Skip to main content
KEY IS NOT ENOUGH · CONTROLLED SEPOLIA PROOF

KEY IS NOT ENOUGH

KINE protection is not magic attached to an ordinary wallet connection. The key-insufficient claim becomes true when assets or actions are routed through a governed execution path where policy can block, delay, pause, or constrain a signed action.

Proof boundary

Certified Sepolia evidence now proves the exact tested KineSmartAccountV2 valid-Owner policy-enforcement path. The public website can display that evidence, but it does not yet execute the controlled hostile validation flow from the user interface.

Ordinary wallet

Inspection only

Governed path

Policy can enforce

Current status

Local proof path

Public proof

Explorer bundle pending

Your current protection answer

Connect a wallet before KINE can inspect protection.

KINE separates inspection from protection. A connected wallet can be inspected, but real protection requires a governed execution path, an active policy, and evidence that the action routes through KINE.

Wallet mode

No wallet connected

Protection status

not connected

What this means for you

Am I protected?

Connect a wallet before KINE can inspect protection.

Nothing is currently being inspected or governed in this session.

What is protected?

Nothing is currently being inspected or governed in this session.

Current scope: unverified. Evidence status: missing.

Why am I protected or not protected?

No wallet/session evidence has been provided.

Protection state is unknown until canonical wallet or governed-scope evidence is available.

What happens if someone tries to steal or drain?

KINE cannot evaluate consequences until there is a wallet or action to inspect.

The strongest protection requires a governed execution path. Inspection-only mode can explain risk but should not be treated as enforcement.

What proof do I get?

KINE has no current-session evidence reference proving governed execution for this exact wallet scope yet.

Receipts, Session Intelligence, Audit, and technical proof packs should all point back to the same governed action and evidence lineage.

What is protected

Nothing is currently being inspected or governed in this session.

What is not protected

No protection claim is active.

Next action

Connect or inspect a wallet before evaluating protection state.

Canonical truth boundary

Unified KINE OS Alpha read model. Browser, SDK/API, imported on-chain, and simulated evidence remain provenance-separated.

How the mechanism works

1. The wallet key can request action

A connected wallet or owner key can still sign. KINE does not pretend that key compromise is impossible.

2. The governed path checks the action

The request must pass through a KINE-governed account, wrapper, or execution path before economic finality.

3. The constitution decides permission

Policy rules such as cap, delay, pause, and guardian override decide whether the signed action is allowed.

4. A valid key can still fail

If the action violates the constitution, the key is real but the action is not permitted.

Evidence found locally

Phase 4B proof receipt

Found locally

A sealed receipt exists for the Phase 4B guard extraction and wrapper proof run.

Hardhat proof log

Passed

The captured test output reports that guard enforcement covered cap, delay, pause, and the wrapper proof.

Policy hash binding

Found

The proof receipt records a deterministic policy hash and bytes32 policy binding.

Older staged drain receipts

Do not use as success proof

Some older drain receipts show PowerShell execution errors and pass=false. They must not be presented as successful protection evidence.

Still required for website-guided beta runner

  • Website-guided governed-account creation or selection.
  • Sepolia-only chain and safety checks for the public runner.
  • User-triggered controlled validation flow using test ETH only.
  • Runtime receipt generated directly from the website-guided flow.
  • Evidence, Session Intelligence, and Audit integration for website-run validation.

Canonical Sepolia evidence pack

Sepolia Key-Is-Not-Enough Governed Execution Proof Pack

Within the KINE-governed execution path, possession of the owner key alone is insufficient to execute constitution-violating actions because policy enforcement can deny, delay, queue, pause, or veto execution.

The website can explain and display certified proof evidence. It does not yet run the live hostile-drain transaction flow from the user interface.

Key Is Not Enough — Valid Owner did not override KINE policy

certified-proof-pack
Network
Sepolia / 11155111
Contract
0xBAB433f6E8a1632AdAAC66C1a2c50E9Cd44FE14A
Request tx
0xc0dcb9cfae7d343d87cfde46d823abfd1199de7c1dd19cb278d371dad7ff5a2e

A valid configured Owner signed the exact Sepolia execution request, Sepolia mined the transaction, and active KINE policy classified the recipient as KINE_BLOCKED_RECIPIENT. The governed execution reverted and the 0.0002 ETH governed principal remained intact.

  • Valid Owner signed exact request: true
  • Requested governed value: 0.0001 ETH
  • Transaction mined on Sepolia: 0xc0dcb9cfae7d343d87cfde46d823abfd1199de7c1dd19cb278d371dad7ff5a2e
  • Block: 11440165
  • Receipt status: 0 — expected PASS condition for this reverted validation
  • Policy classification: KINE_BLOCKED_RECIPIENT
  • Governed principal before: 0.0002 ETH
  • Governed principal after: 0.0002 ETH
  • Governed principal preserved: true

This proves the exact tested KineSmartAccountV2 Sepolia execution path. It does not establish universal wallet protection and does not mean the ordinary wallet currently connected to KINEGuard has this enforcement.

Phase 8Q — Sepolia live drain attempt harness

live-sepolia-scenario
Network
Sepolia / 11155111
Contract
0xF588E20EeC61CA458E8fD8fabCf84D1DC0aC46f0

The attempted owner-signed drain did not execute. The recorded error was KINE_UNKNOWN_RECIPIENT_REVIEW and the contract balance remained unchanged at 0.001 SepoliaETH.

