Mode: PROOF. MOCK is not money. live=e001
PROOF runs monero-wallet-cli check_tx_proof against the invoice address and amount.
Without the binary it refuses. It does not fake success.
# Caveat emptor This is a learning register for a small editioned walk. It is not a payment-processor audit, not a wallet, and not a claim that the operator is hard to school. If you are the kind of buyer who red-teams the cash register, do that. The work invited you. File issues against the protocol, not against the myth that a first public till is finished. ## What this instance claims - The zip on disk was hashed before any unlock. - Unlock is supposed to require a Monero transaction proof for a published address and amount. - A used proof is not supposed to release a second copy. - `STATUS=SOLD` closes POST unlock (410). GET still shows the public hashes. - Ghost is only a link. It does not hold the zip, the container, or the passphrase. - The sealed container is fetchable by hash. The passphrase is not on this VPS, not on Ghost, and not in object storage. ## What this instance does not claim - Anonymity of the operator or of the VPS provider. - That TLS on a rented box equals a sealed device. - That a missing verifier still “counts as verified.” Without the binary, unlock **refuses**. It does not fake success. - That a view key or spend key belongs on this host. They do no
meta.json · full caveat · live