure_metadata
Unknown[{"method":"evm","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 1, 2026, 12:24 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 1, 2026, 12:24 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 1, 2026, 12:24 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 1, 2026, 12:24 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 1, 2026, 12:24 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 1, 2026, 12:24 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 12:24 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 1, 2026, 12:24 AM UTC— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"34187 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"162 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"1544 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1543 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"162 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"34187 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"1626 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1630 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"34187 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"162 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"34069 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"35038 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"1259 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1261 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"1542 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1544 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— payment-offer-discovered
offer → {"method":"evm","intent":"charge","currency":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","chainId":"8453","recipient":…
Evidence: challenge payment metadata
— probe-observation
content_type → application/json; charset=utf-8
Evidence: harmless unauthenticated HTTP observation
— probe-observation
tls_state: not-tested → tested-pass
Evidence: harmless unauthenticated HTTP observation
— endpoint-source-discovered
source:challenge → active
Evidence: https://crypto.forgemesh.io/api/kronos/futures/decision
— probe-observation
challenge_format → mpp-payment-auth
Evidence: harmless unauthenticated HTTP observation
— probe-observation
content_type → application/json; charset=utf-8
Evidence: harmless unauthenticated HTTP observation
— payment-offer-discovered
offer → {"method":"evm","intent":"charge","currency":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","chainId":"8453","recipient":…
Evidence: challenge payment metadata
— endpoint-source-discovered
source:challenge → active
Evidence: https://crypto.forgemesh.io/api/kronos/futures/funding
— probe-observation
tls_state: not-tested → tested-pass
Evidence: harmless unauthenticated HTTP observation
— probe-observation
challenge_format → mpp-payment-auth
Evidence: harmless unauthenticated HTTP observation
— probe-observation
tls_state: not-tested → tested-pass
Evidence: harmless unauthenticated HTTP observation
— payment-offer-discovered
offer → {"method":"evm","intent":"charge","currency":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","chainId":"8453","recipient":…
Evidence: challenge payment metadata