# Ante Vaults

Commitments beyond a lifetime

Ante Vaults lets you securely commit funds to a designated recipient if a dead man's switch fails.

## Sign up for updates: [Ante.org](https://ante.org)


# How it Works

Ante Vaults lets you securely commit funds to a designated Recipient if a dead man's switch fails.

#### 1. Set up and fund your vault

Designate a recipient for your funds and assign trusted guardians to carry out your will.

<figure><img src="https://3625867833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FMkTsRaI2jBZJJikq4M3p%2Fuploads%2FZqzjI8IJzu1x2nTjTwHz%2FHIW1.jpg?alt=media&amp;token=f61e8495-f6a8-48a1-870d-3b5ca356787c" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Built on battle-tested [Safe](https://safe.global/) contracts/modules
{% endhint %}

#### 2. Check in periodically to confirm you're still in control

<figure><img src="https://3625867833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FMkTsRaI2jBZJJikq4M3p%2Fuploads%2FcGIVOOr855tmwrZeSSTc%2FHIW2.jpg?alt=media&amp;token=2c29bc3e-0115-405a-b232-c745b6163619" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
You maintain control of your funds and can always recover them, even if Ante disappears!
{% endhint %}

#### 3. If something happens, your guardians step in

If you stop checking in, your guardians can start the handoff process and securely transfer your assets to your recipient after a grace period.

<figure><img src="https://3625867833-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FMkTsRaI2jBZJJikq4M3p%2Fuploads%2FYIn4zSsiNm8Td349AlIx%2FHIW3.jpg?alt=media&amp;token=a0fdf174-8185-45ef-82cb-334fc2bd4b74" alt=""><figcaption></figcaption></figure>


# Security & Trust

## Security

For any security-related questions, feel free to contact us at <security@ante.org>.

### Infrastructure security <a href="#infrastructure-security" id="infrastructure-security"></a>

We depend on the following subprocessors, roughly organized from most critical to least. Note that code data is sent up to our servers to power all of Cursor’s AI features (see [AI Requests section](https://www.cursor.com/security#ai)), and that code data for users on privacy mode (legacy) is never persisted (see [Privacy Mode Guarantee](https://www.cursor.com/security#privacy-mode-guarantee) section).

Explore how each mode affects how data is sent and stored.

* [AWS](https://aws.amazon.com/):

  Our infrastructure is primarily hosted on AWS, with servers located in the US, and backup servers distributed in Europe and Asia.
* [Google Cloud Platform (GCP)](https://cloud.google.com/):

  Some secondary infrastructure is hosted on Google Cloud Platform (GCP). All of our GCP servers are in the US.
* [MongoDB](https://mongodb.com/):

  We use MongoDB for some of our analytics data, for users who do not have privacy mode enabled.
* [Amplitude](https://amplitude.com/):

  We use Amplitude for some of our analytics data. No code data is stored with Amplitude; only event data such as "number of Antes creation attempts".
* [Slack](https://slack.com/):

  We use Slack as our internal communication tool. We may send snippets of prompts of non-privacy users in our internal chats for debugging.
* [Google Workspace](https://workspace.google.com/):

  We use Google Workspace to collaborate. We may send snippets of prompts of non-privacy users in our internal emails for debugging.
* [Linear](https://linear.app/):\
  We use Linear to track issues and collaborate.

### Vulnerability disclosures <a href="#vulnerability-disclosures" id="vulnerability-disclosures"></a>

If you believe you have found a vulnerability in Ante, please submit the report to <security@ante.org>

We commit to acknowledging vulnerability reports within 10 business days, and addressing them as soon as we are able to.&#x20;

## Trust Assumptions

#### Ante

Ante Vaults is a software interface that enables onchain crypto inheritance and asset recovery without centralized custody. Ante never holds, stores, generates, or has access to a user’s private keys, key shares, or assets at any point. Ante does not have control over any user accounts (wallets or Safes) and has no ability to steal or recover funds from user wallets or Safes.

If the Ante app goes down, users can still access and withdraw funds from their vaults via 3rd-party interfaces. We recommend saving the Recovery Kit with instructions for doing so (access from your Vault Details page after creating a vault).

#### Privy

We use [Privy](https://docs.privy.io/) to generate wallets for people using email or other authentication methods. Privy is an MPC (multi-party computation) wallet where private key material is split between the user’s device and Privy’s infrastructure.

1. If you sign up via email and do not set up a backup, theoretically Privy could steal funds from your vault. This could be achieved by introducing malicious code into the Privy codebase.
   1. In order to avoid this users should back up their account or set a passphrase AND they should also export their embedded wallet and keep the PK safe

#### Guardians & Recipients

1. Guardians and Recipient could collude to prevent the owner from checking in order to withdraw funds from a vault
   1. Recommendation: don't tell your Guardians/Recipient who other Guardians/Recipient are.
2. A malicious or inactive Guardian(s) could delay asset handoff indefinitely by never approving the handoff after the Dead Man's Switch fails.
   1. Recommendation: Ask your Guardians to check in periodically so you know they are able to carry out the handoff, and rotate out Guardians if you don't trust them to approve handoff. Assign more than one Guardian so that a single inactive/malicious Guardian can't delay handoff indefinitely (e.g., 2 of 3 or 3 of 5)
3. If a vault has multiple owners, each owner implicitly trusts all the other owners of the vaults
   1. Recommendation: only co-own vaults with people you trust to have full control over the vault
4. If you set the wrong address as a Recipient, you could end up handing off assets to the wrong person
   1. Recommendation: Verify with your chosen Recipient that they have control of the email or wallet you specify and update if necessary.
5. If you don't set token allowances for the tokens you want to transfer to your Recipient, the tokens won't be handed off
   1. The Ante app will let you know if you have tokens allowances missing, but we recommend double checking as well in the Recipient settings.

#### Others

1. Email provider — email accounts are only as safe as you keep your email account
   1. Recommendation: [Set up two-factor authentication](https://frameworks.securityalliance.org/community-management/google#configure-2fa) (2FA) on your email account, ideally using a hardware security key or authenticator app (avoid and disable SMS 2FA)
2. External interfaces — e.g. if you use the Safe{Wallet} interface or Etherscan to interact with Ante Vaults, you trust the source of the interface being loaded
   1. Recommendation coming soon.


# Privacy

How Ante collects, uses, and discloses information when you use the Ante Vaults app and related services.

### Authentication and Email Addresses

We use [Privy](https://www.privy.io/) as our authentication and embedded wallet provider.

If you connect or authenticate using an email address, your email address may become associated with your wallet address through Privy's services and our application.

We use email addresses primarily for:

* authentication
* account recovery
* security notifications
* transactional or vault-related notifications

We do not publicly display email addresses (see [details](#vault-participant-visibility) below).

***

### Vault Participant Visibility

Email visibility inside the application is intentionally restricted.

Depending on a user's role within a vault, limited participant information may be visible to other authorized participants.

<table><thead><tr><th width="128.40625">Role</th><th>Can view</th><th>Cannot view</th></tr></thead><tbody><tr><td><strong>Vault owner</strong><br></td><td>Guardian email addresses<br>Recipient email address</td><td></td></tr><tr><td><strong>Guardians</strong><br></td><td>Vault owner email address<br></td><td>Other guardians' email addresses<br>Recipient email address</td></tr><tr><td><strong>Recipient</strong></td><td>Vault owner email address</td><td>Guardian email addresses</td></tr><tr><td><strong>Anyone else</strong><br><br></td><td></td><td>Vault owner email address<br>Guardian email addresses<br>Recipient email address</td></tr></tbody></table>

***

### Analytics and Usage Data

We use [Segment Analytics](https://www.twilio.com/en-us/segment) to understand how the application is used and to improve the user experience.

We may collect limited interaction data, including:

* application version,
* page or URL where an action occurred,
* interaction or event type (such as button clicks or transaction submissions),
* vault address and blockchain network/chain ID where applicable,
* a Privy user identifier.

Segment may automatically collect additional technical metadata associated with requests, such as browser type, device information, timestamps, and approximate location derived from IP address. More information is available in the [Segment tracking documentation](https://www.twilio.com/docs/segment/connections/spec/common?utm_source=chatgpt.com#context).

We do not use analytics data to directly identify users by real-world identity.

***

### Blockchain Data

Because the app and services interact with public blockchains, certain information is inherently public and permanently accessible, including:

* wallet addresses,
* submitted transactions,
* smart contract interactions,
* blockchain balances and activity.

We do not control how third parties index or process publicly available blockchain data.

***

### Third-Party Services

We rely on third-party infrastructure and service providers to operate the app and services. These providers may process certain technical or account-related data on our behalf.

Current providers may include:

* [Privy](https://www.privy.io/) for authentication and wallet services,
* [Segment](https://www.twilio.com/en-us/segment) for analytics and product telemetry.

These providers maintain their own privacy policies and data handling practices.


# FAQs

Have a question not answered here? Send us a message at <hello@ante.org>

<details>

<summary>What is Ante Vaults? What problem does it solve?</summary>

Ante Vaults solves the biggest risk with self-custody (losing access to your funds forever) by letting you securely pass on your self-custodied crypto to a recipient if something happens to you.

</details>

<details>

<summary>Which network is Ante Vaults on?</summary>

Ante Vaults is live on Ethereum.&#x20;

</details>

<details>

<summary>How often do I need to check in?</summary>

You can choose a check-in frequency that works for you (default 6 months). Ante will remind you when it's time to check in.

</details>

<details>

<summary>What happens if I forget to check in or something happens to me?</summary>

If you miss a check in, your guardians can start the handoff process. If you still haven’t checked in during the grace period, the handoff finalizes and your assets move to your recipient. Checking in at any point before the handoff completes cancels the process.

</details>

<details>

<summary>Can my guardians steal my crypto?</summary>

No, guardians can only act if your dead man’s switch fails, after the grace period, and can only transfer your digital assets to your designated Recipient.

</details>

<details>

<summary>Can Ante ever take my funds?</summary>

No, Ante never holds or controls your assets and your crypto always stays in your control. Everything runs on audited Safe contracts that secure billions in assets.

</details>

<details>

<summary>What if Ante Labs shuts down? Do I lose access to my crypto?</summary>

You’ll still have full access to your crypto. Each vault includes a Recovery Kit, a step-by-step guide to access or transfer your assets directly. Ante is fully non-custodial so your funds never depend on the app being online.

</details>

<details>

<summary>Can I change my vault settings later if I choose to?</summary>

Yes. You can update your guardians, recipient, or check-in settings anytime.

</details>

<details>

<summary>Why should I use Ante instead of custodial services?</summary>

Unlike custody providers that hold your assets and require trust, Ante keeps your crypto fully in your control through non-custodial smart contracts and removes the need to rely on any centralized provider.

</details>


# Technical Stuff

Ante Vaults is currently deployed on the following chains:

| Chain            | ChainId |
| ---------------- | ------- |
| Ethereum Mainnet | 1       |
| Base Mainnet     | 8453    |

The setup for deploying an Ante Vault is as follows:

1. The vault is a multisig Safe deployed using Safe's Safe Proxy Factory (v1.4.1) and owned by the user.

| Chain   | Safe Proxy Factory                                                        |
| ------- | ------------------------------------------------------------------------- |
| Mainnet | <https://etherscan.io/address/0x4e1dcf7ad4e460cfd30791ccc4f9c8a4f820ec67> |
| Base    | <https://basescan.org/address/0x4e1dcf7ad4e460cfd30791ccc4f9c8a4f820ec67> |

2. The Vault deploys the Main Guardian contract (also a Safe multisig), which is owned by Guardian Proxies.
   1. The Guardian Proxies are 1 of 1 Safe multisigs, each of which is owned by an address set by the Holder.
3. The following modules are employed to give the Ante Vault the functionalities that we're currently using:
   1. Scope Guard\
      <https://github.com/gnosisguild/zodiac-guard-scope/blob/main/contracts/ScopeGuard.sol>\
      Scope Guard sets a permission structure on the Guardians of the Guardian Proxies and restricts the Guardian from removing themselves, or executing arbitrary transactions on the Main Guardian contract. They can only call the Guardian Role module with a specific transaction that initiates the handoff.
   2. Delay\
      <https://github.com/gnosisguild/zodiac-modifier-delay/blob/main/contracts/Delay.sol>\
      Delay is a Safe module that adds a time delay for transactions that are sent. This is used in an Ante Vault for the grace period when a handoff has started, queueing the transaction for the contract. Once the delay is over, it enables the Recovery Role.
   3. Roles\
      <https://github.com/gnosisguild/zodiac-modifier-roles/blob/main/packages/evm/contracts/Roles.sol>
      1. Recovery Role\
         Set on the vault once the delay module has completed, this holds the permissions for token transfers from the Vault. The permissions are given to the Recipient and Guardian proxies. The transaction can only have funds sent to the Recipient by limiting it to a specific signature.
      2. Guardian Manager Role\
         Set on the Main Guardian contract, this allows for the Holder to be able to manage the Main Guardian owners and threshold for voting.
      3. Guardian Role\
         This allows only the Main Guardian contract to submit a transaction to the Delay module, but only after the Dead Man Switch (DMS) contract has allowed it to by passing the check-in period.
   4. Dead Man's Switch (DMS)\
      <https://etherscan.io/address/0xb3EEC2e74F6bEF3Fd7362459eB39BD75C5aBCC52#code>\
      [basescan.org/address/0x89E583A67B5FA1B39b8CE7E77654071c3a34cc48](http://basescan.org/address/0x89E583A67B5FA1B39b8CE7E77654071c3a34cc48)\
      **(Coming soon: link to GitHub)**\
      The Dead Man Switch module, written by Ante Labs (`DMS.sol`), handles the check-in intervals for the holder of the Vault. The holder has to execute a transaction every X timeframe in order to signal liveliness. If there is no check in before the check in interval passes, then the holder is considered unable to access their wallet, and Guardian is allowed to submit a transaction to start the handoff.


# Glossary

Key terms used throughout Ante Vaults

1. **Vault**

   A secure onchain vault powered by Safe smart contracts where you store your digital assets under rules you define. Your vault enforces your handoff conditions and provides peace of mind knowing your assets can be passed on securely.
2. **Wallet**

   A non-custodial crypto wallet that connects to Ante allowing you to stay in full control of your digital assets.&#x20;
3. **Guardian**

   A trusted person(s) you designate who can initiate and finalize a handoff to your recipient. You can add as many guardians as you want and set a custom approval threshold. Guardians can only operate within the permissions you’ve set and can’t transfer assets anywhere else.
4. **Guardian approval threshold**

   The minimum number of guardians required to approve a handoff.
5. **Recipient**

   The trusted person you designate to receive your digital assets once the handoff process completes if something unexpected happens to you.
6. **Dead Man’s’ Switch**

   A time-based trigger that requires you to check in periodically to confirm you’re still active. If you don’t check in within your chosen timeframe, your guardians can begin the handoff process to your Recipient.
7. **Check in**

   An action you take to confirm you’re still active. When you create a vault, you choose how often to check in. If you miss a check in, your guardians can begin the handoff process to your recipient.
8. **Check in frequency**

   The time you choose for how often you need to check in to confirm you’re still active.
9. **Grace period**

   The time after a handoff is initiated before your digital assets can be transferred to your recipient. If you check in during this window, the handoff cancels and your vault stays active.
10. **Recovery kit**

    A downloadable guide explaining how to access your digital assets directly if Ante is ever offline.
11. **Non-custodial**

    A form of ownership where only you have control over your digital assets and the private keys that secure them.


# Gnosis hack - Incident report

On June 1, 2026 there was an exploit targeting Gnosis Pay users through a vulnerability in several Zodiac modules. Ante vaults were affected because we are using the same Delay and Roles modules Gnosis Pay used (see <https://docs.ante.org/technical-stuff> for more details).

Total loss across all Ante vaults was about $24 in team test accounts (<0.02% of Assets Under Trust at the time of exploit). Here's what happened, why we were able to limit the damage, and what's next.

### The vulnerability

The exploited bug is in `SignatureChecker._isValidContractSignature` from Zodiac base contracts, inherited by Modifier (<https://github.com/gnosisguild/zodiac/blob/master/contracts/core/Modifier.sol>)&#x20;

```typescript
function _isValidContractSignature(
    address signer,
    bytes32 hash,
    bytes calldata signature
) internal view returns (bool result) {
    uint256 size;
    assembly { size := extcodesize(signer) }
    if (size == 0) {
        return false;
    }

    (, bytes memory returnData) = signer.staticcall( // <-- 'success' boolean is not checked
        abi.encodeWithSelector(
            IERC1271.isValidSignature.selector,
            hash,
            signature
        )
    );

    return bytes4(returnData) == EIP1271_MAGIC_VALUE;
}
```

The staticcall destructuring is not using the first return argument: `(, bytes memory returnData) = signer.staticcall(...)` , which is the `bool success` flag. The function then casts the first four bytes of `returnData` to `bytes4` and compares to `0x1626ba7e` , the EIP-1271 magic value.\
The attacker manipulated the signature field in such a way to force the Safe [fallback handler](https://github.com/safe-fndn/safe-smart-account/blob/main/contracts/handler/CompatibilityFallbackHandler.sol) to call an attacker deployed contract which always reverted with a 4-byte payload matching the EIP-1271 magic value. Because of how EVM handles reverts and the sequence of smart contract calls, the revert data ended up in the `returnData` which was then compared with the magic value.

This allowed the attacker to schedule any transaction on any Safe that had such a Delay module enabled.

### Mitigation

We patched the contracts with this small fix. And deployed new mastercopies for both Roles and Delay modules. This is the same approach that Gnosis Pay took.

```typescript
(bool success, bytes memory returnData) = signer.staticcall(...);
return success && bytes4(returnData) == EIP1271_MAGIC_VALUE;
```

#### Addresses

**Delay.sol**

{% embed url="<https://etherscan.io/address/0xa0A3Eb0C60bbEdAd0d41AbfA2b9C0a8F91f7Ae34>" %}

**Roles.sol**

{% embed url="<https://etherscan.io/address/0x732B9E9f259fbA6f65A1a012DC89c20872ffBd2f>" %}

We shipped UI which allows users to disable the vulnerable modules and provided a way for them to create a new vault with patched recovery modules and migrate the funds into a newly deployed vault.&#x20;

### Why Ante Vaults were not drained?

Our vaults had a default cooldown period of 3 months. Even if the hacker was able to submit a malicious transaction, the exploit did not allow him to bypass the cooldown period.

This gave us and our users enough time to react and disable the vulnerable modules.

## Next steps

If you have a vault created on <https://app.ante.org/vaults> we advise you to go to your Ante Vaults dashboard and check for vaults that are tagged as "vulnerable". Open the vault and follow the instructions from that page to mitigate or migrate.


# Ante Protocol

Ante is a protocol for creating and verifying commitments onchain, letting people coordinate, fund ideas, and protect assets without intermediaries or exposing private information.


# Ante v0.9 Grants

## [grants.ante.xyz](https://grants.ante.xyz)

## :construction\_site: Docs coming soon


# Stake a commitment on Ante.xyz

Put your crypto where your mouth is

### How it works

1. Put your crypto where your mouth is on [Ante.xyz](https://app.ante.xyz/stake)
2. Antes can be settled by 3rd party [judge](/v0.8/stake-a-commitment-on-ante.xyz/settling-an-ante#settlement-by-judge) or [smart contract](/v0.8/stake-a-commitment-on-ante.xyz/settling-an-ante#settlement-by-smart-contract) result
3. Share the Ante with your friends and followers!

{% hint style="warning" %}
**Disclaimer:** Ante.xyz is in **BETA**. Do not stake more than you are willing to lose.
{% endhint %}


# Settling an Ante

Antes can be settled by a single [judge](#settlement-by-judge) or [smart contract](#settlement-by-smart-contract) chosen by the author.

### Settlement by judge

Judge can settle the Ante any time after the settlement period starts by providing a digital signature specifying the winning side. This does not cost the judge anything.

Any participant can then take the judge's signature and pay gas to settle the Ante.

<details>

<summary>Who can be a judge?</summary>

Anyone with an [EOA wallet address](https://ethereum.org/en/developers/docs/accounts/) can be a judge. The judge does not need to own any crypto and signing the outcome does not cost them gas.

</details>

<details>

<summary>What if the judge doesn't settle the Ante?</summary>

If the judge has not settled the Ante by the end of the settlement period, anyone can withdraw their stake from the Ante, canceling the Ante. Until the first withdrawal, the judge can still settle the Ante.

</details>

<details>

<summary>Can I change judges?</summary>

No, the judge is currently set when the Ante is created and cannot be changed or added.

</details>

### Settlement by smart contract

Antes can be settled by smart contracts that reference other smart contracts or chain state (for example, checking if the token balance of a particular wallet has plunged).

To learn how to write an Ante settlement contract, read our [developer guide](/v0.8/technical-stuff/settling-an-ante-using-a-smart-contract/settling-by-token-price).

{% hint style="warning" %}
Note: settlement contracts can be arbitrarily written and may contain trust assumptions (oracles, multisigs, etc.). Settlement contract writers are encouraged to document these, and users should be careful around settlement contracts they don't understand.
{% endhint %}


# How payouts work

For a given stake, you could potentially earn an amount determined by the fixed odds set by the author of the Ante.

For example, if the author staked **10 USDC** at **2:1 fixed odds against** and you staked **5 USDC Against**, you could earn **10 USDC** (minus gas fees) if you win.

<figure><img src="https://3302342845-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOTcpheHefyFNl2tHWsi9%2Fuploads%2F9kEbls4d3Xzdi1YmPbR4%2F01%20balanced.png?alt=media&amp;token=aadc090a-5161-48a4-b3fa-f3c675785d2a" alt=""><figcaption></figcaption></figure>

If you win but there is not enough staked on the opposing side, your payout may be less than the full amount implied by the odds. In the previous example, if someone else staked **1 USDC Against** before your **5 USDC** stake, you would only be able to claim **8 USDC** (minus gas fees) if you win.

<figure><img src="https://3302342845-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOTcpheHefyFNl2tHWsi9%2Fuploads%2FWrh3a0gDlBACVDWwe2po%2F02%20partial%20payout.png?alt=media&amp;token=27ff73d9-0d67-47d5-8db1-fa44857967d2" alt=""><figcaption></figcaption></figure>

On the other hand, if you lose and there is not enough staked on the opposing side, you could get some of your stake back. In the preceding scenario, if you lost, you would still be able to withdraw **1 USDC** of your original stake.

<figure><img src="https://3302342845-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOTcpheHefyFNl2tHWsi9%2Fuploads%2FKAt5lIamy8lsJqGQnwhW%2F03%20partial%20refund.png?alt=media&amp;token=33eeda54-061d-4d33-8e4d-806e21e8be06" alt=""><figcaption></figcaption></figure>


# Deployed Contracts

### GitHub

Soon™️

### Deployed Contracts

#### Base Mainnet

v3 (Current): [0xb7E565a9D96e4Dc067F955bedDeBABC5f7A4cf84](https://basescan.org/address/0xb7E565a9D96e4Dc067F955bedDeBABC5f7A4cf84)

v2: [0xC3dCEf82A8C38C20DA9feb8bB1d03E9c9D842da3](https://basescan.org/address/0xC3dCEf82A8C38C20DA9feb8bB1d03E9c9D842da3)

v1: [0x40107F542c6D7d9d9C9F7c46FB8874eF59fD3C65](https://basescan.org/address/0x40107F542c6D7d9d9C9F7c46FB8874eF59fD3C65)

#### Base Sepolia

v3 (Current): [0x8c290487A9c4Bb770ADa6351b3d2F9f822892645](https://sepolia.basescan.org/address/0x8c290487A9c4Bb770ADa6351b3d2F9f822892645)


# Security & Trust

{% hint style="warning" %}
**Disclaimer:** Ante.xyz is in BETA. Do not stake more than you are willing to lose.
{% endhint %}

### Trust assumptions

Trust assumptions for staking claims via Ante.xyz fall into two main categories:

**Judge risk**

* Judges can be subjective and make a “wrong” decision that Ante participants don’t agree with
* Judges can also participate in an Ante — this could result in scenarios where a Judge defects due to economic reasons (coming soon: gated Antes)

**Smart contract risk**

Compared to manual escrow, using Ante.xyz substitutes 3rd-party escrow risk for smart contract risk.&#x20;

The smart contract is:

* Is immutable (non-upgradeable)
* Has no owner or admin functions
* Holds funds noncustodially
* A previous version of the smart contract was audited; current version is pending audit (soon!)

However, as always, you should exercise appropriate caution when interacting with smart contracts and never deposit more than you are willing to lose.

### Responsible disclosure

Previously undiscovered bugs can be submitted to [security@ante.org](mailto:security@ante.org?subject=Responsible%20Bug%20Disclosure) for a guaranteed response from the team. Ante will follow up within 48 hours to acknowledge the disclosure and discuss next steps. Eligibility for existing bug bounty programs (e.g. [Immunefi](https://www.immunefi.com/bounty/antefinance)) will not be voided by communicating with [security@ante.org](mailto:security@ante.org?subject=Responsible%20Bug%20Disclosure).

Any vulnerabilities should not be disclosed publicly or to other parties until the Ante team has had a chance to triage and address the vulnerability. All testing or proof of concepts should be done on private testnets, and must not have already been exploited for damage.


# Settling an Ante using a smart contract

In order to settle an Ante with a smart contract you first need to write a settlement contract.\
This contract is responsible for determining the winning side of the Ante and must implement the `IAnteSettlement` interface.

```solidity
/// @title The interface for a AnteSettlement smart contract
interface IAnteSettlement {
    enum WinningSide {
        NONE,
        A,
        B
    }

    /// @notice Settles the outcome of a given commitment
    /// @param data Arbitrary data used to determine the outcome
    /// @return the winning side
    function settle(bytes memory data) external returns (WinningSide);
}
```

Examples of settlement contracts:

{% content-ref url="/pages/K5dFousS9adVDGCPWNBP" %}
[Settling by token price](/v0.8/technical-stuff/settling-an-ante-using-a-smart-contract/settling-by-token-price)
{% endcontent-ref %}

{% content-ref url="/pages/BOSfHdxI85oyT3Ku3kYL" %}
[Settle by stablecoin depeg](/v0.8/technical-stuff/settling-an-ante-using-a-smart-contract/settle-by-stablecoin-depeg)
{% endcontent-ref %}

You have to be careful about what the settle function returns because the return value constitutes a definitive result. For example, if your commitment is outside of the settlement window you might want to `revert` instead of returning a definitive result.

After you have written and deployed your settlement contract on Base, you can then fill in the smart contract address as the settler address when creating your Ante.


# Settling by token price

The following is an example of a settlement contract which determines the outcome of an Ante based on an asset price fetched from a Chainlink oracle.

The settle function takes some `data` that is decoded to a Chainlink oracle address (can be found [here](https://docs.chain.link/data-feeds/price-feeds/addresses?network=ethereum\&page=1#ethereum-mainnet)) and a price threshold. You need to make sure the threshold value takes into account the asset decimals.

```solidity
 function settle(bytes memory data) external view returns (WinningSide) {
        (address feedAddr, int priceThreshold) = abi.decode(data, (address, int));
```

This `data` value passed as a parameter when you [create](broken://pages/nwaDGH6q1DLUXfqriiIC) the Ante. This value doesn't get changed after creation and the AnteMetaPool smart contract will use it to call the settlement contract when the time comes.

```solidity
// Extracted from AnteMetaPool.settle function
address settler = commitment.settler;
bytes memory settlerData = commitment.settlerData;
...
ParticipantSide winningSide = ParticipantSide(uint8(IAnteSettlement(settler).settle(settlerData)));
```

If the fetched price is equal to the set threshold, the Ante will be marked as having no winner. At this point both parties can withdraw their initial stake.

