[2601 Grant] SwaptoX Aggregator – Milestone 1

Thanks for the updates @SwaptoX. Several questions have been circulating in this thread for a while and you have asked for guidance more than once without a clear answer coming back. Rather than adding to that pile, I will try to converge where I can and be explicit about where a wider decision is still needed. I would inviter delegates to be mindful of adding new questions.

On the comparison page:
I would suggest keeping it live until M2 is recorded as closed.
The 55% commitment you made is written as something reviewers can verify at any time using that page, so retiring the page retires the commitment along with it. If the dedicated RPC endpoint is the cost driver, a reasonable middle ground is publishing the scenario list and the raw per route results together with a script others can run against their own endpoint. That preserves the check without keeping infrastructure open indefinitely, and it also closes out what @Tane asked for regarding publishing the scenario set and posting results rather than conclusions.

On audit scope:
Option 1 looks like the right call to me.
The $5k difference buys review of the contract holding admin rights and the fee cap, which is the mechanism the Collective has been asking to see verified since June. Hacken reached the same conclusion independently when they declined to audit the Router alone. One thing bears directly on the scope decision though. If the Router’s executor pointer can be changed without passing through the Timelock, then leaving SwaptoXEntered out means the swap path stays replaceable at will and the Router as security boundary argument weakens. If that change is timelock gated, the narrower scope holds up well.

On audit funding:
I looked at the Grant Guidelines thread for directions on this.
@tamlerner addressed this in early July, noting there is no separate audit fund for now and that the leaning is direct to auditor payment tied to audit readiness rather than an initial tranche. Applied here that points toward the Collective paying MixBytes directly once contracts are frozen, rather than a cash tranche to the project. That said, I am not in a position to commit the Collective to it on my own, so I will open a separate discussion on audit funding so we settle the general rule instead of resolving it case by case and leaving you blocked in the meantime.

On what starts M3:
I think a code freeze is the piece still missing. If audit readiness is the trigger for funding, then readiness has to mean something concrete, and right now the contracts are still moving. Your own notes say the Timelock may change, the fee cap moved from 0.3% to 0.2%, and the Router sits close to the 24KB limit. MixBytes only covers re-review at no cost under a 10% code change, so sending contracts to audit before they are frozen risks paying for the same work twice. I would suggest M3 opens on a frozen contract set for the audit, together with the consolidated scope document you already committed to publishing with the deferred M2 items clearly marked. Worth also recording Cloudflare as delivered with no measurable latency gain so that item does not stay ambiguous.

I will get the audit funding discussion started this week.

1 Like