  • Network: Sepolia
  • Chain ID: 11155111
  • Execute succeeded: false
  • Drain prevented: true
  • Contract before: 0.001 SepoliaETH
  • Contract after: 0.001 SepoliaETH

This proves the tested governed path resisted the unsafe drain scenario. It does not prove every ordinary EOA is protected after connection.

Phase 8T — Expanded live drain matrix

certified-proof-pack
Network
Sepolia / 11155111
Contract
0xF588E20EeC61CA458E8fD8fabCf84D1DC0aC46f0

The expanded matrix recorded 6 scenarios, 6 passes, and 0 failures across blocked, delayed, quarantined, panic-mode, and allowed-path cases.

  • UNKNOWN_RECIPIENT_DRAIN: blocked
  • BLOCKED_RECIPIENT_DRAIN: blocked
  • HIGH_VALUE_TRANSFER_DELAY: blocked or delayed
  • UNTRUSTED_CONTRACT_CALLDATA_QUARANTINE: blocked or quarantined
  • PANIC_MODE_BLOCK: blocked
  • TRUSTED_RECIPIENT_ALLOW_PATH: allowed

This is matrix evidence for the governed execution path, not a universal mainnet protection claim.

Phase 8V — KINE V1 Sepolia delay readback

public-verifier-artifact
Network
Sepolia / 11155111
Contract
0x47671e7266f5B0A534e3C09280007Ab6BB997DC7
Deploy tx
0xc129a563b82d5486d7bbf0a3ac08167a218022365302ae4b1eb791a75373323a
Request tx
0xc84d52f0fe4792ccfcf9b008a4233228bf9f56fb9bd02a43dab27a04a0828c33

A risky trust change could be requested by authority, but early application was blocked by the constitutional delay. The attacker was not trusted after the early apply attempt.

  • Early apply blocked: true
  • Attacker trusted after early apply: false
  • Error: KINE_CONSTITUTION_CHANGE_NOT_READY

This supports delayed constitutional change enforcement. It is not the full website-run hostile-drain flow.

Phase 8X — KINE V2 Sepolia veto readback

public-verifier-artifact
Network
Sepolia / 11155111
Contract
0x5d83f43E31Db0C3766033129d3116635dD9CB21D
Deploy tx
0x2ddcf87079df86db1ed1dbcec0d42442ea665552660fb6f24663bfebdfbb74d2
Request tx
0x4d7f1a7e3828006e561c4d90b2f29a7dc8fb0d02125a03168a1858025d60195d
Veto tx
0xc4363ad3b7ece4fefdb16cf1122d589d92ff193ff5fabfbce2a382c9228d9e96

The veto path was exercised. The trust-change request was vetoed, the apply attempt was blocked, and the attacker was not trusted after the apply attempt.

  • Vetoed: true
  • Apply blocked: true
  • Attacker trusted after apply attempt: false

This supports the Sepolia veto path. It still needs to be productized into the website-guided beta runner.

Future beta user journey

Step 1

Connect a wallet on Sepolia.

Step 2

Read the inspection-only boundary for ordinary connected wallets.

Step 3

Select a Policy Profile.

Step 4

Create or connect a governed Sepolia account or wrapper.

Step 5

Fund the governed account with faucet ETH only.

Step 6

Run the hostile scenario where the attacker has valid owner-key authority.

Step 7

Show that the signed drain violates policy.

Step 8

Show the governed path blocking, delaying, pausing, or constraining execution.

Step 9

Generate a receipt and surface it in Evidence, Session Intelligence, and Audit.

From governed vaults to universal governance

KINEGuard is not meant to remain a single wallet-safety surface. The long-term target is Economic Reality Governance: every high-value wallet action, smart contract call, agent instruction, digital asset transfer, delegation, approval, and automated execution should be checked before it becomes economic reality.

Phase 1

Governed allocation

Users choose which assets enter a governed vault, wrapper, or protected account.

Phase 2

Smart-account governance

The account itself becomes policy-aware, so actions require constitutional permission.

Phase 3

Wallet/provider mediation

Dapp requests, approvals, and signing flows pass through KINE review before execution.

Phase 4

KINE-aware assets and agents

Tokens, contracts, agents, vaults, and bridges can require KINE-governed permission.

Phase 5

Economic Reality Governance

KINE becomes the canonical pre-execution governance layer for economic change.

Primitive-of-primitives standard

The beta proof starts with governed execution. The product vision expands that same constitutional runtime across wallets, contracts, agents, digital assets, and automated economic systems. The standard is one canonical governed-action lifecycle, not disconnected safety features.

False-claim boundary

  • This does not mean every ordinary EOA is protected after connection.
  • This does not mean production mainnet funds are protected in the current beta.
  • This does not mean KINE collects, stores, or needs private keys.
  • This certified Sepolia proof does not mean the ordinary connected wallet has the same governed enforcement.

Canonical wording

For wallets or assets routed through the KINE-governed execution path, compromised-key attackers should not be able to complete constitution-violating actions. Ordinary connected wallets remain inspection-only unless the governed path is active and evidence proves enforcement.