TWIX MAINNET · HARDENED COSMOS EVM STACK

Hardened at the stack.
Not just at the firewall.

TWIX Mainnet combines perimeter isolation with a complete Cosmos EVM remediation program. The August 2026 module review identified 15 security and reliability targets across precompiles, tracing, gas, ERC20 semantics, EVM/Cosmos rollback, IBC, WebSockets, profiling and long-lived workers. The upgraded TWIX stack completed the defined qualification program with 15 of 15 targets passing.

HARDENED QUALIFICATION · 15/15 PASSCOSMOS + EVMCROSS-RUNTIME TESTINGIBC FAILURE INJECTION
REMEDIATION QUALIFICATION15 / 15PASS

What this means: every remediation target defined from the security review passed the TWIX hardened-stack qualification criteria after the upgrade. What it does not mean: no software can honestly be declared permanently vulnerability-free; continued review, regression testing, monitoring and validator decentralization remain part of the security model.

HARDENING DOMAINS

Five boundaries received direct attention.

The highest-risk area was the boundary where EVM execution touches Cosmos SDK state, accounting, conversion, callbacks and IBC.

PRECOMPILES & AUTHORITY

Fail closed.

Registration validation, production allowlisting and consistent capability state reduce phantom or over-broad stateful precompile exposure.

GAS & RESOURCE CONTROL

Bound the work.

Gas accounting, trace limits, timeout controls and native-work pricing are treated as consensus and availability concerns—not performance afterthoughts.

CROSS-RUNTIME ATOMICITY

Failure means rollback.

Failed EVM paths, native hooks, conversion flows and IBC callbacks are exercised with failure injection so state transitions remain intentional and locally atomic.

SEMANTICS & RELIABILITY

One rule everywhere.

ERC20 behavior, disabled-pair policy, virtual-fee metadata and txpool worker error handling were hardened to remove ambiguous or panic-prone states.

PUBLIC ATTACK SURFACE

Expose only what users need.

Unsafe Comet methods, admin/personal/debug/trace/txpool namespaces and raw backend services are excluded from the normal public launch surface.

VALIDATOR BOUNDARY

Consensus security and application services stay separate.

Public validator metadata is intentionally visible. Consensus signing material is not.

CONSENSUS VALIDATORS

Public operator state

Operator address, bonded stake, commission, staking status and jail status are public chain data. TWIX exposes them through the validator directory and Explorer.

DATA ATTESTATION

Separate application keys

The service at validator.twixchain.com uses device Ed25519 keys and a separate EVM anchoring wallet. It never needs the consensus validator private key.

PUBLIC EDGE

Production exposure stays deliberately narrow.

Comet unsafe RPCDISABLED

/dial_seeds, /dial_peers and /unsafe_flush_mempool reject public access.

EVM admin / personalDISABLED

No public node administration or local-account unlock surface.

Debug / trace / txpoolDISABLED

Diagnostic and high-resource namespaces are not part of the normal public RPC surface.

Unprotected EVM txsREJECTED

allow-unprotected-txs = false.

Insecure unlockOFF

allow-insecure-unlock = false.

Public raw backend portsCLOSED

Wallet/developer traffic terminates at TLS virtual hosts rather than exposing validator service ports.

Batch JSON-RPCCAPPED

Public EVM batch request limit is bounded.

CONTINUOUS OPERATIONS

Qualification is a checkpoint, not an endpoint.

CONSENSUS

Height + signing

Watchdog checks chain identity, height advancement, catching-up state and validator signing height.

SERVICES

Listeners + process

Checks the twixd service and expected local listeners without opening internal services publicly.

HOST

Disk + memory

Operational checks include disk and available-memory thresholds plus service restart counts.

Security claim boundary: 15/15 is the result of the defined remediation qualification, not a promise that defects can never exist. TWIX continues to treat source review, failure-injection testing, monitoring, validator diversity and TWIX Lock dogfooding as ongoing work.