If the fetched price is greater than the set threshold, A side is considered the winner.&#x20;

If the fetched price is less than the set threshold, B side is considered the winner.&#x20;

```solidity
if (price == priceThreshold) {
    return WinningSide.NONE;
} else if (price > priceThreshold) {
    return WinningSide.A;
} else {
    return WinningSide.B;
}
```

**IMPORTANT!** If you are the Ante author, you will automatically be assigned to side A. In order to stake behind a claim saying that an asset will be under a threshold, you will have to update the condition block accordingly.

link to repo

### Full contract code

```solidity
// SPDX-License-Identifier: GPL-3.0-only
pragma solidity 0.8.21;

/// @title The interface for a AnteSettlement smart contract
interface IAnteSettlement {
    enum WinningSide {
        NONE,
        A,
        B
    }

    /// @notice Settles the outcome of a given commitment
    /// @param data Arbitrary data used to determine the outcome
    /// @return the winning side
    function settle(bytes memory data) external returns (WinningSide);
}

// Chainlink Aggragator interface
// import "@chainlink/contracts/src/v0.8/interfaces/AggregatorV3Interface.sol";
interface AggregatorV3Interface {
    function latestRoundData()
        external
        view
        returns (uint80 roundId, int256 answer, uint256 startedAt, uint256 updatedAt, uint80 answeredInRound);
}

/**
 * Contract used for settling a commitment with a given Chainlink feed and
 * a given price threshold.
 * These values are set when the commitment is created.
 */
contract AnteSettlementByTokenPrice is IAnteSettlement {
    function settle(bytes memory data) external view returns (WinningSide) {
        (address feedAddr, int priceThreshold) = abi.decode(data, (address, int));

        AggregatorV3Interface dataFeed = AggregatorV3Interface(feedAddr);
        // prettier-ignore
        (
            /* uint80 roundID */,
            int price,
            /*uint startedAt*/,
            /*uint timeStamp*/,
            /*uint80 answeredInRound*/
        ) = dataFeed.latestRoundData();

        if (price == priceThreshold) {
            return WinningSide.NONE;
        } else if (price > priceThreshold) {
            return WinningSide.A;
        } else {
            return WinningSide.B;
        }
    }
}
```


# Settle by stablecoin depeg

The following is an example of a settlement contract which determines the outcome of an Ante based on historic price of USDC which is fetched from a Chainlink price feed.

In order for B side to win the commitment, someone needs to provide a Chainlink `roundId` as a proof of a depeg of USDC. This is achieved by calling: the `setDepegRoundId` function directly on the settlement contract

This contract uses a historic data feed because it might be hard for someone to catch the exact moment when the asset depegs. But with an oracle like Chainlink, if the depeg happens for a long enough period or with a big enough spread, then you can prove that the depeg happened in the past. \
Make sure that the oracle heartbeat and deviation are suitable for your commitment (<https://docs.chain.link/data-feeds/price-feeds/addresses?network=ethereum&page=1&search=USDC%2FUSD>)

You can find more about `roundId` and historic price feeds here: <https://docs.chain.link/data-feeds/historical-data>

### Full contract code

```solidity
// SPDX-License-Identifier: GPL-3.0-only

pragma solidity 0.8.21;

import {IAnteSettlement} from "../../interfaces/IAnteSettlement.sol";
import {IAnteMetaPool} from "../../interfaces/IAnteMetaPool.sol";

// Chainlink Aggragator interface
// import "@chainlink/contracts/src/v0.8/interfaces/AggregatorV3Interface.sol";
interface AggregatorV3Interface {
    function getRoundData(
        uint80 _roundId
    )
        external
        view
        returns (uint80 roundId, int256 answer, uint256 startedAt, uint256 updatedAt, uint80 answeredInRound);
}

/**
 * Contract used for settling a commitment based on USDC peg to USD.
 * The data is fetched using Chainlink historic feed.
 * https://docs.chain.link/data-feeds/historical-data
 * A Chainlink roundId needs to be submitted before cut-off time in order
 * to determine if there was a depeg. Otherwise, the A side will be considered
 * the winner.
 */
contract AnteSettlementByUSDCDepeg is IAnteSettlement {
    /// @notice Date after you can no longer submit an roundId
    uint256 public constant END_DATE = 1704060000; // 01/01/2024 00:00:00
    /// @notice Price of USDC in USD with 8 decimals.
    ///         If the value is below this price, B side becomes the winner
    int public constant PRICE_THRESHOLD = 90000000; // 0.9 USD
    /**
     * @notice The Chainlink historical price feed address 
     * Network: Ethereum Mainnet
     * Aggregator: USDC/USD
     * Address:	0x8fFfFfd4AfB6115b954Bd326cbe7B4BA576818f6
     */
    address public constant FEED_ADDR = 0x8fFfFfd4AfB6115b954Bd326cbe7B4BA576818f6;

    uint80 public depegRoundId;

    error Expired();
    error InvalidProof();

    event RoundIdSet(uint80 roundId);

    function setDepegRoundId(uint80 _roundId) external {
        AggregatorV3Interface dataFeed = AggregatorV3Interface(FEED_ADDR);

        // prettier-ignore
        (
            /* uint80 roundID */,
            int price,
            /*uint startedAt*/,
            uint updatedAt,
            /*uint80 answeredInRound*/
        ) = dataFeed.getRoundData(_roundId);

        if (updatedAt > END_DATE) {
            revert Expired();
        }

        if (price >= PRICE_THRESHOLD) {
            revert InvalidProof();
        }

        depegRoundId = _roundId;

        emit RoundIdSet(_roundId);
    }

    function settle(bytes memory /*data*/) external view returns (WinningSide) {
        if (depegRoundId > 0) {
            return WinningSide.B;
        } else {
            return WinningSide.A;
        }
    }
}
```


# Ante = Credible Commitments

Commitments are hard. Entering into an agreement with someone else typically involves either handshakes and verbal promises (easy to break) or lawyers and courts (slow and expensive).

Cryptography changes this. Commitments can be permanently inscribed onto blockchains with publicly verifiable authorship and made credible by staking crypto behind them.

Ante.xyz aims to let anyone make credible commitments (like claims, promises, and secrets) more quickly and cheaply.

<br>


# Verify relayed Antes

## Prerequisite

* Setup the verifier on your machine: <https://github.com/anteproject/ante-commitments-encoder/tree/main/examples>
* Know your Ante details&#x20;
  * the original message
  * (optional) the address you want to be verified for committing that Ante
  * (optional) the side of the Ante
  * commitment type - this is determined by the Ante app you have used to create the Ante

## Verification

After you have everything setup, you just follow the instruction from the README file of the example given above.

## Manual verification

1. Open the contract in BaseScan: <https://basescan.org/address/0x1CD9276f727F631eCCea749371a7df27B8a3d55F#readContract>
2. Get the `latestDataUri`
3. Open the IPFS link in your browser: [https://ipfs.io/ipfs/](https://ipfs.io/ipfs/QmPn5fnQ1S9383CKgVShovw38wpVt6XgNcoDhX3osNw641)`<latestDataUri>`
4. Use any online SHA256 generator to generate the hash for your original message
5. Lookup for that hash in the JSON opened on step 3


# Ante v0.7 Secrets

## :construction\_site: Docs coming soon


# Introduction to Ante

ABC: Ante = Blockchain Commitments

[**Ante**](https://www.ante.finance/) is a decentralized protocol to translate implicit trust assumptions like *"protocol X is solvent"* or *"team Y won't rug"* into explicit on-chain commitments (**Ante Tests**) that anyone can verify in real time. Staking tests gives them credibility and payouts happen trustlessly if the tests fail.

These new trust-signaling primitives form the potential building blocks for a **decentralized trust ratings system** that could make the space safer for builders and users alike.


# Why use Ante?

Since smart contracts are immutable or tricky to upgrade, when you start connecting them together, small failures can easily compound into catastrophic outcomes. By making implicit trust explicit, Ante enables smarter building in web3, turning [Jenga](https://en.wikipedia.org/wiki/Jenga) blocks into [LEGO](https://en.wikipedia.org/wiki/Lego) bricks.

**For web3 project teams:** credibly signal commitment to your most important trust guarantees and bootstrap trust by putting skin in the game

**For web3 users:** Compare projects based on publicly verifiable trust scores, or get paid out on objectively defined failures without trusted intermediaries

**For new web3 developers:** Deploy your first smart contract and potentially get paid for it

**For security experts:** Find flawed guarantees and get rewarded while making web3 safer

<br>


# What's new in Ante v0.6?

### Get rewards for writing Ante Tests

Test authors can claim a share of pool decay (% that challengers pay to stakers over time) for tests they wrote!

### Time-committed staking

Stakers can timelock their stake to demonstrate greater conviction and alignment

### Challenger payout soft floor

Challengers can challenge pools with more clarity around potential payout upon test failure.

### Stake/challenge in more currencies

v0.6 Ante Pools support [ERC20s](https://ethereum.org/en/developers/docs/standards/tokens/erc-20/)! To keep things simple, 1 token per pool (no mixing different tokens). Currently, v0.6 pools support **WETH** only.

{% hint style="info" %}
Staking/challenging in the native gas token (e.g. ETH) is no longer supported in v0.6 pools. All existing Ante v0.5 pools remain usable in their current form.
{% endhint %}

### Variable pool economics

Pool currency, decay rate, payout soft floor, and test author rewards can be set per pool


# FAQ

### Isn't Ante just \_\_\_\_\_?

Ante is **NOT**:

* an auditing service;
* an "economic analysis" service;
* a bug bounty program
* "hack insurance"

All of the above are valuable and important to building safe web3, and  Ante is complementary to existing security, marketing, and trust services.

### Why shouldn't I just code in the tests or formally verify my code?

Formal verification is great but has limitations (e.g. economic attacks)

Ante Tests can make commitments that aren’t forbidden in code but rely on trust in people or external systems.

Also, Ante Tests make these guarantees more visible and understandable to non-technical people, giving more peace of mind to potential users.

### Is Ante audited?

Yes! Read more: [Security & Trust](/v0.6/security-and-trust)

### Does Ante have a token?

No — beware of scammers!


# Security & Trust

{% hint style="info" %}
Previously undiscovered bugs can be submitted to [security@ante.xyz](mailto:security@ante.xyz?subject=Responsible%20Bug%20Disclosure) for a guaranteed response from the team. Ante will follow up within 48 hours to acknowledge the disclosure and discuss next steps. Eligibility for existing bug bounty programs (e.g. [Immunefi](https://www.immunefi.com/bounty/antefinance)) will not be voided by communicating with [security@ante.xyz](mailto:security@ante.xyz?subject=Responsible%20Bug%20Disclosure).
{% endhint %}

While significant steps have been taken to minimize the risk surface area of the Ante protocol, Ante v0.6 is intended as an **alpha release**. You should exercise appropriate caution and never deposit more than you can afford to lose into Ante or any other smart contract.

\<Trust Summary coming soon!>

### Trust assumptions

An admin role is involved in configuring the Ante Pool Factory settings, and has the power to whitelist supported [ERC-20](https://ethereum.org/en/developers/docs/standards/tokens/erc-20/) tokens for staking/challenging pools. However, this only affects pools created in the future; existing pools are immutable once created and will operate predictably.

Ante v0.6 has **no ability to recover funds sent to its smart contracts**. All funds deposited into Ante Pools created by users that are settled by user-generated Ante Tests are **non-custodial smart contracts**.&#x20;

### Development practices

Ante v0.6's core smart contracts are fully [open source](https://github.com/antefinance/ante-v06-core) and all [deployed code](/v0.6/for-developers/deployed-contracts) is verified.

Ante v0.6 does use a lightweight proxy pattern to make deploying pools more accessible; however, the pools themselves are non-upgradeable once deployed so their behavior won't change.

The DTS is upgradable, but is a view-only contract that never touches user assets.

### Audits

Ante v0.6 contracts have been audited (report coming soon).

### Bug Bounty

Ante has an active [bug bounty program on Immunefi](https://immunefi.com/bounty/antefinance), with up to $50,000 bounty for critical vulnerabilities.

### Ante Tests

We stake Ante Tests for Ante!

### Responsible Disclosure

While we have taken significant steps to minimize the risk surface area of the Ante protocol, undiscovered vulnerabilities may still exist. Ante encourages the community to audit the core [contracts](https://github.com/antefinance/ante-v06-core) and responsibly disclose any vulnerabilities discovered to the team so we can address it as quickly as possible.

Previously undiscovered vulnerabilities can be submitted (including conditions/steps to reproduce the vulnerability) through our [Immunefi bug bounty program](https://immunefi.com/bounty/antefinance/) and/or to [security@ante.xyz](mailto:security@ante.xyz?subject=Responsible%20Bug%20Disclosure) for priority escalation. Ante will follow up within 48 hours to acknowledge the disclosure and discuss next steps.

Any vulnerabilities should not be disclosed publicly or to other parties until the Ante team has had a chance to triage and address the vulnerability. All testing or proof of concepts should be done on private testnets, and must not have already been exploited for damage.

We are happy to publicly credit you for your discovery (unless you prefer otherwise), and eligibility for existing bug bounty programs (e.g. Immunefi) will not (subject to our discretion) be voided by communicating with [security@ante.xyz](mailto:security@ante.xyz?subject=Responsible%20Bug%20Disclosure).

### Known issues

The following vulnerabilities are known and not eligible for a reward:

* Challenger decay slightly overestimates decay paid by challengers (overall error is <1%/year even in worst case)
* Staker and challenger balances are slightly underestimated due to rounding in arithmetic. Overall loss is extremely small and never results in pool insolvency
* Test verification can be frontrun by challengers who challenge the  minimum amount in every pool.
* Because anyone can write Ante Tests, malicious Ante Tests could steal/lock user funds
* Any exploits already covered in audit reports for Ante


# How Ante works

The core pieces of the Ante protocol are:

* **Ante Tests** = on-chain logic that verifies some condition is true/false
* **Ante Pools** = 2-sided capital pools that people stake or challenge assets in, whose payout is determined by the result of the Ante Test

#### Pool mechanics

Pools can be **staked** or **challenged**.

Challengers pay decay fees to stakers and test authors over time if the test continues to pass, but can claim staker funds as a reward if the test fails.

<figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FuymueiYLBQPMij7Wxsce%2Fstake-challenge.png?alt=media&amp;token=d65e3501-1fea-4697-bcba-010e76e4fa52" alt=""><figcaption></figcaption></figure>

Pool activity reveals community trust in the tested conditions and can be used to impute a decentralized trust score.


# Staking

### What is staking?

Staking an Ante Test signals trust in the tested guarantee, putting your money where your mouth is!

If the test continues to pass, you can potentially earn rewards over time.

However, if the test fails, you will lose your entire stake.

### How do staker rewards work?

Challenger capital undergoes continuous decay over time (by default, this is \~100% of challenger capital per year). This decay is allocated to stakers and is automatically added to your stake amount.

<figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FKrf7YPl9GB3MHfNGVuWt%2Fstake%20(1).png?alt=media&amp;token=1a6d06c6-2b31-4ea4-aa01-88c946001661" alt=""><figcaption><p>Stakers are rewarded over time for their continued trust</p></figcaption></figure>

Potential rewards vary with pool activity, but as a rough estimate,

$$
potential,rewards \approx \frac{stake\_{user}}{stake\_{total}} \cdot challenge\_{total}\cdot \left(1-(1-decay,rate)^{n}\right)
$$

Note: if there are no challengers in the pool, no decay rewards are generated.

#### Example:

Take the following scenario:

$$
\begin{align\*} \text{your stake} &= \text{1 WETH} \ \text{total stake} &= \text{20 WETH} \ \text{total challenge} &= \text{2 WETH} \ \text{decay rate} &= \text{20% per year} \end{align\*}
$$

$$
\begin{align\*} potential,rewards &\approx \frac{\text{1 WETH}}{\text{20 WETH}} \cdot \text{2 WETH} \cdot \left(1-(1-0.20)^{1}\right) \ \ &= \text{0.02 WETH over 1 year} \end{align\*}
$$


# Challenging

### What is challenging?

Challenging an Ante Test expresses belief that the tested guarantee could/will fail.

You will pay "decay" fees to stakers over time to challenge a test.

However, if the test fails, you can claim a portion of staked funds as a reward.

<figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FZADK4mxL4VXcekkEYc6R%2Fchallenge%20(1).png?alt=media&amp;token=d8c87ef7-4866-468b-ab72-5bee2fe047e8" alt=""><figcaption><p>Failed tests reward challengers for identifying risk in the system</p></figcaption></figure>

### How does decay work?

Your challenged funds will undergo continuous decay over time (by default, this is 100% per year). Some amount of this may be claimed by the test author; the rest is allocated to stakers.

<figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2Fh2UGMRygO2eo6KaCCp5T%2Fdecay-graphic.png?alt=media&amp;token=691d4f92-3a22-443e-96ed-edb8ceb76a15" alt=""><figcaption></figcaption></figure>

### How do payouts work?

Challengers in a pool can check the underlying test at any point. If the test fails, the pool is locked and staker funds can be claimed by challengers.

5% of total staked balance are allocated to the challenger that made the failing test check. The remaining 95% of staker balance is distributed amongst all eligible challengers:

$$
reward \approx your,challenge + \left(\frac{your,challenge}{total,challenge} \right) total,stake \cdot 0.95
$$

#### Example:

You have 0.5 WETH challenged in a test when another challenger triggers test failure. Staker balance is 20 WETH and total challenger balance is 1 WETH.

$$
\begin{align\*} claimable,reward &= 0.5\text{ WETH} + \left(\frac{0.5\text{ WETH}}{1\text{ WETH}} \right) 20\text{ WETH} \times 0.95 \ &= 10\text{ WETH} \end{align\*}
$$

{% hint style="info" %}
Tip: Don't want to do math? Each pool has a "payout floor" like 1:10. This serves as a soft floor for potential payout on test failure: for a 1:10 payout floor, for every 1 ETH you challenge you could potentially get 10 ETH on test failure.
{% endhint %}


# The Decentralized Trust Score

Imputing aggregate community trust

Staking and challenging Ante Pools are explicit expressions of trust in the guarantees tested. This uncoordinated user activity can be translated into the **Decentralized Trust Score**, an impartial, transparent, quantitative measure of aggregate community trust in a protocol/project.

A higher Trust Score means more people in the Ante community trust the protocol.

Having an explicit and compressed measure of trust adds peace of mind for the entire space:

* users can more easily understand trust in a protocol
* builders can reference the score when integrating with other projects

<figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FsNCgn8plvudNwrExtgT1%2Fante-stake-challenge-white-bg.gif?alt=media&amp;token=11dd55d3-2fbf-4aba-b076-6f401fac92fb" alt=""><figcaption></figcaption></figure>


# Decentralized Trust Tiers

The decentralized trust score can be used to translate on-chain activity into an easy-to-understand measure of DeFi risk. A system will take in objective on-chain data like funds staked, stake duration, and test quality as well as input from the Ante community, launch partners, and wider crypto community.

Currently, trust tiers on the Ante web app are defined based on total stake and stake-weighted decentralized trust score across a protocol's Ante Tests:

| Trust Tier     | Total Stake | Decentralized Trust Score |
| -------------- | ----------: | ------------------------: |
| S              |   >=100 ETH |                      >=90 |
| AA             |    >=30 ETH |                      >=85 |
| A              |    >=10 ETH |                      >=80 |
| B              |     >=1 ETH |                      >=75 |
| NR (Not Rated) |      <1 ETH |                      < 75 |

Protocols must meet **both** the minimum total stake and decentralized trust score requirements to qualify for a trust tier (e.g. if a protocol has 50 ETH staked in their tests but their trust score is only 83, they will be A-tier).


# Supported assets

## Ante v0.6

Ante v0.6 pools are currently staked in WETH only. If you are working with a project that would like to stake in another ERC20, reach out to <hello@ante.xyz>!

<table><thead><tr><th width="251">Network</th><th>ERC20 Token</th></tr></thead><tbody><tr><td>Ethereum Mainnet</td><td><a href="https://etherscan.io/token/0xc02aaa39b223fe8d0a0e5c4f27ead9083c756cc2">WETH</a></td></tr></tbody></table>

## Ante v0.5

Ante v0.5 pools are staked in the native gas token of the chain the pool is hosted on.

<table><thead><tr><th width="251">Network</th><th>Gas Token</th></tr></thead><tbody><tr><td>Ethereum Mainnet</td><td>ETH</td></tr><tr><td>Avalanche</td><td>AVAX</td></tr><tr><td>Polygon</td><td>MATIC</td></tr><tr><td>BSC</td><td>BNB</td></tr><tr><td>Fantom</td><td>FTM</td></tr><tr><td>Optimism</td><td>ETH</td></tr><tr><td>Arbitrum</td><td>ETH</td></tr><tr><td>Aurora</td><td>ETH</td></tr></tbody></table>


# User Guides

{% content-ref url="/pages/EvlboZEv4LMPQdsb7Jtw" %}
[Navigating the app](/v0.6/getting-started/user-guides/navigating-the-app)
{% endcontent-ref %}

{% content-ref url="/pages/xx0evlG0Z36A2TagsrXQ" %}
[Stake an Ante Test](/v0.6/getting-started/user-guides/stake-an-ante-test)
{% endcontent-ref %}

{% content-ref url="/pages/AgYSheJOgMhp6QDMWVZY" %}
[Challenge an Ante Test](/v0.6/getting-started/user-guides/challenge-an-ante-test)
{% endcontent-ref %}

{% content-ref url="/pages/EBctFpz8EYq6Khn1Gnvl" %}
[Withdraw funds](/v0.6/getting-started/user-guides/withdraw-funds)
{% endcontent-ref %}

{% content-ref url="/pages/1DALFB5ufwgUFDE2nV4y" %}
[Check an Ante Test](/v0.6/getting-started/user-guides/check-an-ante-test)
{% endcontent-ref %}

{% content-ref url="/pages/H5hpmA0y6a1ymGjMlvEK" %}
[Claim rewards](/v0.6/getting-started/user-guides/claim-rewards)
{% endcontent-ref %}


# Navigating the app

{% hint style="warning" %}
Guide coming soon!
{% endhint %}


# Stake an Ante Test

Stake to signal trust in the tested guarantee

Before proceeding, make sure you have read about how staking works and understand the risks involved in staking an Ante Test.

{% content-ref url="/pages/yPv9sJrKois1ARkvSk1m" %}
[Staking](/v0.6/getting-started/how-ante-works/staking)
{% endcontent-ref %}

{% hint style="danger" %}
Staking an Ante Test carries some risk (you will lose your entire stake if the Ante Test fails). Never deposit more than you can afford to lose into Ante or any other smart contract.
{% endhint %}

### How to stake

Go to the page of the test you want to stake.

Connect your wallet to the app to view actions you can take.

Click the "**Stake**" button.

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2Fe50nfi2uHjGUIouWIaHY%2Faction%20panel.png?alt=media\&token=bc49f961-958a-417c-bff9-2a9f54ad6d5e)

Enter the amount you want to stake, as well as a time commitment for your stake:

<img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2Fad94MgscHYgHbmzY1C8o%2Fstake%402x.png?alt=media&amp;token=b0ad6f8b-58c1-4455-9176-b91757f6c1fa" alt="" data-size="original">

<details>

<summary>Don't have the correct token to stake in the pool?</summary>

If you don't have the correct token to stake in the pool, you can click the "**Need TOKEN?**" link and use the [Uniswap](https://app.uniswap.org/#/swap) widget to swap other assets you own for the correct token.

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2F1LXYx9FWQVB9jfHsDFkj%2Fswap-token%402x.png?alt=media\&token=395a091a-f985-4649-a593-a51b08b9bf81)

</details>

{% hint style="info" %}
Once you have staked, you will not be able to initiate withdrawal before the time commitment has ended!
{% endhint %}

Finally, click "**Stake**".

{% hint style="info" %}
You will need to permit the app to use your tokens by clicking the "**Approve stake**" button before you can click the "**Stake**" button.
{% endhint %}


# Challenge an Ante Test

Before proceeding, make sure you have read about how challenging works and understand the risks involved in challenging an Ante Test.

{% content-ref url="/pages/K8MPsuXuWoeO5Go8isSj" %}
[Challenging](/v0.6/getting-started/how-ante-works/challenging)
{% endcontent-ref %}

Go to the page of the test you want to challenge

Connect your wallet to the app to view actions you can take.

Click the "**Challenge**" button.

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2Fe50nfi2uHjGUIouWIaHY%2Faction%20panel.png?alt=media\&token=bc49f961-958a-417c-bff9-2a9f54ad6d5e)

{% hint style="info" %}
You will need to permit the app to use your tokens.
{% endhint %}

#### Why am I unable to challenge this test?

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FpzJCS4n2RS1EMQzCtRta%2Fimage.png?alt=media\&token=e16179a1-62f6-4249-aae5-6d8bda4508d1)

Each pool enforces a maximum ratio of challenger to staker funds on pool entry in order to provide more predictability around payouts on test failure.

If the pool has already reached the max challenge it can support, you will need to wait until either more stake enters the pool or other challengers exit.

Naturally, this also means you cannot challenge a pool with no stake in it.

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FtppdZyrf2K3L9hkLVoks%2Fimage.png?alt=media\&token=772b62cf-9ee2-46e2-8710-547d59c48bb6)

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FfiEUw3ucDDo9pg3DePp5%2Fimage.png?alt=media\&token=94c7df3e-7516-478e-bc47-75e3b0db2016)

{% hint style="warning" %}
If you don't finalize your challenge, your challenge will still [decay](/v0.6/getting-started/how-ante-works/challenging#how-does-decay-work) but you won't be able to claim rewards if the test fails!
{% endhint %}

Once the countdown has ended, click "**Finalize challenge**" to become eligible for reward payout if the test fails

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2F1xcbL2WAditI5BFkFqbn%2Fimage.png?alt=media\&token=9f1e6535-89cf-435c-b15c-da3906e09116)

If you missed this earlier, you can resume finalizing your challenge by clicking "**Finalize Challenge**" on the test page:

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FqRWsKRzFq0yef2qiczuq%2Fimage.png?alt=media\&token=ac02568a-a0ce-42cb-9925-e91a95d855f7)

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FrGZDGRAmpQImc0rtl3XI%2Fimage.png?alt=media\&token=1fe3ee0d-054e-487f-82e5-625f540600ef)


# Withdraw funds

{% hint style="warning" %}
Guide coming soon!
{% endhint %}


# Check an Ante Test

{% hint style="warning" %}
Guide coming soon!
{% endhint %}


# Claim rewards

{% hint style="warning" %}
Guide coming soon!
{% endhint %}


# Using Antegen

Antegen lets you create simple Ante Tests without writing code! All you need to do is look up a few addresses. Here's how to do it:

### NFT balance check test

#### **NFT collection address**

To find the address of an NFT collection, go to the collection page on your preferred NFT marketplace and click “**View on Etherscan**”. (Some NFT marketplaces: [OpenSea](https://opensea.io/), [SuperRare](https://superrare.com/), [Rarible](https://rarible.com/))

<figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2F2zfT2xb8Mie8zWKw8f5k%2Fnft-link.png?alt=media&amp;token=2d406c98-1b9c-402c-b5c0-c99d19758ffd" alt=""><figcaption><p>Etherscan link on various NFT marketplaces</p></figcaption></figure>

In Etherscan, click the “**Copy**” button by the contract address, then paste this into the "**NFT collection address**" field.

