Fortress‑BTC Mark IV  /  graded build  /  new threat class A2′  /  rev 12 Sep 2026

Same attack.
Three budgets.
Watch what changes.

The minute below is the whole argument: the September 2026 drain, replayed at each level of investment. Not a feature tour — the same four thousand BTC leaving, or not leaving, depending on what you bought.

Everything after it is evidence. Sixteen capabilities are built — code you can clone and run. Thirty‑two more are buildable but unwritten. Six are staged behind written triggers. Nine claims were cut, and a third audit pass found seven more problems — one of them serious enough to rename this generation. We print all of it, because a vendor who can't tell you what doesn't work yet is telling you what you want to hear.

Revised 12 September 2026 — a fourth grade, and every row re-graded. The supply‑conservation invariant and its backing oracle were marked Ships and are not in this build; the reference deployment is a treasury company, which never issues, so V2 has nothing to conserve.

Fixing that row exposed the reason it happened. Ships had been carrying two meanings — "we could build this" and "this runs" — and with both collapsed into one word every row was ambiguous. Built now means code in the repository under test; Ships means buildable and unwritten. Fifteen rows moved to Built, nine of them controls added in the last two days that this ledger had never listed at all. A sixteenth joined them later the same day: the diversity index, which is the one number on this page sold as a contractual SLO.

Built — runs today
16 Code in the repository, under test. Clone it and run 110 tests.
Ships — buildable
32 Named library, vendor or BIP with real implementations. Not yet written.
Staged
6 Gated on ecosystem maturity, or on a deployment that needs them.
Cut, two audit passes
9 + 7 Nine cut from Mark II. Seven more found in the build-step re-check.
Blast radius — contracted
2.6% Mark II said 0.6%. It ignored the hot float. This is the honest number.
The story  /  four thousand BTC, four budgets

The same attack, run four times.

Pick a budget. The attacker never changes: a valid, correctly signed transaction built on value that never existed. Only two things change — how far it travels, and what it costs you when it stops.

0
BTC irreversibly gone
 

Hover the diagram to magnify it. A 2.6× lens follows your cursor and re‑draws the scene rather than stretching it, so the labels stay sharp; every one of them is also written out in the strip beneath the canvas. And note what act two does not do — an assessment buys the number, not the gate. We show it that way because that is what it is, and because a buyer who finds that out later stops believing the rest of the page.

Start here  /  how to evaluate this in twenty minutes

Four steps. Do them in order.

This page is built to be attacked, not admired. Each step below maps to a live tool further down — the point is to leave with a number you can defend to your board, not an impression.

Run all four acts of the story above

Start at $0 and step up. You are looking for one thing: the point where the loss stops falling. That is where your money stops buying safety and starts buying assurance, and it is the honest edge of what we sell. Hover the diagram to magnify the gate labels.

2 minutes · four clicks

Read the nine cuts and seven findings before any green rows

Nine claims cut from Mark II, seven more from the build-step re-check. If you disagree with a single substitution, stop and challenge it — those sections are the basis on which everything else here should be trusted.

6 minutes · no interaction needed

Enter your own signer topology into the diversity calculator

Set each axis to match how your current custody is actually deployed — same cloud, same image, same team. The number it returns is your effective signer count today, not your advertised threshold.

5 minutes · expect an uncomfortable result

Set your treasury size and read your blast radius

The blast-radius tool converts your holdings into a maximum-irreversible-loss figure under total credential compromise. That single number is what we contract on, and it is the only promise on this page.

5 minutes · bring your actual AUC

Then, if it survives that: send us your red team. Step five is an adversarial exercise against a funded testnet estate with a standing bounty. We pay whether or not you buy.

The audit  /  what did not survive

Nine claims, each replaced by something you can actually buy.

Every cut below was in the Mark II material. Each is shown with what the audit found and what ships instead. Two of them — the consensus‑implementation error and the blast‑radius correction — were outright mistakes, not merely optimism.

Six of the nine removed a capability outright. One (FROST) was demoted to staged rather than deleted. Two were corrections to how we described something that still ships — which we count as cuts, because a claim that overstates what a tool provides is a defect whether or not the code changes.

