unlock e001

Mode: PROOF. MOCK is not money. live=e001

amount 5.000000000000 XMR
address REPLACE_WITH_RECEIVE_ADDRESS
zip sha256 75fe7f4783d84360454907f095bb6d6c733510ea27d11bdd00958461d20b0d7c
root bd750ee9c62e21822ac648056d2c166d5670818125e490d39d9c0c918d5fc32b
fingerprint f432de2f6bd6e1cd2e635401e41552077dc465f591bab296c618c99f840a7925

PROOF runs monero-wallet-cli check_tx_proof against the invoice address and amount. Without the binary it refuses. It does not fake success.

caveat emptor

# Caveat emptor

This is a learning register for a small editioned walk. It is not a payment-processor audit, not a wallet, and not a claim that the operator is hard to school.

If you are the kind of buyer who red-teams the cash register, do that. The work invited you. File issues against the protocol, not against the myth that a first public till is finished.

## What this instance claims
- The zip on disk was hashed before any unlock.
- Unlock is supposed to require a Monero transaction proof for a published address and amount.
- A used proof is not supposed to release a second copy.
- `STATUS=SOLD` closes POST unlock (410). GET still shows the public hashes.
- Ghost is only a link. It does not hold the zip, the container, or the passphrase.
- The sealed container is fetchable by hash. The passphrase is not on this VPS, not on Ghost, and not in object storage.

## What this instance does not claim
- Anonymity of the operator or of the VPS provider.
- That TLS on a rented box equals a sealed device.
- That a missing verifier still “counts as verified.” Without the binary, unlock **refuses**. It does not fake success.
- That a view key or spend key belongs on this host. They do no

meta.json · full caveat · live