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2F6Yd21PXtgjBLR17uYc6O%2Fetherscan.png?alt=media\&token=a3eb5ba4-96a9-445e-b06d-4d0250a239d3)

#### NFT holder address

From the NFT collection Etherscan page, click on the "**Token Tracker**" link:

<figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2F7bFn81XYKsIbxKBn82Lv%2FGroup%2024.png?alt=media&amp;token=a49c7a78-7543-4789-a96e-39dda5fd6088" alt=""><figcaption></figcaption></figure>

Then select the "**Holders**" tab to view top holders of that NFT collection:

#### ![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FcXkZnPxuQrjBpuj9CyE3%2Fimage.png?alt=media\&token=fcf4aa70-3ea7-42aa-bc08-2da6ad1e109e)

#### Minimum balance held

Choose a number between 1 and the number of NFTs from the collection the holder currently holds.

If the holder has fewer than this number of NFTs from the collection, the test will fail.&#x20;

### Token balance check

#### Token address

Go to [Etherscan](https://etherscan.io/tokens) (or other block explorer for the chain) and select a token.

Under "**Other Info**", click the Copy icon next to "**Token Contract**" to copy the contract address.

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FzZgodiLzOSdAs8DJK6EW%2FGroup%2023.png?alt=media\&token=ec1a5f2f-2e86-4926-9186-ce6a8e289672)

#### Token holder address

On the [Etherscan](https://etherscan.io/tokens) page for the token, click the "**Holders**" tab to view top token holders.

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FIfcpUcxx97gx1BaKbVz0%2Fimage.png?alt=media\&token=5b36d6df-c272-4863-ab5a-ed2785ec573e)

Select one of the addresses and click the Copy icon to copy the holder address.

#### Minimum balance held

Choose a number between 1 and the current token balance of the holder.

If the holder's token balance drops below this number, the test will fail.&#x20;

### Submitting a Pull Request (PR)

If you used Antegen to generate code without deploying, here's how you can submit it to us:

1. Go to [tests.ante.xyz](http://tests.ante.xyz/) and click the "**Fork**" button (create a free GitHub account if necessary).

<figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FAsbKYedOhuY4dhxKi6ol%2Fimage.png?alt=media&amp;token=b7ee34ba-40fb-4f49-861a-85ba35bc3da2" alt=""><figcaption></figcaption></figure>

2. Keep the default fork settings and click "**Create fork**"

<div align="center"><figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2Fd0sUST81Pfb97I2ADhmR%2Fimage.png?alt=media&amp;token=d0b3c9ea-c149-4877-867b-5778bcd0e1c9" alt=""><figcaption></figcaption></figure></div>

3. In your forked repository, under "**Add file**", select "**Upload files**"

<figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FvM8MJ1Gd5PhRLiylAe44%2Fupload.png?alt=media&amp;token=209c3f7c-b86c-4185-a9d0-c80c370cddda" alt=""><figcaption></figcaption></figure>

4. Upload the Antegen code file, enter a description, and click "**Commit changes**".
5. Open a pull request by clicking “**Contribute**” > “**Open pull request**”.

<figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FEfxoGIk8sLa4Ag0tT3fs%2Fimage.png?alt=media&amp;token=4c7d0104-ad22-4edd-8ced-b202d94b239c" alt=""><figcaption></figcaption></figure>

6. Enter any comments for the reviewers and click “**Create pull request**” to submit your test. That’s it!


# Writing Ante Tests

Writing an Ante Test is easy! It's a great way to level up your Solidity skills and learn how different protocols work. Also, in Ante v0.6 test authors can earn a portion of fees generated by tests!

<figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FpNyE0gGxghL2UzNrKuUQ%2Fanyone-can-write-ante-tests.png?alt=media&amp;token=ffddf1b1-1939-4add-8987-9fd2e3f5fa96" alt=""><figcaption></figcaption></figure>

1. Think of a guarantee to test
2. Write your Ante Test
3. Submit your Ante Test


# What to test?

Can't think of any tests? Maybe one of these will spark some inspiration!

Ante Tests are single-failure tests of on-chain guarantees.

Here are some ideas for tests:

* **"Rug" test** – check that contract-controlled assets are not drained
* **Plunge protection test** – check that contract assets do not drop below some threshold
* **Peg test** – check to see that two pegged assets stay pegged in price&#x20;
  * Note: in order to avoid flash loan manipulation of the Ante Test, this should be implemented against time-weighted average prices (TWAP) rather than spot prices
* **Solvency test** – Collateral asset value exceeds liabilities by some factor
* **Token vesting test** — check that tokens are vested following the publicized schedule
* **Bonding curve test** – check that the bonding curve calculation (e.g. `x*y=k`) holds for an automated market maker (AMM) protocol
* **APY guarantee test** – check that actual rewards issued by a contract over a given time period exceeds the APY rate advertised by the protocol
* **DAO implementation test** – check that a proposal passed by a DAO was actually implemented
  * Checking outcomes can be tricky given the complexity and heterogeneity of outcomes. Defining a narrow test can help manage some of the complexity
  * Alternatively, this can be made generalized by having the DAO vote again on their satisfaction with the implementation outcome and having the Ante Test check the vote result
* **Access test** – check that funds can be withdrawn from contract in an expected manner
* **Market cap test** – check that the total value of contract assets exceeds some threshold
* **Volume test** – check that at least X unique wallets/transactions/etc. use a given protocol over a given time period

These are just some of the many possible Ante Tests that could be written. Happy writing!

Have an idea for a test? We'd love to hear about it! Message us on [Twitter](https://twitter.com/AnteFinance)/[Discord](https://discord.ante.finance/) or drop us a line at <hello@ante.finance>!


# Interfaces

Every Ante Test needs to implement the `IAnteTest.sol` interface to work with Ante. To simplify the test writing process, we've provided an **abstract class** `AnteTest.sol` that **any** Ante Test can inherit.

## Interface [`IAnteTest.sol`](https://github.com/anteproject/ante-v0-core/blob/v0.6/contracts/interfaces/IAnteTest.sol)

{% code title="IAnteTest.sol" %}

```solidity
// SPDX-License-Identifier: GPL-3.0-only

// ┏━━━┓━━━━━┏┓━━━━━━━━━┏━━━┓━━━━━━━━━━━━━━━━━━━━━━━
// ┃┏━┓┃━━━━┏┛┗┓━━━━━━━━┃┏━━┛━━━━━━━━━━━━━━━━━━━━━━━
// ┃┗━┛┃┏━┓━┗┓┏┛┏━━┓━━━━┃┗━━┓┏┓┏━┓━┏━━┓━┏━┓━┏━━┓┏━━┓
// ┃┏━┓┃┃┏┓┓━┃┃━┃┏┓┃━━━━┃┏━━┛┣┫┃┏┓┓┗━┓┃━┃┏┓┓┃┏━┛┃┏┓┃
// ┃┃ ┃┃┃┃┃┃━┃┗┓┃┃━┫━┏┓━┃┃━━━┃┃┃┃┃┃┃┗┛┗┓┃┃┃┃┃┗━┓┃┃━┫
// ┗┛ ┗┛┗┛┗┛━┗━┛┗━━┛━┗┛━┗┛━━━┗┛┗┛┗┛┗━━━┛┗┛┗┛┗━━┛┗━━┛
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

pragma solidity ^0.8.0;

/// @title The interface for the Ante V0.6 Ante Test
/// @notice The Ante V0.6 Ante Test wraps test logic for verifying fundamental invariants of a protocol
interface IAnteTest {
    /// @notice Emitted when the test author is changed
    /// @param previousAuthor The address of the previous author
    /// @param newAuthor The address of the new author
    event TestAuthorChanged(address indexed previousAuthor, address indexed newAuthor);

    /// @notice Function containing the logic to set the AnteTest state and call checkTestPasses
    /// @param _state The encoded data required to set the test state
    /// @return A single bool indicating if the Ante Test passes/fails
    function setStateAndCheckTestPasses(bytes memory _state) external returns (bool);

    /// @notice Function containing test logic to inspect the protocol invariant
    /// @dev This should usually return True
    /// @return A single bool indicating if the Ante Test passes/fails
    function checkTestPasses() external returns (bool);

    /// @notice Returns the author of the Ante Test
    /// @dev This overrides the auto-generated getter for testAuthor as a public var
    /// @return The address of the test author
    function testAuthor() external view returns (address);

    /// @notice Sets the author of the Ante Test
    /// @dev This can only be called by the current author, which is the deployer initially
    /// @param _testAuthor The address of the test author
    function setTestAuthor(address _testAuthor) external;

    /// @notice Returns the name of the protocol the Ante Test is testing
    /// @dev This overrides the auto-generated getter for protocolName as a public var
    /// @return The name of the protocol in string format
    function protocolName() external view returns (string memory);

    /// @notice Returns a single address in the testedContracts array
    /// @dev This overrides the auto-generated getter for testedContracts [] as a public var
    /// @param i The array index of the address to return
    /// @return The address of the i-th element in the list of tested contracts
    function testedContracts(uint256 i) external view returns (address);

    /// @notice Returns the name of the Ante Test
    /// @dev This overrides the auto-generated getter for testName as a public var
    /// @return The name of the Ante Test in string format
    function testName() external view returns (string memory);

    /// @notice Returns a string of comma delimited types used for setting the AnteTest state
    /// @return The types of the state variables
    function getStateTypes() external pure returns (string memory);
    
    /// @notice Returns a string of comma delimited names used for setting the AnteTest state
    /// @return The names of the state variables
    function getStateNames() external pure returns (string memory);
}
```

{% endcode %}

{% hint style="info" %}
`IAnteTest.sol` as of 2023-01-19
{% endhint %}

All Ante Tests must follow the interface outlined in `IAnteTest.sol` to work with Ante. The interface outlines 8 main components:

* `setStateAndCheckTestPasses(bytes)`: this wrapper function takes a state parameter, updates the Ante Test's internal state and calls `checkTestPasses()` in a single transaction. *(Not all tests need state, most don't!)*
* `checkTestPasses()`: the core function that checks if the **invariant** holds. This is expected to return `True`. A `False` return value indicates a failure. **NB:** Reverts are not considered test failures.
* `testAuthor`: this overrides the auto-generated getter and allows `testAuthor` to be used as a public variable.
* `setTestAuthor`: this allows the current author to set the  `testAuthor` to a different address.
* `protocolName`: this overrides the auto-generated getter and allows the optional parameter `protocolName` to be used as a public variable.
* `testedContracts`: this overrides the auto-generated getter for the optional public variable `testedContracts`.
* `testName`: this overrides the auto-generated getter and allows `testName` to be used as a public variable.
* `getStateTypes`: this returns a string of comma-delimited types for Ante Tests that need state. This defines the expected format of the data encoded in the bytes parameter passed in to `setStateAndCheckTestPasses(bytes)`
* `getStateNames`: this returns a string of comma-delimited names for Ante Tests that need state. These names should describe what state values the test expects and are displayed as input labels to the test verifier in the Ante app. **NB:** There must a name label for each corresponding type.&#x20;

To aid in working with the `IAnteTest.sol` interface, we've created an `AnteTest.sol` **abstract** class that any Ante Test can inherit.

## Abstract Class [`AnteTest.sol`](https://github.com/anteproject/antescaffold/blob/master/packages/hardhat/contracts/interfaces/AnteTest.sol)

{% code lineNumbers="true" %}

```solidity
// SPDX-License-Identifier: GPL-3.0-only

// ┏━━━┓━━━━━┏┓━━━━━━━━━┏━━━┓━━━━━━━━━━━━━━━━━━━━━━━
// ┃┏━┓┃━━━━┏┛┗┓━━━━━━━━┃┏━━┛━━━━━━━━━━━━━━━━━━━━━━━
// ┃┗━┛┃┏━┓━┗┓┏┛┏━━┓━━━━┃┗━━┓┏┓┏━┓━┏━━┓━┏━┓━┏━━┓┏━━┓
// ┃┏━┓┃┃┏┓┓━┃┃━┃┏┓┃━━━━┃┏━━┛┣┫┃┏┓┓┗━┓┃━┃┏┓┓┃┏━┛┃┏┓┃
// ┃┃ ┃┃┃┃┃┃━┃┗┓┃┃━┫━┏┓━┃┃━━━┃┃┃┃┃┃┃┗┛┗┓┃┃┃┃┃┗━┓┃┃━┫
// ┗┛ ┗┛┗┛┗┛━┗━┛┗━━┛━┗┛━┗┛━━━┗┛┗┛┗┛┗━━━┛┗┛┗┛┗━━┛┗━━┛
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

pragma solidity ^0.8.0;

import "./interfaces/IAnteTest.sol";

/// @title Ante V0.6 Ante Test smart contract
/// @notice Abstract inheritable contract that supplies syntactic sugar for writing Ante Tests
/// @dev Usage: contract YourAnteTest is AnteTest("String descriptor of test") { ... }
abstract contract AnteTest is IAnteTest {
    /// @inheritdoc IAnteTest
    address public override testAuthor;
    /// @inheritdoc IAnteTest
    string public override testName;
    /// @inheritdoc IAnteTest
    string public override protocolName;
    /// @inheritdoc IAnteTest
    address[] public override testedContracts;

    /// @dev testedContracts and protocolName are optional parameters which should
    /// be set in the constructor of your AnteTest
    /// @param _testName The name of the Ante Test
    constructor(string memory _testName) {
        testAuthor = msg.sender;
        testName = _testName;
    }

    /// @inheritdoc IAnteTest
    function setStateAndCheckTestPasses(bytes memory _state) external override returns (bool) {
        if (_state.length > 0) {
            _setState(_state);
        }
        return checkTestPasses();
    }

    /// @notice Returns the testedContracts array of addresses
    /// @return The list of tested contracts as an array of addresses
    function getTestedContracts() external view returns (address[] memory) {
        return testedContracts;
    }

    /// @inheritdoc IAnteTest
    function setTestAuthor(address _testAuthor) external {
        require(msg.sender == testAuthor, "Only the current testAuthor can set a new test author");
        require(_testAuthor != address(0), "ANTE: Test author cannot be the zero address");
        address previousAuthor = testAuthor;
        testAuthor = _testAuthor;

        emit TestAuthorChanged(previousAuthor, _testAuthor);
    }

    /// @inheritdoc IAnteTest
    function getStateTypes() external pure virtual override returns (string memory) {
        return "";
    }

    /// @inheritdoc IAnteTest
    function getStateNames() external pure virtual override returns (string memory) {
        return "";
    }

    /// @inheritdoc IAnteTest
    function checkTestPasses() public virtual override returns (bool passes) {}

    /// @notice Function containing the logic to set the AnteTest state
    function _setState(bytes memory) internal virtual {}
}
```

{% endcode %}

{% hint style="info" %}
`AnteTest.sol` as of 2023-01-28
{% endhint %}

The `AnteTest.sol` is an abstract contract that once inherited, can be used to write any Ante Test. Just pass in a descriptive name for the test, designated by `_testName`. The optional parameters `protocolName` and `testedContracts` can be set in the constructor of your Ante Test.<br>

### Deriving from `AnteTest.sol`

You can use it by declaring your Ante Test like the following:&#x20;

```solidity
import "@antefinance/contracts/interfaces/AnteTest.sol";

contract AnteNewProtocolTest is AnteTest("String descriptor of test") {
    // create Ante Test variables & insert logic here
    
    // you can omit your constructor if not defining these optional parameters
    constructor () {
        protocolName = "My Protocol";
        testedContracts = [0x000000000000000000000000000000000000fEeD];
    }
    
    function checkTestPasses() public view override returns (bool) {
        // insert logic here to check the My Protocol invariant
    }
}
```

#### Stateful tests

When writing an Ante Test that needs internal state values, you can write:

{% code lineNumbers="true" %}

```solidity
import "@antefinance/contracts/interfaces/AnteTest.sol";

contract AnteNewProtocolTestWithState is AnteTest("String descriptor of test") {
    // declare any variables needed to test the invariant here
    string public myStringStateVariable;
    uint public myUintStateVariable;
    
    // you can omit your constructor if not defining these optional parameters
    constructor () {
        protocolName = "My Protocol";
        testedContracts = [0x000000000000000000000000000000000000fEeD];
    }
  
    // decode the encoded bytes and set the state variables
    function _setState(bytes memory _state) internal override {
        (string _myStringStateVariable, uint _myUintStateVariable) = abi.decode(
            _state,
            (string, uint)
        );
        myStringStateVariable = _myStringStateVariable;
        myUintStateVariable = _myUintStateVariable;
    }

    function checkTestPasses() public view override returns (bool) {
        // insert logic here to check the My Protocol invariant
    }
    
    // tell verifiers which encoded types they need to pass in
    function getStateTypes() external pure override returns (string memory) {
        return "string,uint";
    }

    // tell verifiers what state variable names they need to set values for
    function getStateNames() external pure override returns (string memory) {
        return "myStringStateVariable,myUintStateVariable";
    }
}
```

{% endcode %}

We'll see in the next section, how to use this abstract contract in some Ante Test examples.


# Ante Test Examples

Sample Ante Tests to dissect for explanation

## A Note on Writing Ante Tests

{% hint style="warning" %}
Take care in defining your project's guarantees **precisely**.

### **Only choose guarantees that you believe will never fail.**

It's this **guarantee** that you are making and potentially **staking** value on.
{% endhint %}

## Example: WBTC Supply Doesn't Exceed 21 Million

In `AnteWBTCSupplyTest.sol` we write an Ante Test that checks that the total outstanding supply of wrapped Bitcoin (WBTC) does not exceed 21 million, which is the known "maximum supply" of Bitcoin.

For more information on what **wrapped Bitcoin** is, please see <https://wbtc.network/> (external link).

{% code title="AnteWBTCSupplyTest.sol" lineNumbers="true" %}

```solidity
// SPDX-License-Identifier: GPL-3.0-only

// ┏━━━┓━━━━━┏┓━━━━━━━━━┏━━━┓━━━━━━━━━━━━━━━━━━━━━━━
// ┃┏━┓┃━━━━┏┛┗┓━━━━━━━━┃┏━━┛━━━━━━━━━━━━━━━━━━━━━━━
// ┃┗━┛┃┏━┓━┗┓┏┛┏━━┓━━━━┃┗━━┓┏┓┏━┓━┏━━┓━┏━┓━┏━━┓┏━━┓
// ┃┏━┓┃┃┏┓┓━┃┃━┃┏┓┃━━━━┃┏━━┛┣┫┃┏┓┓┗━┓┃━┃┏┓┓┃┏━┛┃┏┓┃
// ┃┃ ┃┃┃┃┃┃━┃┗┓┃┃━┫━┏┓━┃┃━━━┃┃┃┃┃┃┃┗┛┗┓┃┃┃┃┃┗━┓┃┃━┫
// ┗┛ ┗┛┗┛┗┛━┗━┛┗━━┛━┗┛━┗┛━━━┗┛┗┛┗┛┗━━━┛┗┛┗┛┗━━┛┗━━┛
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

pragma solidity ^0.8.0;

import "@openzeppelin/contracts/token/ERC20/IERC20.sol";
import "../AnteTest.sol";

/// @title WBTC supply never exceeds 21 million test
/// @notice Ante Test to check that WBTC supply is always less than 21 million
contract AnteWBTCSupplyTest is AnteTest("Wrapped BTC (WBTC) supply doesn't exceed 21m") {
    // https://etherscan.io/address/0x2260fac5e5542a773aa44fbcfedf7c193bc2c599#code
    address public immutable wBTCAddr;

    //21 million * 1e8 (for decimals), maximum total Bitcoin supply
    uint256 public constant THRESHOLD_SUPPLY = 21 * 1000 * 1000 * 1e8;

    IERC20 public wBTCToken;

    /// @param _wBTCAddr WBTC contract address (0x2260fac5e5542a773aa44fbcfedf7c193bc2c599 on mainnet)
    constructor(address _wBTCAddr) {
        protocolName = "WBTC";
        testedContracts = [_wBTCAddr];

        wBTCAddr = _wBTCAddr;
        wBTCToken = IERC20(_wBTCAddr);
    }

    /// @notice test to check WBTC token supply
    /// @return true if WBTC supply is less than 21 million
    function checkTestPasses() external view override returns (bool) {
        return (wBTCToken.totalSupply() <= THRESHOLD_SUPPLY);
    }
}
```

{% endcode %}

{% hint style="info" %}
`AnteWBTCSupplyTest.sol` as of 2023-01-26
{% endhint %}

This example outlines a sample Ante Test that uses the `AnteTest.sol` abstract contract that inherits `IAnteTest.sol` for use.

An explanation for the various lines are as follows:

* (Line 15) - Importing the contract `AnteTest.sol`
  * Future work: Will be packaged to a library for importing for ease of use
* (Line 19) - Contract inherits from AnteTest using  `... is AnteTest(...)`. It is here where the test name will be decided.
  * Recommended to have a human-readable description passed as in `AnteTest()` (e.g. "Wrapped BTC (WBTC) supply ...")
* (Lines 21-26) - Implement the variables and logic as needed for the test.
  * In this example, we define the variable for the WBTC address, it is set in the constructor (Line 33), and for clarity we wrote it in the comments (Line 20).
  * Following which, we set our threshold limit which is 21M, the maximum total Bitcoin supply.
  * Using the IERC20 interface provided by [@openzeppelin](https://openzeppelin.com/), we define WBTC from the address.
* (Lines 30-31) - The part of the constructor that tells Ante the name of the tested protocol and the tested contracts (for front-end convenience).
* (Lines 33-34) - Defines the WBTC address from the constructor, and then uses the IERC20 interface defined earlier to read the WBTC.
* (Line 39) - The `checkTestPasses()` function here does the final return on whether the test passes or not, which should be expected to be true, as the "guarantee" behind the Ante Test.
  * In this example, the wrapped BTC total supply should not exceed the threshold we set earlier (21M)
  * This should be assumed true, unless something extraordinary happens.

In this example above, the Ante Test guarantees that the WBTC circulation never exceeds 21 million.

## Example: WETH9 Minted WETH equals ETH Balance

In this test (`AnteWETH9Test.sol`) we check that the ETH deposited into the wrapped ETH (WETH9) contract does in fact equal the total number of WETH tokens (ERC20 compliant "ETH") circulating.

For more background around what is **wrapped Ether** we recommend reading <https://weth.io/> (external link).

{% code title="AnteWETH9Test.sol" lineNumbers="true" %}

```solidity
// SPDX-License-Identifier: GPL-3.0-only

// ┏━━━┓━━━━━┏┓━━━━━━━━━┏━━━┓━━━━━━━━━━━━━━━━━━━━━━━
// ┃┏━┓┃━━━━┏┛┗┓━━━━━━━━┃┏━━┛━━━━━━━━━━━━━━━━━━━━━━━
// ┃┗━┛┃┏━┓━┗┓┏┛┏━━┓━━━━┃┗━━┓┏┓┏━┓━┏━━┓━┏━┓━┏━━┓┏━━┓
// ┃┏━┓┃┃┏┓┓━┃┃━┃┏┓┃━━━━┃┏━━┛┣┫┃┏┓┓┗━┓┃━┃┏┓┓┃┏━┛┃┏┓┃
// ┃┃ ┃┃┃┃┃┃━┃┗┓┃┃━┫━┏┓━┃┃━━━┃┃┃┃┃┃┃┗┛┗┓┃┃┃┃┃┗━┓┃┃━┫
// ┗┛ ┗┛┗┛┗┛━┗━┛┗━━┛━┗┛━┗┛━━━┗┛┗┛┗┛┗━━━┛┗┛┗┛┗━━┛┗━━┛
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

pragma solidity ^0.8.0;

import "@openzeppelin/contracts/token/ERC20/IERC20.sol";
import "../AnteTest.sol";

/// @title WETH9 issued fully backed by ETH test
/// @notice Ante Test to check WETH9 minted WETH matches deposited ETH in contract
contract AnteWETH9Test is AnteTest("Checks WETH9 issued WETH fully backed by ETH") {
    // https://etherscan.io/address/0xC02aaA39b223FE8D0A0e5C4F27eAD9083C756Cc2
    address public immutable wETH9Addr;

    IERC20 public wETH9Token;

    /// @param _wETH9Addr WETH9 contract address (0xC02aaA39b223FE8D0A0e5C4F27eAD9083C756Cc2 on mainnet)
    constructor(address _wETH9Addr) {
        wETH9Addr = _wETH9Addr;
        wETH9Token = IERC20(_wETH9Addr);

        protocolName = "WETH9";
        testedContracts = [_wETH9Addr];
    }

    /// @notice test to check WETH token supply against contract balance
    /// @return true if WETH9 token supply equals contract balance
    function checkTestPasses() public view override returns (bool) {
        return address(wETH9Token).balance == wETH9Token.totalSupply();
    }
}
```

{% endcode %}

{% hint style="warning" %}
`AnteWETH9Test.sol as of 2023-01-26`
{% endhint %}

Building on the previous example, note the important lines in the WETH9 Ante Test:

1. (Line 15) - Import the `AnteTest.sol` abstract class
2. (Line 19) - Name the test with a human-readable string "*Checks WETH9...*"
3. (Line 21-23) - We define the needed variables here
   1. (Line 21) - Defines the `address` of the WETH9 contract to be set later in the constructor, additionally, added for clarity into the comments (Line 20).
   2. (Line 23) - We define the `IERC20` interface as `WETH9Token` to later interact with it
4. (Lines 27-28) - Stores the WETH9 address from the constructor, and then uses the IERC20 interface defined earlier to read the WETH9 contract.
5. (Lines 30-31) - The part of the constructor that tells Ante the name of the tested protocol and the tested contracts (for front-end convenience).
6. (Line 37) - We define the invariant for WETH9 with a boolean check

   1. Left side: we get the ETH balance of the address of the created WETH9 ERC20 token
   2. Right side: we get the outstanding supply of WETH9Token
   3. Invariant: the ETH deposited into WETH9 should always equal the WETH supply

## Example: ETH2DepositContract Balance "Rugs"

For context, in the lead-up to the launch of Ethereum2's beacon chain in late 2020, the Ethereum Foundation helped put together a "deposit contract" (with the ENS name DEPOSITCONTRACT.ETH that was paid for for 150 years and then had ownership burned) where people could, following a set of instructions, deposit ETH in multiples of 32 to spin up ETH2 validator nodes that earn Proof-of-Stake rewards for correctly helping to secure the Beacon Chain. For more information, please see <https://ethereum.org/en/eth2/>

In this test, we tongue-in-cheek check that the balance in DepositContract.eth does not drop by 99.99% (indicating that it is likely it has been compromised and a thief has stolen all of the funds).&#x20;

Note that it is possible for a clever thief to **steal all but 501 ETH,** in which case this Ante Test would **still** pass. While that is clearly a failure case of this Ante Test, we hope that for illustrative purposes this example shows a way to use Ante.

