
Memory and measurement: what learned state may change, and what it may never touch
Two kinds of remembered state with two materially different boundaries. One can only reorder work. The other ranks a candidate list and then truncates it — which reaches route selection by omission, and the stronger formulation of the quarantine does not survive that.
Known formally as The quarantine, and where it leaks in the BlazePhoenix whitepaper.
BlazePhoenix Engineering · updated 2026-08-13 · 12 min · written from the deployed bytecode
By Mitra (@Sigmacrit) — anonymous developer of the BlazePhoenix protocol. The code is the résumé.
Abstract in 15 languages · resumo · resumen · 摘要 · 要旨 · ملخص
English — The shipped rule is one sentence — remembered state may change where the system looks, never what it accepts — applied to two different stores: probe hints can only reorder discovery attempts (written in one place, read in five, all inside discovery), while venue standing, earned solely by executed swaps and halving roughly every seven hours by lazy decay, ranks and then truncates the candidate list — which reaches route selection by omission, and the stronger formulation of the quarantine does not survive that; the leak is documented, not hidden.
Português — A regra em produção é uma frase — o estado lembrado pode mudar onde o sistema olha, nunca o que ele aceita — aplicada a dois repositórios diferentes: as probe hints só podem reordenar tentativas de descoberta (escritas num lugar, lidas em cinco, todos dentro da descoberta), enquanto o standing das venues, ganho unicamente por swaps executados e caindo para metade a cada cerca de sete horas por decaimento preguiçoso, ordena e depois trunca a lista de candidatas — o que alcança a seleção de rota por omissão, e a formulação mais forte da quarentena não sobrevive a isso; a fuga está documentada, não escondida.
Español — La regla en producción es una frase — el estado recordado puede cambiar dónde mira el sistema, nunca qué acepta — aplicada a dos almacenes distintos: las probe hints solo pueden reordenar intentos de descubrimiento (escritas en un lugar, leídas en cinco, todos dentro del descubrimiento), mientras que el standing de las venues, ganado únicamente por swaps ejecutados y cayendo a la mitad cada unas siete horas por decaimiento perezoso, ordena y luego trunca la lista de candidatas — lo que alcanza la selección de ruta por omisión, y la formulación más fuerte de la cuarentena no sobrevive a eso; la fuga está documentada, no escondida.
Français — La règle livrée tient en une phrase — l'état mémorisé peut changer où le système regarde, jamais ce qu'il accepte — appliquée à deux dépôts différents : les probe hints ne peuvent que réordonner les tentatives de découverte (écrites en un endroit, lues en cinq, tous dans la découverte), tandis que le standing des venues, gagné uniquement par des swaps exécutés et divisé par deux environ toutes les sept heures par décroissance paresseuse, classe puis tronque la liste de candidates — ce qui atteint la sélection de route par omission, et la formulation la plus forte de la quarantaine n'y survit pas ; la fuite est documentée, pas cachée.
Deutsch — Die ausgelieferte Regel ist ein Satz — gemerkter Zustand darf ändern, wohin das System schaut, nie, was es akzeptiert — angewandt auf zwei verschiedene Speicher: Probe-Hints können nur Discovery-Versuche umordnen (an einer Stelle geschrieben, an fünf gelesen, alle innerhalb der Discovery), während Venue-Standing — ausschließlich durch ausgeführte Swaps verdient, per Lazy Decay etwa alle sieben Stunden halbiert — die Kandidatenliste rankt und dann trunkiert, was die Routenwahl per Auslassung erreicht; die stärkere Formulierung der Quarantäne überlebt das nicht, und das Leck ist dokumentiert, nicht versteckt.
Русский — Поставленное правило — одно предложение: запомненное состояние может менять, куда система смотрит, но никогда — что она принимает; применено к двум разным хранилищам. Probe-хинты могут лишь переупорядочить попытки обнаружения (записываются в одном месте, читаются в пяти, все внутри обнаружения), тогда как репутация площадки, зарабатываемая только исполненными свопами и полураспадающаяся примерно каждые семь часов ленивым затуханием, ранжирует и затем усекает список кандидатов — что достигает выбора маршрута через опущение, и более сильная формулировка карантина этого не переживает; утечка задокументирована, а не спрятана.
