# Reverse-engineering the payout engine

Source capture: September 16, 2026. Run `python3 -m research.engine` to reproduce the checks from the saved explorer histories and public RPC. The query URLs and complete-feed states appear in engine_coverage.json. RPC responses retain request parameters, capture timestamps and raw results in the research archive.

## Contract identity and permissions

Live `eth_getCode` at a pinned block must exactly match Blockscout's verified deployed bytecode for ClipperPayout and canonical Disperse. Remove only the Solidity metadata suffix whose byte length is encoded in the final two bytes. The remaining 1,737 bytes are identical. SHA-256: 40ec33a9232e24fd3d1ed26951b077a60253796ebc6dc110b264a9968a52b139.

Disassembly skips PUSH operands before counting opcodes. There are no SLOAD, SSTORE or DELEGATECALL opcodes in the executable runtime. The ABI contains disperseEther, disperseToken and disperseTokenSimple. Source and runtime establish an open dispatcher without an owner, stored roster, scheduler or upgrade method. The direct-token method draws funds from its caller, not from an independently selected donor. Canonical Disperse has the same executable behavior. The CREATE2 trace distinguishes the deployment submitter from the shared factory and the eventual payment accounts.

## Batch census

Four previously documented payment accounts are selected: original USDT0 operator 0x3986…a3f84, builder-payment account 0xc012…59efe, native-USDC operator 0x04ce…92752, and funding wallet 0x6aee…86b34f. This is not a census of every public contract user.

Use complete histories of the four exact Polygon stablecoin contracts. Funding transfers of at least one token into either dispatcher select candidate disperseToken calls. The method selector, token argument, both array offsets, both array lengths, every recipient, every amount, and the total are decoded. The output multiset must equal the successful receipt's outgoing transfers for that contract and token. The caller's incoming funding transfer must match the total. Both direct execution and successful traced delegated execution are supported. Simple-method payouts, direct account transfers, native-currency dispersals and unrelated callers are outside this batch census.

All 154 selected batches reconcile. They contain 24,271 payment entries; 24,268 are in the public CSV, with three established private-scope recipient legs removed from public extracts. Aggregate batch totals use the complete receipts. No excluded address or calldata containing it is exported. Duplicate token logs are deduplicated by transaction and log index.

The 36 builder-account batches consist of seven canonical Disperse batches and 29 ClipperPayout batches. Seven ClipperPayout calls appear inside relayed DelegationManager transactions rather than as direct outer transactions from the account. Call traces establish account → dispatcher. The gas-paying submitter is recorded separately. These public relayers are not assigned ownership of the payment account.

## Funding and accounting

Funding edges use exact token contracts and verified raw Transfer logs. Each preserves its denomination and date range. USDT0 is the current display label for the Polygon contract historically labeled USDT. USDC.e, native USDC and PUSD are not combined into a dollar total.

The original operator's Safe received 446,001 USDT0 gross from owner 0x8037…1ca8a in three transactions on June 5, 2024 and returned one token during that sequence, for 446,000 net. That owner had received 446,000 USDT0 in two transfers from 0x241e…3b5fb on May 31. The Safe paid the operator 321,000.002 USDT0 in 18 transactions through August 31, 2026. Its wider withdrawals and the operator's direct payments are separate from its batch subtotal.

The shared upstream 0x2d50…dea54 paid funding wallet 0x6aee…86b34f 2,100,001 USDC.e and native-USDC wallet 0xb5e4…fc24e 36,000,300 USDC. These totals are gross edges across different periods, not an attribution of every upstream token to downstream payees. The reverse native-USDC edge is separately retained. The latter wallet paid 0x04ce…92752 800,010 USDC. The funding wallet paid that operator another 49,998.071592 USDC. Builder-account funding from 0x6aee…86b34f totals 299,999 USDC.e and, separately, 190,010.193344 PUSD; funding from 0x8669…cece01 totals 190,377.097376 USDC.e. Other funding sources exist outside the selected edge diagram.

For September 15, historical balanceOf reads confirm the builder account had 0.004852 PUSD before the 100,000-PUSD top-up, then swapped its 100,000.004852-PUSD balance to exactly 100,000.004852 USDC.e. Its USDC.e balance increased from 5,077.673344 to 105,077.678196. The two later payouts total 49,999.85 USDC.e. This establishes funding, conversion and payout chronology without assigning a FIFO provenance to a mixed USDC.e balance. PolygonSettler contracts execute swaps and are not labeled as the economic funder.

## Safe authorization checks

For every Safe → original-operator transaction, locate the Safe's successful execTransaction call, including nested calls through submitter services. Read getOwners() and getThreshold() at the previous block. Extract the Safe ExecutionSuccess digest and the signature byte array. For normal EIP-712 signatures, recover the signer with the ecrecover precompile and require that it was an owner. For v=1 approval entries, require that the encoded owner was the caller of the Safe, or had a stored approvedHashes entry; all four observed entries use the caller rule. The first funding transaction used threshold one, while the later seventeen used two. There are 31 recovered EIP-712 signatures and four valid caller approvals.

Owner 0x8037…1ca8a appears in 15 authorizations, 0x0e1b…ec2b in 11, and 0x1c26…92aa0 in nine. These are approving addresses, not 35 separate transactions or named people. The August 31, 2026 transfer was approved by 0x1c26…92aa0 and 0x8037…1ca8a. Current Safe configuration is two of three.

## Public identity and interpretation

Official Polymarket profile lookup maps funding wallet 0x6aee…86b34f to kjlkjlkjlkj. Its DepositWallet owner() read independently returns 0x6aee…86b34f. The treasury lookup returns tommytest. The builder-account query returns a default address-based profile name. Those metadata associations do not provide a verified real-name or X identity. Public ENS resolution checks of the principal operators and Safe keys returned no names.

The verified result identifies funding accounts, approval keys and payout execution. The four callers are not attributed to one person. The already-published builder directory crosswalk provides program context for recent builder-account payments. Shared contract code, factories, exchanges, swap settlement contracts, gas relayers and shared smart-account implementations are not ownership evidence.
