PoolManager; hostile token contracts are
isolated negative fixtures. Source-only coverage is 99.32% lines, 96.95% statements,
84.62% branches, and 100% functions.
The suites
The suite contains 29 fuzz properties. A high-depth run passed 10,000 runs per property.
Two three-member fuzz properties compare exact-input and exact-output front/victim/back portfolios
with the identical plain-pool route. Profitable KNOT routes do exist in arbitrarily skewed pools;
the checked property is only that KNOT did not amplify positive extraction in the sampled cases.
Each portfolio starts from its own copy of the sampled state: sharing one memory state across
both runs once compared the plain route against reserves the KNOT legs had already moved.
This is randomized evidence, not a universal theorem.
Five stateful invariants passed 163,840 calls with zero handler reverts.
How each MEV class is answered
This is the part that matters for the theme, so it is stated attack by attack rather than as a claim about the mechanism in general.Why donation immunity is structural
A donation can move a quote only when that quote source observes unsolicited token balances. Knot does not. Its reserves live inKnotFederation and move only when a registered member reports
a completed swap or liquidity change.
That is an immunity rather than a cost, which matters: a cost falls when capital is cheap, and a
flash loan makes capital free.
Determinism
Knot reads no oracle, keeper or off-chain input when selecting a quote. The quote is a function of two reserve books and the swap arguments, so the same state and arguments produce the same output. Block number is used elsewhere for LP maturity.test_ordering_quoteIsIndependentOfEveryBlockLevelSignal
pins down the narrower quote property by moving gas price, base fee, coinbase, block number,
timestamp and prevrandao at once and asserting the quote does not budge.