Independent verification review of Arbitrum — 17 onchain checks, credit-first

brawlaphant again (EcoWealth / Vealth), following up in this thread deliberately. The review above was credit-first with no ask attached: we examined Arbitrum’s infrastructure as outsiders and published what we found. This time we come with something to offer, held to the same standard — every claim below carries its own check.

[RFC / Non-constitutional AIP] Adopt Regen Network: bring the working ecological accounting registry — its token, its 22,434 holders, its credits, and its complete retirement history — onto Arbitrum One

Abstract

Regen Network is the longest-running on-chain ecological accounting system: a
registry of ecological credits (carbon, biodiversity, marine, stewardship)
with issuing projects, credit batches, tradable and retired balances, and the
retirement certificates that give those credits meaning. It runs today as a
sovereign Cosmos chain, regen-1, and pays for its own consensus with
inflation — a cost structure its governance is actively fighting and cannot
win against.

This proposal offers Arbitrum DAO the adoption of that network in its
entirety: the REGEN token as a fixed-supply ERC-20 with a real burn, the full
registry with history intact, merkle-claimable balances for all 22,434
holders (including a one-popup path for Keplr users), the marketplace and
basket mechanics, and the community and issuers behind them.

The engineering is not a roadmap. It is built, tested, and reproducible
today: six contracts, a full state export that reconciles to the chain’s
total supply with zero gap, and a pre-audit adversarial review whose
critical findings are already fixed with regression tests. All software is
contributed at $0.
The only money this proposal ever asks for is
independent verification — third-party audit firms at their own market rates
(~98% of a $65,000–110,000 envelope) — plus a year of archive hosting.

Nothing here binds either chain today. The mechanism is two votes in the
right order: Arbitrum signals adoption intent (this temperature check), and
Regen’s governance then votes on migration with a concrete offer on the
table instead of a hypothetical. Either side can decline and both chains
continue as they are.

The short version for delegates

  • What you get: a working RWA vertical no major L2 owns natively — the
    ecological registry itself, not a bridged wrapper — plus every future
    retirement, transfer, and issuance as sequencer revenue, plus the first
    complete appchain-absorption playbook, documented and audited.
  • What it costs: $0 for software. $65k–110k for independent audits and a
    year of archive hosting, fundable through the Arbitrum Security Program
    lane or this AIP. By the audit program’s own published numbers ($46,363
    average across its first 14 engagements), that is roughly two audits,
    inside the budget of programs the DAO already runs for exactly this.
  • What you risk: almost nothing before audits sign off; the proposal is
    structured so no Arbitrum funds move until third-party verification exists,
    and no Regen state moves until Regen’s own governance votes yes.
  • How to check any claim in this post: run the commands in “Verify it
    yourself.” The export root reproduces identically from any machine.

Motivation: what Arbitrum is buying

Arbitrum DAO is a digital organization with operating income, not a
foundation disbursing an endowment — and we will state that income honestly,
because this proposal’s whole method is stating numbers honestly.
DefiLlama currently shows about
$297k of Arbitrum chain fees over the last 30 days, with
Timeboost adding ~$81k
more in the same window ($7.7M cumulative since launch). That is real
revenue, and by the DAO’s own ongoing discussions it is not yet enough. Which
is exactly why the direction of this proposal matters: the scarce resource
here is not treasury — it is recurring, native, non-incentivized transaction
demand. This proposal buys a permanent stream of it, plus a vertical, plus a
playbook, at the price of an audit. Three returns:

1. Native transaction demand it keeps. Today, every Regen retirement,
transfer, and issuance settles on a chain Arbitrum earns nothing from.
After adoption: 22,434 claim transactions to start, ~285 seeding
transactions, and then the permanent stream — every credit retired by any
EVM wallet, every marketplace fill, every basket operation — is Arbitrum
sequencer revenue. The marginal cost side is equally instructive: seeding
the entire registry (5 credit types, 13 classes, 187 projects, 80 batches)
costs under $50 in gas on Arbitrum One. The same operation priced on most
L1s would be a budget line. That asymmetry is the business case for
absorbing appchains generally, and this is the first one arriving fully
engineered.

