# Connections research — September 16, 2026

## Firefly identification

The exact builder code is `0xe67c1c7965bf637b6c176c6204384f207aad5c7a46ccfd889fe1e8d9e2c22f77`.

Source: https://data-api.polymarket.com/v1/builders/leaderboard?timePeriod=ALL&limit=50&offset=0

The directory was paginated in steps of 50: 543 entries on 11 pages. The row names Firefly and marks it verified. Its builderLogo filename contains `profile-image-4090895-`. The public-profile endpoint for `0xd3ea7e24ac69ab4e85db00fb248d21021af0ee97` returns the profile name Firefly-EverythingApp, user ID 4090895 and xUsername thefireflyapp. The common user ID supports the join between the builder row and payment profile. The two image URLs themselves differ.

Source: https://gamma-api.polymarket.com/public-profile?address=0xd3ea7e24ac69ab4e85db00fb248d21021af0ee97

The older 40-account sample includes 39 farm-sample wallets and ghost. Its archived maker tally has 19,959 / 26,704 Firefly-code fills for those 39 wallets and 18 / 18 for ghost. Those bulk totals are historical. This run rechecks each of the 39 farm example transactions and all 18 archived ghost logs. Each check requires a successful receipt, an allowlisted V2 exchange, the exact OrderFilled event signature, the sampled address in the indexed maker field and the exact builder value in data word 5. A wallet merely appearing as taker does not qualify. Duplicate transaction/log pairs are removed. Result: 57 verified logs across 40 distinct wallets.

Event definition: https://github.com/Polymarket/ctf-exchange-v2/blob/main/src/exchange/interfaces/ITrading.sol

Attribution documentation: https://docs.polymarket.com/trading/orders/attribution

The builder field establishes order attribution to an integration. Wallet ownership is a separate onchain query. The September identification supersedes the archived interpretation that the code represented private, in-house software.

## Payments and treasury balances

All nine cited transfer legs were checked against raw Polygon receipts fetched through https://polygon.gateway.tenderly.co using eth_getTransactionReceipt. Each requires success status, exact token contract, Transfer topic, sender, recipient, integer log index and six-decimal amount. For the seven direct transfers, eth_getTransactionByHash also confirms the signer, target token contract, transfer(address,uint256) selector and both calldata arguments. The two Firefly payment legs belong to ClipperPayout batches signed by the documented operator.

An explorer displayed an unrelated method name for PUSD transfers because of a selector-label collision. No finding relies on that label; raw calldata and token events establish the transfers.

Historical balanceOf reads use the PUSD contract at blocks 93527617, 93527618, 93527669 and 93527670. Block headers supply timestamps. These are end-of-block balances. Receipts establish the individual 75,000 deposit and 47,006 payment. The two transaction blocks are 78 seconds apart. The pre-deposit treasury balance is 3,937.141718 PUSD.

The machine treasury's January 10 transfer of 100,000 USDC.e to the common sender is included. Amounts are never netted across USDC.e, native USDC and PUSD.

## Funding-wallet census and collection scope

The trace of `0x2d507657ca4ebcc8f9a38f6764c07310b66dea54` reached the January 1, 2026 boundary: 1,959 explorer records. The token allowlist retains 1,736 transfers. `upstream_transfers.csv` and `upstream_counterparties.csv` use explorer records for the full census; `connection_transfers.csv` identifies the nine individually receipt-verified legs. Census rows are not all independently receipt-verified.

Across 47 traced wallets, 40 histories reached their requested boundary and seven hit the page budget. Start dates and completion status are in connection_coverage.csv. The private-only subjects established by this project's prior publication rules remain excluded from discovery and exports.

## Wallet control

At Polygon block 93916082, read bytecode, owner(), getOwners() and getThreshold() for 1,157 candidate wallets. Classify EOAs, EIP-7702 accounts, Safe wallets, contracts with an owner getter and contracts with unresolved control. A revert means the queried getter is unavailable. Transport and rate-limit errors fail collection; they never become an empty owner.

Two shared-controller groups were returned. The underlying contracts are Polymarket infrastructure and Stargate infrastructure. Common infrastructure control is not counted as a shared customer controller. No new shared customer controller was established by this sweep. Legacy proxy wallets whose owner getter is absent remain unresolved.

## Reproduction

```bash
python3 -m research.connections owners
python3 -m research.connections trace
python3 -m research.connection_evidence
python3 build_site.py
python3 -m unittest discover -s tests -v
python3 validate_evidence.py
python3 browser_check.py
```

Collection uses cached dated responses, explicit page boundaries and raw RPC captures. The funding-wallet history was extended to a 100-page cap, reaching its January boundary after 1,959 records. User1244322 was extended to 5,000 records and remains incomplete. Public receipt excerpts include only cited logs; fetch the full receipts by transaction hash to reproduce the checks. The download manifest records SHA-256 hashes of all public artifacts.
