The downloaded bundle is self-verifying. Three independent checks
establish that the position file shown above is what the operator
committed on chain — none of them require trusting Frame.
1. Cryptographic check — offline, ~30s, Go stdlib only
Recomputes every leaf hash from leaf_data, walks each
inclusion proof to the root, and cross-checks the cover invariant
against the balances. Exit codes:
0 OK · 3 leaf failed crypto · 4 invariant mismatch.
Source: cmd/reserve-verify/main.go.
2. On-chain check — one cast call
Returns (true, anchorId) if the position root above is
recorded by ReserveAnchor.sol on chain. The contract
address is the to field of the anchor transaction
(click the tx hash above to open it on the chain explorer) and
also appears in your operator's deploy notes.
This attestation was anchored on the stub chain — a
demo path that emits a deterministic synthetic tx hash without
touching a real chain. On-chain verification does not apply.
Switch the portal to the live anchor (set the
RESERVE_ANCHOR_LINEA_* env triplet) to produce a
chain-checkable attestation.
3. Trust-no-one check — rebuild the verifier in any language
The bundle's verifier_recipe block is sufficient to
re-implement this verifier in ~60 lines of Python (stdlib
hashlib + json) — no Go, no Frame
tooling. If your independent implementation produces the same
verdict, our verifier has no hidden cleverness.
leaf_canonical_form: {"ledger":<int>,"reserve_balance":<int64>,"omnibus_balance":<int64>,"delta":<int64>,"invariant_holds":<bool>}
hash_function: SHA-256
tree_scheme: binary Merkle tree; nodes = SHA-256(left||right);
odd-length layers duplicate the last node as its own right sibling