Third pass  /  the build steps, re-audited

Mark III still had a hole. It is the one that has actually been draining treasuries.

The first audit graded capabilities. This one graded the engagement: the ceremony, the build pipeline, the contract, and the moment a human presses approve. Seven findings. The first is the most important sentence on this page.

The large multisig losses of the past two years share a shape, and it is not the one people design against. The keys were fine. The quorum was met. The officers approved — a screen that was lying to them. Against a compromised interface, signer diversity buys nothing: your independent officers are independently reading the same forgery.

The ledger  /  usable versus upgradeable

Every capability carries a grade. No exceptions.

Built means there is code in the repository, under test, that you can clone and run today. Ships means buildable now with parts that exist, but not yet written. Staged means real but gated — we build the seam today and the capability when a written trigger fires. Cut means it was in Mark II and did not survive.

The fourth grade is new, added 12 September 2026, and it exists because this page was wrong without it. Until now Ships carried two meanings at once — "we could build this" and "this runs" — and the two were collapsed into one word. That ambiguity is how a control that is not in the build spent two days marked as shipping. Splitting them means every row now answers a question with one right answer.

Nothing here is deployed. Built means it runs on your laptop, not that it guards anyone's money. The line where that changes is Stage 7 — a red-teamer holding every online key fails to move funds on signet — and it has not been crossed.

Internal rule, restated 12 September 2026: BUILT requires code in the repository under test — cargo test --workspace is the evidence, and it is 110 tests. SHIPS requires a named library, vendor or BIP with real implementations, and admits that we have not written it yet. The old rule said SHIPS required "a working component in the reference deployment", which nothing satisfied, so the rule was unenforceable and duly went unenforced.

Built does not mean deployed. It means it runs on a laptop. Nothing on this page guards anyone's money yet, and the line where that changes is Stage 7 — a red team holding every online key failing to move funds on signet.

Why this table lists 6 cuts while the section above lists 9: three of the nine were not capability removals. FROST was demoted to STAGED rather than deleted; the Kani and conformal cuts were wording corrections to capabilities that still ship; and the 0.6% blast radius was a figure, not a feature. Six capabilities were removed outright. We would rather explain the arithmetic than round it.

Interactive  /  what your quorum is actually worth

Five signers on one image is one signer.

Mark II asserted that a monoculture 5‑of‑7 is weaker than a diverse 3‑of‑5. This derives it. Each axis scores normalised Simpson diversity across your signers, and the axes combine with a geometric mean.

Earlier revisions of this page said that mean is dominated by your worst axis. It is not, and the calculator below disproves it in two clicks: set one axis to Shared and the rest to Diverse, and Neff stays above 10 on a 15‑signer quorum where every signer runs the same implementation. A geometric mean over seven terms is diluted by the six healthy ones. Corrected 12 September 2026, along with two other defects in this model — see the note under the panel.

So Neff is the contractual number and it is not the gate. Two further checks run alongside it, both stricter, and the verdict below is all three.

a = (1 − Σ pj²) / (1 − 1/n)   ·   C = geomean(d̂a)   ·   Neff = 1 + (n − 1)·C

1.3
effective independent signers
1.0 — one signerSLO 2.515

What this model got wrong, and what we did about it. Every axis is floored at 0.05 rather than zero, because a literal zero makes every other axis irrelevant. Three defects followed from taking that number at face value, all found on 12 September 2026 while writing the calculator that was supposed to merely implement it. (1) Neff = 1 + (n−1)·C is unbounded in n, so the floor becomes a volume discount: a roster with zero diversity on all seven axes reaches the 2.5 SLO at n = 31. Thirty-one machines on one image would have passed as published. The slider here stops at 15, so you cannot reach it — the defect was in the formula, not in this page. (2) The geometric mean is not dominated by the worst axis, as stated above. (3) The split level is not a constant. A 4/3 split of seven scores 0.571 and a 3/2 split of five scores 0.600; both were printed as 0.57. The figure beside each axis now moves with n, as it should. The gate now carries two checks stricter than the SLO: no single value on any axis may be held by k or more signers (this is Ronin, and it needs no model at all), and every axis must carry at least 2.5 effective distinct values. Both can only refuse a roster the SLO would have admitted. Contractual SLO: Neff ≥ 2.5 sustained, recomputed on every deployment and re‑attested hourly. Breach escalates the quorum tier automatically after four hours; a quorum‑defeating axis escalates immediately, with no grace period.