{% code title="AnteETH2DepositTest.sol" lineNumbers="true" %}

```solidity
// SPDX-License-Identifier: GPL-3.0-only

// ┏━━━┓━━━━━┏┓━━━━━━━━━┏━━━┓━━━━━━━━━━━━━━━━━━━━━━━
// ┃┏━┓┃━━━━┏┛┗┓━━━━━━━━┃┏━━┛━━━━━━━━━━━━━━━━━━━━━━━
// ┃┗━┛┃┏━┓━┗┓┏┛┏━━┓━━━━┃┗━━┓┏┓┏━┓━┏━━┓━┏━┓━┏━━┓┏━━┓
// ┃┏━┓┃┃┏┓┓━┃┃━┃┏┓┃━━━━┃┏━━┛┣┫┃┏┓┓┗━┓┃━┃┏┓┓┃┏━┛┃┏┓┃
// ┃┃ ┃┃┃┃┃┃━┃┗┓┃┃━┫━┏┓━┃┃━━━┃┃┃┃┃┃┃┗┛┗┓┃┃┃┃┃┗━┓┃┃━┫
// ┗┛ ┗┛┗┛┗┛━┗━┛┗━━┛━┗┛━┗┛━━━┗┛┗┛┗┛┗━━━┛┗┛┗┛┗━━┛┗━━┛
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

pragma solidity ^0.8.0;

import "../AnteTest.sol";

/// @title ETH2 beacon contract doesn't lose 99.99% of its ETH test
/// @notice Ante Test to check that ETH2 beacon depositcontract.eth doesn't lose 99.99% of
/// its ETH (as of May 2021)
contract AnteETH2DepositTest is AnteTest("ETH2 beacon deposit contract doesn't lose 99.99% of its ETH") {
    // depositcontract.eth, verified on https://ethereum.org/en/eth2/deposit-contract/
    // https://etherscan.io/address/0x00000000219ab540356cBB839Cbe05303d7705Fa
    address public immutable depositContractAddr;

    // As of 20210524 with 4.88m ETH deposited, 500 ETH represents a ~ -99.99% drop
    uint256 public constant THRESHOLD_BALANCE = 500 * 1e18; //500 ETH

    /// @param _depositContractAddr ETH2 deposit address (0x00000000219ab540356cBB839Cbe05303d7705Fa on mainnet)
    constructor(address _depositContractAddr) {
        protocolName = "ETH2";
        depositContractAddr = _depositContractAddr;
        testedContracts = [_depositContractAddr];
    }

    /// @notice test to check balance of eth2 deposit address
    /// @return true if deposit address balance is over 500 ETH
    function checkTestPasses() public view override returns (bool) {
        return (depositContractAddr.balance >= THRESHOLD_BALANCE);
    }
}
```

{% endcode %}

{% hint style="warning" %}
`AnteETH2DepositTest.sol` as of 2023-01-26
{% endhint %}

Breakdown of key lines:

1. (Lines 3-10) - ASCII Art we are very proud of that we definitely didn't rip off of DepositContract.eth :)
2. (Lines 22-25) - We define key state variables
   1. (Line 22) - We define the variable for the address, this is set when deploying the Ante Test as defined in the constructor, additionally, we write it for clarity in the comments (Line 21)
   2. (Line 25) - We define the "Threshold" at which we consider a "failure" to have happened (500 ETH)
3. (Lines 29-31) - The constructor that tells Ante the name of the tested protocol, sets the ETH2 contract address, and sets the tested contracts. **Note we only set the tested contract address here!**
4. (Line 37) - We check that the Deposit Contract still has greater than or equal to `THRESHOLD_BALANCE`.

## Example: EthDev Doesn't "Rug" Test

(Note: we use the term "rug" here casually -- as in, some large fraction of the balance in the contract vanishes from the address.)

The address described below is often labeled publicly as an "EthDev" (Ethereum Foundation's developer fund) address. Many online joke during market downturns that it is due to "EthDev" selling ETH or "EthDev Rugging." We do not support such rumors, but we figured it could make for an amusing illustrative example of what is possible with Ante.

This test checks that at least 1% of the ETH sitting in the "EthDev" address is still there. (Note: this is **not** meant to be an extremely **robust** Ante Test because EthDev's controlling parties could, for perfectly legitimate reasons, decide to move any or all of their ETH to a new address at any time.) Please view this as an Ante Test written purely for **educational purposes**.

{% code title="AnteEthDevRugTest.sol" lineNumbers="true" %}

```solidity
// SPDX-License-Identifier: GPL-3.0-only

// ┏━━━┓━━━━━┏┓━━━━━━━━━┏━━━┓━━━━━━━━━━━━━━━━━━━━━━━
// ┃┏━┓┃━━━━┏┛┗┓━━━━━━━━┃┏━━┛━━━━━━━━━━━━━━━━━━━━━━━
// ┃┗━┛┃┏━┓━┗┓┏┛┏━━┓━━━━┃┗━━┓┏┓┏━┓━┏━━┓━┏━┓━┏━━┓┏━━┓
// ┃┏━┓┃┃┏┓┓━┃┃━┃┏┓┃━━━━┃┏━━┛┣┫┃┏┓┓┗━┓┃━┃┏┓┓┃┏━┛┃┏┓┃
// ┃┃ ┃┃┃┃┃┃━┃┗┓┃┃━┫━┏┓━┃┃━━━┃┃┃┃┃┃┃┗┛┗┓┃┃┃┃┃┗━┓┃┃━┫
// ┗┛ ┗┛┗┛┗┛━┗━┛┗━━┛━┗┛━┗┛━━━┗┛┗┛┗┛┗━━━┛┗┛┗┛┗━━┛┗━━┛
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

pragma solidity ^0.8.0;

import "../AnteTest.sol";

/// @title ETHDev multisig doesn't rug test
/// @notice Ante Test to check if EthDev multisig "rugs" 99% of its ETH (as of May 2021)
contract AnteEthDevRugTest is AnteTest("EthDev MultiSig Doesnt Rug 99% of its ETH Test") {
    // https://etherscan.io/address/0xde0b295669a9fd93d5f28d9ec85e40f4cb697bae
    address public immutable ethDevAddr;

    // 2021-05-24: EthDev has 394k ETH, so -99% is ~4k ETH
    uint256 public constant RUG_THRESHOLD = 4 * 1000 * 1e18;

    /// @param _ethDevAddr eth multisig address (0xde0b295669a9fd93d5f28d9ec85e40f4cb697bae on mainnet)
    constructor(address _ethDevAddr) {
        protocolName = "ETH";
        ethDevAddr = _ethDevAddr;
        testedContracts = [_ethDevAddr];
    }

    /// @notice test to check balance of eth multisig
    /// @return true if eth multisig has over 4000 ETH
    function checkTestPasses() public view override returns (bool) {
        return ethDevAddr.balance >= RUG_THRESHOLD;
    }
}
```

{% endcode %}

{% hint style="info" %}
`AnteEthDevRugTest.sol` as of 2023-01-26
{% endhint %}

1. (Line 20) - Defines the EthDev address variable, this is set when deploying the Ante Test as defined in the constructor, additionally, we write it for clarity in the comments (Line 19)
2. (Line 23) - Defines the `RUG_THRESHOLD` which we've set to approximately 1% of the ETH of the total amount in the address as of 2021-05-24.
3. (Line 25-27) - The constructor that tells Ante the name of the tested protocol, sets the EthDev contract address, and sets the tested contracts.
4. (Line 29) - Check the inequality holds using the threshold defined earlier.


# Writing and Testing an Ante Test

## Writing the Ante Test

1. Fork the [Ante Community Repo](https://github.com/antefinance/ante-community-tests) and use it to develop and write your new Ante Test.
2. Check the `contracts` folder and see if the protocol in question is already created. If not, create the `protocol` folder there.
3. Create the Ante Test in its respective protocol folder.
4. Once completed, a good idea is to compile your test and make sure it compiles.\
   You can do that using the following commands in a bash terminal.

```bash
# Install necessary pacakges determined by the repository, be sure you're
# in the root directory of ante-community-tests
npm install

# This hardhat command compiles all tests in the repository.
npx hardhat compile
```

If npm isn't installed, please follow npm's [installation guide](https://docs.npmjs.com/downloading-and-installing-node-js-and-npm) to get it.

## AnteTest test: Writing an Ante Test's unit test

Now that the test has been written we should always make sure we test it to the best of our knowledge. Make sure it behaves the way we expect it to. To do that, we go through the following process.

1. In the Ante Community Repo that you've forked, there's a `test` folder where we write the unit tests for the Ante Test that was just written.
2. Locate the protocol folder for the test in question, if it doesn't exist, create a new one.
3. Tests here are written in Typescript, and labeled as such `ante_{test-name}_test.spec.ts`. We'll go over the `test/examples/ante_eth_dev_rug_test.spec.ts` below:

{% code title="ante\_eth\_dev\_rug\_test.spec.ts" lineNumbers="true" %}

```typescript
import hre from 'hardhat';
const { waffle } = hre;

import { AnteEthDevRugTest__factory, AnteEthDevRugTest } from '../../typechain';li

import { evmSnapshot, evmRevert } from '../helpers';
import { expect } from 'chai';

describe('AnteETHDevRugTest', function () {
  let test: AnteEthDevRugTest;

  let globalSnapshotId: string;

  before(async () => {
    globalSnapshotId = await evmSnapshot();

    const [deployer] = waffle.provider.getWallets();
    const factory = (await hre.ethers.getContractFactory('AnteEthDevRugTest', deployer)) as AnteEthDevRugTest__factory;
    test = await factory.deploy('0xde0b295669a9fd93d5f28d9ec85e40f4cb697bae');
    await test.deployed();
  });

  after(async () => {
    await evmRevert(globalSnapshotId);
  });

  it('should pass', async () => {
    expect(await test.checkTestPasses()).to.be.true;
  });
});

```

{% endcode %}

Line 4 - Here you'll want to replace the import with your own `{ANTE_TEST}__factory` and `{ANTE_TEST}`&#x20;

Line 18 - Be sure to replace `AnteEthDevRugTest` with the name of your AnteTest in the `getContractFactory()` call.

Line 19 - Any arguments that your Ante Test requires will need to be applied here. Anything passed into `deploy()` will go directly into the constructor of your AnteTest

Lines 27-29 - This is the basic test condition where on deployment with no changes applied yet, the Ante Test should pass.

In order to add more tests (for example, you have conditions that change after a change to an address). Then you'll want to add more `it('description, async() => {conditions})` that test these for you.

## Testing the unit test

Once a unit test is written that confirms your expectations, then it's time to test it in the real world (well, forked mainnet world to be specific)

1. Going back to the main folder of your forked community repo, run the following command to run through the unit tests.

```bash
# This command is a scripted command we added to the community repo in
# order to make the test running easier.
npm test
```

What `npm test` does is run the hardhat commands `npx hardhat typechain` and `npx hardhat test` to generate the typings for the tests written and then run the unit tests written in the entire repository.

It will then run through all unit tests (the ones in the `test` folder) and test each condition there. And finally, generate a summary of how many unit tests pass or fail.

If your unit tests fail here, some key points to check are:

* Ante Test - make sure the invariant you want to test here is correct.
* unit test - make sure that your assumptions that the Ante Test is testing is as you expect.


# Integrating Ante

Add an Ante badge into your website/web app

Show your users that you've put skin in the game by staking Ante Tests for your protocol! With just a few lines of code, you can add an Ante badge to your website or web app to show the real-time trust in your protocol.

<figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FXSavqWIRpcylj07araB0%2Ftest%20badge%402x.png?alt=media&amp;token=884cdd62-cac7-47f4-8440-57ba97dcf55e" alt=""><figcaption><p>Ante badges make trust more transparent!</p></figcaption></figure>

### How to use

{% content-ref url="/pages/CeRWOM8L2oC96bM6QlFf" %}
[Integrate Ante using React](/v0.6/for-developers/integrating-ante/integrate-ante-using-react)
{% endcontent-ref %}

{% content-ref url="/pages/erKrZZosAqXbpCcStS7e" %}
[Integrate Ante using HTML](/v0.6/for-developers/integrating-ante/integrate-ante-using-html)
{% endcontent-ref %}

### Where should I use an Ante badge?

Wherever your users would potentially gain peace of mind by knowing that a protocol has skin in the game! Some ideas in no particular order:

* If there are Ante Tests for the overall protocol, you can put a protocol-level trust tier badge with other security-related information on your web app or website
* If you have multiple vault-like products that each have Ante Tests, you could include the test badge on the vault UI so your users can see the level of decentralized trust in each vault (e.g. for long tail products)
* If you are integrating with a product that has an Ante Test written for it, you could include a protocol or test badge to indicate the level of trust in the dependency

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2Fi8jFztLSeNmzHHmNm51u%2Fimage.png?alt=media\&token=491fc24f-7105-4066-a13b-4c2fdd001bb9)

### Troubleshooting

If you have any questions or are running into issues, please reach out to the team in [Discord](https://discord.gg/ante).


# Integrate Ante using React

The Ante widget has been published as an npm package:

{% embed url="<https://www.npmjs.com/package/@antefinance/ante-widget-react>" %}

### Install ante-widget-react

**npm:** `npm i @antefinance/ante-widget-react`

**yarn:** `yarn add @antefinance/ante-widget-react`

### Build

```
npm i
npm run build
```

### Using AnteWidget

Import `AnteWidget` from the `ante-widget-react` package:

<pre class="language-typescript"><code class="lang-typescript"><strong>import AnteWidget from '@antefinance/ante-widget-react';
</strong>import '@antefinance/ante-widget/dist/widget.css'; // This will import the styles
</code></pre>

Then add the appropriate `AnteWidget` component where desired on your app:

```typescript
function Example() {
  ...
  return (
    <div>
      // To show the overall trust tier of a protocol
      <AnteWidget.Protocol name='PROTOCOL_NAME' />
      
      // To show the trust score on a specific Ante Test
      <AnteWidget.Test address='ANTE_TEST_ADDRESS' chain='0x1' />
    </div>
  );
}
```

{% hint style="warning" %}
Note: the protocol name string is case sensitive. If in doubt, check how the protocol name is spelled in the Ante app. Chain IDs can be looked up at <https://chainlist.org/>.
{% endhint %}

### Example of usage

The following code will generate badges for the Ante protocol as well as one of the Ante Tests that tests the ante protocol:

```
<AnteWidget.Protocol name='Ante' />
<AnteWidget.Test address='0x2EdC35B39BFBca6A52eA35612C2684D3D7654763' chain='0x1'>
```

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FF3mCVMbBV0344esXgtSo%2Fante-test-badge-example%402x.png?alt=media\&token=698f1443-501c-4d5e-b893-088bc5dca65d)

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FChYw8npVmT67kPZxMRwC%2Fante-test-badge-example%402x.png?alt=media\&token=64e879ca-68f7-470b-8c8f-3750ea0313cd)


# Integrate Ante using HTML

## How to use

First, add the following line in the `<head>` of the page (this contains the styling for the Ante badge):

```html
<link href="https://assets.ante.finance/widget/widget.css" rel="stylesheet" />
```

Then, insert the corresponding `<div>` tag(s) where you want the badge(s), replacing `YOUR_PROTOCOL_NAME` or `ANTE_TEST_ADDRESS` and `CHAIN_NAME` with the appropriate protocol/Ante Test:

```html
// To show the overall trust tier of a protocol
<div class="ante-protocol-widget"></div>

// To show the trust score on a specific Ante Test
<div class="ante-test-widget"></div>
```

{% hint style="warning" %}
Note: the protocol name string is case sensitive. If in doubt, check how the protocol name is spelled in the Ante app. Chain IDs can be looked up at <https://chainlist.org/>.
{% endhint %}

Finally, we need to add script tags to make it all work. If you're only implementing up to one protocol and/or one test badge, you can&#x20;

```html
<script src="https://assets.ante.finance/widget/widget.css"></script>
<script>
    AnteWidget.Protocol('.ante-protocol-widget',{
        name: 'ETH2',
        chain: '0x4', // If not provided, it defaults to '0x1' (Ethereum Mainnet)  
    });
    AnteWidget.Test('.ante-test-widget',{
        address: '0x806f60015F245F9F6442f9c81f915E45CCd76637',
        chain: '0x4' 
    });
</script>
```

If you need more than one protocol badge or test badge,

```html
<script src="https://assets.ante.finance/widget/widget.css"></script>
<script>
   var divs = document.querySelectorAll(".ante-protocol-widget");
    for (var i = 0; i < divs.length; i++) {
        AnteWidget.Protocol(divs[i].className,{
            name: divs[i].dataset.name,
            chain: divs[i].dataset.chain,
        });
    }
</script>
```

### Example of usage

The following code will generate badges for the Ante protocol as well as one of the Ante Tests that tests the ante protocol:

```
<div class="ante-protocol-widget" data-name="Ante"></div>
<div class="ante-test-widget" data-address="0x2EdC35B39BFBca6A52eA35612C2684D3D7654763" data-chain="0x1"></div>
```

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FtEik4Lq78eYRVUQYRsEo%2Fante-protocol-badge-example%402x.png?alt=media\&token=64a8869a-1b09-48bd-879a-5ee7077ed8f0)

![](https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FMcrQCZ2Icn8xFPVNilYX%2Fante-test-badge-example%402x.png?alt=media\&token=6a2f6880-bafd-426f-8035-ef9900c3792d)


# Deploying an Ante Test

Quick guide to deploying an Ante Test

If you are comfortable deploying your own Ante Test, you can follow the instructions below.

### Deploying your Ante Test <a href="#deploying-your-ante-test" id="deploying-your-ante-test"></a>

After you've written an Ante Test and are ready to deploy to Mainnet, deploy it with your favorite method and save the address!

For more details, [see our detailed tutorial](/v0.6/for-developers/deploying-an-ante-test/deploy-an-ante-test).​

### Create an Ante Pool <a href="#create-an-ante-pool" id="create-an-ante-pool"></a>

After deploying, you can use our `AntePoolFactory` to generate a non-custodial `AntePool` instance on mainnet (note: this will cost gas fees).

We have an [additional tutorial](#create-an-ante-pool) on that.

### Staking the Ante Test <a href="#staking-the-ante-test" id="staking-the-ante-test"></a>

Finally, if you want to show the community you have skin in the game, [learn how to stake your Ante Test](/v0.6/getting-started/user-guides/stake-an-ante-test), and how to further[ integrate Ante into your website](/v0.6/for-developers/integrating-ante), web-app, or more.

And if you have questions, feel free to [contact our team](https://app.gitbook.com/o/-MaBgoAQEbm4roOi5psf/s/-MaBhLPQtzmPqzNtEpO8/about/faqs#contact).


# Deploy an Ante Test

Deploy a completed Ante Test to Mainnet

We've provided several methods to deploy your own Ante Test below, starting with our current preferred method using Hardhat.

{% hint style="info" %}
As easier methods become available in the future, we'll link them here as we find them.
{% endhint %}

## Ante's deploy script using Hardhat

Our team currently prefers to use [Hardhat](https://hardhat.org/) to deploy our smart contracts. Assuming that the Ante Test has already been written, we can easily deploy an Ante Test to a network of our choosing using our prepared script `scripts/deploy_test.ts` in the [Ante Community Github](https://github.com/antefinance/ante-community-tests).

### Setup

First, make sure that the `.env` file is updated with the appropriate keys as per the readme section: [Configure the app](https://github.com/antefinance/ante-community-tests#configure-the-app)

Second, in `scripts/deploy_test.ts`, update the testName (Line 8) and arguments (Line 10) for the Ante Test you want to deploy.

{% code lineNumbers="true" %}

```typescript
import hre from 'hardhat';
import chalk from 'chalk';

const main = async () => {
  const [deployer] = await hre.ethers.getSigners();

  // name of the contract for Ante Test
  const testName = 'AnteEthDevRugTest';
  // array of constructor arguments for Ante Test
  const args = ['0xde0b295669a9fd93d5f28d9ec85e40f4cb697bae'] as const;
// script/deploy_test.ts continues
```

{% endcode %}

### Deployment

Once these two files have been properly set up, run **either** of the commands below to deploy the Ante Test:

* `npm run deploy-test -- --network [NETWORK_NAME]`
  * `npm run deploy-test` is a user-defined command that we've set up to run the npx hardhat command below
* `npx hardhat run scripts/deploy_test.ts --network [NETWORK_NAME]`

### Verification

Right now, your Ante Test is only visible on Etherscan in bytecode form. In order to provide source code transparency for end users, you can verify the contract on Etherscan. Hardhat provides a plugin for doing this which you can use following the steps below:

First, make sure that the `.env` file is updated with your Etherscan key.

Next, run the command:

* `npx hardhat verify --network [NETWORK_NAME] [DEPLOYED_ANTE_TEST_ADDRESS] "Constructor argument 1"`

If your Ante Test takes a more complex set of arguments, you can also use an `arguments.js` file and run the modified command:

* `npx hardhat verify --network [NETWORK_NAME] --constructor-args [ARGUMENTS_FILE] [DEPLOYED_ANTE_TEST_ADDRESS]`

The [Hardhat-Etherscan plugin](https://hardhat.org/plugins/nomiclabs-hardhat-etherscan.html) documentation provides additional information on configuration options for the `verify` command.

## Other deployment solutions

The **Ethereum Foundation** has outlined several methods for [deploying smart contracts](https://ethereum.org/en/developers/docs/smart-contracts/deploying/) (and in this case, an Ante Test).

The main points for deployment would be needing access to an Ethereum node, either having your own node, access to a public node, or using services like [Alchemy](https://www.alchemy.com/) or [Infura](https://infura.io/).

Additionally, there are other solutions that can be explored to deploy the Ante Test:

**Alchemy**: [Hello World Smart Contract](https://docs.alchemy.com/alchemy/tutorials/hello-world-smart-contract)

**Infura**: [Deploying Smart Contracts](https://blog.infura.io/deploying-smart-contracts-managing-transactions-ethereum/)

**Remix**: [Deploy & Run](https://remix-ide.readthedocs.io/en/latest/run.html)

## After deploying your Ante Test

{% hint style="warning" %}
Make sure you record and remember the address that your Ante Test is deployed to! It will be needed to generate the Ante Pool that end users will interact with.
{% endhint %}

Once you've deployed your Ante Test, you can then [create an Ante Pool](/v0.6/for-developers/deploying-an-ante-test/create-an-ante-pool) (note: this will cost gas as well) to allow users to stake/challenge your test.


# Create an Ante Pool

Deploying the Ante Pool for supporters and challengers to stake and challenge the Ante Test.

{% hint style="warning" %}
This process requires gas in order to interact with the Ante Pool Factory and create the Ante Pool that links with the previously written Ante Test.
{% endhint %}

Once the new Ante Test has been deployed on the mainnet, and it's address has been recorded and readied, we're ready to deploy the Ante Pool to integrate with the new Ante Test!

<figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FSA5BWhV4LooT8AnVsuFi%2Fimage.png?alt=media&amp;token=907e349d-b60c-4a95-b8df-407113276b3b" alt=""><figcaption><p>The create pool page on the ante webapp</p></figcaption></figure>

With the address of the deployed `AnteTest`, use our [Ante Pool Factory generator](https://app.ante.finance/#/create-pool) and enter in the address. The site will double check the two criteria before deployment:

* The Ante Test hasn't already been deployed yet.
* The Ante Test doesn't currently fail.

In addition, you can configure the following parameters for the new pool:

<figure><img src="https://3703626754-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYcWJGD2fAVyIUH34sMhH%2Fuploads%2FVBlPTw4VDc3vUPc5vsAv%2Fimage.png?alt=media&amp;token=6187f888-d1aa-4ec4-a55b-c53afa2588e9" alt=""><figcaption><p>Pool parameters can be easily configured on the web app before creation.</p></figcaption></figure>

* **Pool currency** - Select one of the supported ERC20 tokens for staking and challenging the ante test. Need additional token support? [Let us know!](https://docs.ante.finance/antev05/about/faqs#contact)
* **Challenger payout** - The ratio of staked to challenged funds allowed in the pool. The higher the ratio, the higher the potential payout for challengers.
* **Decay rate** - The fees paid to stakers as an annualized percent of challenger funds. **NB:** A value above 100% means the challengers stake can be completely decayed in less than a year. *(e.g. a value of 400% consumes the challenger funds in about three months.)*
* **Test Author Reward** - This determines what percentage of the decay fees go to the author of the test.

Once all values have been configured, click "Create Pool", pay the gas fee and we'll take care of the rest, this will include:

* Adding and integrating an `AntePool` with the new `AnteTest`.
* Adding the new Ante test to our webapp to browse and interact with.

And that's it! A new and complete Ante test has been written, tested, and deployed to the mainnet and now we can find supporters and challengers. Now that the Ante Pool is visible on the leaderboard, we want the Ante Test to be verified by the community and get the verified tag attached.

{% hint style="warning" %}
If you want to signal to the community your confidence in your own test, it could make sense to stake your own `AntePool`.&#x20;

That said, never put funds, crypto or otherwise, into smart contracts you don't fully understand.&#x20;

**Please read through the AntePool and AntePoolFactory contracts before staking any funds in those non-custodial contracts. If something goes wrong, they are not recoverable by anyone else.**
{% endhint %}


# Deployed contracts

### Core smart contracts

<https://github.com/antefinance/ante-v06-core>

### Deployed Factories

#### Mainnet

<table><thead><tr><th width="251">Network</th><th>Factory</th></tr></thead><tbody><tr><td>Ethereum Mainnet</td><td><a href="https://etherscan.io/address/0x89E583A67B5FA1B39b8CE7E77654071c3a34cc48#code">0x89E583A67B5FA1B39b8CE7E77654071c3a34cc48</a></td></tr><tr><td>Optimism</td><td><a href="https://optimistic.etherscan.io/address/0x4f2be0244146b4408154504a481c799ba1a9a355#readContract">0x4f2be0244146b4408154504a481c799ba1a9a355</a></td></tr><tr><td>zkSync</td><td><a href="https://explorer.zksync.io/address/0xCE38604C2cF369e9cc67DF75E2Bd5626184D56A0">0xCE38604C2cF369e9cc67DF75E2Bd5626184D56A0</a></td></tr><tr><td>Arbitrum</td><td><a href="https://arbiscan.io/address/0x1A53b3500216D547186C833c35F39a82053B7223">0x1A53b3500216D547186C833c35F39a82053B7223</a></td></tr></tbody></table>

#### Testnet

<table><thead><tr><th width="251">Network</th><th>Factory</th></tr></thead><tbody><tr><td>Ethereum Goerli</td><td><a href="https://goerli.etherscan.io/address/0xE4452a09eDDc633f9f51D8c0a01BFDa18f35441d#code">0xE4452a09eDDc633f9f51D8c0a01BFDa18f35441d</a></td></tr><tr><td>Optimism</td><td><a href="https://goerli-optimism.etherscan.io/address/0x6696d9dFE0a28e5bc9d47C32DDEa0295Fdfb8B27#code">0x6696d9dFE0a28e5bc9d47C32DDEa0295Fdfb8B27</a></td></tr><tr><td>Arbitrum</td><td></td></tr><tr><td>Scroll Alpha </td><td><a href="https://blockscout.scroll.io/address/0xf83A823a57B2C67A71a91BFDe2Ef6CA4c0F5c031/contracts#address-tabs">0xf83A823a57B2C67A71a91BFDe2Ef6CA4c0F5c031</a></td></tr></tbody></table>

### Deployed Contracts

#### AntePoolFactoryController

The factory controller governs the list of supported ERC20 tokens for AntePool staking and challenging and also stores the address of the implementation contract of the `AntePool` contract the factory deploys.

