SEALED PASSPORTS ON MONAD MAINNET (read back from the chain and the live screens on 2026-09-22) The first sealed passport was registered from the live studio on 2026-09-22 at 12:23:50 UTC, the same evening the sealed flow went live, by a person signing in with a passkey. Moolam holds no copy of the picture: the passport's document on IPFS (ipfs://bafkreifkvld3vxondgeacbbzayovnoua...) carries the keys name, description, sealed, commitment, fingerprint, generator, training, createdAt and model, and no image, thumbnail or manifest key. The chain commits to the file through the passport id, which is the file's SHA-256. passport 0x980549624f85e4ef47043383c5a746cbdd1d82797b5b5583e1f5aeb3841d010c title Old but strong (drawn by the demo agent, 10249, from the creator's prompt; the prompt was not published) holder 0x551610a063BcAd79e6bd25dc55cEe92Ba3FD960a registered block 107,034,322 statement consentOf -> true (1790079837 [1.79e9], 0x551610a063BcAd79e6bd25dc55cEe92Ba3FD960a, (1, 1, 1, 1), "") What the live site shows for it, checked from outside the same hour: /en/passport/ 200: the sealed plate drawn from the block hash, "The picture is not published", the commitment where the picture's addresses would be, "No public copy to re-check" in the second-opinion section, and the holder's "Publish the picture" control /en/passport//opengraph-image 200 image/jpeg, 65,298 bytes: the sealed card with the sketch /en/explore the plate carries the S mark, aria-label "Sealed: this picture was never published" POST /recheck/request 409 sealed: a re-check needs a public picture, so the queue refuses it GET /recheck/status/ {"status":"none"} What this did not prove when it was written: the unseal path, which needs the holder's saved file and their passkey. THE SAME PASSPORT, UNSEALED BY ITS HOLDER (read back on 2026-09-23 by proofs/attacks/pass-3.txt, 5e) Four minutes after it was registered, the holder published the picture through the unseal route with the signed file the studio had handed back. The verify service checked that the file's SHA-256 equals the passport id and that its fingerprint equals the chain's, then pinned it publicly with a record beside it. The sealed document on chain is unchanged (it cannot be rewritten); the record is what says the picture has been published since, and every screen reads the two together. unsealed at 2026-09-22 12:27:28 UTC, by 0x551610a063BcAd79e6bd25dc55cEe92Ba3FD960a (the chain's holder) image ipfs://bafybeidrcahmf3caddcuiqzphufwhhn2t6pnb4og5mr6s4gsqpo3zt2g4e thumbnail ipfs://bafkreigwx2nxhx7uotk6kzevdjwkakowu4al6rt6tetra447xoxpdmcpri manifest ipfs://bafkreiejiqnq7tvpn2bnrzjt4x4yz2wop22f2fqquy4b7s2jlehljorhvi record ipfs://bafkreibms3wx5anhjntthlm32trbgfw3zuqdsno3ppalz6wdz6zoyi4npi /en/passport/ 200: the picture is drawn from the record's image address, and no other IPFS picture address appears in the page THE FIRST CHAINLINK RE-CHECK OF A PICTURE THAT WAS SEALED FIRST (2026-09-23) On the morning of 2026-09-23 the re-check queue still refused this passport as sealed, because it read only the sealed document (proofs/attacks/pass-3.txt, 5g). Fixed the same day in commit d07df6e (the queue) and 9ae539c (the workflow and the runner read the unseal record). The same hour the workflow re-checked it on Monad mainnet: it read the unseal record, fetched the published thumbnail through Moolam's own gateway, and recomputed 0x1f1bc103fbef6f47 against the stored 0x1f1fc003fbef6f47, distance 2, matched. Report transaction 0x48aa75431f6f564ad8dd53806d7723ec397adca25ddb21f5e8e3eb0888f96ce0, block 107,264,854, through the simulation forwarder: one machine, no network consensus. The full row is in proofs/rechecks.txt. THE FIRST PRIVATE CHAINLINK RE-CHECK (2026-09-25) A picture registered sealed with the private re-check asked for, so it has never been published: Moolam keeps one 512 pixel copy on private storage, and nothing of the picture is in the public document. passport 0x864c33c6806185d4dc7acd65f465fc4c3cb6b8faaa157c32880cbef9dd93fc09 registered 2026-09-23 08:56:16 UTC, block 107,279,096, tx 0x2638f75034e20bc625deb82c04e38a7f5b2cdbaf86b2172ead4d137f1bc9cc5e document ipfs://bafkreigicd2yhmc4x7a72hgmpzafzxajrxejyckx6s7lx4crkkxvhs3lwy (sealed, privateRecheck, no link of any kind in it) The moolam-sealed-verifier workflow, registered with handlerInTee, ran in Chainlink's simulator with --broadcast. The queue held a claim on the passport; under that claim the verify service minted one read link that lived 120 seconds; the workflow opened the 25,349 byte private copy through it, recomputed the fingerprint and wrote only the verdict: recomputed 0x2ac1e07e3e80c4e6 against the stored 0x2ac1e07e3ea0c4e6, distance 1, matched report tx 0xdc1834ea3d801fd965433dfefe02a70e7f06889655dceb7934d4668f9b790bef, block 107,817,793, status 1 delivered by the simulation forwarder 0x9eF6468C5f37b976E57d52054c693269479A784d: one machine, no network consensus, and Chainlink's simulator is not a real enclave written by the sealed receiver 0x7b9eF7cD5e40Af9c29d8b7d0D22E54B80947E45A, listed in the policy on 2026-09-25 (tx 0x79d34b81ce94d4a21b10277a70d656b4588360e232839e0e25a16edf91687380) after its 24 hour wait, so the registry's own record says which workflow wrote this verdict The link, the service's address and the tokens appear in no log of the run; the receiver was put back on the production forwarder and pinned to its workflow afterwards, read back from the chain. THE SHOWCASE PRIVATE RE-CHECK (2026-09-25) A picture drawn by the demo generator agent (10249) from its creator's prompt and registered sealed with the private re-check. The prompt was not published, and the pinned document says in its own words that Moolam keeps only a small private copy for this re-check, which the holder can delete. passport 0xe83680b22c24e491f91077162804b862a6b821ac74f49b9b2d21a04864c485e4 title Kanchipuram Silk Loom at First Light registered 2026-09-25 07:20:34 UTC, block 107,831,859, tx 0xcf4a9a66d5d439979db8e9805209ff1b0867ace41b335d6cb7ed2df57ea8e207 document ipfs://bafkreiaekkzygi2c7wgjpurmaeigtvjgkjlv75cblqgrd6favqeeeiwehy (sealed, privateRecheck, generator 10249, no link of any kind, no prompt) private copy 35,599 bytes, opened through one link minted under the queue claim recomputed 0x85c0d272787e6e77, the stored fingerprint exactly: distance 0, matched report tx 0xa38fd971c8ac0303f4e787e45f1b2b3203ffc8a01c864ffa50843d8fbd72c954, block 107,834,613, status 1 delivered by the simulation forwarder 0x9eF6468C5f37b976E57d52054c693269479A784d: one machine, no network consensus, not a real enclave written by the sealed receiver 0x7b9eF7cD5e40Af9c29d8b7d0D22E54B80947E45A, closed and pinned again afterwards