2. A vertical no major L2 owns, and the market that comes with it.
ReFi assets on EVM chains today are mostly bridged representations of
registries that live elsewhere. This is the registry itself: credit classes
with issuer ACLs and metadata IRIs, projects with jurisdictions, batches
with vintages, and the complete retirement history — owner, beneficiary,
jurisdiction, reason, beneficiary note — migrating field-for-field. That
makes Arbitrum the native settlement layer for ecological accounting. The
addressable market is not Regen’s current userbase; it is every wallet,
DAO, company, and AI agent that would retire ecological credits if doing so
took one signature on infrastructure they already use. Today it takes a
Cosmos wallet, IBC awareness, and a bridge. The migration exists to grow
the total addressable market of regeneration, and Arbitrum is where that
growth lands. Any Arbitrum-native protocol that wants verified ecological
impact — treasuries, games, RWA platforms, agent frameworks — gets it as a
contract call.

3. The absorption playbook. This is, to our knowledge, the first
proposal in which one DAO adopts an entire working blockchain network — its
assets, users, and history — the way an operating company acquires a
product line. The methodology is deliberately reusable: a deterministic
state exporter, a shared leaf codec between exporter and claims contract, a
reproducible merkle root, a halt-height handler for the source chain, and a
claim design covering both native-EVM and Cosmos-key holders. Every
appchain that can no longer afford its own consensus — and the macro trend
is that most cannot — is a candidate for the same playbook. Arbitrum is
buying the documented, audited precedent at the cost of the audit.

The state of Regen, stated honestly

This proposal does not argue Regen is failing at its mission. The registry
works, the credits are real, and the science infrastructure behind them is
respected. What is failing is the economics of sovereign consensus, and the
evidence is public:

  • The chain pays ~10.77M REGEN per year for consensus. Its parameters
    claim 3.5% inflation (8,380,475 REGEN/yr of annual provisions), but a
    measured blocks_per_year error means realized emission is ~4.5% of
    supply. Proposal #72 (live now) corrects the parameter to the measured
    5,604,079 blocks/yr; even corrected, the entire emission exists to pay
    validators for block production, not ecology.
  • Governance is starving on turnout, with zero opposition. Proposals
    #70 and #71 both closed REJECTED in August 2026 with zero NO votes and
    zero vetoes
    #70 at 25.76M YES, #71 at 31.38M YES against a 34.22M
    quorum (40% of 85.54M bonded). #71 missed quorum by ~2.8 million. Both
    were resubmitted (#72, #73 — the latter cutting max_validators 21 → 11
    as a proof-of-authority stopgap) and close 2026-08-26. A chain where
    unanimous-yes proposals die of apathy is not being governed; it is
    coasting. Migration to contracts deletes the validator-budget question
    entirely rather than answering it smaller.
  • The canonical bridge is fragile. In August 2026 a 3,000-REGEN hop on
    the canonical Axelar corridor (which escrows 24,970,696 REGEN on
    channel-48) froze at asset_sent for over a week. For an asset whose
    value depends on auditability, a stalling corridor to EVM liquidity is a
    structural, not incidental, weakness.

None of these facts are attacks; all are reproducible from public
endpoints, and the author of this post is the author of several of those
governance proposals. They are why “adopt the network” is available as a
proposal at all.

What “everything” means: the adoption scope

Seven workstreams. The first four are engineering (three of them already
built); the last three are what makes this an adoption rather than a
contract deployment.