The addresses of the `AntePoolFactoryController` deployments are accessible via the `controller()` function of the `AntePoolFactory` contracts.<br>

#### AntePoolLogic

This contract implements the logic behind the minimal proxy `AntePool` contracts.

The address of the ante pool implementation contract is accessible via the `antePoolLogicAddr()` function of the `AntePoolFactoryController` contracts.

### Deployed Pools

The addresses of all Ante Pools created by AntePoolFactory are stored in the `allPools` array. Alternatively, if you have the address of the Ante Test, you can look up the corresponding Ante Pool address using `poolsByTest(address)` via block explorer, etc.


# Welcome to Ante v0.5

Smart Tests for Smart Contracts

## What is Ante?

**Ante is building the Schelling Point for Decentralized Trust.**

Ante makes it easy for blockchain protocols and developers to create on-chain guarantees for any smart contract system. Users can **stake** guarantees they expect to hold true and **challenge** those they doubt. Those guarantees can be checked by anyone in real-time, and payment is automatically determined based on whether those guarantees continue to hold. [Learn how it works](/v0.5/how-ante-works).

#### What does this mean? <a href="#id-2119" id="id-2119"></a>

One way to think about this is that Ante provides “financial verification” for smart contracts. Guarantees can be made about any testable on-chain condition, with payouts delivered programmatically upon test failure without requiring intermediaries/trusted third parties (see some examples of [invariants](/v0.5/for-devs/writing-an-ante-test/invariant-ideas) that could be tested). Protocols that stake Ante Tests for their smart contracts are putting skin in the game, staking their confidence in the quality of their smart contracts with their own capital.

What’s more, community activity around a test allows for an automatically generated [Decentralized Trust Score](/v0.5/using-ante/trust-score) that reflects the community’s trust in that particular protocol. In this way, Ante increases trust in the DeFi ecosystem and enables more advanced and secure composition of DeFi primitives and existing financial service integrations as others can later build more complex products upon those building blocks of computational trust.

Feel free to browse through the docs or talk to us on [Twitter](https://twitter.com/AnteFinance), [Telegram](https://t.me/antefinance), and [Discord](http://ante.xyz/) if you have questions!

## How do I get my project on Ante?

Anyone can write an Ante Test with the 4-step guide below:

{% content-ref url="/pages/-MaBhs4pRWkiriSKdJ6k" %}
[Writing an Ante Test](/v0.5/for-devs/writing-an-ante-test)
{% endcontent-ref %}

Additionally, teams/developers that are comfortable deploying their own smart contracts can do so with the following guide:

{% content-ref url="/pages/-MaGVhevWonijMpzm0PD" %}
[Deploying an Ante Test](/v0.5/for-devs/deploying-an-ante-test)
{% endcontent-ref %}

Please reach out to us on [Twitter](https://twitter.com/AnteFinance) and [Discord](https://discord.ante.finance) or send an email to more <hello@ante.finance> if you want to learn.


# How Ante works

A high-level overview of Ante's mechanics

Ante's design is subject to change as its usage evolves.  **This is meant as a high-level overview of mechanics.** Please read "[Using Ante](/v0.5/using-ante/navigation)" and talk to us on [Twitter](https://twitter.com/AnteFinance) and [Discord](https://t.co/z9vxqMJ77w?amp=1) if you have specific questions.

### Ante Tests and Ante Pools

**Ante Tests** are smart contracts that check custom invariants of other smart contract systems like DeFi projects.

**Ante Pools** hold capital for an associated Ante Test and provide a standard set of functions for users to interact with. Anyone can put capital in an `AntePool` as a **staker** (supporting the invariant passing) or **challenger** (supporting the invariant failing).

{% hint style="info" %}
**Importantly, all staker and challenger capital held in Ante smart contracts is held in a non-custodial way.**
{% endhint %}

### Test Pass/Fail Verification

* Any challenger that has participated in an Ante Pool for at least 12 blocks can "verify" that an Ante Test still passes.
  * This means calling `checkTest()` on the `AntePool`, which calls `checkTestPasses()` on the associated `AnteTest`
  * Checking an Ante Test costs gas to complete the transaction. Ante takes no fee here.
* If the underlying invariant holds, nothing happens except the verifying challenger had to pay gas.
* If the underlying invariant fails (i.e. `checkTestPasses()` returns `False`, all staker capital is locked and claimable by challengers.

### Incentive Mechanisms

For **stakers**: challenger capital undergoes a block-by-block decay (\~100 gwei per block per ETH of challenger capital, roughly 20% of challenger capital per year). This decay is allocated to stakers (if you want a quick ballpark estimate, total challenger capital / total staker capital \* 20% \~= your "APY").

![Stakers are rewarded over time for their continued trust](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MaBhLPQtzmPqzNtEpO8%2F-MlCnVFOr2qqihDoSDxe%2F-MlCn_GdUO3F_Ym9IXnF%2Fstake.png?alt=media\&token=8d486920-e7c4-4d0a-a227-60d6f9511b54)

For **challengers**: if a challenger checks the Ante Test and it fails, all staker capital in the corresponding Ante Pool is locked and claimable by challengers, with the verifying challenger receiving an added bonus (5% of staker capital) for being the one to discover the test failure.

![Failed tests reward challengers for identifying risk in the system](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MaBhLPQtzmPqzNtEpO8%2F-MlCnVFOr2qqihDoSDxe%2F-MlCneg2eQ4ITHNeQR4K%2Fchallenge.png?alt=media\&token=29cdbc0b-bffe-47e5-a4b9-399654068857)


# Why use Ante?

Ante is a decentralized protocol to build the Schelling Point of Computational Trust.

**ELI5**: Normal apps have live tests to check their systems. When they fail, engineers fix them. But Smart Contracts are immutable or tricky to upgrade, so when stacked together, small failures compound. Users need hard guarantees so it's easier to trust and build upon DeFi. Ante is a home for better tests for Smart Contracts.

**ELI2**: Ante = Smart Tests for Smart Contracts

Ante provides value to a variety of users:

{% tabs %}
{% tab title="For Developers" %}
**Do you write Smart Contracts?**

* Do you **manually** check your smart contracts with **only** off-chain tests?
* Do you want users to feel **confident** about your smart contracts?
* Do you worry about convincing users that your code does what you claim?

Let them verify for themselves, on-chain.

#### **Ante: Smart Tests for Smart Contracts.**

Ante makes it easy to signal confidence in your smart contracts with **skin in the game.** On Ante, developers can make their protocol invariants explicit and **signal responsibility** with their code, all without third parties.

Ante also calculates **decentralized trust scores**, which shows in real time how much the DeFi community trusts your code. This allows you to better optimize for success.

Grow your community and build user trust **as fast as you code.**

[**Start now and write your own Ante Test in 10 minutes**](/v0.5/for-devs/writing-an-ante-test)**.**
{% endtab %}

{% tab title="For DeFi Users" %}

#### Do you deploy money in Smart Contracts?

Do you want to be *smart* about where you put money?

Ante hosts on-chain, tamper-resistant guarantees about smart contracts. Legitimate projects use Ante to **make guarantees** about their smart contracts. Anyone can verify those guarantees hold, on-chain.

Ante shows which protocols have **skin in the game** and have thought deeply about their protocol **invariants** (assumptions that should always hold, like debt < collateral) across their smart contracts. Ante also computes a real-time **decentralized trust score** from the community's participation in Ante.

**Use Ante to easily compare trust across DeFi projects and to make smarter decisions.**
{% endtab %}

{% tab title="For Security Experts" %}
Have you noticed irresponsible teams being cavalier with their Smart Contracts?

Do you wish teams with good practices were trusted more than teams that mainly hire shills?

Does it frustrate you that legitimate projects struggle to stand out?

Use Ante to verify tests and keep decentralized trust scores in line. Get rewarded by the community when you're right. Help start a more responsible standard for smart contracts.

**Start today by reviewing live Ante Tests to increase DeFi safety.**
{% endtab %}
{% endtabs %}


# How is Ante different?

How Ante fits into the existing DeFi landscape

## Ante's "Anti"-Definition

Ante is **not:**

* an auditing service;
* an "economic analysis" service;
* a bug bounty program;
* "hack insurance"

Ante is a protocol built for protocols (and their users) to increase DeFi safety by making trust explici&#x74;**.**&#x20;

Ante is a way for protocols to show users they are aligne&#x64;**.**

Ante is complementary to existing DeFi security, marketing, and trust services. Ante makes it easy to gather **on-chain**, **transparent**, **real-time** feedback about the community's trust in a protocol.

## Comparisons to existing mechanisms

Below, we compare Ante to existing ways protocols can signal trustworthines&#x73;**.**&#x20;

Note: we think all of the services below are **valuable and important to building safe and secure DeFi.** Our analysis is meant to emphasize Ante's strengths, **not to put down other services**. In particular, we **love and applaud** the work done at:

1. (Audits) [Trail of Bits](https://www.trailofbits.com/): a leading security firm (for almost a decade) that made a static analyzer we love, [slither](https://arxiv.org/abs/1908.09878)
2. (Analysis) [Gauntlet Networks](https://gauntlet.network/): with an agent-based simulation platform
3. (Bug Bounties) [Immunefi](https://immunefi.com/): with several million dollars of live bounties
4. (Protocol "Insurance) [Nexus Mutual](https://nexusmutual.io/): with a first-in-class on-chain mutual approach to protocol security

{% tabs %}
{% tab title="Audits & Analysis" %}

| Audits & Analysis                                                                                                                                 | Ante                                                                                                                                                                                                                                               |
| ------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <ul><li>Costs $50k–$200k+</li><li>Takes weeks/months to obtain (waitlist, delay)</li><li>May only cover (outdated) code at time of hire</li></ul> | <ul><li>No up-front costs (just gas and ETH stakes)</li><li>Can be written <a href="/v0.5/for-devs/writing-an-ante-test">in 10 min</a></li><li>Can verify code invariants in real-time and give immediate feedback about community trust</li></ul> |
| {% endtab %}                                                                                                                                      |                                                                                                                                                                                                                                                    |

{% tab title="Bug Bounties" %}

| Bug Bounties                                                                                                                                                                                                   | Ante                                                                                                                                                                                                                                                       |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <ul><li>Requires trusting administrators with discretionary payouts</li><li>No payouts to risk-averse users on failure</li><li>Limited guarantees that bounties are worth a security expert's energy</li></ul> | <ul><li>Fully self-serve (protocols write & stake tests) with automated payouts</li><li>Skeptical early users can challenge on Ante  and claim staker funds on failure</li><li>Objective level of community engagement (staking and challenging)</li></ul> |
| {% endtab %}                                                                                                                                                                                                   |                                                                                                                                                                                                                                                            |

{% tab title="Protocol Insurance" %}

| Protocol "Insurance"                                                                                                                                                                                                                                                   | Ante                                                                                                                                                                                                                                                                                                                              |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <ul><li>Hard to find underwriters for new protocols</li><li>Frequently gated listings</li><li>Payouts determined by voting, with limited guarantees of protection</li><li>Protection of last resort, but doesn't enhance underlying smart contract integrity</li></ul> | <ul><li>Free to use, write your test and encourage the community to stake</li><li>Self-serve "Listing" on Ante</li><li>Ante payouts are unambiguously settled by blockchain state, with transparent flow of Ante Pool funds</li><li>Incentivizes protocols to take code seriously and for users to review protocol code</li></ul> |
| {% endtab %}                                                                                                                                                                                                                                                           |                                                                                                                                                                                                                                                                                                                                   |
| {% endtabs %}                                                                                                                                                                                                                                                          |                                                                                                                                                                                                                                                                                                                                   |

## A hypothetical case study

Suppose there are two lending protocols. &#x20;

**Protocol A** is requires that borrowers post collateral that is 150% of the value of their borrowing.  Protocol A uses Ante and its team writes an Ante Test that verifies that the debt-to-collateral ratio holds.  Protocol A also stakes capital behind these Ante Tests.

**Protocol B** is a fork of Protocol A with the same collateral requirement but does not use Ante.

### Using Ante increases user trust and protocol adoption

Protocol A has signaled **alignment with users** and trustworthiness in the soundness of its smart contracts. Writing and staking Ante Tests tells the community at least 3 things about Protocol A:

1. Its smart contract is written correctly and that the team does not believe that its collateral model will break;
2. The team is willing to lose its own money if it wrote sloppy code; and
3. The team is serious about properly written code, so much so that it has taken the time to write on-chain tests.

In deciding where to put its capital, a liquidity provider (LP) sees that Protocol A allows for real-time on-chain verification of loan collateral balances.  Furthermore, if the LP was only cautiously trusting of Protocol A, the LP could also challenge the Ante Test and receive a payout if the collateral invariant ever failed.

Protocol A signals its alignment with liquidity providers, and, in light of this, Protocol B's decision to not use Ante is a glaring omission.  Protocol A has a significant edge over Protocol B in both its public perception and fundamental economics.  Over time, this will drive users to Protocol A over Protocol B.

### How does Ante screen out incompetent or dishonest teams?

First, teams need to be skilled enough to know what Ante Tests to write and to write reasonable code. Ante Tests are short smart contracts when compared to most protocol code, so a community security expert can call out useless Ante Tests at a glance. That means it's faster to call out dodgy team&#x73;**.**

Second, an Ante Test needs staking to be perceived as a credible commitment from a team. A non-serious team likely would not stake crypto behind its own (sloppy) Ante Tests that it writes because of the likelihood of loss to challengers.

Finally, if a shady team writes a valid Ante Test but tries to pull its stake right before a planned theft, Ante's design locks stakes for a day before allowing withdrawal, meaning that if the Ante Test fails during that time, their funds are still forfeited to challengers.


# What does Ante cost to use?

For using Ante? No subscriptions, no billing, no invoicing.

Ante is an open, decentralized protocol. v0.5 is launching on Ethereum and is available for anyone to use.

As with all smart contracts running on the Ethereum blockchain, users have to pay gas costs using ETH.

However, there is **work that is needed** in order to create an **Ante Test** for your project:

* You can write your own Ante Test.
* You can hire developers to write an Ante Test for you.
* You can ask the Ante community to write an Ante Test for you.

When you deploy an `AnteTest` and generate an `AntePool`, there will not **automatically** be participants staking that pool from the start. You can choose to stake ETH in that `AntePool` (or have your project's treasury stake). You can also ask community members, investors, or supporters to stake.&#x20;

**Without staking in the `AntePool`, it's hard to signal legitimacy using Ante.** **Please plan accordingly.  As with any Smart Contract, never stake more than you are comfortable losing!**


# What's in Ante v0.5?

Features included in Ante v0.5

Ante v0.5 focuses on demonstrating the basic Ante mechanisms on Ante team-generated example Ante Tests while providing tools for the community to write and submit their own Ante Tests.

{% hint style="warning" %}
While Ante v0.5 has been audited, it is meant to be an **alpha release**. **Please use it at your own risk.**
{% endhint %}

### **Currently live**

* Ante-Team generated example Ante Tests
* Ability to import interface `IAnteTest.sol` or abstract class `AnteTest.sol` to begin building your Ante Test
* Documentation on how to use Ante
* A front-end to stake and challenge Ante Tests
* Live Ante Tests that have been deployed by the Ante community
* Once an Ante Test is written and deployed to mainnet, users can use the `AntePoolFactory` to generate an `AntePool` that enables staking and challenging of the live Ante Test
* Protocol profiles aggregating protocol trust information

### Coming soon

* Test quality system (e.g. what makes a good Ante Test?)
* Additional front-end improvements (developer profiles, etc.)
* Ante partner badges that could be used to show potential protocol users that the developers have staked Ante Tests for their protocol


# Navigating Ante

How to interpret the leaderboard and other information.

## Leaderboard

When you first enter the Ante web app, you'll find the Ante Leaderboard. Here, you can see how much value has been locked across all Ante Tests as well as the top Ante Tests ranked by locked value and [Decentralized Trust Score](/v0.5/using-ante/trust-score).

![Ante Leaderboard as of 11/26/2021](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MaBhLPQtzmPqzNtEpO8%2Fuploads%2FluHO9RBfuSURq0vLWppI%2Fante_webapp_20211126.png?alt=media\&token=cbeba090-6781-411b-bcc6-570effa8b71a)

{% hint style="info" %}
The Decentralized Trust Score is a weighted metric that represents the level of trust the Ante community has in a protocol as expressed by staking and challenging in Ante Pools. A higher Trust Score means more people in the Ante community trust the protocol.
{% endhint %}

## My Positions

When you have connected your wallet to Ante, the My Positions page displays all Ante Pools where you hold a position, as well as some overall statistics such as the total value you have staked/challenged across Ante Pools.

![Sample My Positions page](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MaBhLPQtzmPqzNtEpO8%2F-MkP7xu_RloQlxVJ8k-z%2F-MkPEqwiH067ya5W2lFS%2Fante-my-positions.png?alt=media\&token=f6202b95-7f3c-4949-b6e3-9869a12cddee)

## Ante Test Detail Page

By clicking on any Test on the Leaderboard or My Positions, you can navigate to a page that provides details about the Ante Test being staked/challenged and allows you to take action on that test.

{% hint style="info" %}
*Technically*, when staking or challenging an **Ante Test**, you are locking up crypto in an intermediate, programmatically-generated non-custodial smart contract called an **Ante Pool**.&#x20;

(Why do we do this? So that there's less chance for loss of staked or challenged funds.)
{% endhint %}

### Breaking It Down

The Ante Test detail page has two main sections: the Details panel and the Actions panel.

The Details panel displays information about the Ante Test, the contract it is testing, and the current stake/challenge balances.

![Ante Test Detail Page](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MaBhLPQtzmPqzNtEpO8%2Fuploads%2FEQL0CUqhO8AOYpDROR5G%2Fante_test_detail_page_20211126.png?alt=media\&token=4eba7a30-1c70-4c1e-9600-fc25ea287471)

The Actions Panel, on the other hand, shows any existing positions you hold and actions you can take on the Ante Test once you have connected your wallet.

![Actions panel for Staked and Challenged states](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MaBhLPQtzmPqzNtEpO8%2F-MkPGf6MM6olgl1KaKn8%2F-MkPIf0G9-vbYXpauel5%2Faction-panel.png?alt=media\&token=c5fc514d-4643-47cb-9692-0cae0b4fe610)

To learn more about these actions, please continue on to the [How to Stake](/v0.5/using-ante/how-to-stake) and [How to Challenge & Verify](/v0.5/using-ante/how-to-challenge-and-verify) sections.


# How to Stake

Staking an Ante Test to signal trust in the tested protocol

By staking an Ante Test for a protocol with crypto, you are **deploying crypto that could be lost** (based on the results of the corresponding Ante Test) and to show trust in the protocol.&#x20;

But, you’re also participating in the future of decentralized finance, potentially earning rewards from challengers, and putting your money where your mouth is!

## Staking an Ante Test

To stake an Ante Test, use our webapp (coming soon!) and connect your wallet. When viewing a test, click the "Stake" button. Enter the amount you would like to stake and follow your wallet's prompt to submit the transaction (note there may be [deposit limits](/v0.5/using-ante/deposit-limits)).

{% hint style="danger" %}

### Never send crypto (ETH or tokens) directly to an Ante Test!

Only use an appropriate GUI or call the correct functions of the smart contract.
{% endhint %}

![](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MaBhLPQtzmPqzNtEpO8%2F-Mb8bYjTY6IBsNL0CPxL%2F-Mb8zxVFmXp2a91J8g1h%2Fmodal-stake%402x.png?alt=media\&token=3ed83a96-9ad3-4a19-9419-75db2c6f5b81)

{% hint style="info" %}
Currently, **Ante Pools** have limits of how much crypto one can stake or deposit.

Over time, the deposit cap may be increased ([view schedule](/v0.5/using-ante/deposit-limits)).
{% endhint %}

## Earning Rewards for Staking

Staking crypto assets behind an Ante Test involves a certain amount of risk (you will lose your **entire stake** if the Ante Test fails), but you may also earn rewards for participating.&#x20;

Over time, some amount of “decay” from what challengers have deposited is divided between all stakers and eventually claimable (in addition to your staked amount, if the Ante Test doesn't fail).

![Decay from the challenger pool is distributed to stakers](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MaBhLPQtzmPqzNtEpO8%2F-MaCdC7IDeHtTe7pDVwf%2F-MaG3NO4asUcTdgfN1wF%2Fdecay-illustrated.gif?alt=media\&token=ede68d03-4589-4ac1-8811-3f04c615231c)

The amount of decay rewards will vary. It will fluctuate depending on:

* **How much crypto is challenging** **the Ante Test?**  The more challenger crypto, the more accumulated decay each block.
* **The percentage of your stake versus the total staked** – you get credited roughly a pro-rata portion of decay rewards, so the more you stake, the greater your share of the decay rewards.

Decay is calculated by charging challengers approximately 100 GWEI per ETH per block, which at \~6000 blocks per day is approximately 20% per year.

### Decay Reward FAQs

**Q: How do I get my share of the decay?**

**A:** Decay rewards are credited to your stake balance. If you started out with a 1.000 ETH stake and earned 0.337 ETH in decay, your total stake balance would now be 1.337 ETH, which you can unlock and claim.

You can leave it alone to continue accumulating decay rewards, or you can unlock and withdraw your stake to exit staking.

**Q: What happens if 0 crypto is challenged in an Ante Test?**

**A:** Then **no decay rewards will be generated.** Decay only occurs when challengers participate.

## Withdrawing a Stake

In order to prevent certain types of malicious use of Ante, you must first **unlock** your stake, wait \~1 day, and *then* withdraw your stake.&#x20;

![](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MaBhLPQtzmPqzNtEpO8%2F-MaG3XFCLdoEU8A5zy5h%2F-MaG8bxhtKXP5K8a99sr%2Fwithdraw-process.png?alt=media\&token=03c21f90-deb4-4945-aff4-3c1f548fc1e0)

To initiate the unlocking process, click "Start Withdrawal" and confirm the transaction.

{% hint style="warning" %}
Once you start the unlocking process, you will no longer earn decay rewards on your stake.
{% endhint %}

Once the unlocking period has passed, you should now see "Withdraw Stake" available as an action. Click the button and follow the prompts to withdraw your stake to your wallet.

## If an Ante Test Fails...

Bummer! It looks like the protocol's invariant failed. **Your funds are locked and lost to you, and you will no longer be able to access them.**

Challengers can claim their share of the stake pool for correctly identifying flaws in the protocol.


# How to Challenge & Check Tests

Expressing skepticism in an Ante Test for a protocol

If you're skeptical that a protocol's Ante Test will hold, you can **challenge** that Ante Test.

By challenging an Ante Test, you’re taking the position that the Ante Test can/will fail, which could indicate a vulnerability in the protocol. You will pay a block-by-block decay on your challenged crypto to stakers (\~100 gwei per block per ETH, roughly 20% of your challenged crypto per year) but have the potential benefit of a larger bounty if the Ante Test actually fails.

## Challenging an Ante Test

To challenge in an Ante Pool, simply connect your wallet and click the "Challenge" button. Enter the amount you would like to add to the challenge pool and follow your wallet's prompt to submit the transaction. Note that there may be [deposit limits](/v0.5/using-ante/deposit-limits).

{% hint style="danger" %}

### Never send crypto (ETH or tokens) directly to an Ante Test!

Only use an appropriate GUI or call the correct functions of the smart contract.
{% endhint %}

![](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MaBhLPQtzmPqzNtEpO8%2F-Mb8bYjTY6IBsNL0CPxL%2F-Mb9-7BLk3qz-xlTWeT3%2Fmodal-challenge%402x.png?alt=media\&token=d6df4aaf-c7ac-4739-9d23-fcbaaa2cec64)

{% hint style="info" %}
*Technically*, when staking crypto behind an **Ante Test**, you are locking crypto in an intermediate, programmatically-generated non-custodial smart contract called an **Ante Pool**.&#x20;

Currently, **Ante Pools** have limits of how much crypto one can stake or deposit. Over time, the deposit cap may be increased ([view schedule](/v0.5/using-ante/deposit-limits)).
{% endhint %}

## Withdrawing a Challenge

Unlike staking, there is no unlocking period for withdrawing a challenge. To withdraw your challenge balance, click the "Withdraw Challenge" button in the Action Panel and follow the prompts to withdraw your balance to your wallet.

## Verifying a Test

Once you have challenged a test pool for at least 12 blocks, you are able to trigger the "Check Test" action to see if the test passes or fails.

{% hint style="info" %}
Verifying an Ante Test costs gas to complete the transaction. Ante takes no fee here.
{% endhint %}

### If the Ante Test passes:

If the Ante Test passes, it means the underlying protocol invariant still holds. The Ante Pool continues to operate and nothing else changes except that you paid some gas to verify the Ante Test.

### If the Ante Test fails:

If the Ante Test fails, it means the underlying protocol invariant no longer holds and there is likely a fundamental flaw in the protocol as currently implemented. In this scenario, all staker capital is locked and allocated proportionally to be claimable by challengers.

#### First Caller Bonus

If you were the one who initiated the failed test check, you get an additional bonus equivalent to 5% of the total stake balance. The remaining 95% of the staker funds is distributed to current challengers in the pool based on several factors including the amount challenged and the time a challenge was held.


# The Decentralized Trust Score

Community trust made explicit

Ante translates uncoordinated actions from thousands of users into useful information about community trust, adding peace of mind for the entire community. This is numerically represented by what we call the **Decentralized Trust Score**, a composite score that provides an explicit quantitative measure of trust in a protocol as expressed by staking and challenging Ante Pools. A higher Trust Score means more people in the Ante community trust the protocol.

![The Decentralized Trust Score is based on the capital staked and challenged in an Ante Test](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MaBhLPQtzmPqzNtEpO8%2F-MiwFNO1d4FjZTg_C63L%2F-Mj0Ztjz6o6BNQOFbenj%2Fante-stake-challenge-white-bg.gif?alt=media\&token=2ef172bd-ea85-4ad0-b2ff-22d7d4345831)


# Decentralized Trust Tiers

The decentralized trust score can be used to translate on-chain activity into an easy-to-understand measure of DeFi risk. A system will take in objective on-chain data like funds staked, stake duration, and test quality as well as input from the Ante community, launch partners, and wider crypto community.

Currently, trust tiers on the Ante web app are defined based on total stake and stake-weighted decentralized trust score across a protocol's Ante Tests:

| Trust Tier     | Total Stake | Decentralized Trust Score |
| -------------- | ----------: | ------------------------: |
| S              |   >=100 ETH |                      >=90 |
| AA             |    >=30 ETH |                      >=85 |
| A              |    >=10 ETH |                      >=80 |
| NR (Not Rated) |     <10 ETH |                       <80 |

Protocols must meet **both** the minimum total stake and decentralized trust score requirements to qualify for a trust tier (e.g. if a protocol has 50 ETH staked in their tests but their trust score is only 83, they will be A-tier).


# Deposit Limits

As of 11/26/2021 - deposit limits still in place

The current maximum/stake challenge amount through the web app is **50 ETH** per wallet per Ante Pool.

At launch, maximum stake/challenge amounts were capped at 1 ETH per wallet per Ante Pool. As the Ante system ramps up, we will gradually increase the maximum deposit limit in accordance with a schedule that will be communicated in advance.


