{
  "tool_id": "art-494-icm-quorum-forgery-classifier",
  "kernel_id": "art-494-icm-quorum-forgery-classifier",
  "display_name": "ICM Quorum Forgery Classifier",
  "tool_version": "1.0.0",
  "mandate_type": "analytics_mandate",
  "purpose": "Computes the smallest set of a source Avalanche L1's validators that could jointly sign an Interchain Messaging (ICM / Avalanche Warp Messaging) message the receiving L1 would accept: sorts the caller-transcribed stake weights descending, prefix-sums them, and returns the count at which the receiving chain's accepted stake-weight quorum is first satisfied, alongside that group's cumulative share, an HHI-style stake concentration figure, and a verdict against a caller-declared minimum-colluding floor. Quorum semantics follow avalanchego's Warp signature check (signed weight times 100 greater than or equal to total weight times the quorum percentage), evaluated cross-multiplied so no division rounding moves the boundary. The accepted quorum is a caller input with no baked-in default threshold, because it is the receiving chain's own acceptance policy for that source rather than a statutory number, following the precedent art-445 sets by refusing to bake in a concentration limit. Avalanche finality is sub-second with no reorg window, so the challenge-window arithmetic that applies to optimistic bridges does not transfer; this node picks up where that risk relocates, namely who signed the cross-chain message. Borrows only the art-445 helper pattern (fixed-point 2dp rounding, share-of-total, finite gate, NaN-safe coercion); art-445 computes top-N and per-sector rollups and does not compute a minimum-colluding set. Observes no chain: no RPC call and no P-Chain query, with the validator set transcribed by the caller as opaque identifiers. Zero network, zero PII.",
  "control_description": "Computes the smallest set of a source Avalanche L1's validators that could jointly sign an Interchain Messaging (ICM / Avalanche Warp Messaging) message the receiving L1 would accept: sorts the caller-transcribed stake weights descending, prefix-sums them, and returns the count at which the receiving chain's accepted stake-weight quorum is first satisfied, alongside that group's cumulative share, an HHI-style stake concentration figure, and a verdict against a caller-declared minimum-colluding floor. Quorum semantics follow avalanchego's Warp signature check (signed weight times 100 greater than or equal to total weight times the quorum percentage), evaluated cross-multiplied so no division rounding moves the boundary. The accepted quorum is a caller input with no baked-in default threshold, because it is the receiving chain's own acceptance policy for that source rather than a statutory number, following the precedent art-445 sets by refusing to bake in a concentration limit. Avalanche finality is sub-second with no reorg window, so the challenge-window arithmetic that applies to optimistic bridges does not transfer; this node picks up where that risk relocates, namely who signed the cross-chain message. Borrows only the art-445 helper pattern (fixed-point 2dp rounding, share-of-total, finite gate, NaN-safe coercion); art-445 computes top-N and per-sector rollups and does not compute a minimum-colluding set. Observes no chain: no RPC call and no P-Chain query, with the validator set transcribed by the caller as opaque identifiers. Zero network, zero PII.",
  "declared_inputs": [],
  "declared_outputs": [],
  "kernel_digest": "sha256:5d1204c5f516f5975687ac3d86c9f9325f1fbac2071cfebf14f55f33094d7c7f",
  "trust_label": "independently verified: zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-07-31",
  "last_validated": "2026-07-31",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 78,
  "source_url": "https://ainumbers.co/chaingraph/art-494-icm-quorum-forgery-classifier.html",
  "generated_at": "2026-08-15T11:12:17.704Z"
}