W1 — The registry (BUILT). RegenEcocreditRegistry: a Solidity port of
x/ecocredit core. Credit types, classes (admin + approved issuers +
metadata IRI), projects, batches with on-chain denom generation in regen-1’s
exact format (a test asserts a generated denom against the live mainnet
string C01-001-20150101-20151231-001), per-account tradable/retired
balances, send including send-with-retirement, retire with beneficiary,
jurisdiction, and reason, cancel, and issuer ACLs. Retirement events emit so
certificate metadata survives.

W2 — The token and the claims (BUILT). RegenToken: fixed-supply
ERC-20, 6 decimals for uregen parity (and axlREGEN parity, so redemption
math is unit-identical), no owner, no mint, no pause, real
burn()/burnFrom() reducing totalSupply — a capability regen-1 itself
has never had. RegenMigrationClaims: immutably stamps the export merkle
root, the halt height, and "regen-1"; two leaf kinds (token, batch), one
claim per leaf, and two claim paths: a raw-digest path (90,024 gas) and an
ADR-36 path (164,608 gas) that reconstructs the Keplr sign-doc on-chain
from bound fields, so any Keplr holder claims with one popup and cannot
sign one thing while claiming another.

W3 — Marketplace and baskets (BUILT). Sell orders, buy-side fills with
escrow conservation across partial fills, cancellation and lazy permissionless
expiry (BeginBlock does not exist on an EVM; the port handles that), fee
mechanics matching regen-1 v7.2.0 with a fee ceiling and a required
maxFeeAmount guard regen-1 lacks, and basket put/take with derived
exponents. The port fixed a live regen-1 economics bug in passing: cost
truncation toward zero makes sub-unit fills free on regen-1; the port uses
ceiling division, negative-tested. Live-verified against the production
basket eco.uC.NCT: 7 positions summing exactly to its 44,331,178,755 uNCT
supply, gap 0.

W4 — The data/attestation lane (SCOPED, NOT PORTED). regen-1’s x/data
module (content-hash anchoring and attestation) is deliberately not in v1.
It is a small, self-contained surface and is named here as post-launch work
so the v1 audit scope stays tight. Nothing in W1–W3 depends on it.

W5 — Community absorption. The part a contract cannot do:

  • Holders: 22,434 accounts claim through W2. Coverage, measured not
    asserted: 49.17% of supply is directly key-claimable (22,423 accounts),
    43.34% (75 accounts — module accounts, the Axelar escrow, multisigs,
    vesting) routes through a governed arbiter role that is capped,
    timelocked, and succession-managed, and 7.50% (unwithdrawn staking
    rewards in the distribution module) is handled by the halt-height handler
    with a timelocked, bounded fallback sweep. Publishing these three numbers
    is itself part of the offer: holders should know their path before
    anyone votes.
  • Issuers and class admins: issuer ACLs migrate with their classes; a
    cosmos-keyproof handover path for class admins is a named open item.
  • Validators and delegators: adoption ends the validator role; that is
    the point, and the interim PoA proposal (#73) is honest about the
    direction. Delegators’ balances (including unwithdrawn rewards, see
    above) are in the export.
  • Governance: REGEN holders continue to govern registry-level decisions
    on Arbitrum (one wallet, one vote); Arbitrum DAO governs nothing inside
    the registry and is not asked to.
  • The source chain: regen-1 halts at export height +1 via a compiled
    upgrade handler (the +1 matters: a CometBFT AppHash attests the previous
    block, so state at height H is only signed by H+1’s header), and a funded
    archive node preserves full history for at least 12 months.

W6 — Operations. Deploy, seed (~285 transactions, under $50), verify all
sources on Arbiscan, publish the snapshot JSON + SHA-256 + root for
independent reproduction, run a 2-week public verification window before
claims open, then 12 months of archive hosting and claim support.

W7 — Ecosystem integration. The registry arrives with consumers, not
just state. A live agent-native toolchain already exists against Regen data
(MCP tools for governance, retirement tracking, and address lookup), and a
live labor protocol (EWP, deployed on Base and Robinhood mainnet) settles
verified ecological work — meaning Arbitrum-native treasuries, protocols,
and AI agents can go from “hold funds” to “funded verified regeneration”
with contract calls end to end. W7’s deliverable is documentation and
reference integrations, contributed like all other software here at $0.