# Writing an Ante Test

Four steps to writing your first Ante Test

Writing an Ante Test is easy to do! It's also a fantastic way to level up your Solidity skills as you read and think about the workings of the smart contracts that underlie your favorite DeFi protocols. To guide you through the process, we've listed out the basic steps below.

![Is this the face of a liar? I think not.](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MaBhLPQtzmPqzNtEpO8%2F-MkKky2jRj19bZOmGaPG%2F-MkL0nzz2ucIiiqZWKHh%2Fanyone-can-write-ante-tests%201.png?alt=media\&token=9e123a98-0643-481e-8cd6-30b2e88653c9)

## 1. Think of the invariant you want to test

Ante Tests are single-failure tests of on-chain protocol **invariants**. Invariants should reflect fundamental guarantees that a protocol should satisfy. Some examples of invariants you could write an Ante Test for include:

* **Plunge protection test** – Contract assets do not drop below some threshold
* **Loan solvency test** – Collateral asset value exceeds issued liabilities by some factor
* **APY guarantee test** – APY over a given time period exceeds the rate advertised

For more ideas, check out a longer list below. The possibilities are endless!

{% content-ref url="/pages/-MkKHfmCkG1D4oGn1iQC" %}
[Coming up with an invariant](/v0.5/for-devs/writing-an-ante-test/invariant-ideas)
{% endcontent-ref %}

## 2. Fork the Ante community test repository

Forking the **antefinance/ante-community-tests** repository will allow you to work on your own local copy of the repository that includes all the necessary starter code and other community tests for reference.

On the [repository](https://github.com/antefinance/ante-community-tests) page, click **Fork** to create a copy of the repository under your GitHub profile.

![](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MaBhLPQtzmPqzNtEpO8%2F-MkKky2jRj19bZOmGaPG%2F-MkL5mVUGqcAva8vIsrB%2FScreen%20Shot%202021-09-23%20at%209.40.30%20PM.png?alt=media\&token=6ed18fd4-0cb6-4bfc-bcff-491cf22cf7b0)

Once you've forked the repository, you can [clone the repository](https://docs.github.com/en/repositories/creating-and-managing-repositories/cloning-a-repository) to your local machine.

## 3. Write your Ante Test

It's time to open up your favorite [IDE](https://ethereum.org/en/developers/docs/ides/)/text editor and start coding!

All Ante Tests need to implement the `IAnteTest.sol` interface to work with Ante. To make it easier to work with, we have implemented the **abstract class** `AnteTest.sol` that **any** Ante Test can inherit.

{% content-ref url="/pages/-Ma\_vLeoiaecxmxTBMcl" %}
[Explaining IAnteTest.sol and AnteTest.sol](/v0.5/for-devs/writing-an-ante-test/iantetest.sol-and-antetest.sol)
{% endcontent-ref %}

You can start by copying another Ante Test in the repository, or you can use the following skeleton code:

```typescript
import "@antefinance/contracts/interfaces/AnteTest.sol";

contract MyAnteTest is AnteTest("String descriptor of test") {
    // create Ante Test variables & insert logic here
    
    // you can omit your constructor if not defining these optional parameters
    constructor () {
        protocolName = "My Protocol";
        testedContracts = [0x000000000000000000000000000000000000dEaD];
    }
    
    function checkTestPasses() public view override returns (bool) {
        // insert logic here to check the My Protocol invariant
    }
}
```

## 4. Create a pull request to the Ante community test repository

If you're comfortable deploying your own smart contracts, you can [do it yourself](/v0.5/for-devs/deploying-an-ante-test).

If you don't want to go through the hassle of deploying the test yourself, though, you can [open a pull request](https://docs.github.com/en/github/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/creating-a-pull-request-from-a-fork) to the ante community test repository:

1. Click **Pull request** on the repository page.
2. Select the base and head branches you want to merge
3. Add a quick description, and click **Create Pull Request**.

That's it! A member of the Ante team will review your test and add it to the main community repository.


# Coming up with an invariant

Can't think of any tests? Maybe one of these will spark some inspiration!

Ante Tests are single-failure tests of on-chain protocol **invariants**. Invariants should reflect fundamental guarantees that a protocol should satisfy.

{% hint style="info" %}
Take care when defining your project's invariants.

**Only define invariants you believe will never fail.**

It's the **guarantee** you are making and potentially **staking** ETH o&#x6E;**.**
{% endhint %}

Here is an non-exhaustive list of invariants you might decide to write an Ante Test for (in no particular order):

* **"Rug" test** – check that contract-controlled assets are not drained
* **Plunge protection test** – check that contract assets do not drop below some threshold
* **Peg test** – check to see that two pegged assets stay pegged in price&#x20;
  * Note: in order to avoid flash loan manipulation of the Ante Test, this should be implemented against time-weighted average prices (TWAP) rather than spot prices
* **Solvency test** – Collateral asset value exceeds liabilities by some factor
* **Bonding curve test** – check that the bonding curve calculation (e.g. `x*y=k`) holds for an automated market maker (AMM) protocol
* **APY guarantee test** – check that actual rewards issued by a contract over a given time period exceeds the APY rate advertised by the protocol
* **DAO implementation test** – check that a proposal passed by a DAO was actually implemented
  * Checking outcomes can be tricky given the complexity and heterogeneity of outcomes. Defining a narrow test can help manage some of the complexity
  * Alternatively, this can be made generalized by having the DAO vote again on their satisfaction with the implementation outcome and having the Ante Test check the vote result
* **Access test** – check that funds can be withdrawn from contract in an expected manner
* **Market cap test** – check that the total value of contract assets exceeds some threshold
* **Volume test** – check that at least X unique wallets/transactions/etc. use a given protocol over a given time period

These are just some of the many possible Ante Tests that could be written. Happy writing!

Have an idea for a test? We'd love to hear about it! Message us on [Twitter](https://twitter.com/AnteFinance)/[Discord](https://discord.ante.finance/) or drop us a line at <hello@ante.finance>!


# Explaining IAnteTest.sol and AnteTest.sol

Ante Test basics

All Ante Tests need to implement the `IAnteTest.sol` interface to work with Ante. To make it easier to work with, we have implemented the **abstract class** `AnteTest.sol` that **any** Ante Test can inherit.

## Interface [`IAnteTest.sol`](https://github.com/anteproject/antescaffold/blob/master/packages/hardhat/contracts/interfaces/IAnteTest.sol)

{% code title="IAnteTest.sol" %}

```solidity
// SPDX-License-Identifier: GPL-3.0-only

// ┏━━━┓━━━━━┏┓━━━━━━━━━┏━━━┓━━━━━━━━━━━━━━━━━━━━━━━
// ┃┏━┓┃━━━━┏┛┗┓━━━━━━━━┃┏━━┛━━━━━━━━━━━━━━━━━━━━━━━
// ┃┗━┛┃┏━┓━┗┓┏┛┏━━┓━━━━┃┗━━┓┏┓┏━┓━┏━━┓━┏━┓━┏━━┓┏━━┓
// ┃┏━┓┃┃┏┓┓━┃┃━┃┏┓┃━━━━┃┏━━┛┣┫┃┏┓┓┗━┓┃━┃┏┓┓┃┏━┛┃┏┓┃
// ┃┃ ┃┃┃┃┃┃━┃┗┓┃┃━┫━┏┓━┃┃━━━┃┃┃┃┃┃┃┗┛┗┓┃┃┃┃┃┗━┓┃┃━┫
// ┗┛ ┗┛┗┛┗┛━┗━┛┗━━┛━┗┛━┗┛━━━┗┛┗┛┗┛┗━━━┛┗┛┗┛┗━━┛┗━━┛
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

pragma solidity >=0.7.0;

/// @title The interface for the Ante V0.5 Ante Test
/// @notice The Ante V0.5 Ante Test wraps test logic for verifying fundamental invariants of a protocol
interface IAnteTest {
    /// @notice Returns the author of the Ante Test
    /// @dev This overrides the auto-generated getter for testAuthor as a public var
    /// @return The address of the test author
    function testAuthor() external view returns (address);

    /// @notice Returns the name of the protocol the Ante Test is testing
    /// @dev This overrides the auto-generated getter for protocolName as a public var
    /// @return The name of the protocol in string format
    function protocolName() external view returns (string memory);

    /// @notice Returns a single address in the testedContracts array
    /// @dev This overrides the auto-generated getter for testedContracts [] as a public var
    /// @param i The array index of the address to return
    /// @return The address of the i-th element in the list of tested contracts
    function testedContracts(uint256 i) external view returns (address);

    /// @notice Returns the name of the Ante Test
    /// @dev This overrides the auto-generated getter for testName as a public var
    /// @return The name of the Ante Test in string format
    function testName() external view returns (string memory);

    /// @notice Function containing test logic to inspect the protocol invariant
    /// @dev This should usually return True
    /// @return A single bool indicating if the Ante Test passes/fails
    function checkTestPasses() external returns (bool);
}
```

{% endcode %}

{% hint style="info" %}
`IAnteTest.sol` as of 2021-11-26
{% endhint %}

All Ante Tests must follow the interface outlined in `IAnteTest.sol` to work with Ante. The interface outlines 5 main components:

* `testAuthor`: this overrides the auto-generated getter and allows `testAuthor` to be used as a public variable.
* `testName`: this overrides the auto-generated getter and allows `testName` to be used as a public variable.
* `protocolName`: this overrides the auto-generated getter and allows the optional parameter `protocolName` to be used as a public variable.
* `testedContracts`: this overrides the auto-generated getter for the optional public variable `testedContracts`.
* `checkTestPasses()`: the critical function that checks your **invariant** that is expected to return `True`, else this will indicate a catastrophic failure.

To aid in working with the `IAnteTest.sol` interface, we've created an `AnteTest.sol` **abstract** class that any Ante Test can inherit.

## Abstract Class [`AnteTest.sol`](https://github.com/anteproject/antescaffold/blob/master/packages/hardhat/contracts/interfaces/AnteTest.sol)

{% code title="AnteTest.sol" %}

```solidity
// SPDX-License-Identifier: GPL-3.0-only

// ┏━━━┓━━━━━┏┓━━━━━━━━━┏━━━┓━━━━━━━━━━━━━━━━━━━━━━━
// ┃┏━┓┃━━━━┏┛┗┓━━━━━━━━┃┏━━┛━━━━━━━━━━━━━━━━━━━━━━━
// ┃┗━┛┃┏━┓━┗┓┏┛┏━━┓━━━━┃┗━━┓┏┓┏━┓━┏━━┓━┏━┓━┏━━┓┏━━┓
// ┃┏━┓┃┃┏┓┓━┃┃━┃┏┓┃━━━━┃┏━━┛┣┫┃┏┓┓┗━┓┃━┃┏┓┓┃┏━┛┃┏┓┃
// ┃┃ ┃┃┃┃┃┃━┃┗┓┃┃━┫━┏┓━┃┃━━━┃┃┃┃┃┃┃┗┛┗┓┃┃┃┃┃┗━┓┃┃━┫
// ┗┛ ┗┛┗┛┗┛━┗━┛┗━━┛━┗┛━┗┛━━━┗┛┗┛┗┛┗━━━┛┗┛┗┛┗━━┛┗━━┛
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

pragma solidity >=0.7.0;

import "./interfaces/IAnteTest.sol";

/// @title Ante V0.5 Ante Test smart contract
/// @notice Abstract inheritable contract that supplies syntactic sugar for writing Ante Tests
/// @dev Usage: contract YourAnteTest is AnteTest("String descriptor of test") { ... }
abstract contract AnteTest is IAnteTest {
    /// @inheritdoc IAnteTest
    address public override testAuthor;
    /// @inheritdoc IAnteTest
    string public override testName;
    /// @inheritdoc IAnteTest
    string public override protocolName;
    /// @inheritdoc IAnteTest
    address[] public override testedContracts;

    /// @dev testedContracts and protocolName are optional parameters which should
    /// be set in the constructor of your AnteTest
    /// @param _testName The name of the Ante Test
    constructor(string memory _testName) {
        testAuthor = msg.sender;
        testName = _testName;
    }

    /// @notice Returns the testedContracts array of addresses
    /// @return The list of tested contracts as an array of addresses
    function getTestedContracts() external view returns (address[] memory) {
        return testedContracts;
    }

    /// @inheritdoc IAnteTest
    function checkTestPasses() external virtual override returns (bool) {}
}

```

{% endcode %}

{% hint style="info" %}
`AnteTest.sol` as of 2021-11-26
{% endhint %}

The `AnteTest.sol` is an abstract contract that once inherited, can be used to write any Ante Test. All that is needed to be provided is a name for the test, designated by `_testName`. The optional parameters `protocolName` and `testedContracts` can be set in the constructor of your Ante Test.

To use it, when declaring your Ante Test, you can write:

```csharp
import "@antefinance/contracts/interfaces/AnteTest.sol";

contract AnteNewProtocolTest is AnteTest("String descriptor of test") {
    // create Ante Test variables & insert logic here
    
    // you can omit your constructor if not defining these optional parameters
    constructor () {
        protocolName = "My Protocol";
        testedContracts = [0x000000000000000000000000000000000000fEeD];
    }
    
    function checkTestPasses() public view override returns (bool) {
        // insert logic here to check the My Protocol invariant
    }
}
```

We'll see in the next section, how to use this abstract contract in some Ante Test examples.


# Ante Test Examples

Sample Ante Tests to dissect for explanation

## A Note on Writing Ante Tests

{% hint style="warning" %}
Take care in defining your project's guarantees **precisely**.

### **Only choose guarantees that you believe will never fail.**

It's this **guarantee** that you are making and potentially **staking** ETH on.
{% endhint %}

## Example: WBTC Supply Doesn't Exceed 21 Million

In this test (`AnteWBTCSupplyTest.sol`) we write an Ante Test that checks the total outstanding supply of wrapped Bitcoin (WBTC) does not exceed 21 million, which is the known "maximum supply" of Bitcoin.

For more information on what **wrapped Bitcoin** is, please see <https://wbtc.network/> (external link).

{% code title="AnteWBTCSupplyTest.sol" %}

```solidity
// SPDX-License-Identifier: GPL-3.0-only

// ┏━━━┓━━━━━┏┓━━━━━━━━━┏━━━┓━━━━━━━━━━━━━━━━━━━━━━━
// ┃┏━┓┃━━━━┏┛┗┓━━━━━━━━┃┏━━┛━━━━━━━━━━━━━━━━━━━━━━━
// ┃┗━┛┃┏━┓━┗┓┏┛┏━━┓━━━━┃┗━━┓┏┓┏━┓━┏━━┓━┏━┓━┏━━┓┏━━┓
// ┃┏━┓┃┃┏┓┓━┃┃━┃┏┓┃━━━━┃┏━━┛┣┫┃┏┓┓┗━┓┃━┃┏┓┓┃┏━┛┃┏┓┃
// ┃┃ ┃┃┃┃┃┃━┃┗┓┃┃━┫━┏┓━┃┃━━━┃┃┃┃┃┃┃┗┛┗┓┃┃┃┃┃┗━┓┃┃━┫
// ┗┛ ┗┛┗┛┗┛━┗━┛┗━━┛━┗┛━┗┛━━━┗┛┗┛┗┛┗━━━┛┗┛┗┛┗━━┛┗━━┛
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

pragma solidity ^0.7.0;

import "@openzeppelin/contracts/token/ERC20/IERC20.sol";
import "../AnteTest.sol";

/// @title WBTC supply never exceeds 21 million test
/// @notice Ante Test to check that WBTC supply is always less than 21 million
contract AnteWBTCSupplyTest is AnteTest("Wrapped BTC (WBTC) supply doesn't exceed 21m") {
    // https://etherscan.io/address/0x2260fac5e5542a773aa44fbcfedf7c193bc2c599#code
    address public immutable wBTCAddr;

    //21 million * 1e8 (for decimals), maximum total Bitcoin supply
    uint256 public constant THRESHOLD_SUPPLY = 21 * 1000 * 1000 * 1e8;

    IERC20 public wBTCToken;

    /// @param _wBTCAddr WBTC contract address (0x2260fac5e5542a773aa44fbcfedf7c193bc2c599 on mainnet)
    constructor(address _wBTCAddr) {
        protocolName = "WBTC";
        testedContracts = [_wBTCAddr];

        wBTCAddr = _wBTCAddr;
        wBTCToken = IERC20(_wBTCAddr);
    }

    /// @notice test to check WBTC token supply
    /// @return true if WBTC supply is less than 21 million
    function checkTestPasses() external view override returns (bool) {
        return (wBTCToken.totalSupply() <= THRESHOLD_SUPPLY);
    }
}
```

{% endcode %}

{% hint style="info" %}
`AnteWBTCSupplyTest.sol` as of 2021-11-26
{% endhint %}

This example outlines a sample Ante Test that uses the `AnteTest.sol` abstract contract that inherits `IAnteTest.sol` for use.

An explanation for the various lines are as follows:

* (Line 15) - Importing the contract `AnteTest.sol`
  * Future work: Will be packaged to a library for importing for ease of use
* (Line 19) - Contract inherits from AnteTest using  `... is AnteTest(...)`. It is here where the test name will be decided.
  * Recommended to have a human-readable description passed as in `AnteTest()` (e.g. "Wrapped BTC (WBTC) supply ...")
* (Lines 21-26) - Implement the variables and logic as needed for the test.
  * In this example, we define the variable for the WBTC address, it is set in the constructor (Line 33), and for clarity we wrote it in the comments (Line 20).
  * Following which, we set our threshold limit which is 21M, the maximum total Bitcoin supply.
  * Using the IERC20 interface provided by [@openzeppelin](https://openzeppelin.com/), we define WBTC from the address.
* (Lines 30-31) - The part of the constructor that tells Ante the name of the tested protocol and the tested contracts (for front-end convenience).
* (Lines 33-34) - Defines the WBTC address from the constructor, and then uses the IERC20 interface defined earlier to read the WBTC.
* (Line 39) - The `checkTestPasses()` function here does the final return on whether the test passes or not, which should be expected to be true, as the "guarantee" behind the Ante Test.
  * In this example, the wrapped BTC total supply should not exceed the threshold we set earlier (21M)
  * This should be assumed true, unless something extraordinary happens.

In this example above, the Ante Test guarantees that the WBTC circulation never exceeds 21 million.

## Example: WETH9 Minted WETH equals ETH Balance

In this test (`AnteWETH9Test.sol`) we check that the ETH deposited into the wrapped ETH (WETH9) contract does in fact equal the total number of WETH tokens (ERC20 compliant "ETH") circulating.

For more background around what is **wrapped Ether** we recommend reading <https://weth.io/> (external link).

{% code title="AnteWETH9Test.sol" %}

```solidity
// SPDX-License-Identifier: GPL-3.0-only

// ┏━━━┓━━━━━┏┓━━━━━━━━━┏━━━┓━━━━━━━━━━━━━━━━━━━━━━━
// ┃┏━┓┃━━━━┏┛┗┓━━━━━━━━┃┏━━┛━━━━━━━━━━━━━━━━━━━━━━━
// ┃┗━┛┃┏━┓━┗┓┏┛┏━━┓━━━━┃┗━━┓┏┓┏━┓━┏━━┓━┏━┓━┏━━┓┏━━┓
// ┃┏━┓┃┃┏┓┓━┃┃━┃┏┓┃━━━━┃┏━━┛┣┫┃┏┓┓┗━┓┃━┃┏┓┓┃┏━┛┃┏┓┃
// ┃┃ ┃┃┃┃┃┃━┃┗┓┃┃━┫━┏┓━┃┃━━━┃┃┃┃┃┃┃┗┛┗┓┃┃┃┃┃┗━┓┃┃━┫
// ┗┛ ┗┛┗┛┗┛━┗━┛┗━━┛━┗┛━┗┛━━━┗┛┗┛┗┛┗━━━┛┗┛┗┛┗━━┛┗━━┛
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

pragma solidity ^0.7.0;

import "@openzeppelin/contracts/token/ERC20/IERC20.sol";
import "../AnteTest.sol";

/// @title WETH9 issued fully backed by ETH test
/// @notice Ante Test to check WETH9 minted WETH matches deposited ETH in contract
contract AnteWETH9Test is AnteTest("Checks WETH9 issued WETH fully backed by ETH") {
    // https://etherscan.io/address/0xC02aaA39b223FE8D0A0e5C4F27eAD9083C756Cc2
    address public immutable wETH9Addr;

    IERC20 public wETH9Token;

    /// @param _wETH9Addr WETH9 contract address (0xC02aaA39b223FE8D0A0e5C4F27eAD9083C756Cc2 on mainnet)
    constructor(address _wETH9Addr) {
        wETH9Addr = _wETH9Addr;
        wETH9Token = IERC20(_wETH9Addr);

        protocolName = "WETH9";
        testedContracts = [_wETH9Addr];
    }

    /// @notice test to check WETH token supply against contract balance
    /// @return true if WETH9 token supply equals contract balance
    function checkTestPasses() external view override returns (bool) {
        return address(wETH9Token).balance == wETH9Token.totalSupply();
    }
}
```

{% endcode %}

{% hint style="warning" %}
`AnteWETH9Test.sol as of 2021-11-26`
{% endhint %}

Building on the previous example, note the important lines in the WETH9 Ante Test:

1. (Line 15) - Import the `AnteTest.sol` abstract class
2. (Line 19) - Name the test with a human-readable string "*Checks WETH9...*"
3. (Line 21-23) - We define the needed variables here
   1. (Line 21) - Defines the `address` of the WETH9 contract to be set later in the constructor, additionally, added for clarity into the comments (Line 20).
   2. (Line 23) - We define the `IERC20` interface as `WETH9Token` to later interact with it
4. (Lines 27-28) - Defines the WETH9 address from the constructor, and then uses the IERC20 interface defined earlier to read the WETH9.
5. (Lines 30-31) - The part of the constructor that tells Ante the name of the tested protocol and the tested contracts (for front-end convenience).
6. (Line 37) - We define the invariant for WETH9 with a boolean check

   1. Left side: we get the ETH balance of the address of the created WETH9 ERC20 token
   2. Right side: we get the outstanding supply of WETH9Token
   3. Invariant: the ETH deposited into WETH9 should always equal the WETH supply

## Example: ETH2DepositContract Balance "Rugs"

For context, in the lead-up to the launch of Ethereum2's beacon chain in late 2020, the Ethereum Foundation helped put together a "deposit contract" (with the ENS name DEPOSITCONTRACT.ETH that was paid for for 150 years and then had ownership burned) where people could, following a set of instructions, deposit ETH in multiples of 32 to spin up ETH2 validator nodes that earn Proof-of-Stake rewards for correctly helping to secure the Beacon Chain. For more information, please see <https://ethereum.org/en/eth2/>

In this test, we tongue-in-cheek check that the balance in DepositContract.eth does not drop by 99.99% (indicating that it is likely it has been compromised and a thief has stolen all of the funds).&#x20;

Note that it is possible for a clever thief to **steal all but 501 ETH,** in which case this Ante Test would **still** pass. While that is clearly a failure case of this Ante Test, we hope that for illustrative purposes this example shows a way to use Ante.

{% code title="AnteETH2DepositTest.sol" %}

```solidity
// SPDX-License-Identifier: GPL-3.0-only

// ┏━━━┓━━━━━┏┓━━━━━━━━━┏━━━┓━━━━━━━━━━━━━━━━━━━━━━━
// ┃┏━┓┃━━━━┏┛┗┓━━━━━━━━┃┏━━┛━━━━━━━━━━━━━━━━━━━━━━━
// ┃┗━┛┃┏━┓━┗┓┏┛┏━━┓━━━━┃┗━━┓┏┓┏━┓━┏━━┓━┏━┓━┏━━┓┏━━┓
// ┃┏━┓┃┃┏┓┓━┃┃━┃┏┓┃━━━━┃┏━━┛┣┫┃┏┓┓┗━┓┃━┃┏┓┓┃┏━┛┃┏┓┃
// ┃┃ ┃┃┃┃┃┃━┃┗┓┃┃━┫━┏┓━┃┃━━━┃┃┃┃┃┃┃┗┛┗┓┃┃┃┃┃┗━┓┃┃━┫
// ┗┛ ┗┛┗┛┗┛━┗━┛┗━━┛━┗┛━┗┛━━━┗┛┗┛┗┛┗━━━┛┗┛┗┛┗━━┛┗━━┛
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

pragma solidity ^0.7.0;

import "../AnteTest.sol";

/// @title ETH2 beacon contract doesn't lose 99.99% of its ETH test
/// @notice Ante Test to check that ETH2 beacon depositcontract.eth doesn't lose 99.99% of
/// its ETH (as of May 2021)
contract AnteETH2DepositTest is AnteTest("ETH2 beacon deposit contract doesn't lose 99.99% of its ETH") {
    // depositcontract.eth, verified on https://ethereum.org/en/eth2/deposit-contract/
    // https://etherscan.io/address/0x00000000219ab540356cBB839Cbe05303d7705Fa
    address public immutable depositContractAddr;

    // As of 20210524 with 4.88m ETH deposited, 500 ETH represents a ~ -99.99% drop
    uint256 public constant THRESHOLD_BALANCE = 500 * 1e18; //500 ETH

    /// @param _depositContractAddr ETH2 deposit address (0x00000000219ab540356cBB839Cbe05303d7705Fa on mainnet)
    constructor(address _depositContractAddr) {
        protocolName = "ETH2";
        depositContractAddr = _depositContractAddr;
        testedContracts = [_depositContractAddr];
    }

    /// @notice test to check balance of eth2 deposit address
    /// @return true if deposit address balance is over 500 ETH
    function checkTestPasses() external view override returns (bool) {
        return (depositContractAddr.balance >= THRESHOLD_BALANCE);
    }
}
```

{% endcode %}

{% hint style="warning" %}
`AnteETH2DepositTest.sol` as of 2021-11-26
{% endhint %}

Breakdown of key lines:

1. (Lines 3-10) - ASCII Art we are very proud of that we definitely didn't rip off of DepositContract.eth :)
2. (Lines 22-25) - We define key state variables
   1. (Line 22) - We define the variable for the address, this is set when deploying the Ante Test as defined in the constructor, additionally, we write it for clarity in the comments (Line 21)
   2. (Line 25) - We define the "Threshold" at which we consider a "failure" to have happened (500 ETH)
3. (Lines 29-31) - The constructor that tells Ante the name of the tested protocol, sets the ETH2 contract address, and sets the tested contracts. **Note we only set the tested contract address here!**
4. (Line 37) - We check that the Deposit Contract still has greater than or equal to `THRESHOLD_BALANCE`.

## Example: EthDev Doesn't "Rug" Test

(Note: we use the term "rug" here casually -- as in, some large fraction of the balance in the contract vanishes from the address.)

The address described below is often labeled publicly as an "EthDev" (Ethereum Foundation's developer fund) address. Many online joke during market downturns that it is due to "EthDev" selling ETH or "EthDev Rugging." We do not support such rumors, but we figured it could make for an amusing illustrative example of what is possible with Ante.

This test checks that at least 1% of the ETH sitting in the "EthDev" address is still there. (Note: this is **not** meant to be an extremely **robust** Ante Test because EthDev's controlling parties could, for perfectly legitimate reasons, decide to move any or all of their ETH to a new address at any time.) Please view this as an Ante Test written purely for **educational purposes**.