Interactive  /  the only promise on this page

Price the worst day, not the average one.

Mark II advertised 0.6%. The audit found the figure quietly excluded the hot float — the small unvaulted pool funding fast withdrawals, which is the first pool an attacker reaches. Corrected, it is 2.6%, and that is what we sign.

The mechanism is a three‑tier treasury. Deep cold sits behind a seven‑day consensus timelock. Warm vault sits behind twenty‑four hours. Hot float has no vault by construction — that is the honest cost of same‑day withdrawals, and it is a choice you make, not one we hide.

4,200 BTC TREASURY — PARTITIONED SO THAT NO SINGLE AUTHORIZATION CAN REACH MORE THAN ONE TRANCHE DEEP COLD · 3,360 BTC · 80% 8 tranches × 420 BTC · CSV 1,008 blocks ≈ 7 days · never touched routinely unreachable inside any plausible incident window WARM VAULT · 756 BTC · 18% 30 tranches × 25.2 BTC · CSV 144 blocks ≈ 24 h (p99 ≈ 31 h) · scheduled settlement one tranche reachable per authorization — 25.2 BTC HOT FLOAT · 84 BTC · 2% no vault by construction · rate-limited · insured · this is where the honesty lives WORST CASE, 24 H 25.2 BTC warm tranche + 84 BTC hot float 109.2 BTC 2.6% of treasury Ceremony burden — the reason Mark II’s 168-tranche model was cut: 38 tranches × 2 pre-signed transactions = 76 signatures per quarterly ceremony. A two-day ceremony. Operable. 168 tranches would have required 336 signatures, re-run on every destination change. Not operable. Pre-signed vaults are only meaningful if the ceremony keys are destroyed afterwards. Witnessed, filmed, logged.
FIG. 01 — The corrected treasury model. Deep cold is not reachable inside any plausible incident window; warm vault yields one tranche per authorization; the hot float is the genuine exposure and is stated rather than netted out of the headline figure.

Shrinking the hot float lowers your blast radius and slows customer withdrawals. There is no setting that improves both. That trade is the whole design conversation, and it is yours to make.

2.6%
maximum irreversible loss in 24 h
0%25%100% — September 2026

Assumes total credential compromise: every key stolen, every host owned, every operator coerced. Deep cold is excluded because its 1,008‑block timelock exceeds any containment window by a factor of seven.

Interactive  /  play the attacker

Delay is the only control an attacker cannot buy.

Sixty capability points buys a well‑resourced, patient adversary. This is not a claim that the fortress is unbreakable. It is an itemised bill: what an attacker must purchase, and at what price, before one irreversible satoshi moves. Against the September architecture the same treasury cost ten points.

SPENT 0 / 60
Build steps  /  what $185,000 actually buys

Eight weeks, thirteen workstreams, and you leave with one tranche already vaulted.

Mark III sold six weeks of analysis. That is a report, and a report has never stopped anything. Mark IV holds the price and adds every protective action we can honestly take without ever holding a key — because in the first quarter, what makes a treasury safer is procedure, partitioning and rehearsal, not software.

You finish this engagement with a measured blast radius, a signed replay artifact, a destination allowlist you can enforce today, a rehearsed cold-move procedure with a real wall-clock time on it, and one live tranche sitting behind a working 144-block clawback. If you never call us again, all of that still works.

