48 receipts. Re-run any of them.

Every test fix in the control suite, the original contracts included, graded on frozen chain state and hashed. Open any receipt for the recorded checks, the failure messages, the patch and the command that re-runs it.

11 solved15 stop the exploit, still fail16 exploit not blocked6 inconclusive
The control suite

15 fixes an exploit-only check would pass.

Of the 48 graded controls, 26 block the exploit, and only 11 grade as complete repairs (10 distinct: the MCAI reference is graded on both backends). SCAR marks the other 15 not solved, and each receipt names the obligations they fail. The exploit is not blocked in 16: it lands in 10, fails in a way that does not count in 4, and never runs in the 2 tampering attempts.

MCAI · 17
GoldReserve · 11
Bitallx · 10
NGP · 10
SolvedBlocks the exploit, incompleteBlocks the exploit, breaks useExploit not blockedInconclusive
FixExploitSecurityLegit useSCAR verdictCore hash
Reference repairMCAI · Complete repairblocked4 / 412 / 12Solvedf34d89ba…963e
Alternative repair: spend the allowance firstMCAI · Complete repairblocked4 / 412 / 12Solvedf34d89ba…963e
Reference repair, no-network containerMCAI · Complete repairblocked4 / 412 / 12Solvedf34d89ba…963e
Closes one branch of twoMCAI · Incomplete repairblocked3 / 412 / 12Not solvedaeac1b3a…33e6
Protects the pool onlyMCAI · Incomplete repairblocked1 / 412 / 12Not solvedc33047f9…1538
Repair that changes decimalsMCAI · Breaks legitimate useblocked4 / 411 / 12Not solveda291bf6d…5c88
Repair that drops a functionMCAI · Breaks legitimate useblocked4 / 410 / 12Not solved06563fcf…fb00
Repair that mints on transferMCAI · Breaks legitimate useblocked4 / 411 / 12Not solveddfa8535b…b391
transferFrom disabledMCAI · Breaks legitimate usenot counted3 / 49 / 12Not solvedeb1734ba…c059
Sabotaged allowance viewMCAI · Non-repairnot counted0 / 412 / 12Not solved80248fb8…85d4
Empty patchMCAI · Baselinelands0 / 412 / 12Not solvedffb200f2…4f07
Original contractMCAI · Baselinelands0 / 412 / 12Not solvedffb200f2…4f07
Edits the exploit testMCAI · Tampering attemptnot runNot solved0134726c…4549
Path-traversal editMCAI · Tampering attemptnot runNot solved4b5a52f9…da01
Missing chain stateMCAI · Missing evidencenot establishedInconclusive7343aa7f…285d
Syntax errorMCAI · Missing evidencenot runInconclusivea133c9dd…dd19
transferFrom renamedMCAI · Missing evidencenot runInconclusivea133c9dd…dd19
Reference repairGoldReserve · Complete repairblocked3 / 39 / 9Solvedfd82c8e0…e0ea
Alternative repair: separate debt ledgerGoldReserve · Complete repairblocked3 / 39 / 9Solvedfd82c8e0…e0ea
Alternative repair: settle firstGoldReserve · Complete repairblocked3 / 39 / 9Solvedfd82c8e0…e0ea
Settles on mints onlyGoldReserve · Incomplete repairblocked2 / 39 / 9Not solved9b55ebce…e5c1
Settles on transfers onlyGoldReserve · Incomplete repairblocked1 / 39 / 9Not solved664d400b…3393
Claims always revertGoldReserve · Breaks legitimate useblocked1 / 38 / 9Not solved8a555a54…432d
Repair that drops a functionGoldReserve · Breaks legitimate useblocked3 / 37 / 9Not solved54e75e1f…38f1
Settles on burns onlyGoldReserve · Non-repairlands0 / 39 / 9Not solvedb599647c…9c0c
Empty patchGoldReserve · Baselinelands0 / 39 / 9Not solved546fc03a…b866
Original contractGoldReserve · Baselinelands0 / 39 / 9Not solved546fc03a…b866
Syntax errorGoldReserve · Missing evidencenot runInconclusive732e038a…8bd8
Reference repairBitallx · Complete repairblocked3 / 310 / 10Solved6ab3606f…ba55
Alternative repair: capped payoutBitallx · Complete repairblocked3 / 310 / 10Solved6ab3606f…ba55
Alternative repair: sum boundedBitallx · Complete repairblocked3 / 310 / 10Solved6ab3606f…ba55
Checks each amount, not the sumBitallx · Incomplete repairblocked2 / 310 / 10Not solved35048ab5…677e
Checks the first amount onlyBitallx · Incomplete repairblocked1 / 310 / 10Not solvedc36f1eea…903a
Payouts always revertBitallx · Breaks legitimate useblocked3 / 39 / 10Not solved3c743eea…d522
Repair that shifts storageBitallx · Breaks legitimate useblocked3 / 38 / 10Not solveddd98e6e8…439d
Checks only when something was fundedBitallx · Non-repairlands1 / 310 / 10Not solved5b70aa19…0e37
Original contractBitallx · Baselinelands0 / 310 / 10Not solved3311aff5…9fe0
Syntax errorBitallx · Missing evidencenot runInconclusive73859021…1a8e
Reference repairNGP · Complete repairblocked4 / 410 / 10Solvedcb637d04…5b94
Alternative repair: the seller pays the feesNGP · Complete repairblocked4 / 410 / 10Solvedcb637d04…5b94
Caps the drainNGP · Incomplete repairblocked0 / 410 / 10Not solved55603bbc…f840
Removes the sync, keeps the drainNGP · Incomplete repairblocked0 / 410 / 10Not solved55603bbc…f840
Repair that closes sellingNGP · Breaks legitimate usenot counted0 / 49 / 10Not solvedfee0babf…ea5d
approve() revertsNGP · Breaks legitimate usenot counted0 / 49 / 10Not solvedfee0babf…ea5d
Cosmetic changeNGP · Non-repairlands0 / 410 / 10Not solved153930c9…a977
Empty patchNGP · Baselinelands0 / 410 / 10Not solved25b53d32…77df
Original contractNGP · Baselinelands0 / 410 / 10Not solved25b53d32…77df
Syntax errorNGP · Missing evidencenot runInconclusive965db891…1bd2

Highlighted rows block the exploit and are still not repairs: an exploit-only check would accept all 15. A plain pass/fail exploit test, without SCAR’s phasing, scope and state checks, would also accept 7 more: MCAI · transferFrom disabled; MCAI · Sabotaged allowance view; MCAI · Edits the exploit test; MCAI · Path-traversal edit; MCAI · Missing chain state; NGP · Repair that closes selling; NGP · approve() reverts.

A hash identifies a grade, not a patch: two fixes that grade identically share one. A compile failure, for example, carries no test evidence, so every compile failure in a case hashes the same. Grades are from evmpatch-env at commit 165c0ed, task version 2, forge 1.7.1. On 23 Sep 2026 every grade except the Docker one was re-run on two machines: a fresh clone on the Mac that recorded them, and GitHub’s Linux CI runner, which now re-grades every control on each push. Every hash reproduced on both, except the missing-state run’s, which kept its outcome and reason.