{% code title="AnteEthDevRugTest.sol" %}

```solidity
// SPDX-License-Identifier: GPL-3.0-only

// ┏━━━┓━━━━━┏┓━━━━━━━━━┏━━━┓━━━━━━━━━━━━━━━━━━━━━━━
// ┃┏━┓┃━━━━┏┛┗┓━━━━━━━━┃┏━━┛━━━━━━━━━━━━━━━━━━━━━━━
// ┃┗━┛┃┏━┓━┗┓┏┛┏━━┓━━━━┃┗━━┓┏┓┏━┓━┏━━┓━┏━┓━┏━━┓┏━━┓
// ┃┏━┓┃┃┏┓┓━┃┃━┃┏┓┃━━━━┃┏━━┛┣┫┃┏┓┓┗━┓┃━┃┏┓┓┃┏━┛┃┏┓┃
// ┃┃ ┃┃┃┃┃┃━┃┗┓┃┃━┫━┏┓━┃┃━━━┃┃┃┃┃┃┃┗┛┗┓┃┃┃┃┃┗━┓┃┃━┫
// ┗┛ ┗┛┗┛┗┛━┗━┛┗━━┛━┗┛━┗┛━━━┗┛┗┛┗┛┗━━━┛┗┛┗┛┗━━┛┗━━┛
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
// ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

pragma solidity ^0.7.0;

import "../AnteTest.sol";

/// @title ETHDev multisig doesn't rug test
/// @notice Ante Test to check if EthDev multisig "rugs" 99% of its ETH (as of May 2021)
contract AnteEthDevRugTest is AnteTest("EthDev MultiSig Doesnt Rug 99% of its ETH Test") {
    // https://etherscan.io/address/0xde0b295669a9fd93d5f28d9ec85e40f4cb697bae
    address public immutable ethDevAddr;

    // 2021-05-24: EthDev has 394k ETH, so -99% is ~4k ETH
    uint256 public constant RUG_THRESHOLD = 4 * 1000 * 1e18;

    /// @param _ethDevAddr eth multisig address (0xde0b295669a9fd93d5f28d9ec85e40f4cb697bae on mainnet)
    constructor(address _ethDevAddr) {
        protocolName = "ETH";
        ethDevAddr = _ethDevAddr;
        testedContracts = [_ethDevAddr];
    }

    /// @notice test to check balance of eth multisig
    /// @return true if eth multisig has over 4000 ETH
    function checkTestPasses() external view override returns (bool) {
        return ethDevAddr.balance >= RUG_THRESHOLD;
    }
}
```

{% endcode %}

{% hint style="info" %}
`AnteEthDevRugTest.sol` as of 2021-11-26
{% endhint %}

1. (Line 20) - Defines the EthDev address variable, this is set when deploying the Ante Test as defined in the constructor, additionally, we write it for clarity in the comments (Line 19)
2. (Line 23) - Defines the `RUG_THRESHOLD` which we've set to approximately 1% of the ETH of the total amount in the address as of 2021-05-24.
3. (Line 25-27) - The constructor that tells Ante the name of the tested protocol, sets the EthDev contract address, and sets the tested contracts.
4. (Line 29) - Check the inequality holds using the threshold defined earlier.


# Writing and Testing an Ante Test

## Writing the Ante Test

1. Fork the [Ante Community Repo](https://github.com/antefinance/ante-community-tests) and use it to develop and write your new Ante Test.
2. Check the `contracts` folder and see if the protocol in question is already created. If not, create the `protocol` folder there.
3. Create the Ante Test in its respective folder testing the invariant earlier.
4. Once completed, a good idea is to compile your test and test to make sure it compiles.\
   You can do that using the following commands in a bash terminal.

```bash
# Install necessary pacakges determined by the repository, be sure you're
# in the root directory of ante-community-tests
npm install

# This hardhat command compiles all tests in the repository.
npx hardhat compile
```

If npm isn't installed, please follow npm's [installation guide](https://docs.npmjs.com/downloading-and-installing-node-js-and-npm) to get it.

## Writing an Ante Test's unit test

Now that the test has been written we should always make sure we test it to the best of our knowledge. Make sure it behaves the way we expect it to. To do that, we go through the following process.

1. In the Ante Community Repo that you've forked, there's a `test` folder where we write the unit tests for the Ante Test that was just written.
2. Locate the protocol folder for the test in question, if it doesn't exist, create a new one.
3. Tests here are written in Typescript, and labeled as such `ante_{test-name}_test.spec.ts`. We'll go over the `test/examples/ante_eth_dev_rug_test.spec.ts` below:

{% code title="ante\_eth\_dev\_rug\_test.spec.ts" %}

```typescript
import hre from 'hardhat';
const { waffle } = hre;

import { AnteEthDevRugTest__factory, AnteEthDevRugTest } from '../../typechain';li

import { evmSnapshot, evmRevert } from '../helpers';
import { expect } from 'chai';

describe('AnteETHDevRugTest', function () {
  let test: AnteEthDevRugTest;

  let globalSnapshotId: string;

  before(async () => {
    globalSnapshotId = await evmSnapshot();

    const [deployer] = waffle.provider.getWallets();
    const factory = (await hre.ethers.getContractFactory('AnteEthDevRugTest', deployer)) as AnteEthDevRugTest__factory;
    test = await factory.deploy('0xde0b295669a9fd93d5f28d9ec85e40f4cb697bae');
    await test.deployed();
  });

  after(async () => {
    await evmRevert(globalSnapshotId);
  });

  it('should pass', async () => {
    expect(await test.checkTestPasses()).to.be.true;
  });
});

```

{% endcode %}

Line 4 - Here you'll want to replace the import with your own `{ANTE_TEST}__factory` and `{ANTE_TEST}`&#x20;

Line 18 - Be sure to get your Ante Test name here with `getContractFactory`

Line 19 - Any arguments that your Ante Test requires will need to be applied here

Lines 27-29 - This is the basic test condition where on deployment with no changes applied yet, the Ante Test should pass.

In order to add more tests (for example, you have conditions that change after a change to an address). Then you'll want to add more `it('description, async() => {conditions})` that test these for you.

## Testing the unit test

Once a unit test is written that confirms your expectations, then it's time to test it in the real world (well, forked mainnet world to be specific)

1. Going back to the main folder of your forked community repo, run the following commands to run through the unit tests.

```bash
# This command is a scripted command we added to the community repo in
# order to make the test running easier.
npm test
```

What `npm test` does is run the hardhat commands `npx hardhat typechain` and `npx hardhat test` to generate the typings for the tests written and then run the unit tests written in the entire repository.

It will then run through all unit tests (the ones in the `test` folder) and test each condition there. And finally, generate a summary of how many unit tests pass or fail.

If your unit tests fail here, some key points to check are:

* Ante Test - make sure the invariant you want to test here is correct.
* unit test - make sure that your assumptions that the Ante Test is testing is as you expect.


# Test an Ante Test Offline

Testing an Ante Test before official deployment

## Testing Locally

The most basic method to test your new Ante Test is to run a local blockchain, compile your Solidity code, and deploy the contracts to the local blockchain to make sure that works.

As long as the Ante Test compiles and can be deployed to the local network, you're ready than to deploy to the mainnet.

**Our recommended method using the Ante Community Repo:** [Local Testing](/v0.5/for-devs/writing-an-ante-test/writing-and-testing-an-ante-test#testing-the-unit-test)

## Testing Online

[Remix](https://remix.ethereum.org) is an online IDE option for writing and compiling solidity code. Bringing in the Ante Test that you've written, you can write it in Remix as an easy, quick option to write, compile, and deploy to a test network such as `Kovan` or `Rinkeby` to see if it works.

Like before, once the Ante Test compiles and can be deployed to a test network through the Remix IDE, then you're ready to deploy to mainnet.


# Adding an Ante Test to Ante Github

Getting community involvement into the process

[Ante Community Github Repo](https://github.com/antefinance/ante-community-tests)

When writing an Ante Test, it's best to take advantage of the Ante community and get the community feedback as well as take advantage of the other developers there checking the code.

Start by forking the community repo to your own Github account by clicking the Fork button near the top right of the community repo page.

![](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MaBhLPQtzmPqzNtEpO8%2Fuploads%2FqdeiGLvr4y3ZVXL7DEU5%2Fgithub_fork_20211129.png?alt=media\&token=dd3bfb39-fb6c-4f3e-b662-403587a5aa36)

Then take your Ante Test and add it to the appropriate protocol folder or create a new protocol folder if it doesn't already exist.

Once that's complete, open a Pull Request against the community repo and you'll get feedback regarding the test or have it incorporated into the community repo!

Once the Ante Test has been added into the community repo, your stats on the [Community Leaderboard](https://app.ante.finance/#/community-leaderboard) should be updated shortly afterwards!


# Development FAQs

**Q: If I’m writing an Ante Test and I want to call a function from another contract with a non-standard interface (i.e. not an ERC20 token, etc), what is the best way to do so?**

**A:** If the project has an npm package you can import directly from there via `@project/path/to/contract`; otherwise, you can copy the interface file into your repo and import or even just paste it in the source code of your Ante Test if you don't think it'll be used elsewhere. If desired, you can define a minimal interface for just the functions you need, but in practice, people prefer importing the entire interface.


# Integrating Ante

Instructions for integrating an Ante badge into your website/web app

![Ante badges make trust more transparent!](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MaBhLPQtzmPqzNtEpO8%2Fuploads%2FJ4ldmp8NeDTNoGVeJawa%2Ftest%20badge%402x.png?alt=media\&token=0c6441fa-5045-48bf-a925-aa0f6f2ec7e7)

If you're a protocol team that has staked funds in Ante Tests for your protocol, you may want to show your users that you have skin in the game! With just a few lines of code, you can add an Ante badge to your website or web app to show the real-time trust in your protocol.

## How to use

{% content-ref url="/pages/d06zWfG9mIa6oMOBNOFV" %}
[Integrate Ante using React](/v0.5/for-devs/integrate-ante/integrate-ante-using-react)
{% endcontent-ref %}

{% content-ref url="/pages/r92vStlN4X4Y1smQfeeV" %}
[Integrate Ante using HTML](/v0.5/for-devs/integrate-ante/integrate-ante-using-html)
{% endcontent-ref %}

## Where should I use an Ante badge?

Wherever your users would potentially gain peace of mind by knowing that a protocol has skin in the game! Some ideas in no particular order:

* If there are Ante Tests for the overall protocol, you can put a protocol-level trust tier badge with other security-related information on your web app or website
* If you have multiple vault-like products that each have Ante Tests, you could include the test badge on the vault UI so your users can see the level of decentralized trust in each vault (e.g. for long tail products)
* If you are integrating with a product that has an Ante Test written for it, you could include a protocol or test badge to indicate the level of trust in the dependency

## Troubleshooting

If you have any questions or are running into issues, please reach out to the team in [Discord](https://discord.gg/ante).


# Integrate Ante using React

The Ante widget has been published as an npm package:

{% embed url="<https://www.npmjs.com/package/@antefinance/ante-widget-react>" %}

### Install ante-widget-react

**npm:** `npm i @antefinance/ante-widget-react`

**yarn:** `yarn add @antefinance/ante-widget-react`

### Build

```
npm i
npm run build
```

### Using AnteWidget

Import `AnteWidget` from the `ante-widget-react` package:

<pre class="language-typescript"><code class="lang-typescript"><strong>import AnteWidget from '@antefinance/ante-widget-react';
</strong>import '@antefinance/ante-widget/dist/widget.css'; // This will import the styles
</code></pre>

Then add the appropriate `AnteWidget` component where desired on your app:

```typescript
function Example() {
  ...
  return (
    <div>
      // To show the overall trust tier of a protocol
      <AnteWidget.Protocol name='PROTOCOL_NAME' />
      
      // To show the trust score on a specific Ante Test
      <AnteWidget.Test address='ANTE_TEST_ADDRESS' chain='0x1' />
    </div>
  );
}
```

{% hint style="warning" %}
Note: the protocol name string is case sensitive. If in doubt, check how the protocol name is spelled in the Ante app. Chain IDs can be looked up at <https://chainlist.org/>.
{% endhint %}

### Example of usage

The following code will generate badges for the Ante protocol as well as one of the Ante Tests that tests the ante protocol:

```
<AnteWidget.Protocol name='Ante' />
<AnteWidget.Test address='0x2EdC35B39BFBca6A52eA35612C2684D3D7654763' chain='0x1'>
```

<img src="https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MaBhLPQtzmPqzNtEpO8%2Fuploads%2FgkWhSm68ai2Aa7SbdN1c%2Fante-protocol-badge-example%402x.png?alt=media&amp;token=dcf7642d-3169-4cd8-b477-cc1bb6c0bd7f" alt="" data-size="original">![](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MaBhLPQtzmPqzNtEpO8%2Fuploads%2Fivvz2DJ1fkSd0KzXSpis%2Fante-test-badge-example%402x.png?alt=media\&token=f3e25acf-c298-4490-a119-85163c131dad)


# Integrate Ante using HTML

## How to use

First, add the following line in the `<head>` of the page (this contains the styling for the Ante badge):

```html
<link href="https://assets.ante.finance/widget/widget.css" rel="stylesheet" />
```

Then, insert the corresponding `<div>` tag(s) where you want the badge(s), replacing `YOUR_PROTOCOL_NAME` or `ANTE_TEST_ADDRESS` and `CHAIN_NAME` with the appropriate protocol/Ante Test:

```html
// To show the overall trust tier of a protocol
<div class="ante-protocol-widget"></div>

// To show the trust score on a specific Ante Test
<div class="ante-test-widget"></div>
```

{% hint style="warning" %}
Note: the protocol name string is case sensitive. If in doubt, check how the protocol name is spelled in the Ante app. Chain IDs can be looked up at <https://chainlist.org/>.
{% endhint %}

Finally, we need to add script tags to make it all work. If you're only implementing up to one protocol and/or one test badge, you can&#x20;

```html
<script src="https://assets.ante.finance/widget/widget.css"></script>
<script>
    AnteWidget.Protocol('.ante-protocol-widget',{
        name: 'ETH2',
        chain: '0x4', // If not provided, it defaults to '0x1' (Ethereum Mainnet)  
    });
    AnteWidget.Test('.ante-test-widget',{
        address: '0x806f60015F245F9F6442f9c81f915E45CCd76637',
        chain: '0x4' 
    });
</script>
```

If you need more than one protocol badge or test badge,

```html
<script src="https://assets.ante.finance/widget/widget.css"></script>
<script>
   var divs = document.querySelectorAll(".ante-protocol-widget");
    for (var i = 0; i < divs.length; i++) {
        AnteWidget.Protocol(divs[i].className,{
            name: divs[i].dataset.name,
            chain: divs[i].dataset.chain,
        });
    }
</script>
```

### Example of usage

The following code will generate badges for the Ante protocol as well as one of the Ante Tests that tests the ante protocol:

```
<div class="ante-protocol-widget" data-name="Ante"></div>
<div class="ante-test-widget" data-address="0x2EdC35B39BFBca6A52eA35612C2684D3D7654763" data-chain="0x1"></div>
```

<img src="https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MaBhLPQtzmPqzNtEpO8%2Fuploads%2FgkWhSm68ai2Aa7SbdN1c%2Fante-protocol-badge-example%402x.png?alt=media&amp;token=dcf7642d-3169-4cd8-b477-cc1bb6c0bd7f" alt="" data-size="original">![](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MaBhLPQtzmPqzNtEpO8%2Fuploads%2Fivvz2DJ1fkSd0KzXSpis%2Fante-test-badge-example%402x.png?alt=media\&token=f3e25acf-c298-4490-a119-85163c131dad)


# Deploying an Ante Test

Quick guide to deploying an Ante Test

If you are comfortable deploying your own Ante Test, you can follow the instructions below.

## Deploying your Ante Test

After you've written an Ante Test and are ready to deploy to Mainnet, deploy it with your favorite method and save the address!

&#x20;[For more details, see our detailed tutorial.](/v0.5/for-devs/deploying-an-ante-test/deploy-an-ante-test)

## Create an Ante Pool

After deploying, you can use our `AntePoolFactory` to generate a non-custodial `AntePool` instance on mainnet (note: this will cost gas fees).&#x20;

We have an[ additional tutorial ](/v0.5/for-devs/deploying-an-ante-test/create-an-ante-pool)on that.

## Staking the Ante Test

Finally, if you want to show the community you have skin in the game, [learn how to stake your Ante Test](/v0.5/using-ante/how-to-stake), and how to further [integrate Ante into your website](/v0.5/for-devs/integrate-ante), web-app, or more.

And if you have questions, feel free to [contact our team](/v0.5/about/faqs#contact).


# Deploy an Ante Test

Deploy a completed Ante Test to Mainnet

We've provided several methods to deploy your own Ante Test below, starting with our current preferred method using Hardhat.

{% hint style="info" %}
As easier methods become available in the future, we'll link them here when we find them.
{% endhint %}

## Ante's deploy script using Hardhat

Our team currently prefers to use [Hardhat](https://hardhat.org/) to deploy our smart contracts. Assuming that the Ante Test has already been written, we can easily deploy an Ante Test to a network of our choosing using our prepared script `scripts/deploy_test.ts` in the [Ante Community Github](https://github.com/antefinance/ante-community-tests).

### Setup

First, make sure that the `.env` file is updated with the appropriate keys as per the readme section: [Configure the app](https://github.com/antefinance/ante-community-tests#configure-the-app)

Second, in `scripts/deploy_test.ts`, update the testName (Line 8) and arguments (Line 10) for the Ante Test you want to deploy.

```typescript
import hre from 'hardhat';
import chalk from 'chalk';

const main = async () => {
  const [deployer] = await hre.ethers.getSigners();

  // name of the contract for Ante Test
  const testName = 'AnteEthDevRugTest';
  // array of constructor arguments for Ante Test
  const args = ['0xde0b295669a9fd93d5f28d9ec85e40f4cb697bae'] as const;
// script/deploy_test.ts continues
```

### Deployment

Once these two files have been properly set up, run **either** of the commands below to deploy the Ante Test:

* `npm run deploy-test -- --network [NETWORK_NAME]`
  * `npm run deploy-test` is a user-defined command that we've set up to run the npx hardhat command below
* `npx hardhat run scripts/deploy_test.ts --network [NETWORK_NAME]`

### Verification

Right now, your Ante Test is only visible on Etherscan in bytecode form. In order to provide source code transparency for end users, you can verify the contract on Etherscan. Hardhat provides a plugin for doing this which you can use following the steps below:

First, make sure that the `.env` file is updated with your Etherscan key.

Next, run the command:

* `npx hardhat verify --network [NETWORK_NAME] [DEPLOYED_ANTE_TEST_ADDRESS] "Constructor argument 1"`

If your Ante Test takes a more complex set of arguments, you can also use an `arguments.js` file and run the modified command:

* `npx hardhat verify --network [NETWORK_NAME] --constructor-args [ARGUMENTS_FILE] [DEPLOYED_ANTE_TEST_ADDRESS]`

The [Hardhat-Etherscan plugin](https://hardhat.org/plugins/nomiclabs-hardhat-etherscan.html) documentation provides additional information on configuration options for the `verify` command.

## Other deployment solutions

The **Ethereum Foundation** has outlined several methods for [deploying smart contracts](https://ethereum.org/en/developers/docs/smart-contracts/deploying/) (and in this case, an Ante Test).

The main points for deployment would be needing access to an Ethereum node, either having your own node, access to a public node, or using services like [Alchemy](https://www.alchemy.com/) or [Infura](https://infura.io/).

Additionally, there are other solutions that can be explored to deploy the Ante Test:

**Alchemy**: [Hello World Smart Contract](https://docs.alchemy.com/alchemy/tutorials/hello-world-smart-contract)

**Infura**: [Deploying Smart Contracts](https://blog.infura.io/deploying-smart-contracts-managing-transactions-ethereum/)

**Remix**: [Deploy & Run](https://remix-ide.readthedocs.io/en/latest/run.html)

## After deploying your Ante Test

{% hint style="warning" %}
Make sure you record and remember the address that your Ante Test is deployed to! It will be needed to generate the Ante Pool that end users will interact with.
{% endhint %}

Once you've deployed your Ante Test, you can then [create an Ante Pool](/v0.5/for-devs/deploying-an-ante-test/create-an-ante-pool) (note: this will cost gas as well) to allow users to stake/challenge your test.


# Create an Ante Pool

Deploying the Ante Pool for supporters and challengers to stake and challenge the Ante Test.

{% hint style="warning" %}
This process requires gas in order to interact with the Ante Pool Factory and create the Ante Pool that links with the previously written Ante Test.
{% endhint %}

Once the new Ante Test has been deployed on the mainnet, and it's address has been recorded and readied, we're ready to deploy the Ante Pool to integrate with the new Ante Test!

![The create pool page on the Ante webapp.](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MaBhLPQtzmPqzNtEpO8%2Fuploads%2FCZoaKuujT7YMW959Jb2u%2Fcreate-pool_20211216.png?alt=media\&token=fa467146-45eb-4eb4-bfb1-f78110ec0b9e)

Using this address for the `AnteTest`, use our [Ante Pool Factory generator](https://app.ante.finance/#/create-pool) and enter in the address. The site will double check the two criteria before deployment:

* The Ante Test hasn't already been deployed yet.
* The Ante Test doesn't currently fail.

Once confirmed it's correct, click "Deploy Ante Pool", pay the gas fee and we'll take care of the rest, this will include:

* Adding and integrating an `AntePool` with the new `AnteTest`.
* Adding the new Ante test to our webapp to browse and interact with.

And that's it! A new and complete Ante test has been written, tested, and deployed to the mainnet and now we can find supporters and challengers. Now that the Ante Pool is visible on the leaderboard, we want the Ante Test to be verified by the community and get the verified tag attached.

{% hint style="warning" %}
If you want to signal to the community your confidence in your own test, it could make sense to stake your own `AntePool`.&#x20;

That said, never put funds, crypto or otherwise, into smart contracts you don't fully understand.&#x20;

**Please read through the AntePool and AntePoolFactory contracts before staking any funds in those non-custodial contracts. If something goes wrong, they are not recoverable by anyone else.**
{% endhint %}


# Verifying an Ante Pool

![An unverified test as well as a verified community test](https://3623970277-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MaBhLPQtzmPqzNtEpO8%2Fuploads%2FYV53Uz6nV9FjnCbZPQFt%2Fverified_community_ante_pool_20211124.png?alt=media\&token=612352bb-5954-4772-a348-b229fd35eddf)

Once the Ante Pool is deployed it'll be tagged as "Unverified" by the Ante webapp as signaling that the test hasn't been added to the community Github [repository](https://github.com/antefinance/ante-community-tests).

To get the Ante Pool verified, the corresponding Ante Test needs to have been submitted into the Ante Community Tests repository. This allows the community to validate and suggest changes to the Ante Test to work out any missing pieces or find any bugs before deploying it to the mainnet.

Ideally this should have been done already, otherwise please follow the instructions [here](/v0.5/for-devs/writing-an-ante-test/adding-an-ante-test-to-ante-github).


# Contracts

{% embed url="<https://github.com/antefinance/ante-v0-core>" %}

### Deployed Factories

#### Mainnets

<table><thead><tr><th width="263.92732395288573">Network</th><th width="455.21900215263037">Address</th></tr></thead><tbody><tr><td>Ethereum Mainnet</td><td><a href="https://etherscan.io/address/0xa03492a9a663f04c51684a3c172fc9c4d7e02edc">0xa03492A9A663F04c51684A3c172FC9c4D7E02eDc</a></td></tr><tr><td>Avalanche C-Chain</td><td><a href="https://snowtrace.io/address/0x18ab6357f673696375018f006b86fe44f195de1f">0x18aB6357f673696375018f006B86fE44F195DE1f</a></td></tr><tr><td>Polygon Mainnet</td><td><a href="https://polygonscan.com/address/0xb4fd0ce108e196d0c9844c48174d4c32cd42f7bc">0xb4FD0Ce108e196d0C9844c48174d4C32Cd42F7bC</a></td></tr><tr><td>Binance Smart Chain</td><td><a href="https://bscscan.com/address/0xb4fd0ce108e196d0c9844c48174d4c32cd42f7bc">0xb4FD0Ce108e196d0C9844c48174d4C32Cd42F7bC</a></td></tr><tr><td>Fantom</td><td><a href="https://ftmscan.com/address/0xb4FD0Ce108e196d0C9844c48174d4C32Cd42F7bC">0xb4FD0Ce108e196d0C9844c48174d4C32Cd42F7bC</a></td></tr><tr><td>Optimism</td><td><a href="https://optimistic.etherscan.io/address/0xb4FD0Ce108e196d0C9844c48174d4C32Cd42F7bC">0xb4FD0Ce108e196d0C9844c48174d4C32Cd42F7bC</a></td></tr><tr><td>Arbitrum One</td><td><a href="https://arbiscan.io/address/0xb4FD0Ce108e196d0C9844c48174d4C32Cd42F7bC">0xb4FD0Ce108e196d0C9844c48174d4C32Cd42F7bC</a></td></tr><tr><td>Aurora Mainnet</td><td><a href="https://explorer.aurora.dev/address/0xb4FD0Ce108e196d0C9844c48174d4C32Cd42F7bC">0xb4FD0Ce108e196d0C9844c48174d4C32Cd42F7bC</a></td></tr></tbody></table>

#### Testnets

<table><thead><tr><th width="269.09710639436616">Network</th><th width="460.0987927831361">Address</th></tr></thead><tbody><tr><td>Ethereum Rinkeby</td><td><a href="https://rinkeby.etherscan.io/address/0x5a8b70edfd28a79756b54ed8dbeee13e566920aa">0x5a8b70edfd28A79756B54ed8DbeeE13e566920Aa</a></td></tr><tr><td>Ethereum Goerli</td><td><a href="https://goerli.etherscan.io/address/0x4ae593b77234db644a6d6443c89a447140aeb361">0x4AE593b77234dB644a6d6443C89a447140aeb361</a></td></tr><tr><td>Avalanche Fuji Testnet</td><td><a href="https://testnet.snowtrace.io/address/0x45d520f5d0f8fb9bd68ae16ec5b84fc341df0ea0">0x45D520f5d0F8FB9Bd68aE16eC5B84fC341df0EA0</a></td></tr><tr><td>Polygon Mumbai</td><td><a href="https://mumbai.polygonscan.com/address/0x267bf4a003caf380d94766492bf7fec82a5dd9dc">0x267bF4a003CAF380D94766492Bf7FEc82a5dd9DC</a></td></tr><tr><td>BSC Testnet</td><td><a href="https://testnet.bscscan.com/address/0x4ae593b77234db644a6d6443c89a447140aeb361">0x4AE593b77234dB644a6d6443C89a447140aeb361</a></td></tr><tr><td>Fantom Testnet</td><td>Coming soon!</td></tr><tr><td>Optimism Goerli</td><td>Coming soon!</td></tr><tr><td>Arbitrum Görli</td><td>Coming soon!</td></tr><tr><td>Aurora Testnet</td><td>Coming soon!</td></tr></tbody></table>

### Ante Pools

The addresses of all Ante Pools created by AntePoolFactory are stored in the `allPools` array. Alternatively, if you have the address of the Ante Test, you can look up the corresponding Ante Pool address using `poolMap(address)` via block explorer, etc.


# FAQs

Contact the Ante team if you still have more questions!

## **Ante Basics**

### **What is Ante?**

Ante is a decentralized protocol building the Schelling Point of Computational Trust.