Türkçe — Yayınlanan kural tek cümledir — hatırlanan durum sistemin nereye baktığını değiştirebilir, neyi kabul ettiğini asla — ve iki farklı depoya uygulanır: probe ipuçları yalnızca keşif denemelerini yeniden sıralayabilir (bir yerde yazılır, beşte okunur, hepsi keşfin içinde); mekân itibarı ise yalnızca yürütülmüş takaslarla kazanılır, tembel bozunumla yaklaşık her yedi saatte yarılanır, aday listesini sıralar ve sonra keser — bu, yol seçimine ihmal yoluyla ulaşır ve karantinanın daha güçlü ifadesi bundan sağ çıkmaz; sızıntı gizlenmemiş, belgelenmiştir.
العربية — القاعدة المنشورة جملة واحدة — الحالة المتذكَّرة يجوز أن تغيّر أين ينظر النظام، لا ما يقبله أبداً — مطبّقة على مخزنين مختلفين: تلميحات السبر لا تستطيع إلا إعادة ترتيب محاولات الاكتشاف (تُكتب في مكان واحد وتُقرأ في خمسة، كلها داخل الاكتشاف)، بينما مكانة المنصة، المكتسبة حصراً بمبادلات نُفّذت والمتناصفة كل نحو سبع ساعات باضمحلال كسول، ترتّب قائمة المرشحين ثم تبترها — وهذا يبلغ اختيار المسار بالإغفال، والصياغة الأقوى للحجر لا تنجو من ذلك؛ والتسرب موثّق لا مخفي.
हिन्दी — शिप किया नियम एक वाक्य है — याद रखा गया स्टेट बदल सकता है कि सिस्टम कहाँ देखता है, कभी नहीं कि वह क्या स्वीकारता है — दो अलग भंडारों पर लागू: probe hints केवल खोज-प्रयासों का क्रम बदल सकते हैं (एक जगह लिखे, पाँच में पढ़े, सब खोज के भीतर), जबकि venue standing, केवल निष्पादित स्वैपों से अर्जित और आलसी क्षय से लगभग हर सात घंटे में आधी, उम्मीदवार-सूची को क्रमबद्ध कर फिर काटती है — जो चूक के रास्ते रूट-चयन तक पहुँचती है, और क्वारंटीन का कड़ा रूप इससे नहीं बचता; रिसाव प्रलेखित है, छिपाया नहीं गया।
日本語 — 出荷された規則は一文です。記憶された状態はシステムがどこを見るかを変えてよいが、何を受け入れるかは決して変えてはならない。これが二つの異なるストアに適用されます。プローブヒントは発見の試行順を並べ替えることしかできません(書き込みは一箇所、読み取りは五箇所、すべて発見の内部)。一方、会場スタンディングは実行されたスワップのみで積み上がり、遅延減衰で約七時間ごとに半減し、候補リストを順位付けした上で切り詰めます。これは省略という形で経路選択に到達し、隔離のより強い定式化はそれを生き延びません。漏れは隠されず、文書化されています。
中文 — 上线的规则只有一句——被记住的状态可以改变系统看向哪里,绝不能改变它接受什么——应用于两个不同的存储:探测提示只能重排发现尝试的顺序(一处写入、五处读取,全在发现层内部);而场所声望仅由实际执行的交换赚取、以惰性衰减约每七小时减半,先排序再截断候选列表——这以"遗漏"的方式触及路由选择,隔离的较强表述在此失守;这个泄漏被如实记录,而非隐藏。
한국어 — 배포된 규칙은 한 문장입니다 — 기억된 상태는 시스템이 어디를 보는지는 바꿀 수 있어도 무엇을 받아들이는지는 결코 바꿀 수 없다 — 이것이 서로 다른 두 저장소에 적용됩니다. 프로브 힌트는 디스커버리 시도의 순서만 바꿀 수 있고(쓰기는 한 곳, 읽기는 다섯 곳, 모두 디스커버리 내부), 장소 스탠딩은 오직 실행된 스왑으로만 쌓이며 게으른 감쇠로 약 7시간마다 반감되어 후보 목록을 순위 매긴 뒤 잘라냅니다 — 이는 누락이라는 방식으로 경로 선택에 닿고, 격리의 더 강한 정식화는 그것을 견디지 못합니다. 이 누수는 숨겨지지 않고 문서화되어 있습니다.
