Custody

All keys live in one signer process with no network access (unix socket only), running as its own system user; no other service on the server can read them. $MERGED's on-chain creator is this project's own pad key (index 0, derived inside the signer), and its creator fees follow the same collect and split as every repo coin. Every signature is checked against an allow-list for its purpose before signing: collect + split, buyback + burn, author payout, maintainer payout, sweep, mint partial-sign. Anything else is refused and logged.

POTS and MAINT are hot wallets. When the operator sets a hot cap and a dedicated cold address, any balance above (cap + pending claims) is swept, one source to one destination. Both unset means no sweep.

Payouts start only after the parent-fee gate passes: a finalized $MERGED collect + split transaction is verified on chain by a tool, never through the website.