Summary
The repository records do not match the mainnet deployment, and interfold config check warns mainnet operators without cause.
Evidence (checked 2026-09-25)
getCiphertextVerifier(keccak256("fhe.rs:BFV")) on mainnet Interfold returns 0x80D217d3b2e16fF2ecc178cC75655C773895c549, a Risc0BfvCiphertextVerifier with imageId() 0x9d3e21fd7cc08e629cb467e5ca6bfc8e1a645b483bfd91b6b1648ced259110fc. CiphertextVerifierSet history: the mock 0xB568…9297 at block 25,788,974, 0x40a1…ff2c at 25,813,839, and 0x80D2…c549 at 26,004,622.
getDecryptionVerifier and getPkVerifier return the routers 0xA66C…eEa7 and 0x7CD1…63d1. Their routes point to real BfvDecryptionVerifier and BfvPkVerifier contracts (bytecode matched against the artifacts).
mainnet-protocol.deployment.json still lists the mock ciphertext verifier and the first decryption and pk verifiers. No file in the repo records 0x80D2…c549, its image ID, or the routers. 0x40a1…ff2c appears only in examples/CRISP/.../deployed_contracts.json.
deployments/manifest.json sets mocks: true for mainnet, because deployed_contracts.json lists MockE3Program (genManifest.ts:95-100). On-chain, e3Programs(MockE3Program) is false and CRISPProgram is enabled.
crates/cli/src/config.rs:141-146 prints mainnet is a mock deployment - proofs are accepted without being verified for that flag.
Suggested direction
Record the live verifiers and the image ID, regenerate the manifest, and base mocks on the enabled programs and the live verifiers.
Summary
The repository records do not match the mainnet deployment, and
interfold config checkwarns mainnet operators without cause.Evidence (checked 2026-09-25)
getCiphertextVerifier(keccak256("fhe.rs:BFV"))on mainnetInterfoldreturns0x80D217d3b2e16fF2ecc178cC75655C773895c549, aRisc0BfvCiphertextVerifierwithimageId()0x9d3e21fd7cc08e629cb467e5ca6bfc8e1a645b483bfd91b6b1648ced259110fc.CiphertextVerifierSethistory: the mock0xB568…9297at block 25,788,974,0x40a1…ff2cat 25,813,839, and0x80D2…c549at 26,004,622.getDecryptionVerifierandgetPkVerifierreturn the routers0xA66C…eEa7and0x7CD1…63d1. Their routes point to realBfvDecryptionVerifierandBfvPkVerifiercontracts (bytecode matched against the artifacts).mainnet-protocol.deployment.jsonstill lists the mock ciphertext verifier and the first decryption and pk verifiers. No file in the repo records0x80D2…c549, its image ID, or the routers.0x40a1…ff2cappears only inexamples/CRISP/.../deployed_contracts.json.deployments/manifest.jsonsetsmocks: truefor mainnet, becausedeployed_contracts.jsonlistsMockE3Program(genManifest.ts:95-100). On-chain,e3Programs(MockE3Program)isfalseandCRISPProgramis enabled.crates/cli/src/config.rs:141-146printsmainnet is a mock deployment - proofs are accepted without being verifiedfor that flag.Suggested direction
Record the live verifiers and the image ID, regenerate the manifest, and base
mockson the enabled programs and the live verifiers.