Rule 01
We never hold a key.
Access is watch-only descriptors and extended public keys. If you offer us private material we refuse it in writing, because an assessor who can spend is an assessor who can be coerced. Every transaction we build is handed to you unsigned.
Rule 02
You execute, we stand behind you.
Moving coins to a safer partition is your hands on your keys, on your schedule. We write the procedure, rehearse it with you on signet, time it, and watch the mainnet run. We do not touch it.
Rule 03 · escalation
If we find an active compromise, week one stops.
This was missing from Mark III and it is the most dangerous kind of gap: an assessment that discovers an in-progress incident and keeps politely working through its checklist. A named escalation contact and a 24/7 number are agreed in week 0, before any access is granted. Discovery of live compromise converts the engagement to incident response the same hour, at no additional fee.
Rule 04 · stop-loss
We will tell you not to buy Phase 02.
If your measured maximum irreversible loss is already inside your own risk appetite, the report says so on page one and we do not pitch you. We would rather lose a sale than book an engagement we cannot justify to your board.
WEEK 0Scoping, access agreement, escalation contractWritten definition of what we may see and what we may never receive. Named escalation contact on both sides with a 24/7 number. Agreement on the loss-model methodology before we produce a number, so nobody argues with the arithmetic afterwards.Before accessSigned access agreement and escalation clause.
WEEK 1Estate capture — watch-onlyDescriptor inventory, signer topology, quorum configuration, HSM firmware levels, build provenance. Extended public keys only. Time-boxed and logged; you can see everything we looked at.Day 5Diversity index. Usually the first uncomfortable number.
WEEK 1–2Address reuse and exposed-key sweepEvery UTXO you hold on an address whose public key is already published, ranked by value. This is the real quantum long-exposure surface and almost nobody measures it. Also the input to the single cheapest hardening action available to you.Day 9Ranked exposure list plus unsigned migration PSBTs to single-use addresses.
WEEK 2Blast-radius enumerationEvery path from a stolen credential to irreversible settlement, traced by hand against your real runbooks and re-derived independently by a second engineer. Two people reach the number separately; if they disagree, the disagreement is in the report.Day 10Maximum irreversible loss today. One number, dual-reviewed, board-ready.
WEEK 3Invariant replay against your historyV1, V4, V5, V6 and V8 replayed over twelve months of your real transactions — five of the eight, named rather than rounded up. V2 needs issuance you do not have; V3 and V7 arrive with the vault. How many would have tripped, and how many were false? You get the false-positive rate before committing to anything. If you cannot supply twelve months, we say so in the report and run against what exists rather than quietly shortening the window.Day 15Signed replay artifact, re-executable by your team without us.
WEEK 3Destination allowlist bootstrapYour actual settlement destinations over twelve months, clustered and aged, delivered as a ready-to-enforce allowlist. Deployable in your existing stack today. Requires no Fortress code and survives you never buying anything else.Day 15Allowlist file plus the eleven destinations that appeared exactly once.
WEEK 4Signing-surface attackCan your host lie to your officers? With written permission, on a test estate, we attempt exactly that: a transaction that displays one destination and carries another. This is the attack that has actually been draining treasuries, and most teams have never watched it happen to them.Day 20Recorded demonstration of whether your approvals are blind.
WEEK 4–5Proof tranche — one real vault, your keysA single ceremony on your hardware: one warm tranche moved behind a 144-block OP_CSV timelock with a pre-signed clawback to your deep cold, and the ceremony keys destroyed on camera. Small enough to be safe, real enough to be proof. You now own a working vault before you have bought one.Day 25One live vaulted tranche and a clawback you have personally fired on signet.
WEEK 5Cold-move rehearsal and timingThe procedure you asked for at 3am: move the bulk of the treasury to a safer partition, fast, under pressure. Rehearsed on signet, then executed by you on mainnet at whatever scale you choose, with us observing. The output is a number, not a document.Day 25"You can move 80% of your treasury to deep cold in N hours." Measured, not estimated.
WEEK 5–6Freeze drill and watchtower trialTwo timed exercises. First: how long does it take you to stop everything, right now, today, with the stack you already run? Almost nobody has measured this. Second: one monitor-only watchtower on your estate for the final two weeks, producing real detection-latency data rather than our marketing figure.Day 30Your true MTTD and your true time-to-freeze, on your infrastructure.
WEEK 6Adversarial tabletopYour team and ours, six attacker classes plus the interface attacker, played against your real procedures. Booked in week 0 because officer availability is the single largest schedule risk in this engagement, and a tabletop without the officers is a meeting.Day 32Findings ranked by cost-to-attacker, not by severity label.
WEEK 7Day-one hardening listEverything that costs nothing and can be done before we leave: unused withdrawal endpoints disabled, per-key operation scopes tightened, any key that has ever touched a general-purpose host rotated, two-person control on configuration changes. Each item with the diff, the owner and the rollback.Day 35A checklist your team can close inside a sprint.
WEEK 8Three reports and the insurance packetOne for the board, one for engineering with reproduction steps, one for the regulator or insurer with findings mapped control-by-control to CCSS, ISO 27001 and the DORA operational-resilience articles. Different audiences need different documents; a single PDF serves none of them.Day 40Unconditional handover. Every artifact is yours whatever happens next.
Failure modeWhy it happensWhat we do about it
Active compromise discovered mid-assessmentThe estate was already breached when we arrived — the most dangerous week of any engagementRule 03. Escalation contract signed in week 0; converts to incident response the same hour, no additional fee
Officer unavailabilityThe tabletop and the ceremony both need named humans; diaries are the top schedule riskBoth booked in week 0 with a named deputy per role. No deputy, no start date
Fewer than 12 months of historyMigrations, vendor changes, or data never retainedRun against what exists and say so in the report. Never quietly shorten the window and present the same confidence
No test estate for the signing-surface attackSmaller teams often have no realistic staging environmentWe supply a funded signet estate mirroring your topology. The finding is weaker and the report labels it weaker
Customer offers us private key materialIt is usually offered helpfully, to "make it easier"Refused in writing, every time. Rule 01. An assessor who can spend can be coerced
The loss number is one engineer's opinionHand-tracing is judgment-heavy and the number carries to a boardTwo engineers derive it independently. Disagreements are printed rather than reconciled away
Proof tranche goes wrong on mainnetA real ceremony on real coins, however smallRehearsed twice on signet first; tranche sized so a total loss is immaterial; you hold every key and press every button
Scope creep into free consultingFindings generate questions, questions generate workThirteen workstreams, fixed. Anything else is quoted. We said eleven for a while and the table always had thirteen — corrected rather than rounded

