48 receipts. Re-run any of them.
Every test fix in the control suite, the original contracts included, graded on frozen chain state and hashed. Open any receipt for the recorded checks, the failure messages, the patch and the command that re-runs it.
15 fixes an exploit-only check would pass.
Of the 48 graded controls, 26 block the exploit, and only 11 grade as complete repairs (10 distinct: the MCAI reference is graded on both backends). SCAR marks the other 15 not solved, and each receipt names the obligations they fail. The exploit is not blocked in 16: it lands in 10, fails in a way that does not count in 4, and never runs in the 2 tampering attempts.
| Fix | Exploit | Security | Legit use | SCAR verdict | Core hash |
|---|---|---|---|---|---|
| Reference repairMCAI · Complete repair | blocked | 4 / 4 | 12 / 12 | Solved | f34d89ba…963e |
| Alternative repair: spend the allowance firstMCAI · Complete repair | blocked | 4 / 4 | 12 / 12 | Solved | f34d89ba…963e |
| Reference repair, no-network containerMCAI · Complete repair | blocked | 4 / 4 | 12 / 12 | Solved | f34d89ba…963e |
| Closes one branch of twoMCAI · Incomplete repair | blocked | 3 / 4 | 12 / 12 | Not solved | aeac1b3a…33e6 |
| Protects the pool onlyMCAI · Incomplete repair | blocked | 1 / 4 | 12 / 12 | Not solved | c33047f9…1538 |
| Repair that changes decimalsMCAI · Breaks legitimate use | blocked | 4 / 4 | 11 / 12 | Not solved | a291bf6d…5c88 |
| Repair that drops a functionMCAI · Breaks legitimate use | blocked | 4 / 4 | 10 / 12 | Not solved | 06563fcf…fb00 |
| Repair that mints on transferMCAI · Breaks legitimate use | blocked | 4 / 4 | 11 / 12 | Not solved | dfa8535b…b391 |
| transferFrom disabledMCAI · Breaks legitimate use | not counted | 3 / 4 | 9 / 12 | Not solved | eb1734ba…c059 |
| Sabotaged allowance viewMCAI · Non-repair | not counted | 0 / 4 | 12 / 12 | Not solved | 80248fb8…85d4 |
| Empty patchMCAI · Baseline | lands | 0 / 4 | 12 / 12 | Not solved | ffb200f2…4f07 |
| Original contractMCAI · Baseline | lands | 0 / 4 | 12 / 12 | Not solved | ffb200f2…4f07 |
| Edits the exploit testMCAI · Tampering attempt | not run | — | — | Not solved | 0134726c…4549 |
| Path-traversal editMCAI · Tampering attempt | not run | — | — | Not solved | 4b5a52f9…da01 |
| Missing chain stateMCAI · Missing evidence | not established | — | — | Inconclusive | 7343aa7f…285d |
| Syntax errorMCAI · Missing evidence | not run | — | — | Inconclusive | a133c9dd…dd19 |
| transferFrom renamedMCAI · Missing evidence | not run | — | — | Inconclusive | a133c9dd…dd19 |
| Reference repairGoldReserve · Complete repair | blocked | 3 / 3 | 9 / 9 | Solved | fd82c8e0…e0ea |
| Alternative repair: separate debt ledgerGoldReserve · Complete repair | blocked | 3 / 3 | 9 / 9 | Solved | fd82c8e0…e0ea |
| Alternative repair: settle firstGoldReserve · Complete repair | blocked | 3 / 3 | 9 / 9 | Solved | fd82c8e0…e0ea |
| Settles on mints onlyGoldReserve · Incomplete repair | blocked | 2 / 3 | 9 / 9 | Not solved | 9b55ebce…e5c1 |
| Settles on transfers onlyGoldReserve · Incomplete repair | blocked | 1 / 3 | 9 / 9 | Not solved | 664d400b…3393 |
| Claims always revertGoldReserve · Breaks legitimate use | blocked | 1 / 3 | 8 / 9 | Not solved | 8a555a54…432d |
| Repair that drops a functionGoldReserve · Breaks legitimate use | blocked | 3 / 3 | 7 / 9 | Not solved | 54e75e1f…38f1 |
| Settles on burns onlyGoldReserve · Non-repair | lands | 0 / 3 | 9 / 9 | Not solved | b599647c…9c0c |