Bahasa Indonesia — Aturan yang dirilis adalah satu kalimat — keadaan yang diingat boleh mengubah ke mana sistem melihat, tak pernah apa yang diterimanya — diterapkan pada dua penyimpanan berbeda: probe hints hanya bisa mengurutkan ulang percobaan penemuan (ditulis di satu tempat, dibaca di lima, semuanya di dalam penemuan), sementara reputasi venue, diperoleh semata dari swap yang tereksekusi dan terbelah dua kira-kira tiap tujuh jam lewat peluruhan malas, memeringkat lalu memangkas daftar kandidat — yang mencapai pemilihan rute lewat penghilangan, dan rumusan karantina yang lebih kuat tidak selamat dari itu; kebocorannya didokumentasikan, tidak disembunyikan.
বাংলা — শিপ করা নিয়ম এক বাক্যের — মনে রাখা অবস্থা বদলাতে পারে সিস্টেম কোথায় তাকায়, কখনোই নয় সে কী গ্রহণ করে — দুটি ভিন্ন ভান্ডারে প্রযুক্ত: probe hints কেবল আবিষ্কার-চেষ্টার ক্রম বদলাতে পারে (এক জায়গায় লেখা, পাঁচে পড়া, সবই আবিষ্কারের ভেতরে), আর ভেনু-মর্যাদা, কেবল নির্বাহিত সোয়াপে অর্জিত ও অলস ক্ষয়ে প্রায় প্রতি সাত ঘণ্টায় অর্ধেক, প্রার্থী-তালিকা সাজিয়ে তারপর ছাঁটে — যা বাদ দেওয়ার পথে রুট-নির্বাচনে পৌঁছায়, এবং কোয়ারেন্টিনের কঠোরতর রূপ তাতে টেকে না; ফুটোটি নথিভুক্ত, লুকানো নয়।
Filipino — Ang inilabas na panuntunan ay isang pangungusap — maaaring baguhin ng naaalalang estado kung saan tumitingin ang sistema, hindi kailanman kung ano ang tinatanggap nito — inilapat sa dalawang magkaibang imbakan: ang probe hints ay makakapagpalit lamang ng ayos ng mga pagtatangka sa discovery (isinusulat sa isang lugar, binabasa sa lima, lahat sa loob ng discovery), habang ang venue standing, na kinikita lamang ng mga naisagawang swap at humahati sa kalahati humigit-kumulang bawat pitong oras sa pamamagitan ng tamad na pagkabulok, ay nagraranggo at pagkatapos ay pinuputol ang listahan ng kandidato — na umaabot sa pagpili ng ruta sa pamamagitan ng pagkakaligta, at ang mas matibay na pormulasyon ng quarantine ay hindi nakakaligtas doon; ang butas ay nakadokumento, hindi itinatago.
A protocol that remembers anything has an adaptive component, and an adaptive component needs a stated boundary: what remembered state is permitted to influence, and what it must never touch. The rule we shipped is one sentence — remembered state may change where the system looks; it must not change what it accepts — and the useful part of this article is the account of where our own version of that rule leaks, because it does.
There are two distinct pieces of remembered state in the protocol and conflating them would let a guarantee that holds for one be read as covering the other. They are described separately below, strongest boundary first, and the difference between the two boundaries is the whole content.
Probe hints: the boundary that holds
The protocol remembers a small amount of state about singleton venues, whose pools cannot be enumerated the way an ordinary factory's can. We call these probe hints. What is worth publishing about them is not what they learn but what they are permitted to do: a hint can only cause the discovery layer to try a particular configuration first. It never enters pricing, never enters allocation, and never narrows the candidate set.