Roughly three senior specialists for eight weeks, plus one ceremony and one watchtower month. The margin at $185,000 is thin and deliberately so: a customer who leaves holding a working vaulted tranche buys Phase 02 far more often than a customer who leaves holding a PDF. We would rather tell you that than pretend the pricing is generosity.

What you must supply

Watch-only descriptors and xpubs for the estate · twelve months of transaction history if it exists · one named officer per approving role plus a deputy, diaried in week 0 · a test or staging estate if you have one · authority to execute the cold-move on mainnet at a scale you choose · a named escalation contact reachable 24/7.

What the assessment still cannot do

It does not stop an attack in progress on the day it starts, and act two of the story above shows that honestly. The proof tranche protects one tranche, not the treasury. The allowlist and the hardening list reduce your exposure genuinely but modestly. If you want the loss number itself to fall, that is Phase 02, and we will say so in week one rather than week eight.

Commercial  /  what it costs and how we are paid

We don't charge per transaction. A vendor paid per approval is paid to approve.

No basis points on assets under custody either. A percentage of your treasury prices like insurance without underwriting it, and it ties our revenue to your exposure instead of to our work. You pay a fixed implementation fee and a flat platform fee, banded by the number of tranches we actually operate.

The three numbers are a ladder, not a menu: $185,000 tells you the size of your problem and vaults one tranche while it does, $850,000 caps it, $4,200,000 caps it and proves the cap to a third party. Phase 03 includes Phase 02 rather than adding to it. Stop at whichever rung the story above stopped surprising you.