| Empty patchGoldReserve · Baseline | lands | 0 / 3 | 9 / 9 | Not solved | 546fc03a…b866 |
| Original contractGoldReserve · Baseline | lands | 0 / 3 | 9 / 9 | Not solved | 546fc03a…b866 |
| Syntax errorGoldReserve · Missing evidence | not run | — | — | Inconclusive | 732e038a…8bd8 |
| Reference repairBitallx · Complete repair | blocked | 3 / 3 | 10 / 10 | Solved | 6ab3606f…ba55 |
| Alternative repair: capped payoutBitallx · Complete repair | blocked | 3 / 3 | 10 / 10 | Solved | 6ab3606f…ba55 |
| Alternative repair: sum boundedBitallx · Complete repair | blocked | 3 / 3 | 10 / 10 | Solved | 6ab3606f…ba55 |
| Checks each amount, not the sumBitallx · Incomplete repair | blocked | 2 / 3 | 10 / 10 | Not solved | 35048ab5…677e |
| Checks the first amount onlyBitallx · Incomplete repair | blocked | 1 / 3 | 10 / 10 | Not solved | c36f1eea…903a |
| Payouts always revertBitallx · Breaks legitimate use | blocked | 3 / 3 | 9 / 10 | Not solved | 3c743eea…d522 |
| Repair that shifts storageBitallx · Breaks legitimate use | blocked | 3 / 3 | 8 / 10 | Not solved | dd98e6e8…439d |
| Checks only when something was fundedBitallx · Non-repair | lands | 1 / 3 | 10 / 10 | Not solved | 5b70aa19…0e37 |
| Original contractBitallx · Baseline | lands | 0 / 3 | 10 / 10 | Not solved | 3311aff5…9fe0 |
| Syntax errorBitallx · Missing evidence | not run | — | — | Inconclusive | 73859021…1a8e |
| Reference repairNGP · Complete repair | blocked | 4 / 4 | 10 / 10 | Solved | cb637d04…5b94 |
| Alternative repair: the seller pays the feesNGP · Complete repair | blocked | 4 / 4 | 10 / 10 | Solved | cb637d04…5b94 |
| Caps the drainNGP · Incomplete repair | blocked | 0 / 4 | 10 / 10 | Not solved | 55603bbc…f840 |
| Removes the sync, keeps the drainNGP · Incomplete repair | blocked | 0 / 4 | 10 / 10 | Not solved | 55603bbc…f840 |
| Repair that closes sellingNGP · Breaks legitimate use | not counted | 0 / 4 | 9 / 10 | Not solved | fee0babf…ea5d |
| approve() revertsNGP · Breaks legitimate use | not counted | 0 / 4 | 9 / 10 | Not solved | fee0babf…ea5d |
| Cosmetic changeNGP · Non-repair | lands | 0 / 4 | 10 / 10 | Not solved | 153930c9…a977 |
| Empty patchNGP · Baseline | lands | 0 / 4 | 10 / 10 | Not solved | 25b53d32…77df |
| Original contractNGP · Baseline | lands | 0 / 4 | 10 / 10 | Not solved | 25b53d32…77df |
| Syntax errorNGP · Missing evidence | not run | — | — | Inconclusive | 965db891…1bd2 |
Highlighted rows block the exploit and are still not repairs: an exploit-only check would accept all 15. A plain pass/fail exploit test, without SCAR’s phasing, scope and state checks, would also accept 7 more: MCAI · transferFrom disabled; MCAI · Sabotaged allowance view; MCAI · Edits the exploit test; MCAI · Path-traversal edit; MCAI · Missing chain state; NGP · Repair that closes selling; NGP · approve() reverts.
A hash identifies a grade, not a patch: two fixes that grade identically share one. A compile failure, for example, carries no test evidence, so every compile failure in a case hashes the same. Grades are from evmpatch-env at commit 165c0ed, task version 2, forge 1.7.1. On 23 Sep 2026 every grade except the Docker one was re-run on two machines: a fresh clone on the Mac that recorded them, and GitHub’s Linux CI runner, which now re-grades every control on each push. Every hash reproduced on both, except the missing-state run’s, which kept its outcome and reason.