CommitmentVault V1 Compensation (CV-01)
Incident record and urgent Council proposal for the IFR that price-conditioned CommitmentVault V1 tranches can never release.
Status: urgent Council vote open, no deadline. Not approved. This page records a proposal. It does not authorize anything: no IFR is paid out before the Council approves, and every payout also needs its own executed Safe transaction. Signatures received so far are listed under Vote; results are recorded in the Council Agenda & Vote Log.
What Happened
The deployed CommitmentVault V1 (0x0719…73d3) accepts four lock types:
TIME_ONLYPRICE_ONLYTIME_OR_PRICETIME_AND_PRICE
Its price check is a placeholder that always reads a price of zero:
- The deployed bytecode contains no oracle call.
- Setting
priceOraclethrough Governance cannot change that.
As a result:
PRICE_ONLYandTIME_AND_PRICEtranches can never be unlocked.TIME_OR_PRICEtranches unlock normally after their time condition.TIME_ONLYtranches unlock normally after their time condition.
The repository source has rejected price-conditioned locks for future deployments since September 2026. The deployed V1 predates that guard.
A Mainnet-fork simulation confirmed the result on 2 October 2026:
- Governance set an oracle reporting the highest possible price, and time was advanced by ten years.
- All
PRICE_ONLYandTIME_AND_PRICEtranches still reportedconditionMet = false.
Timeline
Verified dates only, from on-chain events and the public repository. The purpose of individual locks is not recorded and is not inferred here.
- 4 April 2026: CommitmentVault V1 is deployed with the placeholder price check.
- June 2026: P0 is set on-chain to 300,000,000 wei per IFR (Governance proposal #16).
- 28 June 2026, 21:32–21:37 UTC: wallet C2 creates ten
TIME_ONLYtranches (blocks 25,418,863–25,418,886). - 29 June 2026, 06:59 UTC: the website publishes a self-service lock form that offers all four lock types, including price targets.
- 29 June 2026, 07:33 UTC: wallet C1 creates tranche #0,
TIME_AND_PRICE(block 25,421,853). - 29 June 2026, 22:38–22:42 UTC: wallet C3 creates tranches #0–#9,
PRICE_ONLY(blocks 25,426,358–25,426,377). At 22:56 UTC, C1 creates tranche #1,TIME_OR_PRICE(block 25,426,451). - 14 September 2026: the community audit (finding CWA-03) reports that the deployed price check always reads zero, so price-conditioned tranches cannot unlock. It checked C2's tranches, which are all time-based, and did not identify the price-conditioned tranches of C1 and C3.
- 28 September 2026: the repository source starts rejecting price-conditioned locks for future deployments.
- 2 October 2026: an on-chain review of every tranche identifies and quantifies the eleven affected tranches, and a Mainnet-fork simulation confirms that they can never unlock. CV-01 is opened the same day.
V1 has no rescue function and is not upgradeable. The IFR token cannot move another address's balance. Nobody can recover these tokens.
Impact Permanent
26,418,467.994338353 IFR are permanently locked in CommitmentVault V1. This is about 2.65 % of the current total supply. On 2 October 2026 the vault held 47,952,476.871794375 IFR; C2 then withdrew its ten unlocked time tranches (20,156,940.952845656 IFR). At block 26,113,577 (3 October 2026, 18:22:23 UTC) the vault held 27,795,535.918948719 IFR, of which 1,377,067.924610366 IFR are in time-based tranches that unlock normally.
Affected Tranches and Compensation Status
Each row is one locked tranche. You can verify every row with getTranches(wallet) on the vault.
Under CV-01, the compensation for a tranche would follow the conditions the tranche was locked with:
- its original unlock date, where there is one;
- its original price target,
P0 × multiplierwith P0 = 0.3 gwei per IFR.