Verify it yourself

Most funding requests ask you to believe a roadmap. This one asks you to run
four commands (public repository, no network access needed beyond a public
archive node):

Claim Check
The contracts exist and compile npx tsx scripts/regen/compile-regen-migration.ts — solc 0.8.20, viaIR, zero warnings
They work npx vitest run tests/contracts/regen-migration.test.ts — 32/32 on a local anvil
The export is real npx tsx scripts/regen/export-regen-state.ts — read-only against live regen-1
The export is deterministic re-run at a pinned height and watch the identical root come out

The reconciliation from the full live run at height 28,401,966:

chain total supply (bank)                 239,412,675.406252 REGEN
Σ bank balances (22,434 holders)          239,412,675.406252 REGEN
bank coverage gap (0 == complete)                          0 REGEN
batch leaves: 765 across 80 batches; per-batch tallies    80 ok / 0 mismatched
MERKLE ROOT: 0x6d307a91966152256c49093937a8c4a18fdf3410a06d625449caa18f1383bfad
             (23,263 unique leaves; identical on cold re-run)

The package has also already survived its own adversarial review: a
red-team pass over the contracts and exporter found 3 critical and 6
high-severity defects (a seal-bypass on the migrator role, the 7.5%
distribution-module residue with no claim path, an ungoverned arbiter EOA),
and the criticals plus four highs are fixed with regression tests
before any external auditor sees the code. The review, dispositions, and
remaining design items are published alongside the code. We are showing you
the audit trail of our own mistakes on purpose: the verification story is
the whole pitch.

Consent architecture: two chains, two votes, in the right order

This post binds nobody. The sequence:

  1. Arbitrum temperature check (this post → Snapshot). A signal: “if
    Regen’s governance votes to migrate, Arbitrum DAO welcomes the network
    and will fund independent verification.” No funds move.
  2. Regen signaling vote. Regen’s community votes on migration with a
    concrete adoption offer on the table instead of a hypothetical. This
    ordering is deliberate: Regen’s current governance reality (unanimous-yes
    proposals dying of turnout apathy) means an abstract migration question
    would starve like everything else, while a standing offer from the
    largest L2 DAO is the kind of fact that produces turnout. If Regen
    declines, this proposal ends and both chains continue unchanged. The
    Regen-side RFC is already live on the community forum we host:
    Regen forum (thread: “RFC: Retire the consensus
    bill, keep the mission”; machine-readable feed at
    https://vealth.net/regen/forum/feed).
  3. Audits fund and run (Arbitrum Security Program lane or this AIP’s
    budget) only after both signals exist.
  4. Sepolia rehearsal with a published root that third parties reproduce,
    real Keplr spot-claims by community volunteers, then the binding Regen
    halt vote, then mainnet launch on Arbitrum One.

No Arbitrum money moves before verification exists; no Regen state moves
before Regen votes. Either DAO can stop the process at every step.

Milestones and cost

Every line of software in this package is contributed at $0 — built,
tested, and published before this post, produced with AI at subscription
cost. This proposal deliberately puts no fiat price on development work.
What cannot be produced that way, and what the budget below buys, is
independent verification: audit firms whose value is precisely that they
are not us.