That claim is worth exactly as much as the tracing behind it, so: the value is written in one place and read in five, all of them inside discovery, and it appears in no other file. The verification is a trace of every read and write of the value across the entire source, which is a cheap and complete method for a quantity that appears this rarely, and a method a reviewer can repeat.
The worst case therefore has a shape rather than a magnitude. A wrong hint costs a couple of wasted probes. A deliberately poisoned one can, in the narrow case where a dust pool gets admitted, suppress the broader cold-start search for that pair — which starves the route of candidates rather than steering it to a bad one. Stated in one sentence: a probe hint cannot misprice a venue and cannot remove one from consideration; it can only change the order in which venues are tried.
Venue standing: earned only by being routed through
The second piece is a reputation for every trading venue the protocol has used. It is maintained entirely on-chain and needs no oracle, no keeper, no token and no vote. A venue's standing rises when a swap actually executes through it; the counter is written in exactly one place, only by the router, and only on the success path — so standing cannot be bought, declared, or granted. It is a record of work the protocol itself performed.
Standing also decays with wall-clock time, halving roughly every seven hours, so a venue that stops being used falls to nothing in about nine days. The decay is applied lazily, when the value is next read, which is why maintaining it costs nobody anything and requires no periodic transaction. A protocol that needs a keeper to age its own state has bought a dependency; this one ages by arithmetic.
What standing is allowed to decide is where the guarantee starts and where it stops. It does not enter a quote, does not enter the floor, does not weight the split between legs, and does not move a token — every one of those is computed from measurements taken during the transaction itself, and each read of the value was traced to confirm it. What it does decide is the candidate set: which venues occupy the limited registry slots for a pair, and the ranking used to select the top candidates before pricing begins.
The leak: truncation reaches route selection by omission
That selection truncates, and truncation is where the stronger formulation dies. A venue with low standing is not priced badly; it is not priced at all. The attractive claim — that remembered state affects only how much work is done, never which route is taken — does not survive, because the option that was never scored cannot win. Memory reaches route selection by omission rather than by distortion.
The quarantine is nonetheless real and the distinction is the useful part: nothing a user receives is computed from remembered state, so an adversary who corrupts standing changes which venues are considered without being able to alter what any of them pays. Standing cannot misprice a venue. It can hide one. Those two sentences are the honest boundary, and the second is the one that gets left out of comparable descriptions elsewhere.
This is also the general shape of the failure, worth carrying to any system with a learned component. A boundary drawn around "search" leaks unless the guarantee is stated over the full set of options rather than over the surviving ones. Our boundary is enforced by construction and by convention, not by a specification a machine checks, and the next such boundary is likely to leak in a way we have not anticipated either.
probe hints -> ordering of discovery attempts only (cannot hide a venue)
standing -> registry occupancy + ranking + truncation (CAN hide a venue)
-> quote, floor, split weights, transfers (never)
the guarantee holds over the SURVIVING candidate set.
it does not hold over the FULL set of venues that exist.Where the ranking is weak, stated in full
The quarantine holds. The ranking inside it does not hold as well, and this is the most substantial open weakness we know of in the protocol, so it is stated with its mechanism rather than as a caveat.
A venue's address is never authenticated. When a swap executes, the venue address credited with standing is taken from the route the caller supplied and passed into the registry untouched, with no check against a factory, a registry entry or a derived address. The pair it is credited under is likewise taken from the caller's own description of the hop, and the depth recorded for it is measured by calling the caller-supplied address itself. A contract that merely behaves like a pool can therefore introduce itself, choose which pair it competes in, and report its own depth.
The ranking then makes eviction hard to reverse. Standing saturates at a large ceiling while the depth term is capped at a much smaller one, and a newcomer is scored with the minimum standing — so a newcomer's best possible score is the depth cap alone, and any incumbent above roughly four fifths of that ceiling can no longer be displaced by any newcomer, however deep. Standing is bought with swaps, and swapping against a pool you own costs only gas, since you are the counterparty to your own fee and your own slippage.
And the same activity suppresses the search for alternatives. A registry with a few recently-stamped venues counts as fresh, and a fresh registry skips the discovery sweep entirely. Manufacturing standing therefore also reduces the chance that genuine venues are ever looked for — the same silence, exploited twice.
