Fail closed.
Registration validation, production allowlisting and consistent capability state reduce phantom or over-broad stateful precompile exposure.
TWIX Mainnet combines perimeter isolation with a complete Cosmos EVM remediation program. The August 2026 module review identified 15 security and reliability targets across precompiles, tracing, gas, ERC20 semantics, EVM/Cosmos rollback, IBC, WebSockets, profiling and long-lived workers. The upgraded TWIX stack completed the defined qualification program with 15 of 15 targets passing.
What this means: every remediation target defined from the security review passed the TWIX hardened-stack qualification criteria after the upgrade. What it does not mean: no software can honestly be declared permanently vulnerability-free; continued review, regression testing, monitoring and validator decentralization remain part of the security model.
The highest-risk area was the boundary where EVM execution touches Cosmos SDK state, accounting, conversion, callbacks and IBC.
Registration validation, production allowlisting and consistent capability state reduce phantom or over-broad stateful precompile exposure.
Gas accounting, trace limits, timeout controls and native-work pricing are treated as consensus and availability concerns—not performance afterthoughts.
Failed EVM paths, native hooks, conversion flows and IBC callbacks are exercised with failure injection so state transitions remain intentional and locally atomic.
ERC20 behavior, disabled-pair policy, virtual-fee metadata and txpool worker error handling were hardened to remove ambiguous or panic-prone states.
Unsafe Comet methods, admin/personal/debug/trace/txpool namespaces and raw backend services are excluded from the normal public launch surface.
Public validator metadata is intentionally visible. Consensus signing material is not.
Operator address, bonded stake, commission, staking status and jail status are public chain data. TWIX exposes them through the validator directory and Explorer.
The service at validator.twixchain.com uses device Ed25519 keys and a separate EVM anchoring wallet. It never needs the consensus validator private key.
/dial_seeds, /dial_peers and /unsafe_flush_mempool reject public access.
No public node administration or local-account unlock surface.
Diagnostic and high-resource namespaces are not part of the normal public RPC surface.
allow-unprotected-txs = false.
allow-insecure-unlock = false.
Wallet/developer traffic terminates at TLS virtual hosts rather than exposing validator service ports.
Public EVM batch request limit is bounded.
Watchdog checks chain identity, height advancement, catching-up state and validator signing height.
Checks the twixd service and expected local listeners without opening internal services publicly.
Operational checks include disk and available-memory thresholds plus service restart counts.