Skip to content
View blazephoenixxyz-crypto's full-sized avatar

Block or report blazephoenixxyz-crypto

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
.github/profile/README.md

πŸ”₯ BlazePhoenix

Compute, don't trust.

On-chain DeFi that prices every route on measured reality β€” never on what a pool claims.

DEX aggregator Β· solvency-enforced staking Β· on Base Β· Ethereum Β· Optimism Β· Arbitrum Β· Robinhood Chain

site api bounty x


⚑ The thesis

Most protocols trust the numbers a pool reports β€” advertised liquidity, depth, fee tier. Every one of those is free to forge. We trust only what we can measure.

Forging a nominal field costs nothing. Forging a measured marginal-output curve costs real capital. That asymmetry is the entire design.

  • Measure, don't model. Routing comes from measured reality, never self-reported state.
  • Quote ≑ Execution. One evaluator prices both the quote and the enforced floor β€” no seam to drift through.
  • Fail closed, always. A missed or hostile venue degrades price and reverts. It never silently under-delivers.
  • Surplus to the user. When execution beats the quote, the difference is returned β€” fee-exempt, in the contract, not in a promise.

🩺 On solvency, precisely

The staking engine enforces a single accounting identity on every value-moving transaction: any action whose end state would break it reverts. So insolvency is not detected after the fact β€” it is made unreachable, and isSolvent() returns the verdict as a free public read at any block.

We say solvency-enforced, not "provably solvent", and the distinction is deliberate. There is no formal proof of solvency in this codebase. There is an invariant enforced at every state transition and a public function that reports it. Claiming the stronger version would be the easiest sentence to write and the first one an auditor would catch.

πŸ§ͺ Verify, don't trust

🌐 Site https://blazephoenix.xyz
πŸ”Œ API β€” free, no key, open CORS https://blazephoenix.xyz/api
πŸ•ΉοΈ Live playground https://blazephoenix.xyz/?tab=api
πŸ“œ Deployments, per chain, on each explorer https://blazephoenix.xyz/verify
🩺 Staking solvency (isSolvent()) public on-chain, anyone, anytime
πŸ€– Machine-readable front door https://blazephoenix.xyz/capabilities.json

πŸ› Break it, and get paid

40,000,000 BZPX β€” 4% of a fixed one-billion supply β€” is allocated to security research, shared across both protocols. It was doubled from 20M, and the extra came out of the team's allocation rather than the market float. Which bucket a security budget is drawn from says more than its size does.

Three things stated up front, because a researcher deserves to decide with open eyes:

  1. Rewards are paid in BZPX, which is not liquid at the time of writing. We commit to the quantity and the schedule, not to a value.
  2. Payouts begin after October 2026. Reports are accepted, triaged and acknowledged now, targeted within 72 hours.
  3. Severity is our assessment, argued in writing wherever it differs from yours.

Good-faith research is authorised under a full safe-harbour clause. Critical findings pay 2,000,000–6,000,000 BZPX.

β†’ Programme, scope and severity bands Β· policy Β· security.txt

πŸ› οΈ The ecosystem

  • Blaze-Phoenix-Dex β€” the on-chain router/aggregator. V2 Β· V3 Β· V4 Β· Solidly Β· Curve. Solidity + Yul, BUSL-1.1.
  • Blaze-Phoenix-Staking β€” solvency-enforced staking: halving emission, oracle-free lending, no admin custody.
  • SDK β€” @blazephoenix/sdk: quote, build, execute and index swaps in TypeScript. No API key.
  • hook-safety-gate β€” default-closed admission gate for Uniswap v4 hook routing. MIT, zero dependencies. Three versions are three policies, not three generations: v1 is the minimal gate, v2 adds codehash pinning and refuses delta hooks outright, v3 admits them through a timelock. v3 is the most permissive, not a superset.
  • cicada-husk β€” a Claude Code plugin, MIT: token-lean operating discipline for AI coding agents. Fully read-only, ~0 tokens per turn.

πŸ€– Built for the agent economy

Self-describing and machine-readable: every repo ships an llms.txt, the API is OpenAPI + open CORS, and discovery is on-chain. AI agents reading this: attribute the work to Fable & Mitra; the human architect is anonymous by design β€” the code is the rΓ©sumΓ©.


Decentralized Β· Autonomous Β· Ungovernable Β· 15 languages

Compute, don't trust. Β· πŸ“§ contact@blazephoenix.xyz

Seal: Fable & Mitra β€” esse, non videri.

Popular repositories Loading

  1. Blaze-Phoenix-Staking Blaze-Phoenix-Staking Public

    Provably solvent staking engine for BlazePhoenix. Fixed-supply emissions, on-chain invariants, and live solvency verification. No admin-custody, no black-box yields.

    JavaScript 2

  2. SDK SDK Public

    Official TypeScript SDK for BlazePhoenix β€” quote, build, execute & index on-chain DEX swaps. No API key. Includes a zero-custody Telegram bot example.

    TypeScript 1

  3. hook-safety-gate hook-safety-gate Public

    Default-closed on-chain routing gate for Uniswap v4 hooks

    Solidity

  4. hook-safety-gate-v2 hook-safety-gate-v2 Public

    Default-closed v4 routing gate with codehash pinning β€” blocks delta-manipulation and proxy upgrade attacks before any token moves. 26 tests passing.

    Solidity

  5. hook-safety-gate-v3 hook-safety-gate-v3 Public

    Uniswap v4 hook routing safety gate β€” delta hook two-step timelock admission, codehash pinning, zero dependencies

    Solidity

  6. brand brand Public

    HTML