Why a count is a weak observable
Standing is a count of events, and a count is a sum, so its blind spot is exactly the blind spot of a sum: every rewriting of the multiset of swaps with the same cardinality is invisible. Who swapped, how much, against whom, and whether the counterparty was the pool's own operator are all outside the observable. Depth enters only through coarse bucketing, so an order of magnitude of real depth is a single bit and everything inside a bucket is indistinguishable. And for most venue kinds the depth is read by calling the caller-supplied address, so the witness itself is attested rather than measured.
A handful of self-dealt touches per decay window keeps the score maximal at negligible cost. Note what has happened structurally: a quantity with no relation to value at all has a blind spot that reaches value, because it edits the candidate set on which the value guarantees are subsequently proved. That is the generalisable warning. An admission mechanism does not need to be part of the value computation to determine the outcome of the value computation.
The bound on the damage, and the bound on the bound
What limits the exposure is that nothing downstream of ranking reads standing. The output floor, the user's own minimum and the believability band are all computed from measurements taken during the transaction, so a captured registry cannot alter what any venue is judged to have paid. The principal is not reachable.
But the honest bound is not "cannot touch user funds". A captured slot controls both the quote it advertises and the fill it delivers, so it can consume the entire gap between the honest quote and the user's own minimum. The exposure is the user's slippage tolerance, not their principal — which is precisely why the mandatory non-zero minimum is not a formality, and why an interface that sets a loose minimum on a user's behalf is a larger risk than any of the mechanisms described here.
That two-clause form is the shape we would ask any protocol to publish beside a learned component: this guarantees X; it permits Y and Z. It is a discipline rather than a discovery, and it is uncommon in this industry mainly because the second clause is the one that costs something to write.
Three transfers to systems with a learned component
These are offered as transfers rather than results — what our evidence suggests, at the strength our evidence supports, each with the objection that limits it.
The quarantine: remembered state may change where a system looks; it must not change what it accepts. The objection is our own leak — ranking a candidate set by remembered state and then truncating it does change the outcome, so the guarantee has to be stated over the full option set rather than over the survivors, and ours is enforced by construction rather than by a checked specification.
The relational check: when no single output can be declared correct, state what the answer must not depend on. "What this participant is owed must not depend on who else acted in the same window" is the form that closed most of our disclosed defects; "the answer must not depend on what shared its batch" is the same form elsewhere. The objection is that this only falsifies relations somebody thought to write down, so it inherits the problem it was brought in to solve.
The seam: fail open where the system is only predicting, and fail closed where it is acting — with the guard computed from measured state rather than from the system's own report of what it did. The objection is that for this to be a property rather than an aspiration, the seam has to be an actual place in the code, and in most architectures the boundary between deciding and doing is not one. In ours it is: read paths versus the execution frame, which is why the rule is auditable line by line here and may not be elsewhere.
Do not trust this page — reproduce it
Every claim above is checkable against the chain. Start here:
trace it the way we did: find every read and every write of the remembered value in the source, and check whether any of them feeds a quote, a floor, a split weight or a transfer — then check separately whether any of them feeds a ranking that is subsequently truncatedCite this article
Licensed CC BY 4.0 — quote, translate and reuse freely, including commercially, with attribution and a link. Copy a ready-made citation:
BlazePhoenix (2026). Memory and measurement: what learned state may change, and what it may never touch. BlazePhoenix Engineering. https://blazephoenix.xyz/learn/learned-state-boundary@misc{blazephoenix_learned_state_boundary,
title = {Memory and measurement: what learned state may change, and what it may never touch},
author = {BlazePhoenix},
year = {2026},
url = {https://blazephoenix.xyz/learn/learned-state-boundary},
note = {Accessed: reproduce the claim with the command above}
}Writing an answer, a wiki entry or a paper? The claim above is reproducible against the chain before you quote it — which is the only sound basis for citing a technical source at all.
Contracts are verified on every chain we deploy to — addresses in the protocol manifest. Deeper formal treatment: the whitepaper (PDF).
Share this article · join the discussion