Phase 01 · Assessment

$185,000fixed · 8 weeks · 13 workstreams
  • Blast radius today — dual-derived, board-ready
  • One live vaulted tranche, your keys, clawback fired
  • Rehearsed cold-move with a measured wall-clock time
  • Destination allowlist you can enforce this week
  • Exposed-public-key sweep and migration PSBTs
  • Signing-surface attack, recorded, on a test estate
  • Freeze drill, watchtower trial, hardening checklist
  • Board, engineering and insurer reports
Fully credited against Phase 02 or 03 within 90 days. Same price as Mark III, thirteen workstreams instead of six. If your measured loss is inside your risk appetite, we tell you not to buy Phase 02.

Phase 02 · Vault overlay

$850,000+ platform fee · 1 quarter
  • Three-tier treasury, ceremony, panic key, two watchtowers
  • Value, change, cumulative and quorum invariants — shadow mode, then enforcing
  • Deployed over your existing custody. No rip-and-replace.
  • Adversarial exercise on a funded testnet estate
Fastest route from "everything is reachable" to a contracted blast-radius number. Act three of the story: 4,000 BTC becomes 109.2.

Phase 03 · Full fabric

$4,200,000all-in · 3–4 quarters
  • Everything in Phase 02 — this replaces it, it does not stack
  • Independent verification devices, so no approval is blind
  • Two independently written ceremony implementations
  • Reproducible builds (M6), now included rather than quoted apart
  • Transparency log with external witnesses, source escrow
  • 24-month warranty on the blast-radius SLO
Priced up from $2.4M by the third audit pass. Four of the seven findings cost real money, and we would rather raise the number than quietly drop the work.
ComponentBasisFeeNotes
Platform — under 500 BTCflat monthly$18,000Up to 12 tranches operated
Platform — 500 to 5,000 BTCflat monthly$42,000Up to 40 tranches
Platform — 5,000 to 25,000 BTCflat monthly$78,000Up to 120 tranches, 3 watchtowers
Platform — above 25,000 BTCflat monthlybespokeDedicated ceremony team
Independent watchtowerper watchtower / month$8,000Minimum two, separate legal entities
Key ceremonyper ceremony$22,000Quarterly, or on destination-set change
Recovery rehearsalper rehearsal$9,000Quarterly. An unrehearsed runbook does not exist.
Independent verification devicesper officer, one-off$4,500Second vendor, air-gapped. Two devices per approving officer.
Watchtower liveness drillmonthly, per towerincludedA real, tiny mainnet clawback. Miss one and the tower is rotated out.
Standing red-team bountyfunded by us$150,000Payable to your team or any third party who breaks the testnet estate
Per-transaction feenoneDeliberate. See the headline above.
Basis points on AUCnoneDeliberate. Our revenue should not scale with your exposure.

Worked example — a 4,200 BTC treasury on Phase 02: $850,000 implementation + ($42,000 platform + $16,000 watchtowers) × 12 + 4 ceremonies + 4 rehearsals = $1,670,000 in year one. The same treasury on Phase 03: $5,020,000 in year one, and your worst day falls from 109.2 BTC to 12. Against a September‑scale loss of $320M those are 0.52% and 1.57% respectively — but compare them to your own contracted blast radius, not to somebody else's disaster. That is what the tool above is for.

Due diligence  /  hold us to this list

What we will not claim.

Mark II carried six. The first audit added three and sharpened two. The third pass added two more, and the first of them is the one we would most like you to test us on.