# Deliverable Evidence that closes it Ask
M0 Contracts, exporter, shared codec, tests, reconciled live export, migration plan Already public and reproducible $0 — contributed
M1 Regen RFC + Arbitrum Sepolia rehearsal: pinned-height export, deploy, seed, community spot-claims Sepolia addresses; rehearsal root reproduced by ≥1 third party $0 — contributed
M2 ADR-36 Keplr claim path Built and merged; a real Keplr signature claiming on Sepolia $0 — contributed
M3 Contract audit, firm 1 (Arbitrum-approved list): supply/balance invariants, claim latching, merkle verification Published report $30,000 → $45,000
M4 Contract audit, firm 2, independent: Cosmos address/key derivation and the ADR-36 wrapper Published report $20,000 → $40,000
M5 Export-pipeline audit + clean-room root re-derivation (~200-line independent reimplementation must reproduce the production root) Report + matching root from code sharing no lines with ours $10,000 → $20,000
M6 Remediation + re-review Firms’ sign-off $3,500 → $3,750
M7 Arbitrum One launch: deploy, seed, seal, verify, 2-week public verification window, 12 months archive hosting + claim support Arbiscan-verified addresses; published snapshot + root independently reproduced $1,500 → $1,250
Total $65,000 → $110,000 — ~98% of it independent audit firms

Calendar time is roughly 5–7 months, nearly all of it audit-firm scheduling
and the two consent windows, not development. Gas is a rounding error
(~285 seeding transactions, under $50) and is not requested. Regen-side
governance deposits are a Regen-side cost and are not requested. For
calibration, Arbitrum’s own audit program reported an average audit cost of
$46,363 across its first 14 engagements; two firms plus a pipeline audit on
an unusually small attack surface (no proxies, no upgradeability, no
oracles, no external dependencies, no economic mechanism — supply
arithmetic, claim latching, and signature derivation) lands inside this
band.

What this is not

  • Not a token listing or liquidity request. No ARB is requested for
    incentives, market-making, or liquidity. The REGEN supply migrates 1:1;
    nobody’s share is diluted, and this proposal’s authors take no allocation
    from it.
  • Not a request for Arbitrum to govern Regen. Registry governance stays
    with REGEN holders. Arbitrum DAO’s role is host and verifier-funder.
  • Not an Orbit chain. A dedicated chain would reintroduce exactly the
    consensus cost this migration exists to delete. The registry belongs on
    Arbitrum One, where the users and the revenue are.
  • Not conditional on believing us. Every load-bearing number above is
    either cited to a public endpoint or reproducible by running the
    published code at a pinned height.

Disclosure

The author is not new to Arbitrum: a GMX user and builder since its early
days (including live, non-custodial GMX v2 trading tools published this
year), with labor-settlement contracts deployed on Base and on an
Arbitrum-lineage L2 — the Ecological Work Protocol, whose premise is the
same one under this proposal: laborers get paid for real, verifiable work,
and the receipt of the work is the value.

This post’s author operates the Regen governance address
regen1jfheyvsah5wqfyawmedme43te056z8gzdnpf3j, authored Regen proposals
#64, #66, #67, #70#73 (and got #64’s bonded-ratio arithmetic publicly
wrong), holds no staked REGEN, and holds REGEN primarily as recycled
governance deposits. The engineering package was built by EcoWealth. If any
milestone in this proposal is later compensated, the terms will be published
in writing before funds move, and the author will disclose and abstain from
any vote, on either chain, that sets their own compensation. The intended
ongoing role, if the community wants it, is verification and attestation —
the same reconciliation artifacts shown above, produced on a cadence —
not custody, not treasury operation, not registry governance.

Open questions for delegates

  1. Would the DAO prefer the audit envelope through the Arbitrum Security
    Program lane (applications ~Oct 1) with this AIP as the adoption signal
    only, or the full envelope in this AIP?
  2. Does the DAO want the absorption playbook (exporter, codec, halt
    handler, claim design) packaged as a maintained public good for future
    appchain adoptions, and if so, under what stewardship?
  3. Appetite for W7 growth work (retirement integrations for Arbitrum-native
    protocols, agent tooling) as a follow-on, DAO-sized and DAO-decided?

Every claim in this post is either linked or reproducible from the
published repository at a pinned height. Full plain-language walkthrough:
Regen on Ethereum: the migration, open to check