The Conditions now column is calculated live from the current block and the IFR/WETH Uniswap V2 spot price. It is indicative only and never changes a status. A tranche turns green only when the Council has approved and a TWAP record for it has been published here: start and end blocks with their hashes, start and end times at least 7 days apart, the TWAP from the pair's cumulative prices, the reviewer, and a reproducible calculation (script, repository commit and evidence file). The record is reviewed by people; this page only checks that it is complete and consistent and does not recompute the TWAP itself.
| Wallet | Tranche | Lock type | Amount (IFR) | Original conditions | Conditions now | Status |
|---|---|---|---|---|---|---|
| Total permanently locked | 26,418,467.994338353 | |||||
Loading live conditions…
Proposal CV-01 (urgent vote)
| Scope | The 11 tranches above, 26,418,467.994338353 IFR in total. Time-based tranches are not affected. |
|---|---|
| Payout pool | LP Reserve Safe 0x5D93…6C04 (3-of-5, holds 400,600,000 IFR). |
| Amount | Each tranche is compensated with exactly its locked amount, credited to the wallet that locked it. The LP Reserve Safe is not fee-exempt, so the transfer is grossed up for the transfer fee. That way the wallet receives the full tranche amount; the worst case is about 27.38 M IFR gross. |
| Time condition | Block timestamp at or after the tranche's original unlock date. This applies only to TIME_AND_PRICE. |
| Price condition | The 7-day time-weighted average price of IFR/WETH from the Uniswap V2 pair 0xbE49…31A0 must be at or above the tranche's target. It is calculated from the pair's cumulative prices; the start and end block numbers are published with each payout. A single spot price never counts. |
| Execution | One Safe transaction per tranche, once its conditions are verified. Its status turns green here before the transaction is proposed, and the transaction hash is added to the vote log. |
| If rejected | No compensation is paid. The tranches stay recorded as permanently locked. |
Vote
The Council vote is held by the Safe signers. Each signer signs the published vote text with their Safe owner wallet on Etherscan; anyone can verify each signature. The signed text refers to this proposal at repository commit f08ce370.
- Council: five members, M.G., A.M., Y.K., A.P. and G.M. G.M. abstains from this vote.
- Eligible: the other four, M.G., A.M., Y.K. and A.P.
- Required: 3 YES votes. Until then the proposal is not approved.
- Deadline: none. A deadline can only be set by a separate Council vote.
- Status: vote open, 2 of 3 required YES votes received. Not approved.
| Signer | Wallet | Vote | Signature |
|---|---|---|---|
| M.G. | 0x17F8…72d4 | YES | verifySig/339696 |
| Y.K. | 0xA086…b275 | YES | verifySig/339697 |
| G.M. | 0x6b36…Fed67 | Abstain | Recorded |
| A.M. | 0x0c48…ED74 | Not yet signed | — |
| A.P. | 0x32cF…0fE9 | Not yet signed | — |
Supply Accounting
The 26,418,467.994338353 IFR stay in the total supply, because they were never burned. They are recorded as permanently locked and counted as non-circulating. Any compensation paid later moves IFR from the LP Reserve Safe to the affected wallets and is recorded in the vote log.
Repair
- V1 cannot be changed. It has no pause or upgrade path.
- The wiki lock form offers only time-based locks.
- The production Web3 app at web3.ifrunit.tech still offers price-conditioned V1 locks. The code fix that restricts it to time-based locks is merged but not yet deployed or verified. Do not create new CommitmentVault locks in the Web3 app until that release is verified.
- CommitmentVault V2 is deployed:
0x8efa…7c8F, deployed on 2 October 2026 (transaction), owned by Governance.- It accepts
TIME_ONLYlocks only and rejects every price-conditioned lock, so an impossible condition cannot be created again. - It has no price oracle and no rescue path.
- It accepts
- V2 is not wired yet. Governance proposal #17,
setFeeExempt(V2, true), is queued and can be executed from 4 October 2026, 21:53:11 UTC. Until it is executed, V2 is not fee-exempt and the interfaces keep using V1. - Price-conditioned locks need a separate proposal. A reviewed, manipulation-resistant oracle and a rescue path for conditions that can never be met are future work. Neither is part of the deployed V2.
See the decision register (lane 2).