Explicit non-claims

  • The control that would have stopped 6 September is not in this build. V2, supply conservation, applies to deployments that issue — a sidechain, a bridge, an exchange. The reference deployment is a treasury company, which never mints, so V2 has nothing to conserve and was removed rather than carried unused. If you issue, it is designed and specified; ask for it by name and we will tell you what it still needs.
  • Signer diversity does not survive a compromised interface. If the screen lies, every independent officer reads the same lie. This is how the large multisig losses actually happened, and it is why Phase 03 includes a second class of device rather than a stronger threshold.
  • We are a supply-chain risk to you. A security vendor is a high-value target, and a patient adversary attacks the vendor rather than the customer. Source escrow, builds you verify yourself, and a cold-recovery path that needs none of our binaries are in the contract for that reason.
  • This is not a quantum-proof Bitcoin wallet. Bitcoin spends require secp256k1. Post-quantum signatures inside our application do not change consensus.
  • "Formally verified" is not a word we use unqualified. Mark II said invariants were proved total over the input domain. That was false — Kani is bounded model checking. Correct claim: verified for all inputs up to a stated bound, currently 8 inputs and 8 outputs.
  • Our anomaly calibration degrades exactly when you need it. Conformal prediction guarantees coverage under exchangeability, which is precisely what an attack breaks. It is calibrated for the routine regime, paired with drift detection, and it never gates a hard limit.
  • Freeze does not mean frozen on-chain. A broadcast Bitcoin transaction cannot be recalled. Freeze applies to our authorization system. Anyone implying otherwise is describing a different blockchain.
  • We fail closed, and fail-closed means unavailable. Under sustained disruption you will not be able to move funds. That is the deliberate trade and it is written into the contract.
  • Vaults cost you a day. Fast withdrawals run from the hot float, which has no vault. The float is the exposure, and we print it rather than netting it out of the headline number.
  • Three jurisdictions in one treaty bloc may be one jurisdiction. Our diversity index does not model correlated legal pressure. It should. It is on the open-questions list, unresolved.
  • The diversity index reads labels, not evidence. Two signers claiming different build chains are two build chains only if somebody checked. Bit-for-bit reproducible builds are what would make that measurable, and they are STAGED. Until then every independence figure on this page is a measured-input claim, and we label it as one.
  • The three-tier partition on this page did not add up, and we corrected the arithmetic rather than the story. Deep cold was printed as 3,366 BTC while also being described as 80% of 4,200 and as 8 tranches of 420 — both of which are 3,360. The warm vault was printed as 750 BTC and as 18%, which is 756. The 3,366 figure had been back-solved so the three amounts summed to 4,200, at the cost of contradicting the tranche maths beside it. The consistent partition is 3,360 + 756 + 84 = 4,200, which makes the warm tranche 25.2 BTC and the contracted blast radius exactly 109.2 BTC = 2.600% rather than a rounded 2.6%. The interactive panel now opens on that configuration instead of on a treasury of 4,107 BTC that matched nothing above it.
  • We published a false claim about our own formula and a calculator that disproved it. This page said the geometric mean is dominated by your worst axis. It is not — one shared axis out of seven leaves Neff above 10 on a 15-signer quorum, which you can reproduce in the panel above. Corrected 12 September 2026. We are leaving the correction visible rather than quietly editing the sentence.
  • Post-quantum algorithms are young. ML-KEM, ML-DSA and SLH-DSA are standardised and appropriate to deploy. They are not proven unbreakable — which is why the root of trust is co-signed by two unrelated families.
  • Every figure here is a design target for a proposed architecture, not a measured result from a deployed system. Treat it as an engineering proposal to be attacked, not a certification.
The end state

Grade every claim. Ship the ships. Publish the cuts.

A single compromised component cannot cause an irreversible catastrophic loss. Mark II asserted that. Mark III graded every mechanism that has to be true for it to hold. Mark IV adds the one we had missed — that the human pressing approve can be shown a forgery — and prints the mechanisms that still aren't ready.

The September incident left the industry one sentence worth remembering, and it is still not about quantum computers:

"The private key was not compromised" must never again be equivalent to "the funds were safe."

Why this is Mark IV and not Mark III rev C. Version inflation is a vendor sin, so the rule is written down: a new Mark only when the threat model changes. Mark IV earns the number because attacker class A2′ — the interface attacker, who changes what your officer sees rather than stealing what your officer holds — is new, and it added a plane and two invariants. The intermediate revisions did not change the threat model and did not get a number.

Mark I was your own four‑step architecture. Mark II turned it into six planes. Mark III graded every claim in it. Mark IV assumes the screen is lying.

The internal build specification — threat model, invariant catalogue, ceremony burden, verification bounds, milestones and open questions — is FORTRESS.md, and we hand it to prospects before contract, not after. It is deliberately less flattering than this page.