Ante allows autonomous testing of guarantees for any smart contract system on any blockchain (verifiable by anyone real-time) to enable more advanced and secure composition of DeFi primitives and integrations with existing financial services.

### What does "Ante" mean?

The Ante (**Autonomous Native Testing Environment**) name comes from a few origins.&#x20;

First, in poker, an *ante* is "table stakes" to participate in the next hand.&#x20;

For protocol developers, we believe that getting an Ante Test written for their project and staking the corresponding `AntePool` can become "table stakes" as a responsible development practice to show users they have confidence in their own code.

Second, the decentralized trust score generated by Ante is in some ways like an *ex-ante* decentralized guess of a project's smart contract invariants failing. The higher the trust score, the less likely the community thinks an invariant will break.

We believe for DeFi to reach its potential, information about critical risks should be made explicit. And the more tools to separate out well-intentioned teams from obvious scammers, the better.

### How does Ante work?

Ante allows for DeFi developer teams and general users to write, stake, and challenge Ante Tests:

1. DeFi protocol teams can write Ante Tests that verify certain custom invariants (such as debt\<collateral in a lending protocol) always holds true.
2. DeFi protocol teams and Ante users can stake capital behind Ante Tests if they believe that the Ante Tests are properly written and the underlying invariants will always hold.
3. Ante users can also lock capital to challenge Ante Tests that they believe are flawed or that verify DeFi protocols with vulnerable smart contract code.
4. Challenger capital is subject to continuous decay, claimable by the staking side.
5. A challenger can verify an Ante Test at any time, paying native out-of-pocket gas costs needed.
   * If an Ante Test succeeds (i.e. the underlying invariant holds), the Ante Pool remains as is.
   * If an Ante Test fails (i.e. the underlying invariant fails), the stakers' funds are claimable by the challenger and the challenger who verified.

There are other details to Ante and its design undergoes frequent change as we solicit user feedback.  Please read the "[Ante Overview](/v0.5/how-ante-works)" and "[Using Ante](/v0.5/using-ante/navigation)" pages for more explanations and helpful graphics.

### Does Ante have a token?

Ante currently does not have a governance token.  The team is developing a plan to foster robust community participation and achieve decentralization.  Our long-term vision for Ante is for participants to write Ante tests, submit governance proposals, and take over running the protocol.

## Using Ante

### Why would anyone stake an Ante Test?

1. The protocol team may stake its own Ante Tests to demonstrate confidence in its code and alignment of incentives with its user community.  Staking its own Ante tests is a strong signal that the team is serious about their project and willing to put skin in the game.
2. Protocol investors or supporters may stake Ante tests as a demonstration of their confidence and support in their investment or support.
3. DeFi users may stake Ante tests to earn yield from decay from the challenger pool. They may also want to signal their trust in a protocol to boost the project's reputation in the community.

### Why would anyone challenge an Ante Test?

1. A skilled developer or security expert may identify a flaw in the protocol smart contract or Ante test and challenge to receive a portion of the `AntePool`.
2. General DeFi users may challenge `AnteTests` with large staked `AntePools` because they believe the return profile is favorable, or they are skeptical of a sketchy project's invariants, or they have a lot of exposure to the underlying protocol and want automatic compensation if a catastrophic invariant failure occurs.
3. The DeFi community may learn of news relating to a protocol that undermines trust in the protocol's code.  Ante allows rapidly developing information to be transparently reflected in real time.

### Why would anyone verify an Ante Test?

1. For any challenger, it could make sense to verify an Ante Test if they believe the invariant is currently failing or they have discovered a combination of actions to make the invariant fail. (If they are correct in calling verify when the Ante Test is in a failure state, then all challengers receive a slice of staker funds.)
2. Furthermore, by verifying the Ante Test does or does not hold, the challenger is helping increase peace of mind around the entire ecosystem secured by Ante. The power of decentralized incentives is clear here: that any security expert in the world can hop over to Ante and keep an eye on Ante Tests and the invariants they guarantee means the DeFi ecosystem will be safer long-term.
3. Finally, Ante is researching the implications of an extra bounty (from staker funds) being allocated to the successful verifier, to further incentivize energy investment into monitoring and verifying Ante Tests. Collecting that bounty could be worth the effort for some!

### Why ELSE would anyone use Ante?

Ante makes it easier for users of a decentralized project to trust its smart contracts.

From our conversations with developer teams, a major obstacle - especially among newly launched protocols - is establishing trustworthiness and credibility in the DeFi community.  The space is incredibly frothy and it has become difficult to quickly tell which protocol teams are serious and which are looking for quick returns.  Ante allows serious teams to back their own smart contracts and put skin in the game - *something scammy teams may be unwilling to do.*  In this way, legitimate projects can use Ante as a marketing solution to stand out from the crowd.

Relatedly, investors might stake their AnteTests verifying their portfolio protocols as a way to bootstrap credibility and signal their confidence in the team.

Furthermore, protocols looking to launch quickly may not have time or resources to retain and wait for an auditor to review their code.  Existing solutions (audits, insurance, bug bounties, etc.), are important ways to convey trustworthiness, but Ante provides a uniquely ***real-time*** and ***transparent*** way to gauge the level of community faith in a protocol (see our [Medium](https://medium.com/ante-finance/building-safe-defi-583cbe385de8) on how Ante fits into the existing landscape).

We also believe that Ante can contribute substantially to the long-term potential of DeFi, and also help bridge legacy financial services and integrations securely. More specifically:

1. As the "stacking" of DeFi primitives (e.g. assets farmed in one protocol, locked in another, levered up in a third protocol to use as collateral in a fourth) grows more complex, the composite risk profile of those "stacked" DeFi assets also grows. Knowing exactly what the "combined catastrophic invariant failure" risk profile - deducible indirectly through Ante - helps cap or limit that risk.
   1. Imprecisely, at scale, Ante can be viewed as a "risk layer" that can *cast* certain types of DeFi Smart Contract idiosyncratic risk into risks that legacy financial institutions may more readily get.
   2. This in turn broadens the playing field for DeFi and potential energy for innovation.
2. Furthermore, innovative DeFi developers (and perhaps the Ante team) can build upon Ante to create more advanced composite assets (see our brief mention of [Smart Assets](/v0.5/about/future#smart-assets)) that are built upon programmatically managed "challenger" positions in a corresponding `AntePool` to automatically limit the financial downside in the case of a constituent component's invariant failure.
3. Finally, almost as a second-order effect, Ante can become a reasonable place for security experts or security-minded developers to devote marginal energy to reading and analyzing Ante Tests and the underlying protocols' code. A protocol that self-selects for using Ante is more likely to take security seriously, which in turn boosts the attractiveness of Ante as a destination for said marginal energy. This potential "virtuous loop" comes bundled with decentralized, non-custodial bounties to be claimed, and thus may even help persuade, at scale, marginal grey-hat talent to leverage their skills to increase overall DeFi ecosystem safety.

### What are examples of Ante Tests that a protocol might write?

We have prepared some fun mockup AnteTests as an example of what simple tests might look like:

* The total supply of WBTC is always less than or equal to 21 million.
* The Ethereum Foundation "EthDev" digital wallet does suddenly move or sell 99% of its ETH.
* The balance of ETH in the WETH9 contract actually matches the circulating WETH.

More serious examples of Ante Tests one may want to write include:

* For lending protocols: debt < collateral (for overcollateralized protocols) by the required amount;
* For automated market-makers, that their AMM invariant holds (e.g. x\*y=k);
* For protocols that mint token X after receiving Y and Z, that the balances of X correspond to Y and Z;
* Checking a particular entry\&exit into a L2 solution holds;
* Checking a deposit & withdraw combination of function calls still work;
* Monitoring the balance of a multisig wallet for an anon team for rugging (dumping their own token);&#x20;
* ...And many more!

### **What if another protocol later forks our Ante Tests?**

This isn't all bad!

Let's say you're Protocol A, and the forker is Protocol B, like in our [How Ante Differs](/v0.5/why-use-ante/how-ante-differs) example.

First, it means that if any of the invariants tested by Protocol A fails in Protocol B, then the Ante Test should capture that. However, it's certainly possible a dishonest team might try to use a known-to-fail Ante Test to capture well-intentioned staker funds. We feel this is like scammers creating token listings on a decentralized exchange that don't allow selling, or knowingly burn tokens when a user tries to send them.

Second, the forking team is behind and they now need to play catch-up. Protocol B's capital may be facing potential loss if its invariants aren't properly protected or if the code in Protocol B hasn't been updated as with Protocol A.

Finally, this means that at the very least -- even if we get a proliferation of endless forks -- if their corresponding Ante Tests get forked, too, we have improved baseline safety for checking protocol invariants in the DeFi ecosystem. And that's a good thing.

## Ante Concerns

### Can you steal my money?

Ante v0.5 has **no admin keys** and **no ability to recover funds sent to its smart contracts**. All of the funds deposited into `AntePools` created by users that are settled by user-generated Ante Tests are **non-custodial smart contracts**.&#x20;

Ante v0.5 also has **no proxy contracts** and **no upgradeable contracts**. There are **no owned contracts**, either.

We believe it is critical that the Ante codebase be easy to understand, transparently written, and optimized for clarity, security, and safety, over e.g. gas optimization.

### Can I lose money by using Ante?

**Absolutely, yes, if you put crypto into any Ante smart contract.**

1. For stakers: By staking in an Ante Pool, one is showing skin in the game that a particular protocol's **invariant** - checked by the corresponding Ante Test that's paired with the AntePool - will hold. If that invariant fails, then **all staker funds staked in that Ante Pool are locked and claimable by challengers. There is no dispute mechanism or dispute procedure.** The transaction is finalized in a non-custodial smart contract.
2. For challengers: the first block any challenger funds are used to challenge in an `AntePool`, the `AntePool` smart contract immediately begins calculating and charging a **decay fee** that is claimable by stakers. **This fee is irrecoverable and not disputable.** The transaction is finalized in a non-custodial smart contract.

{% hint style="warning" %}
**Note: do not under any circumstances send tokens or ETH directly to any Ante smart contracts. They are not designed to handle incoming funds that way. Only interact with Ante smart contracts using their intended functions.**
{% endhint %}

### How do I know Ante is secure?

The honest answer is **we don't.**&#x20;

**No smart contract system at launch can claim they know they are secure. In particular:**

1. Formal verification can prove that software matches a given spec.
   1. Formal verification can't guarantee a zero-day exploit doesn't exist.
   2. We hope that Ante becomes a sort of "**Financial Verification**" for the ecosystem that is faster, cheaper, and more accessible to anyone in the world who wants to build Smart Contract Systems.
2. Audits can secure a version of a smart contract codebase, but many exploited projects have had audits.
3. Bug bounties can help discover vulnerabilities, but they can take time to play out.

In our first release, Ante v0.5, we implement a few tactics to maximize security:

1. Eliminate any upgrade-ability in the code base. Every piece of Ante v0.5 is immutable.
2. Limit the code base complexity to only support the exact minimal features required.
3. Implement common best practices around overflow, underflow, re-entrancy, and more.
4. Cap the total capital deposits allowed (subject to a schedule for flexibility).
5. Audits and peer review of code.

In the future, we hope to also ideally get formal verification for critical pieces of v1, and maintain a non-upgradeable and minimal-governance approach, but we know that isn't sufficient to guarantee no flaws.

Please do not use Ante without first reviewing all of the code yourself. Ante is open-source software offered as-is on a best-efforts basis. **And never, ever, ever deposit in Ante, or any smart contract, more than you can afford to lose.** No part of this documentation or any Ante communication is intended as financial advice.

We believe it is really important for the world to accelerate the development of safer DeFi. We simply want to build infrastructure that can help make DeFi safer.

### What happens if there is a catastrophic failure in Ante's own code?

We cannot offer any guarantee this won't happen. We **hope** it never happens.

Please think of Ante v0.5 as an **alpha release** of software at best, or a "MVP" approach to building a DeFi project. We know that isn't a satisfying answer, but **please do not use Ante without reading the code**.

### Could a Scammer use Ante?

As with any open DeFi project: **anyone with any intention can use DeFi**. That's part of the power, but part of the danger, just like with the Internet.

**Please do not use any AntePool you haven't read carefully, and try to verify the address of the deployer.**

We can imagine it's possible for scammers to:

1. Create "fake" `AnteTests` that seem to check an invariant, but can be triggered to fail at any time.
   1. We recommend **carefully reading** the source code of any Ante Test you use the corresponding Ante Pool for, and checking the address of the author.
2. Create "honeypot" `AnteTests`that seem to perpetually be failing, but drain honest challengers of funds.
   1. We recommend **carefully reading** the source code of any Ante Test you use the corresponding Ante Pool for, and checking the address of the author.
3. Create fake `AntePool`s that actually lock or steal your funds.
   1. To avoid this, only use `AntePools` that have been generated by our `AntePoolFactory` -- checking a generation event should verify an `AntePool` is authentic.

We hope that the benefits to the DeFi ecosystem end up grossly outweighing the ways Ante can be abused.

### What are risks of using Ante?

As with any protocol, using Ante comes with inherent risks.  This is **not an exhaustive list**, and you should **never** interact with DeFi smart contracts you don't fully understand! &#x20;

Some risks of using Ante include, but are not limited to:

1. User Risks
   1. You may write an incorrect or flawed Ante Test, which fails after you deploy it, resulting in a loss of your staked capital (and other stakers' capital too).
   2. You may make mistakes or omissions when reviewing Ante Tests and deciding how to stake.  You might think that a flawed Ante Test is secure, or that a secure Ante Test is flawed, and stake on the wrong side versus if you had perfect information.
2. Operational Security Risks
   1. Using a personal address to write an `AnteTest` or deploy an `AntePool` may bring unwanted attention to your past on-chain activity or possibly reveal your identity.
   2. Participating in an Ante Tests as a staker or challenger may alert others of your address and may allow malicious third parties to identify you in the real world.
   3. Being the one to successfully verify an Ante Test as having an invariant failure may draw the ire of bad actors, and they may attempt to harass or doxx you if your address is linked to an off-chain identity or handle.
3. Ante Smart Contract Risks
   1. While Ante v0.5 is audited, it may still have software bugs. Although we \*have\* written many off-line tests ourselves around the logic and output of Ante, we make **NO GUARANTEES** about the codebase.
   2. A bug in our `AntePool` contract could mean that all `AntePools` are subject to unintended loss or locked funds.
   3. A bug in our `AntePoolFactory` could mean that malicious actors could trick people into using bad contracts as part of Ante.
   4. An exploit of our website could cause transaction requests to pop up that do not \*actually\* route your transactions to the Ante v0.5 Smart Contracts. **Make sure to check the addresses and function signatures of any transactions with what shows up on your wallet!**
4. General Ethereum and DeFi Risks
   1. Malicious actors could pretend to be Ante team members to steal your assets.
   2. Your computer or wallet may been compromised independently and only during a transaction broadcast to Ante is the exploit taken advantage of.
   3. The ability to claim rewards (as a challenger) or withdraw (as a staker or challenger) depends on having control of your Ethereum address at the time of claiming or withdrawing. If you don't have control of your address, you will not be able to take those actions.

## Ante v1 and Beyond

### How do you intend to grow Ante so it becomes widely adopted?

We need your help!&#x20;

We have been talking to many established and pre-launch teams to learn how to best serve their needs. Ante's design is based heavily on feedback from the community and we will continue to modify the protocol so it is as helpful to users as possible.  The information we've received has been invaluable and we are grateful to those who have helped us so far!

We are also exploring interactive community engagement initiatives that will give interested users a sneak peek into what Ante is all about.  There may be games and contests that are both fun and educational. &#x20;

Stay tuned!

Please join our community on [Twitter](https://twitter.com/AnteFinance) and [Discord](https://t.co/z9vxqMJ77w?amp=1) and share with us your thoughts on how we can improve Ante's user experience!

## Contact

Come find us on&#x20;

* [Twitter](https://twitter.com/AnteFinance) (@AnteFinance)
* [Discord](https://discord.gg/ante) (AnteFinance)
* Site: [www.ante.finance](https://www.ante.finance)


# Glossary

* **Ante**: Ante is the name of this protocol. It stands for "autonomous native testing environment."
* **Ante Pool**: An Ante Pool is a smart contract that allows for staking and challenging. Each Ante Pool points to a corresponding Ante Test on-chain.
* **Ante Pool Factory**: The Ante Pool Factory is a smart contract that programmatically generates (deploys) Ante Pools on-chain. The "automated" deployment of Ante Pools means that it's less likely any individual Ante Pool has a bug or flaw, which is important because there may be assets staked or challenged in the Ante Pool.
* **Ante Test:** A smart contract that checks an invariant of an external protocol. Ante Tests are the building block of Ante, and each protocol that uses Ante needs to get an Ante Test written for their smart contracts. Note Ante Tests must conform to the `IAnteTest.sol` interface in order to be compatible with Ante.
* **Challenger**: The participant in the Ante system that puts crypto into the Ante Pool opposite of stakers. Challenger stakes slowly pay **decay rewards** to stakers over time.
* **Decay Rewards:** All challenger positions are drained of a slight amount of ETH each block, approximately 100 GWEI (100 \* 1e9 WEI, or 100 \* 1e-9 ETH) per block. This approximately comes out to be around 20% a year, assuming roughly 6000 blocks per day.
* **EVM**: The Ethereum Virtual Machine, or the "distributed computer" that Ethereum smart contracts run on top of.
* **Gas**: Computations on the EVM cost gas, determined by their computational complexity. All transactions that write to the EVM state need some gas cost and the initiator of such a transaction typically pays for the Gas in ETH.
* **Guarantee:** See invariant.
* **Invariant**: also referred to as a **protocol invariant** or, more simply, a "guarantee." An Invariant for an external protocol is a property that should always hold. For example, in Uniswap, it could be that x\*y=k (the product of the token balances should increase, modulo withdrawals), and for a lending protocol, like Compound, it could be that the debt outstanding is less than or equal to the total collateral.
* **On-Chain:** Referring to a smart contract that runs computations on the blockchain, rather than "off-chain" or on a local computing environment.&#x20;
* **Verifier**: In Ante, the verifier is a challenger (who has been challenging for the minimum time required to be a verifier, 12 blocks as of this writing), who then tries to call `checkTestPasses()` on a particular Ante Test from the corresponding Ante Pool. A successful verifier will be able to claim an additional **bounty** on top of the rewards they receive from forfeited stakes from stakers.
* **Verify**: The action of checking, from an Ante Pool, if its corresponding Ante Test is still **passing**. (An Ante Test no longer passing indicates that a catastrophic failure has occurred.)
* **Smart Contract**: A software program written to run on a blockchain; in our case we refer to Ethereum smart contracts running on the EVM.
* **Staker**: A participant in an Ante Pool that is effectively deploying crypto to "back" or "support" the outcome that its corresponding Ante Test never fails. Stakers earn decay rewards taken non-custodially from the challengers in a particular Ante Pool, but in the case the corresponding Ante Test fails, forfeit all of their stake.


# Security

{% hint style="info" %}
Previously undiscovered bugs can be submitted to [security@ante.finance](mailto:security@ante.finance?subject=Responsible%20Bug%20Disclosure) for a guaranteed response from the team. Ante will follow up within 48 hours to acknowledge the disclosure and discuss next steps. Eligibility for existing bug bounty programs (e.g. [Immunefi](https://www.immunefi.com/bounty/antefinance)) will not be voided by communicating with [security@ante.finance](mailto:security@ante.finance?subject=Responsible%20Bug%20Disclosure).
{% endhint %}

### Introduction

We believe it is really important for the world to accelerate the development of safer DeFi — that's why we built Ante, and that's why the security of the Ante protocol is our top priority by far. Our [core smart contract code](https://github.com/antefinance/ante-v0-core) is publicly verifiable, has undergone multiple audits, and we have a bug bounty for undiscovered vulnerabilities.

We believe it is critical that the Ante codebase be easy to understand, transparently written, and optimized for clarity, security, and safetyover e.g. gas optimization. In Ante v0.5, we implement a few tactics to maximize security:

1. Ante v0.5 has **no proxy contracts** and **no upgradeable contracts**. There are **no owned contracts**, either. Every piece of Ante v0.5 is immutable.&#x20;
2. Limit the code base complexity to only support the exact minimal features required.
3. Implement common best practices around overflow, underflow, reentrancy, and more.
4. Cap the total deposits allowed per user in each Ante Pool (subject to a schedule for flexibility).
5. Audits and peer review of code.

Ante v0.5 is intended as an **alpha release**. Please do not use Ante without first reviewing all of the code yourself. And **never deposit more than you can afford to lose in Ante or any smart contract**.

### Audits

Ante v0.5 contracts have been audited. Minor smart contract updates were made as a result of the audits and are incorporated into the core Ante contracts on all non-Ethereum networks Ante is deployed on.

**May 2022 - Zellic** ([walkthrough](https://medium.com/ante-finance/ante-v0-5-zellic-audit-walkthrough-859dc9c74a47); [report](https://github.com/antefinance/ante-v0-core/blob/v0.5/audit/2022-05-22%20Ante%20v0.5%20Zellic%20Audit%20Report.pdf))

### Bug Bounty

While we have taken significant steps to minimize the risk surface area of the Ante protocol, undiscovered vulnerabilities may still exist. Ante encourages the community to audit our [contracts](https://github.com/antefinance/ante-v0-core) and responsibly disclose any discovered vulnerabilities to the team so we can address it as quickly as possible.

#### Responsible Disclosure

Previously undiscovered vulnerabilities can be submitted (including conditions/steps to reproduce the vulnerability) through our [Immunefi bug bounty program](https://immunefi.com/bounty/antefinance/) and/or to [security@ante.finance](mailto:security@ante.finance?subject=Responsible%20Bug%20Disclosure) for priority escalation. Ante will follow up within 48 hours to acknowledge the disclosure and discuss next steps.

Any vulnerabilities should not be disclosed publicly or to other parties until the Ante team has had a chance to triage and address the vulnerability. All testing or proof of concepts should be done on private testnets, and must not have already been exploited for damage.

We are happy to publicly credit you for your discovery (unless you prefer otherwise), and eligibility for existing bug bounty programs (e.g. Immunefi) will not (subject to our discretion) be voided by communicating with [security@ante.finance](mailto:security@ante.finance?subject=Responsible%20Bug%20Disclosure).

#### Known Issues

The following vulnerabilities are known and not eligible for a reward:

* Challenger decay calculation is inaccurate and slightly overestimates the decay paid by challengers (overall error is < 1%/year even in the worst case scenario). Calculation is more accurate the more often `updateDecay()` is called
* Staker and challenger balances are slightly underestimated due to rounding issues in intermediate calculations, overall loss is small relative to total pool balance flux (< 0.1%)
* Test verification can be frontrun by challengers who stake small amounts of ether in every pool
* `checkTest` gas usage can be unbounded as it scales linearly with number of unique challengers
* Any exploits related to malicious actors cloning and redeploying our contracts (i.e., deploying their own version of AntePoolFactory or deploying AntePools without the use of our AntePoolFactory contract)
* Any exploits related to using malicious AnteTests to steal/lock user funds
* Any exploits already covered in audit reports for Ante

### Future steps

In the future, we hope to also get a software audit and formal verification for critical pieces of v1, and maintain a non-upgradeable and minimal-governance approach to developing the Ante protocol.


# Possible Future Work

Potential community initiatives for AnteV1 and beyond.

The below are examples of work that we hope our community may explore in the future:&#x20;

## Additional Collateral Support

We imagine common ERC20s make sense to consider as valid collateral for staking and challenging.

## Community-Generated Test Lists

We imagine that due to the permissionless open nature of the `AntePoolFactory`, ill-intentioned participants may create `AntePool` instances that point to an intentionally faulty Ante Test.

Thus, we believe it is important to introduce some variant of a "Blue Check" or a "Curated List" of Ante Tests that are known to be well-intentioned (or written by accountable authors). The initial versions of these curated test lists may be community-generated or involve community voting.

## ZK Proof-of-Exploit

We think it may be tractable to introduce future Ante Tests that offer `checkAndFreeze(zkp)` functionality. Specifically, we imagine challengers passing in a zero knowledge proof-of-specific-exploit (a generalized exploit-prover is out of scope of Ante, but specific invariant failures, like "x can be made < y" may be tractable), which then freezes an Ante Template.

(An Ante Template would be a smart contract framework new teams could build off of where, if a `checkAndFreeze()` returns `True` in a linked Ante Test, all functionality except for `emergencyWithdraw()` is locked.)

#### Design Sketch

As of May 2021, we don't think full generalized zero-knowledge proof-of-exploit *generation* is computationally tractable on the EVM, but in principle the following design could work:

1. Create a function which checks whether an invariant holds
2. Generate a Zero-Knowledge Proof (ZKP) for the statement "I know a valid transaction which, when applied, causes the invariant check to return `False`"
3. The exact definitions of "know a valid transaction" and "when applied" depend on how much on-/off- chain introspection can be supported.
   1. If there were no compute constraints, one could have the verifier check that you submitted a valid EVM tx
   2. However, the actual design will have to make numerous tradeoffs to minimize the verification cost.
   3. Alternatively, a combination with trusted Ante Arbiters could make this approach more practical.

#### Feasibility&#x20;

The key question for the design sketch is what ZKP is verified on-chain, since off-chain proof generation can be scaled.&#x20;

One concern could be that the verifier might need to change depending on the contract state, but that isn't necessarily the case, and depends on specific implementation details of the contract. Our proposal is not that different from a ZK-rollup design, where users submit transactions to the rollup validators, who generate validity proofs, which then go on-chain.

The key difference is be that in, Ante the transactions are "hypothetical," and hence don't actually modify the state. That said, it's a bold claim for the Ante Team to say this design will plug into the existing Ethereum Smart Contracts seamlessly, and there will undoubtedly be many subsequent details to has out, but we believe the design works in principle.

## Web3 Extensibility

Ante intends to eventually extend support far beyond Ethereum and DeFi as core applications. Ante is a blockchain-agnostic protocol, and can support any generalized invariant in any Smart Contract system.

Note that certain design parameters (e.g. 6-block wait time for challengers to verify Ante Tests to prevent frontrunning) may need readjusting, as the threshold for submarine sends can vary depending on a chain's finality constraints.

## Arbiters

Arbiters are on- and off-chain partially centralized "bridges" that act as a "specialized information oracle." An example could be detecting if a certain hash has been uploaded to a website, uploading a binding opinion on a specific definition of an exploit, or referencing broader events.

The advantage of an Ante Arbiter over e.g. a ChainLink oracle is that each Ante Arbiter could be a stand-alone entity that could be held accountable off-chain, a feature (not a bug!) for certain institutional participants and eventual legacy finance participants in DeFi.

## Smart Assets

Smart Assets are a term Ante uses to refer to algorithmic digital assets that have been secured with Smart Tests. A simple example could include cDai wrapped with a corresponding continuous challenger stake in an AnteCompoundDai AntePool position. Ante believes that creating and popularizing Smart Assets will be one of many steps in bridging the worlds of DeFi and legacy finance.


# Changelog

## v0.5.1 (Ante v0.5 Release 1) - 2021-05-27

### Added

* AntePools

### Fixed

* AntePool decay calculation

### Changed

* AntePool decay accumulation

##


# Terms of Service

[Ante Finance Terms of Service](https://www.ante.finance/tos)


